Privacy Policy
This policy explains what personal data Syncture processes, why, on what legal basis, and what rights you have. In short: Syncture stores your project files for you, in the region your account was created in. Beside them it holds an account record, who you have shared things with, and how many bytes you are using.
1. Controller
The controller within the meaning of Article 4(7) GDPR is DI Osama Almughanni BSc, sole proprietor, Döblergasse 3/3/8, 1070 Vienna, Austria, trading as "Syncture". Registration details are in the Legal Notice.
Requests under Articles 15 to 22 GDPR go to mail@syncture.com. We are not required to appoint a Data Protection Officer and have not appointed one. Requests reach the controller directly, and the person who answers is the person who wrote the code.
2. Project files, and who holds them
Syncture stores customer project files, being models, drawings, folder names and everything inside them. We hold them. Files move between the customer's Windows computers and that storage through our API, over a credential that lasts one hour and reaches one account.
Where those files contain personal data, the customer is the controller and we are the processor under Article 28 GDPR. The Data Processing Agreement carries the detail that Article requires, including the categories of data and data subjects, the security measures and the sub-processors. We process those files only to store, serve and protect them, on the customer's instructions, and for no purpose of our own. Nothing published is used to train any model.
A workspace is created either with encryption on or with encryption off, and off is the default. The choice is made when the workspace is created and is fixed for its life. What we can read follows from it, so both cases are set out here.
Where a workspace is created with encryption off, project files are stored in a form we are able to read, and we could be required to produce one in readable form under valid legal process. What limits that access is this policy, the Terms, the Data Processing Agreement and Austrian law. It is not limited by cryptography.
In an encrypted workspace, the bytes of every file inside a published version, and every element-ownership document, are encrypted by the Syncture add-in on the customer's own Windows machines under a 256-bit key generated on their side and never transmitted to us. We hold no key with which to open them and nothing from which one could be derived. A customer who loses that key loses the versions published into that workspace.
In both kinds of workspace we hold in readable form: workspace, folder and project names; the relative path and exact byte length of every file in every version; the number and stored size of each piece; the sequence, time, author, note and Revit release of every publish; the share graph with its capabilities; and which machine holds a lock. A version's file list is written to object storage as plain JSON when it is too large for its database row, and that is the one place object storage carries a file name.
Content is stored in pieces addressed by a hash of the bytes held, so two hundred versions of a model cost the model plus what changed. Pieces are deduplicated within one account and are never shared between accounts.
3. Where the data sits
Project file contents are stored as objects in Cloudflare R2, in one of six regions, fixed when the account is created from where the first request came from. It does not move afterwards. An account placed in the wrong region can be copied to another one if you ask.
- European Union (Western Europe)
- European Union (Eastern Europe)
- United States (East)
- United States (West)
- Asia-Pacific
- Oceania
The two European regions are held under Cloudflare's EU jurisdiction, which is a contractual guarantee that those objects do not leave the European Union. It is the default, and it is also where an account goes when the region cannot be determined.
Everything else is held in one Cloudflare D1 database: the account record, the folder and project names, each version's file list, the share graph, the device records and the invoices. That database is created under Cloudflare's EU jurisdiction, which restricts it to run and store its data inside the European Union. This applies to every account, wherever its project files are kept.
For a European account, therefore, both the drawings and the names of them stay in the European Union.
4. Deletion, and what it means
There is no trash, no recovery window and no copy kept by the product. Deleting a folder or a project removes its structure at once and releases the bytes underneath it, which are removed from storage once nothing else refers to them. It cannot be undone by you or by us.
One qualification, stated because it is true. Rows removed from our database persist for up to thirty days in the platform's own point-in-time recovery, which is always on and exists so the service can be restored after a fault. It is not reachable as a customer feature, nothing is restored from it at a customer's request, and it ages out on its own.
Closing an account removes its workspaces, its sessions and its device credentials. The user record is deliberately kept: the email address, the display name and which identity provider was used. It is what records that an address has been seen before, and removing it would silently reopen every share naming that address. Ask under section 14 and it is erased.
Invoices already issued are kept. They are accounting records in a gap-free sequence, they carry billing details and never file contents, and section 9 says for how long.
