PRIVACY POLICY
Version 1.0 · Effective: July 2025 · UAE Jurisdiction
Applicable Law: This Privacy Policy is governed by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). Where users are located in the EEA, the EU General Data Protection Regulation (GDPR) also applies.
Privacy Policy
Syncly (“Syncly”, “we”, “us”, “our”) is committed to protecting the privacy of everyone who uses our platform. This Privacy Policy explains what personal data we collect from Brand Users and Creator Users, the purposes for which we process it, who we share it with, how long we keep it, and the rights you hold over your information.
This Policy applies to all users of the Syncly website, mobile application, and any associated services. It should be read alongside the Syncly Terms & Conditions, which are incorporated by reference. By using Syncly, you acknowledge and accept the data practices described in this Policy.
1. Who We Are & How to Contact Us
Syncly operates as the data controller for all personal data processed through the Platform. As data controller, Syncly determines the purposes and means of processing your personal data and is responsible for ensuring that processing is carried out lawfully.
Contact Type | Details |
Legal Entity | Syncly FZ-LLC |
Registered Address | Dubai, United Arab Emirates |
General Privacy Enquiries | |
Data Protection Officer (DPO) | |
Legal & Compliance | |
Website |
The DPO is Syncly’s primary contact for GDPR-related matters (for EEA users) and UAE PDPL matters (for UAE-resident users). All data rights requests and privacy complaints should be directed to the DPO in the first instance.
2. Scope of This Policy
This Policy covers personal data collected and processed by Syncly in connection with the operation of its Platform, including data from Brand Users, Creator Users, website visitors, and individuals who contact Syncly’s support team.
This Policy does not cover data processing activities carried out by Brand Users or Creator Users on their own systems outside of the Syncly Platform. Brand Users who use Creator data accessed through the Platform are independently responsible for their own data protection compliance.
This Policy does not govern the privacy practices of third-party social media platforms (TikTok, Instagram, Snapchat, YouTube) whose APIs Syncly integrates with. Users should consult the respective privacy policies of those platforms independently.
3. Personal Data We Collect
3.1 Brand User Data
When a business registers as a Brand User, Syncly collects the following categories of data:
Category | Specific Data Points | How Collected |
Business Identity | Company name, trade licence number, legal form, registered address, industry sector | Registration form |
Contact Information | Primary contact name, email address, phone number, job title | Registration form & account settings |
Billing & Payment | Billing address, VAT registration number, transaction history (card details tokenised by payment processor) | Subscription checkout |
Campaign Data | Campaign briefs, Offer descriptions, targeting criteria, content guidelines, deliverable records | Campaign creation workflow |
Creator Interaction Data | Creator profiles viewed, applications approved/declined, Voucher Codes issued, content reviewed and approved | Platform activity |
Communications | In-platform messages with Creator Users, support ticket history | Platform messaging & support tools |
Account Activity | Login timestamps, feature usage, session data, IP address | Automated (server logs & analytics) |
3.2 Creator User Data
When an individual registers as a Creator User and connects their social media accounts, Syncly collects:
Category | Specific Data Points | How Collected |
Identity | Full name, email address, phone number, date of birth (age verification) | Registration form |
Social Media Profile | Display name, username, profile picture, bio, verified status, connected platforms | OAuth (user-authorised) |
Follower & Reach Metrics | Follower count, following count, total likes/views, post frequency | Social media API (OAuth) |
Audience Demographics | Aggregated age ranges, gender split, top geographies (never individual follower identities) | Social media API (OAuth) — aggregated only |
Engagement Data | Average engagement rate, video/post performance metrics | Social media API (OAuth) |
Content Metadata | Captions, hashtags, content category of recent posts | Social media API (OAuth) |
OAuth Tokens | Access & refresh tokens for connected social accounts (encrypted at field level) | Social platform OAuth flow |
Campaign Activity | Applications submitted, approvals received, Voucher Codes redeemed, Deliverables submitted, content links published | Platform Campaign workflow |
Communications | In-platform messages with Brand Users, support history | Platform messaging & support tools |
3.3 Technical & Usage Data (All Users)
Device & Browser Data: IP address, device type, operating system version, browser type, and unique device identifiers.
Log Data: Platform access times, pages and features visited, search queries, errors encountered, and session duration.
Cookie Data: Session identifiers, analytics tags, and preference tokens. See Section 10 for the full Cookie Policy.
