Syncflow Compliance Register
Syncflow's public GDPR compliance artefacts, maintained alongside the Privacy Policy and Data Privacy Plan. Together they fulfil the "Data Inventory & Classification" milestone of Syncflow's Q2 2026 privacy roadmap.
Contents
| Document | Purpose | Regulatory reference |
|---|---|---|
| Data Inventory | Categories of personal data that Syncflow processes. | Art. 30 GDPR |
| Lawful-Basis Mapping | The Art. 6 lawful basis relied upon for each processing purpose. | Art. 6, Art. 9 GDPR |
| Tier Classification | Classification of each data category as Essential, Functional, or Optional, with retention principles. | Art. 5(1)(c), Art. 5(1)(e) GDPR |
| Processor Data Flows | Summary of personal data shared with Syncflow's processors. | Art. 28, Art. 44–49 GDPR |
| Data Protection Impact Assessment | ICO-template DPIA covering Syncflow's processing, including Addendum A on Autopilot. | Art. 35 GDPR |
Autopilot
Autopilot lets a user write rules and have Syncflow act on their own tasks: researching, planning, drafting, and, where the user raises the limit themselves, completing an item and asking for approval. It is covered across the register rather than in a document of its own, because it is the same personal data being processed in a new way:
| Question | Where it is answered |
|---|---|
| What Autopilot stores | Data Inventory §10 |
| How long it is kept, and what deletes it | Tier Classification, "Autopilot retention" |
| Why the processing is lawful | Lawful-Basis Mapping §§1.12, 1.13 and the assessment in §2.3 |
| Whether any new company receives data | Processor Data Flows §§2.3, 2.7 (no new processor) |
| What runs on the user's own machine, and why that is not a disclosure to a third party | Processor Data Flows §2.7 |
| Automated processing, Art. 22, and the human-in-the-loop defaults | DPIA Addendum A |
Scope and authority
- Controller: the operator of the Syncflow service.
- Scope: personal data processed by the Syncflow web application.
- Review cycle: annually, and on any material change to processing activities, processors, or the regulatory environment.
- Contact: requests, complaints, and correction suggestions should be directed to the contact address in the Privacy Policy.
How to use these documents
- If you are a user checking what Syncflow does with your data, start with the Data Inventory and the Processor Data Flows.
- If you are a business customer performing vendor due diligence, the Lawful-Basis Mapping and DPIA will be most relevant.
- If you are a regulator or auditor, the full set is intended to be read together.
Relationship to the Privacy Policy
The Privacy Policy is the legally operative notice under Art. 13 GDPR. The documents in this register are the underlying compliance material that the Privacy Policy summarises. Where any inconsistency exists, the Privacy Policy prevails for notice purposes and this register is updated to match.
Change log
| Date | Change |
|---|---|
| 2026-04-16 | Initial publication of inventory, lawful-basis mapping, tier classification, processor flow summary, and DPIA. |
| 2026-09-18 | Autopilot: new inventory category, retention periods with a daily cleanup job, two lawful bases with a legitimate-interests assessment, the local-executor flow, and DPIA Addendum A. |