Security

Security that lives in the product – not in the brochure.

Tenant isolation, encryption, EU hosting and traceable AI actions: this is how Synadesk protects your customers’ data – including a straight answer on where conversation content is processed.

Tenant isolation in the database

Tenant-scoped business data is separated by database-level access rules; the database enforces the tenant context. Global registries as well as authentication and partner tables follow separate access rules.

Encryption

All transfers run over TLS. Stored credentials for connected systems are encrypted with AES-256-GCM; file uploads live in EU object storage with encryption at rest.

EU hosting

Operations and primary data storage take place in the EU; file uploads sit under EU jurisdiction. AI model and speech processing may happen outside the EU – with the safeguards named in the privacy policy.

AI processing openly declared

To answer widget conversations, the conversation content is transmitted to the AI model provider; this processing may take place outside Switzerland/the EU (in the US). That is stated in the privacy policy – not hidden in the small print.

Identity verification before sensitive disclosures

The AI agent shares status and document information only after the person asking has confirmed their identity with a one-time code (OTP).

Traceable AI actions

The AI agent’s actions are recorded in an append-only audit log – so it stays traceable what was triggered, and when.

Retention and deletion

Personal data from conversations, bookings and handovers is automatically anonymised after the defined periods – as a rule 90 days after the contact, and for appointments after the appointment. Chat files become due for deletion after 90 days, are no longer made available to users and are passed to the technical deletion process. Statutory retention and legal-hold cases as well as data held by external providers remain reserved; you manage access, export and deletion requests directly in your customer account.

AI labelling – cannot be switched off

Visitors see before every conversation that they are writing with an AI agent. This notice is built in and cannot be deactivated – not even under white label.

Availability is monitored

The platform is monitored automatically around the clock – with uptime checks every 10 minutes and alerts to the operations team after one confirmed failed check.

Details on data processing

Data processing follows the Swiss Data Protection Act (DSG/FADP) and, where applicable, the GDPR. Recipient categories, cross-border transfers and your rights are set out in the privacy policy; a data processing agreement (DPA) and the current sub-processor list are available on request.