Location Data: Approximate geolocation derived from IP address, used for regional feature customisation. GPS-level location data is never accessed.
4. How We Collect Your Data
Directly from you: When you complete the registration process, update your profile, submit a Campaign brief, apply for a Campaign as a Creator, or contact our support team.
Via social media OAuth: When a Creator User connects a TikTok, Instagram, Snapchat, or YouTube account, Syncly receives access only to the data scopes the user approves during the OAuth authorisation flow. Users can view and revoke these permissions at any time.
Automatically through the Platform: Through server logs, analytics tools, and cookies as users navigate the Syncly website and application.
From third-party verification services: Syncly may use identity verification and Know Your Business (KYB) services to validate the legitimacy of Brand User registrations and trade licences.
From social media platforms post-Campaign: With Creator permission, Syncly may retrieve post-publication reach and engagement data directly from social media APIs for the purpose of generating Campaign performance reports for Brand Users.
5. Legal Basis for Processing
Syncly processes personal data only where it has a valid legal basis to do so. The table below sets out the primary legal bases relied upon:
Processing Purpose | Legal Basis |
Account registration and management | Contractual necessity |
Creator matching and recommendation engine | Contractual necessity |
Campaign creation, distribution, and management | Contractual necessity |
Voucher Code generation and issuance | Contractual necessity |
Monthly Campaign performance reporting | Contractual necessity |
Payment processing and billing | Contractual necessity / Legal obligation |
Identity & business verification (Brand Users) | Legitimate interest (fraud prevention) |
Follower authenticity scoring | Legitimate interest (platform integrity) |
Platform security, fraud detection, and abuse prevention | Legitimate interest |
Improving the matching algorithm (using anonymised data) | Legitimate interest |
Sending transactional notifications and service updates | Contractual necessity |
Marketing communications (opt-in) | Consent (can be withdrawn at any time) |
Compliance with UAE law and regulatory obligations | Legal obligation |
Dispute mediation and legal claims | Legitimate interest / Legal obligation |
Marketing: Syncly only sends promotional communications to users who have opted in. You may withdraw consent at any time through your notification settings or by emailing hello@synclydigital.com
6. How We Use Your Data
6.1 For Brand Users
To create and manage your Brand account and subscription.
To display your Campaign briefs to matched Creator Users.
To process Campaign fee payments and commission charges.
To generate and deliver Monthly Campaign Performance Reports.
To verify your business registration and trade licence details.
To send invoices, payment confirmations, and billing notifications.
To detect and prevent fraudulent use of the Platform.
To respond to support requests and Dispute submissions.
6.2 For Creator Users
To create and manage your Creator profile and social media connections.
To power Syncly’s AI-matching engine to surface relevant Campaign opportunities.
To issue Voucher Codes upon Campaign approval and track redemption.
To display a summarised, derived profile to Brand Users (never raw API data).
To process and deliver monetary compensation for paid Campaigns (where applicable).
To generate post-Campaign performance summaries for Brand Users.
To send Campaign notifications, approval updates, and platform alerts.
To verify the authenticity of your social media following and engagement.
7. Social Media Platform Data Processing
Syncly integrates with the following social media platforms via their official developer APIs. Data is only accessed following explicit authorisation by the Creator User through each platform’s OAuth flow.
Platform | Data Accessed via API | Syncly’s Purpose |
TikTok | Profile info, follower/engagement metrics, aggregated audience demographics, video metadata | Matching, reach scoring, niche classification, campaign reporting |
Instagram (Meta) | Profile info, follower/engagement metrics, aggregated audience demographics, post metadata | Matching, reach scoring, niche classification, campaign reporting |
Snapchat | Profile info, subscriber count, engagement metrics | Matching and reach scoring |
YouTube (Google) | Channel profile, subscriber count, view metrics, content categories | Matching and reach scoring |
Scope Limitation: Syncly requests only the minimum API scopes necessary to provide the matching and reporting services. Scopes will not be expanded without updating this Policy and obtaining fresh user consent.
No Individual Audience Data: Syncly never accesses, stores, or processes the personal data of individual followers or viewers. All audience data is consumed in aggregated, anonymised form as provided by platform APIs.
No Content Download: Syncly does not download or permanently archive video or image files created by Creator Users. Only content metadata (captions, hashtags, categories) is processed.
