1. Controller
Syvorex
Austria
Email: support@syvorex.com
Website: https://syvorex.com
Updated: 13 August 2026
Information about how Syvorex processes personal data, account data, AI inputs and connected publishing providers.
This legal page is currently available in English. A reviewed translation for the selected language is not available yet.
Syvorex
Austria
Email: support@syvorex.com
Website: https://syvorex.com
We process personal data to provide the website, user accounts, workspaces, AI functions, publishing integrations, support and billing. Depending on the processing, the legal basis may be contract or pre-contractual steps (Article 6(1)(b) GDPR), a legal obligation (point (c)), legitimate interests in secure and reliable operation (point (f)), or consent (point (a)).
The final legal allocation, including balancing tests for logs, platform roles and international transfers, remains subject to legal review.
Depending on your use of Syvorex, we may process the following categories of data:
Supabase processes the email address, user ID and authentication data for authentication. Syvorex does not store a readable or reversibly retrievable password. Plan, account status, workspace membership and permissions are managed server-authoritatively.
Company/Brand Knowledge, campaigns, AI inputs/outputs, Creative Assets, publishing data and available analytics are processed within the workspace. Technical controls include server-side authorisation, Row Level Security and tenant isolation.
When AI functions are used, data may be transferred to the selected AI provider. Scope, processing location, retention and further processing depend on the provider, product/API and selected configuration. A catalog entry does not mean that the provider is active for every workspace.
Managed AI uses provider access supplied by Syvorex. Bring Your Own Key (BYOK) uses the encrypted credential saved by the user; BYOK does not prevent the necessary transfer to the selected provider. Syvorex documents technically executable providers. Further contractual and privacy review of individual providers is part of the ongoing compliance process; no blanket guarantee is made about region, training or retention.
Payments are processed by Stripe Payments Europe Ltd. Stripe processes payment data independently.
More information: https://stripe.com/privacy
We use Supabase for user management, authentication and account-related storage.
More information: https://supabase.com/privacy
Syvorex is hosted on Vercel. Domain and security services may be provided by Cloudflare. Technical access data can be processed when visiting the website.
Syvorex uses technically necessary cookies and browser storage for language, login, security, session management and account functionality.
Google AdSense and advertising consent are managed on approved editorial pages through the published Google CMP for European regulations. The AdSense script is not loaded on login, registration, redirect, utility, review or other pages without approved editorial main content. On approved content pages Google may present the CMP and serve ads according to the consent status recorded there. The separate Syvorex setting in the footer controls Google Analytics only; Analytics is loaded only after explicit consent. Both choices can be changed at any time through their respective settings. The legal basis for these optional services is Article 6(1)(a) GDPR together with section 165(3) Austrian Telecommunications Act 2021. More information: https://policies.google.com/privacy
Users may voluntarily connect only their own accounts or organisation accounts they are authorised to manage. OAuth connections exist for LinkedIn, X, Pinterest, TikTok, YouTube/Google, Facebook, Instagram Business and Google Business Profile; WhatsApp Business uses authorised Meta credentials. WordPress, Ghost, Mailchimp, Brevo and LINE use API or application credentials supplied by the user. A connection is not required for other Syvorex functions.
Before authorization, the respective platform provider displays the requested permissions. Syvorex receives and processes only the data and permissions explicitly authorized by the user. Syvorex does not read, connect or manage third-party accounts and does not process content or data from accounts the user did not connect.
Syvorex processes the account, profile, channel, page, board, list or location identifier supplied by the provider, the display name and, where provided, a profile image, along with granted scopes, token and connection metadata. TikTok data may include Open ID and Union ID; Meta data may include managed Pages and the linked Instagram Business account.
The purpose is to display the connected target, retrieve selectable destinations, prepare content chosen by the user and execute explicitly requested publishing, draft, newsletter or connection-test operations.
Publication or transmission to a platform occurs only after the user's explicit action or approval and within the granted permissions. Syvorex does not publish without such action or approval and does not read, import or manage third-party accounts.
Access and refresh tokens and provider credentials are encrypted and stored server-side in the database provided by Supabase and used by Vercel Functions only for authorised requests. Tokens and secrets are not returned to the browser, sold or used for advertising.
