Snyte AI Platform Privacy Policy
Effective Date: May 10, 2026
Last Updated: May 10, 2026
1. Introduction
Snyte, Inc. ("Snyte," "we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Snyte AI business intelligence platform (the "Service").
This policy applies to all users of our Service, including enterprise customers, individual users, and visitors to our website.
2. Information We Collect
2.1 Personal Information You Provide
- Account Information: Name, email address, phone number, company name, job title
- Authentication Data: Username, password (encrypted), two-factor authentication information
- Profile Information: User preferences, profile picture, organizational settings
- Communication Data: Messages, support tickets, feedback, and correspondence with us
2.2 Information Automatically Collected
- Technical Information: IP address, browser type, device information, operating system
- Usage Data: Pages viewed, features used, time spent, click patterns, navigation paths
- Log Data: Server logs, error reports, performance metrics, API calls
- Cookie Data: Session identifiers, preferences, authentication tokens
2.3 Business Intelligence Data
- Connected Data Sources: Database connections, API integrations, file uploads
- Query Data: SQL queries, search terms, filter preferences, report configurations
- Generated Content: Dashboards, reports, visualizations, AI-generated insights
- Collaboration Data: Shared reports, comments, team interactions
2.4 Information from Third Parties
- Single Sign-On (SSO): Profile information from identity providers, brokered through WorkOS (supporting enterprise providers such as Okta and Azure AD)
- Data Integrations: Metadata from connected business systems (CRM, ERP, databases)
- Payment Processors: Billing information processed by third-party payment services
3. How We Use Your Information
3.1 Primary Purposes
- Service Delivery: Provide, operate, and maintain the Snyte AI platform
- Authentication: Verify user identity and manage account access
- Data Processing: Generate insights, reports, and AI-powered business intelligence
- Personalization: Customize user experience and recommend relevant features
3.2 Communication Purposes
- Service Communications: Send system notifications, security alerts, updates
- Support: Respond to inquiries, troubleshoot issues, provide technical assistance
- Marketing: Send promotional materials, product updates (with consent)
- Legal Compliance: Fulfill legal obligations and enforce our terms
3.3 Analytics and Improvement
- Usage Analytics: Understand how users interact with our platform
- Performance Monitoring: Monitor system performance and identify issues
- Product Development: Improve existing features and develop new capabilities
- Security: Detect and prevent fraud, abuse, and security threats
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), our legal basis for processing personal information includes:
- Contract Performance: Processing necessary to provide services under our agreement
- Legitimate Interests: Improving our services, security, and business operations
- Legal Compliance: Meeting regulatory requirements and legal obligations
- Consent: Where explicitly obtained for marketing or optional features
5. Information Sharing and Disclosure
5.1 We Do Not Sell Personal Information
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5.2 Authorized Disclosures
We may share information in the following circumstances:
Service Providers
- Cloud Infrastructure: Hosting appropriate to the selected deployment model; self-hosted deployments keep data in customer infrastructure
- Authentication Services: WorkOS for identity and SSO management
- Payment Processing: Stripe for billing and subscription management
- AI Model Providers: OpenAI and Anthropic for natural-language features
The current subprocessor list is maintained at https://snyte.ai/subprocessors.
Legal Requirements
- Legal Process: Court orders, subpoenas, or legal investigations
- Safety: Protecting rights, property, or safety of users or the public
- Compliance: Meeting regulatory requirements or law enforcement requests
Business Transfers
- Mergers/Acquisitions: In connection with business transactions
- Due Diligence: During evaluation of potential business arrangements
5.3 Data Minimization
We limit data sharing to what is necessary for the specified purpose and require confidentiality agreements from service providers.
6. Data Security
6.1 Technical Safeguards
- Encryption: AES-256 encryption for data at rest and TLS 1.3 for data in transit
- Access Controls: Role-based access control (RBAC) and multi-factor authentication
- Network Security: VPC isolation, firewalls, and intrusion detection systems
- Monitoring: Continuous security monitoring and automated threat detection
6.2 Organizational Safeguards
- Security Training: Regular security awareness training for all employees
- Access Management: Principle of least privilege for internal access
- Incident Response: Comprehensive security incident response procedures
- Compliance: Controls aligned with SOC 2 Type II (certification in progress) and ISO 27001 (on the roadmap); Snyte holds no security certifications today
6.3 Enterprise Features
- Single Sign-On (SSO): Integration with enterprise identity providers
- IP Whitelisting: Restrict access to specified IP addresses
- Audit Logging: Comprehensive audit trails for all user activities
- Data Residency: Options for regional data storage requirements
7. Data Retention
7.1 Retention Periods
- Account Data: Retained while account is active plus 90 days after closure
- Usage Data: Anonymized after 24 months, aggregated data retained indefinitely
- Security Logs: Retained for 7 years for security and compliance purposes
- Support Data: Retained for 3 years after issue resolution
7.2 Deletion Procedures
- User-Initiated: Users can delete their accounts and associated data
- Automated: Automated deletion of expired data according to retention schedules
- Secure Disposal: Secure deletion procedures for all storage media
8. Your Privacy Rights
8.1 Rights for All Users
- Access: Request information about data we collect and process
- Correction: Update or correct inaccurate personal information
- Deletion: Request deletion of your personal information (with limitations)
- Data Portability: Export your data in a machine-readable format
8.2 Additional Rights (GDPR/CCPA)
- Opt-Out: Object to processing for marketing purposes
- Restriction: Limit how we process your information
- Portability: Transfer data to another service provider
- Automated Decision-Making: Opt-out of automated profiling
8.3 Exercising Your Rights
To exercise your privacy rights, contact us at:
- Email: privacy@snyte.ai
- Portal: Account Settings, then Privacy Controls, in the Snyte application
- Mail: Snyte Privacy Team; postal address provided on request via privacy@snyte.ai
Response time: We will respond within 30 days (GDPR) or 45 days (CCPA).
