Privacy Policy
Last updated: September 2026
Data controller
Synaptic Four (sole proprietorship)
Owner: Alexander Senf
Königstraße 5, 70173 Stuttgart, Germany
Contact: contact@synapticfour.com
Phone: +49 177 1492210
Data Protection Officer
A Data Protection Officer is currently not required for our business. For data protection requests, please contact us directly using the email address provided in the Impressum.
What data do we collect?
Contact forms: Data you enter (name, email, message) are processed and transmitted for the purpose of handling your enquiry. Forms also send an email subject line to the form service (Formspree) so enquiries can be sorted in our mailbox. If you open a form page via an internal link with a topic in the URL, that subject line may be pre-filled in your browser before you submit; you can edit it. When campaign parameters (UTM parameters such as utm_source, utm_medium, utm_campaign, utm_term, utm_content) are present in the URL at submission, those values may be stored with the enquiry so we can evaluate internally which channels generate enquiries. We do not pass these UTM parameters on to third parties.
Server logs: The site is hosted on GitHub Pages (GitHub, Inc.). When you visit the site, access data (e.g. IP address, browser, time) may be collected by the host as our processor. These data are necessary for the operation of the site. This website does not set any non-essential cookies.
External course checkout: when you open checkout from the training page, you leave this website and are redirected to Systeme.io. The external provider processes data under its own responsibility according to its privacy policy.
Links to GitHub: When you open links to github.com or other GitHub-controlled pages, GitHub, Inc. may process personal data as set out in GitHub’s privacy statement. That processing is outside our control and is governed solely by GitHub.
Legal basis (GDPR and TDDDG)
Contact forms: Art. 6(1)(a) GDPR (consent via checkbox). If an enquiry leads to a contract, further processing as needed for pre-contractual or contractual steps: Art. 6(1)(b). Server logs: Art. 6(1)(f) (provide and secure the site). localStorage for the cookie notice: TDDDG § 25(2) no. 2 (strictly necessary so the same notice is not repeated) and, where personal data is involved, Art. 6(1)(f) GDPR. Optional UTM parameters stored with a submitted enquiry: Art. 6(1)(f) (understand which channels generate enquiries). Statutory retention of business correspondence where applicable: Art. 6(1)(c). Consent may be withdrawn at any time with effect for the future.
Technical and organisational safeguards
The website is delivered over HTTPS. We apply data minimisation and only process data required for operation, contact handling, and the listed external services. No analytics or advertising trackers are used on this site.
Is data provision mandatory?
Providing your data is generally voluntary. Without the required contact form details (name, email, message and consent), we cannot process your enquiry via the form.
Retention period
Closed enquiries and related correspondence are deleted or anonymised after typically 6–12 months, unless a longer statutory retention period applies to commercial letters (German commercial and tax law can require up to ten years for certain records). Formspree retains personal data only as long as needed to provide the form service and meet its legal obligations. Hosting and mailbox provider logs are retained according to those providers’ configurations. Exact durations can vary by data type.
Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object (Art. 21)—including to processing based on Art. 6(1)(f) (e.g. server logs and cookie-notice preference) on grounds relating to your particular situation. You may lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), or with any other supervisory authority in the EU.
To exercise these rights, please contact us at the email address given in the imprint. We will process your request without undue delay, generally within one month (Art. 12(3) GDPR). We do not build classic visitor profiles ourselves; however, when the website is accessed, technically required access data are processed by the hosting provider GitHub as our processor (e.g. IP address, timestamp). Your rights also concern contact form data (via Formspree) and any correspondence we keep.
Disclosure and external recipients
Data are disclosed only in the cases described below (in particular to technical service providers and platform operators).
Processor: Contact form
The contact form is operated by Formspree (Formspree.io, USA). Your entries are transmitted to Formspree’s servers. Formspree offers a data processing agreement (DPA) under its published terms; we use Formspree on that basis. Where data are transferred to the USA, transfer is based on the EU Commission’s standard contractual clauses and/or other mechanisms Formspree documents. Further information: https://formspree.io/.