Tokens and connection metadata are retained only while the respective connection remains active and they are needed for the user-requested function. A technically necessary encrypted connection cookie is limited to a maximum of 90 days. Expired or revoked tokens are not used; a new authorization may technically replace them.
Users can disconnect integrations in Social Publishing or revoke access at the provider. Disconnecting removes the active server-side token/credential connection and related metadata. Remote revocation is attempted where technically supported by the provider; it is not universally available.
Data export and account erasure can be requested through Privacy Center, https://syvorex.com/data-deletion or support@syvorex.com. The erasure preflight blocks deletion while billing, publishing or unresolved integration operations remain; the controlled workflow then removes registered Storage objects, workspace/account data, active tokens and Auth data. Externally published content must be managed at the platform provider.
Vercel Inc. processes technical requests and provides hosting for the website and application. More information: https://vercel.com/legal/privacy-policy
Supabase, Inc. provides authentication and database services; encrypted OAuth tokens and connection metadata are stored there and assigned to the Syvorex user account. More information: https://supabase.com/privacy
Stripe and Cloudflare are used for the purposes described above. Their exact legal role may vary by processing and remains subject to legal review. A direct production Resend integration is not currently evidenced in the technical implementation and is therefore not listed as an active direct provider.
Platform providers and official privacy notices: TikTok (https://www.tiktok.com/legal/page/eea/privacy-policy/en), Google/YouTube/Google Business Profile (https://policies.google.com/privacy), Meta/Facebook/Instagram/WhatsApp Business (https://www.facebook.com/privacy/policy/), LinkedIn (https://www.linkedin.com/legal/privacy-policy), X (https://x.com/en/privacy), Pinterest (https://policy.pinterest.com/en/privacy-policy), LINE (https://terms.line.me/line_rules), WordPress.com/Automattic where used (https://automattic.com/privacy/), Ghost (https://ghost.org/privacy/), Mailchimp (https://www.intuit.com/privacy/statement/) and Brevo (https://www.brevo.com/legal/privacypolicy/). For self-hosted WordPress, the respective website operator is also responsible.
The legal classification as processor, independent controller or joint controller is processing-specific and is not finally determined by this technical description.
Data is retained only as long as required for its purpose, contractual performance, security, dispute resolution or legal duties. Tokens/credentials generally remain until disconnected, and workspace content until user deletion or account erasure. Technical retention defaults are documented but the final periods for publishing history, logs, billing data and backups remain subject to legal approval.
Backup deletion generally occurs through expiry and overwrite of the backup cycle. A restore must replay erasures recorded after the recovery point. The final backup-erasure and retention rules remain subject to legal review.
Vercel, Supabase, Stripe, AI and platform providers may process data outside the EEA. Depending on provider and destination, adequacy decisions, Standard Contractual Clauses or other safeguards may apply. Account-specific DPAs, SCCs and transfer impact assessments have not yet received final legal review for every provider.
Subject to the legal conditions, you have rights to information, access, rectification, erasure, restriction, portability, objection and withdrawal of consent. Send privacy and deletion requests to support@syvorex.com.
You may also lodge a complaint with a data protection authority, in particular the Austrian Data Protection Authority: https://www.dsb.gv.at/
We implement risk-appropriate technical and organisational measures, including workspace/tenant isolation, Row Level Security, private workspace-media storage, expiring signed URLs, server-side authorisation, encrypted provider credentials and OAuth tokens, and logging redaction. Absolute security cannot be guaranteed.
Syvorex has implemented privacy-readiness controls for data inventory, export/DSAR, account erasure, retention documentation, logging redaction, workspace isolation and subprocessor documentation. Formal legal review of DPAs, SCCs, TIAs, provider roles, legal bases and international transfers remains outstanding. This is not a guarantee of complete GDPR compliance.
Account, authentication and workspace data required for the selected function must be supplied so the contract and requested function can be performed. Optional integrations, analytics consent and additional AI context are voluntary.
Syvorex uses AI to create and prepare content but does not use it to make solely automated decisions with legal or similarly significant effects about the user. Users review and approve results and external publications themselves.