Token Security: OAuth access and refresh tokens are stored with field-level encryption. They are never shared with Brand Users, sub-processors, or any third party beyond what is strictly required for Platform functionality.
Revocation: Disconnecting a social media account through Platform settings immediately revokes Syncly’s API access for that platform. Syncly will queue the deletion of data sourced from that account within 30 days of revocation.
8. Matching Algorithm & Automated Processing
Syncly’s core matching functionality relies on automated processing of Creator User data to generate relevance scores and Campaign recommendations for Brand Users. This constitutes automated decision-making under applicable data protection law.
Inputs to the Algorithm: Each Creator is scored against a Campaign’s criteria based on: content niche relevance, audience demographic alignment with Brand targeting criteria, overall engagement rate, reach tier classification, follower authenticity score (based on follower-to-engagement ratios and platform signals), and historical Campaign performance within Syncly.
What Brand Users See: Brands receive derived profile summaries including reach tier, engagement band, top audience geography, content niche label, and a Syncly-generated match score. They never receive raw social API responses, OAuth credentials, or the identities of individual followers.
No Legally Significant Automated Decisions: Syncly’s algorithm generates recommendations only. All final decisions to approve or decline Creator applications are made by Brand Users. No solely automated process produces a legally or similarly significant effect on any individual.
Right to Explanation: Creator Users may request an explanation of why they received a particular match score or were not surfaced for certain Campaign categories. Requests can be submitted to hello@synclydigital.com
Opting Out of Categories: Creator Users may exclude specific industry verticals or content categories from their profile, and Syncly will not surface them for Campaigns in those excluded areas.
9. Data Sharing & Third Parties
Syncly does not sell personal data. Data is shared only as described below.
9.1 Sharing Creator Data with Brand Users
Restricted: Brands only see derived, Syncly-generated metrics. No raw API data, OAuth tokens, or individual audience member identities are ever shared with Brand Users.
Data Element | Visible to Brand? | Notes |
Creator display name & profile photo | Yes | As connected from social profile |
Content niche / category label | Yes | Syncly-derived classification |
Reach tier (follower band) | Yes | Banded range, not exact count |
Engagement rate bucket | Yes | Banded range, not exact figure |
Top audience geography | Yes | Country-level only |
Syncly match score | Yes | Proprietary algorithm output |
Exact follower counts (raw API) | No | Never exposed to Brand Users |
OAuth tokens | No | Encrypted; never shared |
Individual follower identities | No | Never accessed or stored |
Creator email or phone number | No | Only if Creator shares via messaging |
Post-campaign reach & engagement stats | Yes (campaign-specific) | Provided in Monthly Report only |
9.2 Sub-Processors
Syncly works with third-party sub-processors to deliver Platform services. All sub-processors are bound by Data Processing Agreements (DPAs) with data protection standards equivalent to this Policy. Key sub-processor categories include:
Cloud Infrastructure: Encrypted hosting, storage, and database services (servers in EU and/or UAE).
Payment Processing: PCI-DSS Level 1 certified payment gateway (card data never stored on Syncly’s servers).
Analytics & Monitoring: Platform usage analytics and error tracking tools (data processed in anonymised or pseudonymised form where possible).
Email & Notifications: Transactional email and push notification delivery services.
Identity & KYB Verification: Business identity verification services for Brand User onboarding.
Customer Support: Help desk and ticketing tools (access limited to support personnel; subject to confidentiality obligations).
A current list of sub-processors is available on request at hello@synclydigital.com.
9.3 Legal & Regulatory Disclosures
Syncly may disclose personal data to UAE law enforcement, regulatory bodies, or courts where required by law, a valid court order, or to protect the safety, rights, or property of Syncly or third parties.
In the event of a merger, acquisition, or sale of substantially all of Syncly’s business assets, user data may be transferred to the acquirer, subject to the same level of data protection described in this Policy. Affected users will be notified in advance.
10. Cookies & Tracking Technologies
Syncly uses cookies and similar technologies to operate the Platform, ensure security, and improve the user experience. Your cookie preferences can be managed through the Cookie Consent banner on first visit or through your browser settings.