Email (receipt): Private Email (privateemail.com)
The information you submit via the contact form (including for handling your enquiry) is processed using an email mailbox hosted by Private Email (privateemail.com), a product of Namecheap. We use this mailbox exclusively for communication related to your enquiry. After processing is complete, we delete emails unless legal retention obligations or technical reasons (e.g. security/backup processes) apply. Namecheap/Private Email is a US-based provider; transfers outside the EEA may occur. Where required, transfers rely on the provider’s published mechanisms (e.g. standard contractual clauses and/or the EU–US Data Privacy Framework). A processor arrangement applies to the extent Namecheap processes mailbox data on our behalf. Details: https://privateemail.com/privacy.
Hosting provider: GitHub Pages
The website is hosted on GitHub Pages (GitHub, Inc., USA). We are the controller for operating this website. GitHub processes technically necessary access data (e.g. IP address, timestamp, user agent) as hosting provider/processor when pages are requested. Servers may be located in the USA. International transfers are based on GitHub’s applicable transfer mechanisms (e.g. EU Commission standard contractual clauses and/or the EU–US Data Privacy Framework, where applicable). Details: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement.
Social media presence: LinkedIn
We maintain a company presence on LinkedIn (LinkedIn Ireland Unlimited Company / LinkedIn Corporation, USA). This website does not embed LinkedIn plugins or pixels. When you visit our LinkedIn page or interact with our content there, LinkedIn may process personal data (e.g. usage data, device information). In that context, joint controllership under Art. 26 GDPR may apply; the applicable framework is defined by LinkedIn’s published terms and notices. For transfers to the USA, LinkedIn uses, among other mechanisms, the EU Commission’s standard contractual clauses. Privacy: https://www.linkedin.com/legal/privacy-policy.
External course checkout: Systeme.io
Course checkout is provided by Systeme.io (ITACWT Limited, Ireland). When you click the checkout link, you leave our website and are redirected to a Systeme.io page. Data processed there (e.g. technical access data, order and payment data) is handled under Systeme.io’s responsibility. For payment processing, additional payment providers (e.g. Stripe) may be used within the checkout flow; the specific provider and its privacy terms are shown there. Privacy: https://systeme.io/privacy-policy.
External services: PCMS (map.synapticfour.com)
When you open PCMS at https://map.synapticfour.com (including via links on this site), you leave synapticfour.com; processing there is described in PCMS’s own Art. 13 notice: https://map.synapticfour.com/privacy (English), https://map.synapticfour.com/de/privacy (German), https://map.synapticfour.com/fr/privacy (French), or https://map.synapticfour.com/sw/privacy (Kiswahili). The controller is Synaptic Four (Stuttgart), as on this page and in our imprint. PCMS handles pseudonymous research session data; the assessment flow does not ask for your name, email, or postal address. Consent is obtained in a multi-step flow inside PCMS (Art. 6(1)(a) GDPR), and optional cloud storage in the research database is performed only with explicit opt-in. Hosting is provided via Vercel (USA; international transfers are addressed in that notice); optional cloud research storage may use Supabase (often in the EU region for production—operators should verify). For study deployments, operators may enable a documented research configuration that hides lightweight share controls so participants rely on full session exports rather than compressed URL payloads (see the PCMS repository). PCMS does not use advertising or marketing analytics cookies, as stated there. The ethics framework and validation protocol are additionally available inside the PCMS web app at https://map.synapticfour.com/ethics and https://map.synapticfour.com/validation (with locale prefix for non-default languages, e.g. German: /de/ethics and /de/validation).
External services: Mycelium (mycelium-beta.vercel.app)
When you open the Mycelium landing at https://mycelium-beta.vercel.app (including its /privacy notice), you leave synapticfour.com. The controller is Synaptic Four (Stuttgart), as on this page and in the imprint. That host is a technical-beta landing on Vercel (Vercel Inc., USA). It publishes its own privacy notice. GitHub sources for Mycelium and mycelium-web are not public; access is on request. Mycelium is LAN and nearby-device mesh messaging, not an emergency service. Visiting that landing is typically Art. 6(1)(f) GDPR (inform about the project) unless that host obtains consent for additional processing. International transfers to Vercel as described in that notice and for GitHub Pages above.
Cookies and local storage
This site does not set any non-essential cookies. No analytics or marketing cookies are used. A notice banner stores your acknowledgment (“Got it”) only locally in your browser (localStorage) so the notice is not shown again. That storage is strictly necessary to provide the requested site without repeating the same notice (TDDDG § 25(2) no. 2). It is not used for tracking and is not marketing consent.