9. Cookies and Tracking Technologies
9.1 Types of Cookies
- Essential: Required for basic platform functionality
- Performance: Analytics and performance monitoring
- Functional: User preferences and personalization
- Marketing: Promotional content and advertising (with consent)
9.2 Cookie Management
Users can control cookies through:
- Browser Settings: Disable or limit cookies in browser preferences
- Cookie Banner: Manage preferences through our consent management platform
- Account Settings: Control optional tracking in user dashboard
9.3 Third-Party Tracking
We do not currently load third-party analytics or tracking tools. Only
essential cookies required for authentication and platform functionality are
set by default. If we introduce third-party analytics, we will update this
policy and the cookie consent banner before any such tool loads.
10. International Data Transfers
10.1 Data Processing Locations
- Managed deployments: Primary processing in United States regions, with European Union regions available for EU customers
- Self-hosted deployments: Data remains in the infrastructure and regions the customer operates
- Backup: Encrypted backups in the same region group as primary processing
10.2 Transfer Safeguards
- Standard Contractual Clauses (SCCs): For transfers to countries without adequacy decisions
- Binding Corporate Rules: Internal data transfer policies
- Data Processing Agreements: Contractual protections with processors
10.3 Data Residency Options
Enterprise customers can choose data residency preferences:
- US Only: Data stored exclusively in US regions
- EU Only: Data stored exclusively in EU regions
- Multi-Region: Data replicated across regions for performance
11. Children's Privacy
The Snyte platform is designed for business use and is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information.
12. California Privacy Rights (CCPA)
12.1 Information Categories
We collect the following categories of personal information:
- Identifiers: Name, email, IP address, unique identifiers
- Professional Information: Job title, company, work contact information
- Commercial Information: Subscription details, usage patterns
- Internet Activity: Browsing behavior, search history, interactions
12.2 Business Purposes
We use personal information for:
- Service Operations: Platform functionality and support
- Security: Fraud prevention and system security
- Analytics: Service improvement and development
- Communications: Customer support and notifications
12.3 CCPA Rights
California residents have the right to:
- Know: What personal information we collect and how it's used
- Delete: Request deletion of personal information
- Opt-Out: Opt-out of sale (we do not sell personal information)
- Non-Discrimination: Equal service regardless of privacy choices
13. Changes to This Privacy Policy
13.1 Policy Updates
We may update this Privacy Policy to reflect:
- Legal Changes: New privacy regulations or legal requirements
- Service Changes: New features or changes to our platform
- Business Changes: Corporate restructuring or acquisitions
13.2 Notification Process
For material changes, we will:
- Email Notice: Send notification to registered users
- Platform Notice: Display prominent notice in the application
- Website Update: Post updated policy on our website
- Advance Notice: Provide 30 days advance notice for significant changes
13.3 Continued Use
Continued use of the Service after changes indicates acceptance of the updated Privacy Policy.
14. Contact Information
Privacy Officer
Email: privacy@snyte.ai
Mail: Snyte Privacy Team; postal address provided on request via privacy@snyte.ai
Data Protection Officer
Email: dpo@snyte.ai
Snyte has not yet appointed an EU representative under GDPR Article 27.
Inquiries from EU data subjects are handled through dpo@snyte.ai.
Response Times
- General Inquiries: 5 business days
- Privacy Rights Requests: 30 days (GDPR) / 45 days (CCPA)
- Security Incidents: 24 hours
- Breach Notifications: 72 hours (where required)
15. Supervisory Authorities
EU users have the right to lodge a complaint with their local supervisory authority:
- List: EU Data Protection Authorities
- Process: Contact your local authority for guidance on filing complaints
- Alternative: Try to resolve issues with us first through privacy@snyte.ai
Document Control:
- Version: 1.0
- Classification: Public
- Owner: Legal and Privacy Team
- Review Cycle: Annual
- Next Review: May 10, 2027