// legal
Privacy policy
What this website collects, which company sees it, and how to get rid of it. This describes the site we actually built, tool by tool.
01 Who we are
Synapse Research Ltd runs this website and decides what happens to the data described below. Under the GDPR that makes us the controller.
- Company number: 515882744, registered in Israel.
- Registered office: Shmuel Shnitzer St 4, Tel Aviv-Yafo 6958313, Israel.
- Privacy contact: ben@synapsereality.io. Ben reads every request and answers it himself.
We have not appointed a Data Protection Officer. We have no representative in the EU or in the UK either. Send every privacy request to the address above.
02 The short version
- Our own server logs each form you send, each audit you run and each unsubscribe. It sets no cookie unless you accept analytics, stays on our infrastructure and never holds your IP address.
- Three third-party analytics tools can run: Google Analytics 4, Microsoft Clarity and PostHog. In the EU, the EEA, the UK and Switzerland they load only after you accept them. Elsewhere they load on every visit, once you scroll, click, tap or press a key. If you do none of that, they load after about 12 seconds.
- Fill in a form and what you typed lands in our own database. Our emails go out through Resend and record when you open them or click a link.
- We do not sell personal data, and this site carries no advertising pixel.
- There is no login, no payment and no account on this site, so there is nothing else to hold.
03 What we collect
Forms, audits and unsubscribes
Our server writes one row to a table called visitor_event when you send a form, run the audit tool or unsubscribe. Reading a page does not write a row.
The row records the path, the time, the site you came from and your browser's user agent string. It also keeps your browser language, device type and any campaign tags in the link. Cloudflare adds the country, region, city and network of the connection. An ad blocker does not stop it, which is why we rely on it instead of on a tag.
It never stores your IP address. To tell one visit from the next, it uses a code made from your connection and browser. That code changes every day and cannot be turned back into an address. If you accept analytics, it sets a cookie called sy_vid instead. It holds a random ID for 13 months, so your later actions join up with earlier ones. Declining, or withdrawing consent later, deletes it.
Anything you type into a form
The contact form, the lead forms and the instant audit tool post what you typed to our own API on this domain. That is your name, your email address, your message, and the URL you asked us to look at if you used the audit tool. We use it to answer you and to run the work you asked about. Your email address reaches two places, our database and Resend, which delivers the mail.
The forms also carry a hidden field that only a bot fills in, and we limit how often one address can send. Both exist to stop spam, and neither is used to profile you.
Email we send you
Automated mail comes from hello@synapsereality.io. Resend sends it from its EU region, in Ireland. Replies reach Ben.
- Marketing and follow-up emails record when you open them, through a tracking pixel. They also record the links you click, which pass through links.synapsereality.io on the way.
- The acknowledgement we send after an enquiry records delivery, opens and clicks in the same way.
- The newsletter uses double opt-in. Nothing is subscribed until you click the link in the confirmation email.
- Every commercial email has a one-click unsubscribe.
None of this is a cookie. The pixel and the links live in the email, so the cookie banner does not change them. Blocking remote images in your mail app stops the open record.
Analytics, if you accept them
The three third-party tools below measure which pages lead to an enquiry. In the EU, the EEA, the UK and Switzerland they are off until you say yes. Refusing them costs you nothing on this site.
04 Who processes it
This is the whole chain. If a company is not in this table, it does not touch data from this website.
| Who | What it does here | What it sees | Browser storage | Runs in the EU, EEA, UK and Switzerland |
|---|---|---|---|---|
| Cloudflare | CDN, DNS, firewall and the tunnel the site is served through. Every request passes it. | IP address, requested URL, user agent, TLS and request metadata. | May set __cf_bm and cf_clearance for bot management and challenges. Strictly necessary. | Yes. It is the network the site runs on. |
| Cloudflare Zaraz | Loads and runs the Google Analytics tag from our own domain at Cloudflare's edge instead of from googletagmanager.com. | The same page data GA4 would see, before passing it to Google. | The GA4 client identifier, written through Zaraz. | Only after you accept. |
| Google Analytics 4 | Traffic and audience measurement. | Page URL, referrer, device and browser, coarse location, a client identifier. | Yes. Non-essential, so it waits for consent. | Only after you accept. |
| Microsoft Clarity | Session replay and heatmaps, so we can see where a page confuses people. | Pointer movement, scrolling, clicks and page structure. Clarity masks text input by default. | Yes. Non-essential, so it waits for consent. | Only after you accept. |
| PostHog | Product analytics, hosted in PostHog's EU cloud. Events go to /ingest/ on this domain first, and our server forwards them. | Pages viewed, funnel events such as starting a form, and a device identifier once you consent. | None until you accept. If you refuse, PostHog counts you with a rotating hash and stores nothing in your browser. | Only after you accept. |
| Cloudflare Web Analytics | Cookieless page counts and Core Web Vitals. | Page URL, referrer, coarse device data, loading timings. | None. It sets no cookie and builds no cross-site identifier. | Yes. It sets no cookie and stores nothing in your browser. |
| Resend | Sends our automated mail from hello@synapsereality.io, from its EU region in Ireland. Reports delivery, opens and link clicks. | Your email address, your name, the content of that message, and when you open it or click a link in it. | None. Open and click tracking lives in the email itself and sets no cookie. | Yes, for mail we send you. Nothing loads in your browser. |
| Synapse, on our own server | The visitor_event log, the form database, the sy_vid cookie, and the API behind them. | Everything in section 03. | None. | Yes. |
Each of these companies is used under its own data processing terms, which allow it to act on our instructions and forbid it from using what it sees for its own purposes.
