The paperwork, in plain sight.
Privacy policy, terms of service, the list of companies that process data on our behalf, and the AI disclosure your reviewer can fetch directly.
The SalesSynq privacy policy is published at salesynq.com/privacy, and the rest of the paperwork sits beside it: terms of service, the data processing agreement, the list of everyone who touches your data, the AI Act transparency record, and an AI disclosure your reviewer can fetch as a file — no account, no NDA, no call first.
You should not have to sign an NDA to read a privacy policy.
The usual sequence in this category is a call, then an NDA, then a security questionnaire, then — weeks later — the documents. Your reviewer waits, the decision waits, and a quarter you had already won on the product quietly goes past. Everything on this page is public right now, so the review can start today.
Where is each document?
All of it is here, published rather than available on request. Every link below resolves today, and none of them is behind a form, a login or a sales conversation.
Privacy Policy
What personal data SalesSynq processes, on what basis, for how long, and how to exercise a data protection right. Includes the retention table and the address for privacy questions.
/privacy
Terms of Service
The agreement governing use of the Service: subscription terms, who owns your data, warranties, liability, and how changes reach you. This is the operative text — nothing on this hub page modifies it.
/legal/terms
Data Processing Agreement
The processor terms: instructions, confidentiality, security measures, sub-processor engagement, help with data subject requests, and international transfer mechanisms. Published in full rather than sent on request.
/legal/dpa
Sub-processor list
Who else touches the data, grouped by purpose — infrastructure, AI inference, operational and observability tooling, and cookie-consent-gated marketing analytics — with what each one handles.
/trust/subprocessors
AI Disclosure
The human-readable version: what the AI assistance does, what is recorded, which parts are ordinary code rather than generated text, and how to switch it off. Written for a reader, not a parser.
/ai-disclosure
AI Disclosure endpoint (JSON)
The machine-readable version of the same disclosure: public, unauthenticated, no account and no NDA. This is the artifact to send a reviewer who would rather read a control map than a brochure.
/ai-disclosure
AI Act transparency record
Our preliminary self-classification, the obligations we read as applying, and the controls mapped against them in code. It says plainly which parts counsel has not yet signed off.
/legal/ai-act-conformity
Security overview
How the platform is built and defended: how one customer’s data is kept apart from another’s, how decisions are recorded so they can be examined later, and how the product is developed.
/security
Trust Center
The plain-language version of the whole posture — restraint, evidence, consent and the floors that cannot be loosened — with links back into every document on this page.
/trust
Service status
Current operational status. We publish status; we do not publish availability or capacity figures, because we have not measured them under real load.
/status
The documents are the operative text. Nothing on this hub varies or qualifies them, and where a description here and a clause there ever disagree, the clause wins.
What can I send my reviewer before we talk?
All of it, right now. A reviewer who can start on day one is a reviewer who is not the reason a decision slips a quarter — and the difference between a three-week security review and a three-day one is almost never the product. It is how long the paperwork took to arrive.
- 1
Forward this page
Everything your reviewer needs is on it and public. No portal, no form, no waiting on us to attach documents to an email.
- 2
They read the actual documents
Not a summary of a policy — the policy. Privacy, processor terms, who touches the data, and the AI control map they can fetch as a file.
- 3
They come back with questions, not a questionnaire
The first call starts at the specifics, because the general answers were already read and marked up a week earlier.
- The AI disclosure as a machine-readable file your reviewer can fetch this morning — no account, no NDA, no call booked first.
- The data processing agreement and the list of everyone who touches your data, both published in full, so an impact assessment can start before anyone signs a mutual NDA.
- The AI Act transparency record, which states our preliminary classification and marks what counsel has not yet signed off rather than implying it is settled.
- The security overview, including how decisions are recorded so that a question asked in November can still be answered about something that happened in March.
On compliance the wording is the same everywhere on this site: a preliminary classification we made ourselves, a control map anchored in the code, and counsel review still open. SOC 2 and ISO 27001 are evidence programmes in progress. We hold no certification and do not describe ourselves as certified.
Who processes our data, and where?
The list is published in full and grouped by purpose — infrastructure, AI inference, operational and observability tooling, and cookie-consent-gated marketing analytics — with what each one handles stated per entry. Read it before the data processing agreement: it is the document that tells you what the agreement is actually about.
Where the product runs and where your data sits are a written answer you get before you sign anything, naming what runs where and what moves between them. What you will not get is a residency badge, because data residency is a deployment conversation rather than a certification anybody holds.
SalesSynq does not train models on customer data. Every path where free text can reach an AI provider at all is named in the processor list rather than described in general terms — read that entry closely if it matters to your assessment.
How do we exercise a data protection right?
Through the privacy address published in the privacy policy, or through the data subject request flow inside the Service if you are already a customer. The policy sets out what is processed, on what basis and for how long, and its retention table is the reference point for any deletion request.
One asymmetry worth knowing before you ask: the record of decisions can be added to but not edited afterwards. That is what makes it useful months later, and it is a different promise from retention. We will tell you in writing which applies to which data rather than leaving you to work it out from a policy.
Questions from legal and privacy teams
Send this page to your reviewer, then get on with the quarter
Policies, processor terms and a fetchable AI control map — all public, all current, none of it behind a form. The review starts today instead of in week three.
Private beta is invite-only and requires approval. General availability targeted for Q3 2026.
Last updated . We refresh beta status, availability dates and integration status on a monthly sweep.