Cookie Type | Purpose | Mandatory? |
Strictly Necessary | Session authentication, security tokens, load balancing, CSRF protection | Yes — cannot be disabled |
Functional | Language preferences, saved search filters, UI personalisation settings | No — off by default |
Analytics | Anonymised page view tracking, feature usage, error diagnostics | No — off by default |
Performance | A/B testing, platform optimisation | No — off by default |
Marketing (opt-in only) | Conversion tracking, retargeting pixels, social media integration | No — requires explicit opt-in |
Marketing cookies are only activated where you have provided explicit, informed consent. You may withdraw cookie consent at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawal of consent for strictly necessary cookies may impair Platform functionality.
11. Data Retention
Syncly retains personal data only for as long as necessary for the stated processing purpose, or as required by applicable law.
Data Category | Retention Period | Reason |
Brand account registration data | Active account + 12 months post-closure | Dispute resolution, fraud prevention |
Creator registration data | Active account + 12 months post-closure | Dispute resolution, fraud prevention |
Social API metrics (Creator) | Duration of social connection + 30 days after revocation | Matching functionality |
OAuth tokens | Until revoked or account closed | Platform operation |
Campaign records & Deliverables | 7 years from Campaign close | UAE tax law & legal compliance |
Voucher Code records | 3 years from Campaign close | Audit & dispute evidence |
Billing & payment records | 7 years | UAE tax regulation (FTA requirements) |
In-platform communications | 2 years from Campaign close | Dispute evidence |
Monthly Performance Reports | 3 years | Brand audit & legal compliance |
Server logs & access records | 13 months | Security monitoring & incident response |
Marketing consent records | Duration of consent + 3 years | Regulatory compliance |
Support ticket history | 3 years from ticket closure | Quality assurance & dispute evidence |
Upon account deletion, Syncly initiates a data purge within 30 days for operational data. Data subject to longer statutory retention obligations (e.g., billing records, Campaign data) will be retained for the minimum period required by law and then securely deleted.
12. International Data Transfers
Syncly is headquartered in the UAE. Some sub-processors and cloud infrastructure providers operate in jurisdictions outside the UAE, including the EU and the United States. Where personal data is transferred internationally, Syncly applies the following safeguards:
UAE PDPL Transfer Mechanisms: Transfers outside the UAE comply with the cross-border transfer provisions of UAE Federal Decree-Law No. 45 of 2021 and implementing regulations issued by the UAE Data Office.
EU Standard Contractual Clauses (SCCs): For EEA-resident user data, Syncly relies on European Commission-approved SCCs incorporated into all DPAs with sub-processors operating outside the EEA.
Adequacy Decisions: Where the recipient country has been granted an adequacy decision by the relevant authority, Syncly relies on that decision as the transfer mechanism.
Data Localisation: Where technically feasible and required by applicable law, Syncly processes UAE-resident user data within UAE-located infrastructure.
13. Data Security
Syncly implements industry-standard technical and organisational security measures designed to protect personal data against unauthorised access, loss, disclosure, alteration, or destruction. Key measures include:
Encryption: All data in transit is protected using TLS 1.3. Data at rest is encrypted using AES-256. OAuth tokens are encrypted at field level and stored separately from user-facing data.
Access Controls: Personal data is accessible only to Syncly personnel with a verified business need. All access is logged, audited, and reviewed regularly. Administrative access requires multi-factor authentication.
Security Testing: Syncly conducts regular third-party penetration testing and vulnerability assessments. Critical findings are remediated on a prioritised basis.
Incident Response: In the event of a confirmed personal data breach, Syncly will notify affected users within 72 hours of becoming aware, and will report to the relevant supervisory authority (UAE Data Office / national DPA for EEA users) where required by law.
Employee Training: All Syncly personnel with access to personal data complete mandatory data protection and security awareness training at onboarding and annually thereafter.
Vendor Due Diligence: All sub-processors are assessed for security compliance prior to engagement and reviewed annually. Sub-processors must maintain documented information security programmes.
14. Your Data Rights
Depending on your location and the legal framework applicable to your data, you hold the following rights. All requests should be submitted to hello@synclydigital.com. Syncly will respond within 30 days (extendable by a further 30 days for complex requests, with written notice). Requests are free of charge unless manifestly unfounded or excessive.
