Legal & Data Protection
Privacy Policy for the "Sylaxis" Platform
As of: September 2, 2026
1. Preamble and Scope
Sylaxis GmbH (hereinafter "Sylaxis", "we", or "us") operates a multi-tenant enterprise documentation and AI platform (hereinafter "Platform" or "Service") under https://app.sylaxis.com as well as associated domains, application programming interfaces (APIs), and browser extensions.
The protection of your personal data and compliance with the requirements of the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG) are our highest priority.
This Privacy Policy informs you comprehensively and transparently about the nature, scope, purpose, and legal bases of the processing of personal data when using our Platform, as well as the rights available to you as a data subject.
2. Name and Contact Details of the Controller
Controller within the meaning of the GDPR (Art. 4 No. 7 GDPR):
Sylaxis GmbHAm Studio 2 a (Center for IT and Media 3)
12489 Berlin, Germany
Phone: +49 (0) 30 23591882
Email: team@sylaxis.com
Authorized Managing Director: Nico Tobien
Commercial Register: Local Court Charlottenburg (Berlin), HRB 288382 B
VAT Identification Number (USt-IdNr.): DE463388068
Business Identification Number (W-IdNr.): DE463388068-00001
Data Protection Contact & Data Subject Requests
For all inquiries regarding data protection, IT security, or exercising your data subject rights, you can reach our internal data protection coordination team at:
Postal Address: Sylaxis GmbH, Attn: Data Protection, Am Studio 2 a, 12489 Berlin, Germany
3. Principles of Data Processing & Legal Bases
We always process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality (Art. 5 GDPR).
Unless specifically stated otherwise in this policy, we base our processing on the following legal grounds:
- Consent (Art. 6(1)(a) GDPR): Where you have granted us explicit consent for specific processing operations.
- Contract Performance & Pre-contractual Inquiries (Art. 6(1)(b) GDPR): For providing our contractual services, authentication, user and tenant management, and payment processing.
- Legal Obligation (Art. 6(1)(c) GDPR): For compliance with statutory obligations (e.g., commercial and tax retention periods, payment services regulations, and anti-money laundering laws).
- Legitimate Interests (Art. 6(1)(f) GDPR): To ensure IT security, defend against cyberattacks and bots, prevent fraud, and optimize our platform architecture.
- Terminal Equipment Storage / Access (§ 25 TDDDG): For technically strictly necessary storage on the user's terminal equipment (§ 25(2) No. 2 TDDDG).
4. Provision of the Platform, Hosting & Server Log Files
4.1. Infrastructure & EU Hosting
Sylaxis follows a strict EU hosting and data residency strategy. All core databases, data storage, and server-side compute capacities reside in ISO/IEC 27001- and SOC 2-certified data centers within the European Union:
- Frontend Hosting & Content Delivery Network (Firebase Hosting): Provision and delivery of the static web application via Google's global, highly available CDN (Google Ireland Limited / Google LLC) with integrated SSL/TLS protection.
- Supabase Backend (PostgreSQL Database with Row-Level Security, Authentication & Edge Functions): Hosted on AWS infrastructure in the EU-Central-1 region (Frankfurt am Main, Germany).
- Google Cloud Platform (GCP) Cloud Run Microservices: Hosted dedicatedly in Google's data center in the europe-west3 region (Frankfurt am Main, Germany).
- File Storage for Customer Uploads (Google Cloud Storage / GCS): Hosted redundantly in the European Union (EU) multi-region.
- Google Cloud Gemini Enterprise Platform (AI Inference & Embeddings): Provision and inference via endpoints in the European Union (EU) multi-region.
4.2. Collection of Server Log Data
When accessing our Platform, the servers automatically collect and store technical information in log files:
- IP address of the requesting device
- Date and time of access
- Name and URL of the requested resource / API endpoint
- Data volume transferred and HTTP status code
- Browser type, browser version, and operating system
- Referrer URL (previously visited website)
Purpose & Legal Basis: The temporary processing of the IP address is technically required to deliver the Platform to your device, ensure system stability and security, and investigate misuse or cyberattacks (e.g., DDoS).
- Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure and error-free operation).
- Retention Period: Log files are automatically deleted or irreversibly anonymized after 30 days at the latest, unless security-related incidents require longer retention for evidentiary purposes.
5. User Accounts, Registration & Authentication
5.1. Registration and User Profile
Creating a user account is required to use the Platform. The following data is collected:
- Email address
- First name and last name
- Password (stored exclusively as a cryptographic one-way hash via Argon2/Bcrypt; plaintext passwords are never visible to Sylaxis)
- Tenant assignment (Tenant ID, Company Name)
- Assigned system and feature roles (e.g., Admin, Editor, Viewer)
Legal Basis: Art. 6(1)(b) GDPR (contract performance).
5.2. Transactional Email Delivery via Brevo
For sending transactional emails required for authentication and account management (e.g., registration confirmations, magic links, password reset notifications, workspace invitations), we use Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France):
- Processed Data: Recipient email address, name, IP address, transaction and system metadata, and transmission timestamps.
- Server Location: Processing and email dispatch take place via ISO 27001-certified data centers within the European Union (e.g., France/Germany).
- Legal Basis: Art. 6(1)(b) GDPR (contract performance) and Art. 28 GDPR (data processing agreement).
5.3. Bot Protection & Abuse Prevention via Cloudflare Turnstile
To protect login, registration, and form submission flows against automated attacks (bots, brute-force attacks, credential stuffing), we use Cloudflare Turnstile, operated by Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany, or Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA:
- Functionality: Turnstile analyzes non-invasive technical browser characteristics (e.g., HTTP headers, browser environment, challenge behavior) without interactive puzzles to determine whether an interaction originates from a genuine user or a bot.
- Privacy & Data Protection: Turnstile does not use cookies for behavioral advertising, does not read private device data, and does not build cross-platform user profiles.
- Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in IT security, platform stability, and fraud prevention) and § 25(2) No. 2 TDDDG.
- Data Transfers: A Data Processing Agreement including EU Standard Contractual Clauses (SCCs) and certification under the EU-U.S. Data Privacy Framework (DPF) safeguard any international data transfers.
5.4. Multi-Factor Authentication (MFA / 2FA) & Multi-Layer Auth
- MFA: Sylaxis supports time-based one-time passwords (TOTP via authenticator apps). MFA key generation and verification take place encrypted on the server side within our Supabase infrastructure.
- 5-Tier Defense: Every backend request undergoes CORS validation, JWT signature verification (OAuth 2.1), CSRF token validation, server-side cryptographically validated tenant isolation, and PostgreSQL Row-Level Security (RLS).
Legal Basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR.
6. Single Sign-On (SSO) / OAuth 2.0 & OAuth 2.1
We provide the option to sign in using third-party Single Sign-On services:
6.1. Google Identity / Google Workspace OAuth
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Processing: Upon redirection and consent, Google transmits your email address, name, and a unique Google user ID to us.
- Legal Basis: Art. 6(1)(b) GDPR (contract performance).
6.2. Microsoft Entra ID (Azure Active Directory)
- Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
- Processing: Authentication via your Microsoft enterprise account. Your email address, profile name, and directory ID are transmitted.
- Legal Basis: Art. 6(1)(b) GDPR (contract performance).
7. Tenant Isolation & Authorization Architecture
Sylaxis implements hardware- and database-level tenant isolation:
- Tenant Isolation: Every record is strictly bound to a tenant ID (
tenant_id). Database triggers and PostgreSQL Row-Level Security (RLS) enforce at the database level that unauthorized modifications or cross-tenant queries are blocked. - 3-Tier Permission Concept:
- Tier 1: Tenant Role (organization-level membership)
- Tier 2: Module & Feature Capabilities (
editor_feature_access) - Tier 3: Entity Permissions (granular whitelist-based access control for documents, workspaces, kanban boards, AI agents, and files)
Legal Basis: Art. 6(1)(b) GDPR and Art. 32 GDPR.
