1. Controller and contact
Michael Rooijakkers, operating the pre-registration Synlara brand in the Netherlands, is the controller for personal data processed directly through synlara.com. For privacy questions, requests, or complaints, email info@synlara.com.
2. Scope
This policy applies to synlara.com, business enquiries submitted through the contact form, and related email follow-up. External websites and services linked from synlara.com operate under their own privacy notices.
3. Data you provide
The contact form may collect:
- Full name, email address, and message.
- Company name and the service you are interested in.
- Weekly quote-request volume when you select the Quote Inbox Pilot.
- Information you later provide by email, during a call, or in other business conversations.
Full name, email address, message, and successful spam verification are required to submit the form. Company name, service selection, and quote volume are optional unless clearly indicated otherwise.
4. Technical, security, and usage data
When you use the website, the following technical data may be processed:
- IP address and request information used for hosting, security, and spam verification.
- Browser, operating system, device type, referrer, page path, and approximate location.
- Page-view, session, and website performance measurements.
- Turnstile browser or device signals, verification token, and verification outcome.
The form also contains a hidden anti-spam field. Normal visitors are not expected to complete that field.
5. Purposes and legal bases
Personal data is processed for the following purposes:
- Responding to a requested business enquiry and taking requested steps before a possible agreement. Depending on who submits the enquiry, the legal basis is pre-contractual necessity or the legitimate interest in responding to business contacts.
- Operating, protecting, troubleshooting, and improving the website. The legal basis is the legitimate interest in maintaining a secure and effective website.
- Detecting and blocking spam or abusive submissions. The legal basis is the legitimate interest in protecting the form, inbox, and website.
- Keeping records or responding to lawful requests where a legal obligation applies.
6. Contact form delivery and email
Contact form submissions are checked using Cloudflare Turnstile, processed by the Synlara server route, sent through FormSubmit, and delivered to a Proton email inbox. These providers process the information needed to perform their respective security, delivery, hosting, or email functions.
If automated delivery is unavailable, the website may offer a direct email fallback. Do not send special category data, passwords, payment details, or other highly sensitive information through the form or ordinary email.
7. Analytics and performance
Synlara uses Vercel Web Analytics and Vercel Speed Insights to understand aggregated website usage and real-user performance. This may include page paths, filtered query information, referrers, browser and device categories, approximate location, and performance measurements.
Vercel states that Web Analytics does not use third-party cookies and does not collect personal identifiers for tracking people across websites. Synlara does not use the website for behavioural advertising.
8. Cookies and similar technologies
Synlara does not intentionally set advertising cookies. Vercel Web Analytics is configured as a cookie-free analytics service. Cloudflare Turnstile processes minimal browser and device signals, tokens, and any strictly necessary technical identifiers required to distinguish legitimate visitors from automated submissions.
9. Service providers and recipients
Personal data may be processed by providers that support the website and enquiry flow, including:
- Vercel for website hosting, analytics, performance monitoring, and server infrastructure.
- Cloudflare for Turnstile spam and abuse protection.
- FormSubmit for contact form delivery.
- Proton for receiving and managing enquiry email.
Personal data is not sold. It may also be disclosed when required by law, to establish or defend legal claims, or to protect the website and its users.
10. Scheduling through Cal.com
Booking links on synlara.com lead to Cal.com. Cal.com receives information only when you choose to visit or use its service and handles that information under its own privacy notice. Cal.com is not embedded as the Synlara contact form.
11. International processing
Some service providers may process data outside the Netherlands or the European Economic Area. Where required, those providers use recognised safeguards such as adequacy decisions or standard contractual clauses. Further information about applicable safeguards can be requested by email.
12. Retention
Business enquiries are retained for up to twelve months after the last meaningful contact unless they become part of a customer relationship, a dispute, a legal claim, or a record that must be kept for longer by law.
Security, hosting, analytics, and performance data are retained according to the relevant provider settings and only for as long as needed for their stated purposes.
13. Automated spam decisions
Cloudflare Turnstile automatically assesses whether a form interaction appears legitimate. A failed check can prevent an online submission, but it does not produce a legal or similarly significant decision about you. If the form is blocked incorrectly, you can contact Synlara directly by email.
14. Security
Reasonable technical and organisational measures are used to protect personal data, including encrypted website connections, spam verification, restricted access, and established hosting and email providers. No internet or email system can guarantee absolute security.
15. Your rights
Subject to the conditions in applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent without affecting earlier lawful processing.
Send a request to info@synlara.com. A response will normally be provided within one month. Identity verification may be requested where reasonably necessary.
You may also lodge a complaint with the Dutch Data Protection Authority.
16. Children
The website and contact form are intended for business users and are not directed at children. Synlara does not knowingly request personal data from children through this website.
17. Updates
This policy may be updated when the website, providers, legal status, or data practices change. The current version and update date will remain available on this page. Registered business details will be added before Synlara begins paid work.