Right | What It Means | How to Exercise |
Right of Access | Obtain a copy of all personal data Syncly holds about you | Email request to hello@synclydigital.com |
Right to Rectification | Correct inaccurate or incomplete data held about you | Update in account settings, or email request |
Right to Erasure | Request deletion of your personal data (subject to legal retention obligations) | Account settings > Delete Account, or email request |
Right to Restriction | Pause processing while a correction or dispute is pending | Email request to hello@synclydigital.com |
Right to Portability | Receive your data in a structured, machine-readable format (JSON or CSV) | Email request to hello@synclydigital.com |
Right to Object | Object to processing based on legitimate interest, or to direct marketing | Account notification settings, or email request |
Right to Withdraw Consent | Revoke any consent given (social account OAuth, marketing emails) | Account settings > Connected Accounts or Notifications |
Right to Human Review | Request human review of any significant automated processing decision | Email request to hello@synclydigital.com |
Complaints: If you are not satisfied with how Syncly has handled a privacy matter, you have the right to file a complaint with the UAE Data Office (hello@synclydigital.com) or, for EEA residents, with your national Data Protection Authority.
15. Children’s Privacy
Strict Policy: The Syncly Platform is exclusively for users aged 18 and over. We do not knowingly collect or process personal data from anyone under the age of 18.
All users must confirm they are 18 or older at registration. Syncly may require additional age verification at any time.
If Syncly becomes aware that it has inadvertently collected data from a user under 18, the account will be immediately suspended and data deleted within 14 days.
Brand Users must not design Campaigns or Offers that specifically target individuals under the age of 18, or that promote products or services unsuitable for minors.
16. Social Account Connections & Revocation
Connecting an account: When connecting a social media account, Creator Users are redirected to that platform’s official OAuth authorisation page. Syncly receives only the data scopes explicitly approved. The requested scopes and their purposes are displayed before authorisation.
Revoking access: Creator Users can disconnect any social media account at any time via Settings > Connected Accounts. Disconnection immediately halts Syncly’s API access for that platform.
Effect of revocation: API-derived data from a disconnected account is queued for deletion within 30 days of revocation. Aggregate campaign performance data already incorporated into historical Monthly Reports is retained per the retention schedule in Section 11.
Re-connection: Users may reconnect accounts at any time. A new OAuth authorisation is required.
Third-party platforms: Syncly’s data practices are independent of TikTok’s, Meta’s, Snapchat’s, and Google’s own privacy policies. We encourage all users to review the privacy policies of each connected platform.
17. Third-Party Links & Integrations
The Syncly Platform may contain links to external websites, Brand landing pages, or third-party tools integrated for Campaign tracking purposes. Syncly is not responsible for the privacy practices or content of these external sites. Users access third-party links at their own risk. We recommend reviewing the privacy policy of any external website before submitting personal data.
18. Marketing Communications
Syncly sends promotional emails and push notifications only to Brand Users and Creator Users who have explicitly opted in to marketing communications during registration or via their account settings.
You may opt out of marketing communications at any time by clicking the “Unsubscribe” link in any marketing email, or by updating your preferences in Account Settings > Notifications. Opt-out requests are processed within 5 business days.
Opting out of marketing communications does not affect transactional notifications, which are required for the operation of your account (e.g., Campaign approvals, payment confirmations, Dispute updates).
Syncly does not share your email address or contact information with Brand Users or third parties for their own marketing purposes without your explicit consent.
19. Changes to This Policy
Syncly may update this Privacy Policy periodically to reflect changes in data practices, Platform features, legal obligations, or regulatory guidance.
Material changes will be communicated by email and in-app notification at least 14 days before they take effect.
Where a change requires a new legal basis for processing (e.g., processing data for a new purpose), Syncly will seek explicit consent before commencing that processing.
Continued use of the Platform after the effective date of a non-material update constitutes acknowledgement of the updated Policy. For material changes, continued use after notification and the opportunity to object constitutes acceptance.
A version history of this Policy is accessible in the Syncly Help Centre.
20. Contact & Data Rights Requests
To exercise your data rights, raise a privacy concern, or report a potential data breach:
Syncly FZ-LLC
Dubai, United Arab Emirates
General Privacy Enquiries: hello@synclydigital.com
Data Protection Officer: hello@synclydigital.com
Legal & Compliance: hello@synclydigital.com
Website: www.synclydigital.com
If you are a UAE resident and are not satisfied with our response to a data rights request or complaint, you may contact the UAE Data Office at www.dataoffice.ae. If you are an EU/EEA resident, you may escalate to your national Data Protection Authority.
Syncly Privacy Policy · v1.0 · July 2025 · All rights reserved.
Last updated July 22, 2026