8. Artificial Intelligence, Workflows, MCP & Email Triggers
8.1. Gemini Enterprise Agent Platform (formerly Vertex AI) & Gemini Models
To provide intelligent assistance features (e.g., AI Assistant, AI Agents, document analysis, rich text editor workflows), Sylaxis uses the Gemini Enterprise Agent Platform (formerly Vertex AI) on Google Cloud Platform with Google Gemini family models:
- AI Inference Hosting Region: Data centers within the European Union (EU) multi-region.
- Processed Data: Prompts entered by users, workspace context, referenced document excerpts, and optional multimodal attachments.
8.2. Binding Privacy Guarantee: Zero Model Training (Zero-Training Policy)
Customer and enterprise data is NEVER used to train, retrain, or improve underlying AI base models operated by Google or Sylaxis.
All API calls through the Gemini Enterprise Agent Platform are governed by Google Cloud's enterprise data protection agreements (Customer Data Processing Addendum). Data processing is volatile (stateless) and transient, strictly limited to generating the specific model response.
8.3. Vector Embeddings & Semantic Search (RAG)
To provide Retrieval-Augmented Generation (RAG) and semantic search, document contents are converted into mathematical vector representations:
- Embedding Inference & Storage: Vector generation is executed via endpoints within the European Union (EU) multi-region. The resulting vector embeddings are stored exclusively in our tenant-isolated PostgreSQL database (
pgvector) in Frankfurt am Main. - Access Control: Vector embeddings are equally subject to full tenant isolation and permission boundaries via Row-Level Security.
8.4. Optional DLP & Pseudonymization Pipeline (Opt-In)
When uploading sensitive documents, Sylaxis provides a user-controlled DLP and pseudonymization pipeline. This processes content transiently in isolated Google Cloud Run containers (Frankfurt am Main, purely in-memory RAM processing, strict zero logging) to mask personally identifiable information (PII) before further processing upon user request.
8.5. Email Triggers for Workflows (Inbound Email via Brevo)
Users can optionally configure workflows or AI agents to trigger upon incoming emails (e.g., for automated documentation, task creation, or workspace updates):
- Functionality: Inbound emails sent to dedicated workspace addresses are received via Brevo's inbound parse service and delivered via encrypted webhook to our Serverless Edge Functions.
- Processed Data: Sender address, subject line, email body, attachments, and receipt timestamp.
- Legal Basis: Art. 6(1)(b) GDPR (contract performance upon user request) or Art. 28 GDPR (data processing agreement).
8.6. Model Context Protocol (MCP) & API Actions
Users can connect custom API actions and Model Context Protocol (MCP) servers directly through the Platform:
- Data Flow: When executing an MCP action, Sylaxis forwards structured data exclusively upon explicit instruction by the user or an authorized AI agent to the configured target endpoint.
- Responsibility: The respective operator of the third-party service is responsible for data processing at the external endpoint.
Legal Basis: Art. 6(1)(b) GDPR or Art. 28 GDPR.
8.7. Transparency and Information Obligations (Art. 50 EU AI Act)
To ensure maximum transparency and in compliance with the regulatory requirements of Regulation (EU) 2024/1689 (EU AI Act) and the GDPR, the following applies to the use of our AI features:
- Transparency Regarding AI Interaction: Pursuant to Art. 50(1) of Regulation (EU) 2024/1689 (EU AI Act), we inform you that when using AI features (such as Chat Assistant, text generation, data extraction, and AI workflows), you are interacting directly with an artificial intelligence system.
- Content Labeling: All outputs generated by the Platform are visually identified in the user interface as AI-generated and presented transparently to the user.
- No Automated Individual Decision-Making: Data processing by Sylaxis takes place strictly on instruction within the scope of user-triggered actions. No fully automated decision-making producing legal effects concerning data subjects pursuant to Art. 22 GDPR takes place. Responsibility for reviewing and approving outputs remains with the respective deployer (tenant / customer).
Legal Basis: Art. 6(1)(b) GDPR, Art. 28 GDPR, and Art. 50 Regulation (EU) 2024/1689.
