Security

Security that lives in the product – not in the brochure.

Tenant isolation, encryption, EU hosting and traceable AI actions: this is how Synadesk protects your customers’ data – including a straight answer on where conversation content is processed.

Controlled access within the team

Team accounts come with no per-head surcharge – but not without control: roles and permissions decide who may manage settings, billing and the team, sign-in can be secured with multi-factor authentication (MFA), and security- and privacy-relevant events are kept as an audit trail in the Cockpit.

Transcript, not recording

Every conversation leaves its transcript and audit trail in the Cockpit, traceable down to the single action – but no audio recording. That is a decision, not a gap: you can evidence any case without archiving your customers’ voices.

Only on your domains

The widget runs exclusively on the domains you approve in the customer account. Anyone embedding the code on a foreign site gets no answer – and binding actions additionally require your visitor’s explicit confirmation.

Tenant isolation in the database

Tenant-scoped business data is separated by database-level access rules; the database enforces the tenant context. Global registries as well as authentication and partner tables follow separate access rules.

Encryption

All transfers run over TLS. Stored credentials for connected systems are encrypted with AES-256-GCM; file uploads live in EU object storage with encryption at rest.

EU hosting

Operations and primary data storage take place in the EU; file uploads sit under EU jurisdiction. AI model and speech processing may happen outside the EU – with the safeguards named in the privacy policy.

AI processing openly declared

To answer widget conversations, the conversation content is transmitted to the AI model provider; this processing may take place outside Switzerland/the EU (in the US). That is stated in the privacy policy – not hidden in the small print.

Identity verification before sensitive disclosures

Your AI employee shares status and document information only after the person asking has confirmed their identity with a one-time code (OTP).

Traceable AI actions

Your AI employee’s actions are recorded in an append-only audit log – so it stays traceable what was triggered, and when.

Retention and deletion

Conversations and messages generally have a 90-day retention timestamp; after that, the scheduled retention run removes content and assignment data. Bookings are cleaned up no earlier than 90 days after the appointment ends, and handovers 90 days after their creation. Chat files receive a 90-day deletion timestamp on upload and, after expiry, pass through a scheduled technical deletion process that is retried after errors. Statutory duties and active legal holds for attributable local visitor data may suspend local steps; external providers have their own periods and deletion processes.

AI labelling – cannot be switched off

Visitors see before every conversation that they are writing with an AI employee. The AI label is built in and cannot be deactivated – not even under white label.

Availability is monitored

The platform is monitored automatically around the clock – with uptime checks every 30 minutes and alerts to the operations team after one confirmed failed check.

Details on data processing

Data processing follows the Swiss Data Protection Act (DSG/FADP) and the European GDPR. Recipient categories, cross-border transfers and your rights are set out in the privacy policy; the data processing agreement (DPA), with the sub-processor list as an annex, is public at synadesk.ai/en/dpa and automatically forms part of the contract.