Privacy Policy
Last updated: 6 October 2026
This privacy policy explains what personal data Syndicbase collects and how we handle it, in line with the General Data Protection Regulation (GDPR). It covers this website, our waitlist and the Syndicbase application. For the personal data our customers enter into the application about their owners, tenants and suppliers, we act only as a processor on their behalf; that processing is governed by our Data Processing Agreement.
1. Data controller
The controller of your data is Syndicbase BV, Luxemburgstraat 86, 9890 Gavere, Belgium, company number 0800.381.741.
For any question about this policy or to exercise your rights, contact us at privacy@syndicbase.be. We have not appointed a data protection officer; if that changes, we will update this policy.
When you use the Syndicbase application as a syndic (our customer), we are the controller of your account data. For the personal data you enter about owners, tenants, suppliers and other parties, you are the controller and we act as your processor; that processing is governed by our Data Processing Agreement.
If you are a co-owner who uses the client portal made available by your syndic, we act as a processor on behalf of your co-ownership (VME). Please direct any request about your data to your syndic.
2. What data we collect
Data you provide. When you join the waitlist we collect the data you enter: your name and email address, and optionally your company or co-ownership, phone number, the number of buildings or units you manage and your message. Providing this data is not a legal obligation, but without it we cannot add you to the waitlist.
Account data. When you use the Syndicbase application, we collect the data needed to run your account: your name, email address, login credentials, and your workspace, role and settings, together with usage and log data about how you use the service.
Usage statistics. When you use the Syndicbase application, our servers record a limited set of usage events: that you opened the application on a given day, and key actions such as creating a building, sending a mailing or generating a settlement. Each event carries your user ID, your workspace and the time, never the content you enter. When an error occurs, we also record the technical error report. These events are recorded on our servers; nothing is stored on or read from your device for this purpose.
Data we collect automatically. When you visit this website, our servers automatically record technical data such as your IP address, the type of browser and device you use and the date and time of your request. We use this data only to keep the website secure and to prevent abuse.
We do not knowingly collect data from anyone under the age of 16 through this website.
3. Cookies and similar technologies
This website uses only strictly necessary local storage, to remember your language choice and that you have seen our cookie notice. We do not use advertising or analytics cookies and do not track your browsing. The usage statistics of the Syndicbase application described in section 2 are recorded on our servers and do not use cookies or any other storage on your device. For details, see our cookie policy.
4. Purposes and legal basis
We use the data you provide to keep you informed about the launch of Syndicbase and to contact you about your request. The legal basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
When you use the Syndicbase application, we process your account and usage data to provide, secure and support the service. The legal basis is the performance of our agreement with you (Article 6(1)(b) GDPR) and our legitimate interest in a reliable service (Article 6(1)(f) GDPR).
We process usage statistics and error reports to understand how the application is used, to improve it and to detect and fix errors. The legal basis is our legitimate interest in developing and maintaining a reliable service (Article 6(1)(f) GDPR). We limit this to the events described in section 2 and do not use them for advertising or profiling. You can switch this off at any time in the application (Settings, Legal tab) or object by email (see section 10). When you switch it off, we stop recording usage events for your account; error reports are then sent without your user ID.
We process technical and log data to secure the website and prevent abuse. The legal basis is our legitimate interest in a safe and reliable service (Article 6(1)(f) GDPR).
5. How long we keep your data
We do not keep your data longer than necessary for the purposes described above. We keep waitlist data until Syndicbase launches and for a reasonable period afterwards to contact you, and in any event no longer than 24 months after your last contact with us, unless you ask us to keep it longer.
Account data is kept for as long as you use the Syndicbase application and is deleted or returned afterwards in line with our Data Processing Agreement, unless a longer period is required by law, for example for accounting records.
We erase your data sooner if you withdraw your consent or ask for deletion. Technical log data is kept for a short period only.
Usage statistics and error reports are kept for at most 12 months.
6. Recipients and processors
We do not share your data with third parties for commercial purposes. We do rely on processors that help us deliver the service: Vercel (hosting), Supabase (database), Amazon SES / Resend (email), PostHog (usage statistics and error reports), Upstash (temporary cache and protection against misuse), Cloudflare (bot protection on forms and the login), EasyPost (postal letters and Peppol e-invoices), Anthropic (AI reading of invoices) and OpenAI / Cerebras (automatic translation of texts). These processors act only on our instructions and under a data processing agreement.
When you connect a Google or Microsoft mailbox or calendar, we exchange data with that account on your instruction. For that data, Google and Microsoft act as your own service providers.
We may disclose data where we are legally required to do so, for example at the request of a competent authority.
7. International transfers
We aim to process your data within the European Union. Where data is nonetheless processed outside the EU, this is done with appropriate safeguards such as the European Commission's standard contractual clauses.
8. Data security
We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access, including encrypted connections and access controls. No method of transmission or storage is completely secure, but we continuously work to protect your data.
9. Automated decision-making
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
10. Your rights
You have the right to access, rectification, erasure, restriction and portability of your data, and the right to object to processing, including the usage statistics described in section 4. Where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. To exercise these rights, contact us at privacy@syndicbase.be.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels, www.dataprotectionauthority.be).
11. Changes to this policy
We may update this privacy policy from time to time. The date at the top shows when it was last changed. We encourage you to review it periodically.