05 What EU, EEA, UK and Swiss visitors get
If Cloudflare reports your connection as coming from the EU, the EEA, the UK or Switzerland, you see a consent banner. Until you accept, no Google Analytics, no Clarity and no PostHog loads. You get the page, our own server-side log, and Cloudflare Web Analytics, which counts the visit without a cookie or any identifier.
How that decision is made: the page asks Cloudflare's /cdn-cgi/trace endpoint which country its edge saw, and only then decides whether anything else may load. If that request fails, times out or answers something unexpected, we treat you as a visitor who has to be asked. The check looks at the connection, so a VPN exit in Frankfurt reads as European, and a European on a US exit does not.
06 Why we are allowed to hold it
- Legitimate interests for the first-party log, the firewall and the spam checks. We have to know the site works and keep it from being abused, and the data involved is thin.
- Consent for Google Analytics, Clarity and PostHog in the EU, the EEA, the UK and Switzerland. You can take it back later. Elsewhere, our legitimate interest in measuring how the site is used.
- Steps taken at your request before a contract when you send an enquiry, plus our legitimate interest in replying to it.
- Legal obligation for the records we have to keep, such as an unsubscribe suppression list and proof of what you consented to.
07 Where it goes
We are based in Israel, which the European Commission has recognised as providing an adequate level of protection, so data reaching us needs no extra transfer mechanism.
Google, Microsoft, PostHog, Cloudflare and Resend are US companies with global infrastructure. Transfers to them rely on the mechanism set out in each one's data processing agreement, which is the EU standard contractual clauses, the EU to US Data Privacy Framework, or both.
Two of them keep our data in Europe. PostHog holds it in its EU cloud in Frankfurt, and it discards your IP address before anything is stored. Resend sends our mail from its EU region in Ireland.
08 How long we keep it
- The visitor_event log: 13 months.
- Form submissions and the CRM record: 24 months after our last contact with you.
- Audit tool jobs: deleted after 24 hours.
- Resend delivery logs: 30 days, which is Resend's retention for our plan.
- Google Analytics 4: set to 14 months, the longest a standard property allows.
- Microsoft Clarity: session recordings 30 days, heatmap data 9 months. Microsoft sets both.
- PostHog Cloud EU: event data up to 7 years under PostHog's terms, and session replays up to 90 days.
- Cloudflare Web Analytics: 6 months.
One record has no end date. We keep an unsubscribe for as long as the address is suppressed, because deleting it would let the mail start again.
09 Your rights
If the GDPR or the UK GDPR applies to you, you can ask us to show you what we hold, correct it, delete it, limit what we do with it, hand it over in a portable file, or stop processing that rests on legitimate interests. You can withdraw consent for analytics whenever you like, which stops collection from that moment but does not undo what came before.
Email ben@synapsereality.io. Ben answers inside one month, which is the statutory limit, and we do not charge for it.
You can also complain to a supervisory authority: the one in the EU country you live in, or the Information Commissioner's Office in the UK. If you are in Israel, the Protection of Privacy Law gives you a right to see and correct data held about you, and the Privacy Protection Authority takes complaints.
10 Children
This site sells services to businesses. It is not aimed at children, we do not knowingly collect anything from them, and Microsoft's own terms forbid running Clarity on a site that targets under-18s. If you think a child has sent us something, tell us and we will delete it.
11 Changes to this page
The date at the top is real. If we add a processor or change what we collect, that date moves and we say what changed. Adding a tool quietly would make this page a lie, which defeats the point of writing it.
Asking us something about this
Privacy requests go to ben@synapsereality.io. Anything else about the site goes through the contact page. A security problem has its own route: report it here.