9. Payment Processing & Subscriptions (Stripe)
For paid Sylaxis subscriptions, invoicing, and payment processing via credit card or SEPA direct debit, we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland; Parent company: Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA):
9.1. Nature and Scope of Processed Data
During payment transactions, Stripe processes directly:
- Name of cardholder / account holder
- Billing address and company name
- Email address
- Payment data (full credit card number, expiration date, CVC code, or IBAN/BIC for SEPA direct debit)
- Transaction details (purchase amount, currency, timestamp, subscription ID)
- Technical telemetry data for fraud detection (IP address, device fingerprint)
9.2. No Storage of Sensitive Payment Data at Sylaxis
Sylaxis never stores full credit card numbers or bank account details on its own servers.
Collection takes place through direct, secured interfaces (Stripe Elements / Stripe Checkout), so sensitive payment data is transmitted directly to Stripe and processed according to the highest security standard PCI-DSS Level 1. Sylaxis only receives a pseudonymous payment token, transaction status, and masked data (e.g., the last 4 digits of the card) for invoice reconciliation.
9.3. Legal Bases & Fraud Prevention
- Contract Performance & Billing: Art. 6(1)(b) GDPR.
- Legal Obligations & Strong Customer Authentication (PSD2): Art. 6(1)(c) GDPR in conjunction with Payment Services Directive requirements (SCA) and tax retention requirements.
- Fraud Prevention & Risk Analysis: Art. 6(1)(f) GDPR (legitimate interest in preventing payment defaults and card misuse). Stripe acts as an independent data controller for regulatory payment and fraud prevention purposes.
- Third-Country Transfers: Safeguarded by certification under the EU-U.S. Data Privacy Framework (DPF) and EU Standard Contractual Clauses (SCCs).
10. Device Storage & Session Handling (§ 25 TDDDG)
Sylaxis uses no third-party advertising, tracking, or profiling cookies.
To securely maintain user sessions (Session Management) and authentication, we store technical state data in your browser's LocalStorage or in secured, encrypted cookies:
- Stored Data: JSON Web Tokens (JWT Access & Refresh Tokens), tenant identifiers, UI theme preferences.
- Purpose: User authentication across page navigation and prevention of session hijacking.
- Legal Basis: § 25(2) No. 2 TDDDG (technically strictly necessary to provide the telemedia service explicitly requested by the user) in conjunction with Art. 6(1)(b) GDPR.
11. Distinction from Data Processing on Behalf (Art. 28 GDPR)
When using our enterprise platform, two scopes of responsibility must be distinguished:
- Sylaxis as Controller (Art. 4 No. 7 GDPR): For data required to establish, execute, and bill the contractual relationship (master account data, billing details, security logs).
- Sylaxis as Data Processor (Art. 28 GDPR): Insofar as you, as an enterprise customer, process personal data of third parties (e.g., employees, customers, suppliers) within workspaces, documents, notes, kanban boards, or AI prompts, Sylaxis acts exclusively on behalf of and under the instruction of your organization.
In this case, executing a Data Processing Agreement (DPA / AVV) including documented Technical and Organizational Measures (TOMs) pursuant to Art. 28, 32 GDPR is required. We provide this agreement in standardized form within our customer portal.