5. Visiting this website
The site is served by Cloudflare, which processes the ordinary technical data any web server receives: the IP address, the time, the address requested, the referrer, the user agent, the status and the number of bytes. It is used to serve the page, to keep the service available and to defend it against abuse. The legal basis is Article 6(1)(f) GDPR and the interest is operating a website that works. These are short-lived infrastructure logs, kept in the order of days.
There is no advertising cookie, no third-party analytics, no tag manager and no profile of you. Nothing on this site loads a script or a font from another company's server. That is why there is no consent banner. Your choice of light or dark is kept in your own browser's local storage under Section 165(3) TKG 2021, and one strictly necessary cookie holds your session when you are signed in.
6. Accounts and sign-in
Signing in is Microsoft or Google over OpenID Connect, or a six-character code we email you. There is no password anywhere in this product, so there is none of yours for us to store or to leak. Where you use an identity provider, the token is verified against that provider's published signing keys and we receive your email address, your display name and the identifier that provider uses for you. Your own multi-factor and conditional access policies are enforced by that provider and we cannot weaken them.
A sign-in code is usable for fifteen minutes, survives five wrong guesses, and is stored only as a peppered hash. The row that holds it also holds the address it was sent to, and a sweep removes that row once it is more than a day past expiry.
We hold, per account: the email address and its domain, the display name, which provider was used and that provider's identifier for you, the times the record was created and changed, the storage region, bytes used and bytes allowed, and the share and group rows naming you. Sessions and device credentials are held only as hashes. We record no IP address against an account and keep no record of which projects anybody opened. Abuse limits use a salted hash of the address that cannot be reversed.
The legal basis is Article 6(1)(b) GDPR, and the data is kept for the life of the account.
Accepting the Terms. When you accept the Terms of Service after signing in, we record which version you accepted, when, that it was done in a signed-in browser, and the email address you were signed in with. Nothing else is recorded with it, and no IP address. The record is what shows which contract applies, so the legal basis is Article 6(1)(b) GDPR and our legitimate interest under Article 6(1)(f) in being able to prove it. It is kept as long as the user record. If that record is erased, the acceptance is restricted and kept only while a claim under the contract could still be brought, as Article 17(3)(e) allows.
An account with no paid storage that nobody has signed in to or published to for twelve months is written to three times: once at the year, once a fortnight later, and once a month after that. Each message says what is about to happen, and that signing in once stops it. Thirty days after the final notice the account and everything in it is deleted, bytes included, about ten weeks from the first message.
Signing in at any point in that sequence cancels it, and you hear nothing further. The deletion itself is the ordinary one: no trash, no copy kept, and every chunk nothing else references removed from storage.
This applies only to accounts with no paid storage. An account with paid storage is never swept for inactivity, at any age, and nothing is ever deleted for non-payment or for a trial that ended. The account becomes read-only, with every file still readable and exportable.
7. The machines you sign in on
A machine holds a device secret that lasts ninety days and is replaced every time it is used, and exchanges it for an access token that lasts one hour. Both are stored only as hashes. A person is signed in on at most three machines, and a fourth sign-in signs out whichever has gone longest unused.
Each machine carries a label. When it is first adopted the label is composed from the operating system your browser reports and the city Cloudflare derives from the request. The machine then replaces it with its own Windows computer name every time it renews. No IP address is stored, and no hardware identifier of any kind is collected: no motherboard serial, no MAC address, no disk id and no Windows installation GUID.
8. Writing to us
The contact form takes your name, your email address, your company and your message, and mails them to us. It is sent by Cloudflare's own mail service through a platform binding. There is no email provider in that path and no marketing platform anywhere in this product.
We use what you send to respond to your enquiry. We do not sell your information or use it for marketing without your specific consent. The legal basis is Article 6(1)(b) GDPR where you are asking about a contract, and Article 6(1)(f) for ordinary correspondence. Enquiries are kept for up to twenty-four months after the last contact and then deleted.
9. Billing and accounting records
For a paying customer we hold the billing name, the billing address, a VAT identification number if the customer has one, the billing email address, the storage size, the price and every invoice issued.
There is no payment processor. Storage is ordered by email and paid by SEPA transfer that you initiate, so no card number, no direct debit mandate and no payment-account credential of yours is ever collected, processed or stored by us or by anybody on our behalf. What we see is our own bank statement.