Withdrawal of consent
You may withdraw consent you have given (e.g. for contact) at any time with effect for the future. Contact us at the email address given in the imprint.
Automated decision-making (Art. 22 GDPR)
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you in connection with this website.
No medical devices, no diagnosis
None of the solutions described on this site are designed or approved as medical devices under the EU MDR. They are not intended to diagnose, treat, or monitor diseases or health conditions and do not replace medical or psychological advice.
Disclaimer for AI-based content and software
The content, software solutions, and AI-based applications provided on this site are intended solely for informational, research, and support purposes. They do not constitute medical, therapeutic, legal, or any other professional advice and do not replace consultation with qualified professionals. Despite careful development and review, no guarantee can be given for the accuracy, completeness, or timeliness of AI-generated content. Use of the provided applications is at your own risk. In particular, in medical or health-related contexts, the information provided must not be used as a basis for diagnosis or treatment decisions. Any liability for damage arising directly or indirectly from the use of the content or software offered is excluded to the extent permitted by law. The results of AI-based systems may be unpredictable or erroneous; users are responsible for reviewing results before making decisions based on them.
External product suite: Synaptic Products
When you follow links from this website to Synaptic Products or its apps (digital kits storefront, SitePulse AI, SynaptiSec, AZAV-Akte), you leave synapticfour.com. Synaptic Four remains the controller unless an app states otherwise. Operator imprint is this Impressum. This Privacy Policy covers operator processing for those apps. Host-specific notices also exist at the kits storefront `/privacy`, SitePulse `/privacy`, SynaptiSec `/privacy`, and AZAV-Akte `/privacy`. The Synaptic Products hub has no `/privacy` page; operator notices stay here. Availability may be public demo, paid checkout, allowlist, or invite-only. Product apps are documentation, engineering, or field-workflow tools unless a specific page states otherwise; they are not legal advice, not regulatory certification (including not ISO, not OSHA, not AZAV Zulassung, not GA4GH certification), and not medical devices.
Processors for Synaptic Products apps (hosting, auth, payments, email)
Those apps are typically hosted on Vercel (Vercel Inc., USA). Account and application data may be stored in Supabase (Supabase Inc.; production region should be verified per project — often EU). Authentication may use Google sign-in (Google LLC / Google Ireland) where enabled; public sandbox demos on SynaptiSec and AZAV-Akte create temporary tenants without Google. Paid kits and SitePulse subscriptions use Stripe (Stripe Inc. / Stripe Payments Europe) for payment. Transactional email (e.g. SitePulse report delivery) may use Resend. International transfers rely on each provider’s published mechanisms (e.g. EU Commission standard contractual clauses and/or the EU–US Data Privacy Framework, where they participate). Details: https://vercel.com/legal/privacy-policy, https://supabase.com/privacy, https://policies.google.com/privacy, https://stripe.com/privacy, https://resend.com/legal/privacy-policy. Legal basis is typically Art. 6(1)(b) GDPR for using a service you requested, and Art. 6(1)(f) for technically necessary hosting logs.
AI and transcription providers (SitePulse and internal kit generation)
SitePulse sends jobsite audio and derived transcripts/text to configured US providers so the product can transcribe speech and structure an OSHA-style audit: Anthropic PBC (Claude; default paid writer Claude Haiku), Google LLC (Gemini as failover or if Anthropic is unset), Deepgram (default paid transcription), and/or OpenAI (Whisper fallback). Outputs may be emailed via Resend. This is product functionality, not a consulting default. Do not upload special-category health data or other data you are not allowed to send to those providers. Kit-storefront generation (admin/operator side, not the public shop UX) may use Anthropic, Google Gemini, Cerebras, and OpenAI for text or cover images. SynaptiSec and AZAV-Akte do not use LLMs. Provider notices: https://www.anthropic.com/legal/privacy, https://policies.google.com/privacy, https://deepgram.com/privacy, https://openai.com/policies/privacy-policy. Transfers to the USA as above. Legal basis for SitePulse customer use is typically Art. 6(1)(b) (contract) for the service you request; where an app asks for consent, Art. 6(1)(a).
Fonts and analytics
This site uses system fonts only (no Google Fonts). No analytics or tracking tools are used.