12. Subprocessors & Service Providers
To provide the Platform, we employ selected technical service providers bound by Data Processing Agreements (Art. 28 GDPR) or dedicated data protection terms:
| Service Provider | Purpose / Service | Location / Data Center | Legal Basis & Safeguards |
|---|---|---|---|
| Supabase Inc. | Backend, authentication, PostgreSQL database, local storage services | Frankfurt am Main, Germany (EU-Central-1) | Art. 28 GDPR, EU Hosting, EU-US DPF / SCCs |
| Google Cloud EMEA Ltd. / Google Ireland Ltd. | • Web frontend hosting & CDN (Firebase Hosting for secure application delivery) • Cloud Run Microservices (DLP / Backend logic) • Gemini Enterprise Agent Platform (Inference & Embeddings) • Google Cloud Storage (GCS object storage) | • Frontend / CDN: Global Google edge network / EU nodes • Cloud Run: Frankfurt am Main, Germany (europe-west3) • AI Platform & GCS: European Union (EU) multi-region | Art. 28 GDPR, EU Hosting / CDN delivery, ISO/IEC 27001 / SOC 2 / C5, EU-US DPF / SCCs |
| Brevo (Sendinblue SAS) | Transactional email delivery (Auth/password) & inbound email triggers for workflows | European Union (France / Germany) | Art. 28 GDPR, EU Hosting, ISO/IEC 27001 |
| Cloudflare Germany GmbH / Cloudflare, Inc. | Bot protection, abuse prevention & form security (Cloudflare Turnstile) | Global CDN / EU edge routing | Art. 28 GDPR, ISO 27001, EU-US DPF / SCCs |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing (credit card, SEPA), subscriptions & fraud prevention | Ireland / EU (processing pursuant to PCI-DSS Level 1) | Art. 6(1)(b), (c), (f) GDPR, DPA, EU-US DPF / SCCs |
Third-Country Transfers: Primary storage and processing occur within the EU. Should administrative access from third countries (e.g., USA) occur for globally operating providers, data protection levels are safeguarded by the EU-U.S. Data Privacy Framework (DPF) and the execution of EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
13. Duration of Storage & Retention Periods
We retain personal data only for as long as necessary to fulfill the respective purposes or as required by statutory retention periods:
- User Accounts & Workspace Data: Retained for the duration of the active contractual relationship. Upon contract termination or workspace deletion by the customer, production data is irreversibly deleted within 30 days.
- Rolling Database Backups: Overwritten system-wide after at most an additional 30 days for technical reasons.
- Accounting & Tax Records / Payment Records: Retained for 6 to 10 years pursuant to statutory tax and commercial retention laws (§ 147 AO, § 257 HGB).
- Security & Audit Logs: Automatically deleted or anonymized after at most 30 days.
14. Technical and Organizational Measures (TOMs) & Trust Center
To protect your data, we implement state-of-the-art security architectures pursuant to Art. 32 GDPR:
- Transport Encryption: End-to-end TLS 1.3 encryption with strict HTTPS enforcement.
- Encryption at Rest: Full AES-256 encryption across all databases and file object stores.
- Zero-Trust & Tenant Isolation: PostgreSQL Row-Level Security (RLS) with server-side BEFORE INSERT / UPDATE triggers to prevent tenant hopping.
15. Rights of Data Subjects
As a data subject, you are entitled to comprehensive rights under the GDPR against the controller:
- Right of Access (Art. 15 GDPR): You can request information about your personal data processed by us.
- Right to Rectification (Art. 16 GDPR): You have the right to request rectification of inaccurate data or completion of incomplete data.
- Right to Erasure (Art. 17 GDPR): You can request the deletion of your data stored with us ("Right to be Forgotten"), provided no statutory retention obligations apply.
- Right to Restriction of Processing (Art. 18 GDPR): You can request restriction of processing if accuracy is contested or processing is unlawful.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your data in a structured, commonly used, and machine-readable format or request transfer to another controller.
- Right to Object (Art. 21 GDPR): Where we process your data based on legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to processing at any time on grounds relating to your particular situation.
- Right to Withdraw Consent (Art. 7(3) GDPR): You can withdraw previously granted consent at any time with future effect without formality.
To exercise your rights, simply send an email to: datenschutz@sylaxis.com.
16. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe the processing of your personal data violates the GDPR.
The competent supervisory authority for Sylaxis GmbH is:
Berliner Beauftragte für Datenschutz und InformationsfreiheitAlt-Moabit 59–61
10555 Berlin, Germany
Phone: +49 (0) 30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de
17. Currency and Changes to this Privacy Policy
Due to ongoing platform development, the integration of new AI models or workflows, or statutory changes, updates to this Privacy Policy may become necessary.
The current, legally binding version can always be accessed and printed at https://sylaxis.com/en/privacy-platform/.