The legal basis is Article 6(1)(b) for the contract and Article 6(1)(c) for the records we are required to keep. Accounting records are kept for seven years under Section 132 BAO, and longer where a specific obligation requires it. That obligation survives a request to erase, and section 14 says so.
10. Who else receives data
Annex III of the Data Processing Agreement is the authoritative list, and it is short:
- Cloudflare, Inc. for website hosting, the API, edge compute, the database, object storage and outbound mail. Everything the service holds passes through it.
- Microsoft Corporation and Google LLC, where a person chooses to sign in with them. They receive the fact of a sign-in and process it as controllers of that authentication under their own terms.
- Our tax adviser and our bank, who receive invoicing and accounting data about a customer as an organisation. They reach no project file and are not processors of customer files.
There is no advertising network, no analytics vendor, no error tracking service, no support desk product and no payment processor. Beyond the list above, data is disclosed only where the law requires it, to establish or defend a legal claim, or on a transfer of the business. Where we are the processor and a request concerns a customer's files, we refer the requesting party to that customer and tell them, unless we are lawfully forbidden from telling them.
11. Transfers outside the EEA
Objects belonging to a European account do not leave the European Union, under the jurisdiction guarantee in section 3, and the database holding every account's records is under the same guarantee. The project files of an account created outside Europe are stored in its own region.
Cloudflare, Microsoft and Google are established in the United States, and support correspondence may be read from outside the EEA. Those transfers rest on an adequacy decision under Article 45 GDPR where one covers the recipient, and otherwise on the Standard Contractual Clauses under Article 46(2)(c) together with supplementary measures. We will send you the safeguards we rely on if you ask.
12. No automated decisions
There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR, and no profiling.
13. Security
Requests travel over HTTPS on every path. Objects in storage are encrypted at rest by Cloudflare under keys Cloudflare manages, which protects them if a disk is stolen and against nothing else. Sessions, device secrets and sign-in codes are held only as peppered hashes, so losing the database would not hand somebody a working credential. Access is decided by the service on every single request, against workspace membership, shares and groups. No workstation holds a storage credential and there is no bucket to address. Annex II of the Data Processing Agreement is the full list.
Encryption at rest under a provider's own keys protects against media loss. It does not protect against us. Where a workspace was created with encryption off, whether anybody here may read a model is settled by contract and by law, not by mathematics. In an encrypted workspace the file contents are held under a key we never receive, and the names, paths and sizes in section 2 are not.
Breaches. Where a personal data breach affects data we process for a customer, we tell that customer without undue delay on the terms in the Data Processing Agreement. Where we are the controller, we notify the Austrian Data Protection Authority within 72 hours under Article 33 GDPR and, if the risk to individuals is high, tell them under Article 34. Article 34(3)(a) unintelligibility is available only for file contents in a workspace created with encryption on, and never for the names, paths and sizes in section 2.
What we do not hold: an ISO 27001 certificate and a SOC 2 report. There is also no agreed uptime figure, service level or credit, and none is implied anywhere on this site. The security page sets out what stands in their place.
14. Your rights
You have the right to access your data under Article 15, to have it corrected under Article 16, erased under Article 17, restricted under Article 18, ported under Article 20, and to object under Article 21. Where processing rests on consent you may withdraw it at any time, without affecting what was lawful before.
Portability needs no request. The Syncture application writes the whole of an account to a folder on disk in one command, in a documented layout. For a workspace created with encryption on, run it on a machine holding the key.
Write to mail@syncture.com and we answer within one month. We may need to verify who you are first. Where your data sits inside a customer's project files we are the processor, and we will pass you to that customer, who is the controller. Erasure does not reach accounting records we are required by Section 132 BAO to keep, and those are restricted rather than deleted.
You may complain to the Austrian Data Protection Authority, Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, at dsb.gv.at, or to the authority where you live or work.
15. Providing data, and changes
You are not required by law or by contract to give us personal data, except that an account needs an email address, a contact request needs a name and an email address, and an invoice needs the billing details Section 11 UStG requires.
This policy is updated when the service or the law changes. The current version is always published here with its date, and a material change is notified by email to paying customers.
Version of 24 September 2026.