Privacy at Synk

JABP GROUP PTY LTD · Updated 6 October 2026 · Version 2026-10-06.production-1

Who to contact

JABP GROUP PTY LTD operates Synk. Contact our privacy team at privacy@synkai.co to ask a question, request a copy of this information in another format, or raise a concern. You can ask general questions anonymously or use a pseudonym.

Information we handle

We handle account names, email addresses, organisation and group memberships, account preferences, dated records of your terms acceptance and privacy-policy acknowledgement, training activity, conversation transcripts, generated feedback and evaluations you submit. Voice interactions send audio to speech services. Uploaded documents, images or voice references may also contain personal information. Security and service diagnostics can include technical identifiers and activity records.

You provide information when signing up, training, uploading material or contacting us. Your organisation may also provide your name and email to invite you. Account details are needed to secure accounts and associate training with the correct person and organisation. You can choose not to start a voice session or upload material.

Why it is used and who can see it

We use information to provide training, generate conversations and feedback, manage access, support users, understand service performance, and protect the platform. Authorised administrators of your organisation can access training records and reports. Synk staff may access information for administration, support, security and privacy requests.

Synk uses external hosting, database, authentication, email, speech, AI and communication services. The services involved depend on the feature and configuration. Information may be processed outside Australia. For speech-driven avatar animation, generated character speech may be processed by rented GPU hosts. Our avatar animation provider notice identifies the reported locations, including the Australian standby hosts available to production and development, and outstanding access and retention checks. Contact us for details about the services and processing locations relevant to your organisation.

Your organisation determines its own training purposes and how it uses reports. Ask it whether results are used in employment, education or other decisions about you. AI feedback is a generated assessment and can be wrong. It requires human review before consequential use.

AI conversation providers and failover

The following list describes the providers for Cerebras Qwen character conversations, including live training and text previews. It is not the complete list of Synk hosting, speech and other service providers; contact us for the providers relevant to your organisation.

This production release enables the same-model Cerebras-to-Groq failover already used in development. It applies only to supported Qwen character conversations and previews, not every character or Synk AI feature.

Development and testing use a separate Cerebras account for their Cerebras requests, including superadministrator sessions, text previews, avatar-design suggestions and Character Lab tests. Depending on the feature, Cerebras receives character instructions, conversation text (which may include transcribed speech), design descriptions, test prompts and related settings, and returns generated responses. This account change does not add raw microphone audio to Cerebras requests. It applies to the configured development and test environments, not only to a user role; production keeps its existing account. The credential is held on the server and is not distributed to users.

The development account has separate account administration, billing and usage records. Its inference contract, processing and support locations, model-training treatment and retention or deletion controls remain to be verified for that account; another account’s settings are not evidence of its controls. We have not moved historical provider-held records or established that those records have been deleted.

Information may be processed outside Australia. Groq states that inference content is not retained by default, but may be logged for reliability or abuse investigations for up to 30 days, or longer when legally required, unless the applicable zero-data-retention setting is enabled. Groq retains usage metadata and describes retained customer content as stored in the United States. We have not verified Synk’s account-specific zero-retention settings or all inference and support locations for these providers; no Australian-only processing or universal zero-retention promise is made.

See Groq’s data handling information and Cerebras’s privacy information. Ask our privacy team about the configuration, locations, retention or deletion arrangements relevant to your organisation. Policy acknowledgement does not replace any separate consent or customer notification obligation.

Avatar service change

This release removes the Streamoji creator, authentication, import and sync integrations and external avatar-thumbnail fallbacks from production. Existing models and preserved thumbnails are served from Synk storage. Historical information held by Streamoji or its infrastructure providers has not been confirmed deleted; account closure, provider identity and deletion arrangements remain under review.

Speech and live communication

Deepgram receives microphone audio for speech recognition through its configured Australian API endpoint. That endpoint does not establish that all provider support, logs or other handling stays in Australia. Daily carries live audio and conversation transcript messages to the session participants; transcript messages now use the existing SDK connection. Account-specific retention, support-access locations and deletion controls remain separate checks. No Australian-only processing or universal zero-retention promise is made.

Keep training material appropriate

Use fictional personal details in role-play. Do not include real client records, sensitive health information, passwords, passport numbers, Medicare numbers or other government identifiers unless an authorised, specifically assessed workflow requires it. Report accidental disclosures through the form below so they can be reviewed and removed or restricted where appropriate.

Security and retention

We use account authentication and access controls to restrict information to authorised users. Information is held in application databases, file storage and the systems of relevant service providers. Retention depends on the record, training purpose, organisation arrangements and applicable obligations. Request deletion or ask for the retention arrangements that apply to your records using the contact details below.

If you neither log in nor use a training session for 365 consecutive days, we email you a deletion notice. The notice gives you 30 days to log in and stop automatic deletion. If you remain inactive, we automatically delete your account and associated training records in the first daily deletion run at least 31 days after sending the email. Logging in or using a training session before deletion cancels the pending deletion and starts a new 365-day inactivity period.

The automatic deletion schedule has the following exceptions. Administrator accounts, unfinished signups, accounts without an email address, accounts that own shared media, and accounts with a retention hold or unresolved privacy request require review before automatic deletion. Backups, records needed for legal obligations, and information subject to a preservation requirement may need separate handling. If you ask us to delete your data separately from this automatic process, we assess that request before taking action.

Privacy breaches

We investigate suspected privacy breaches promptly and take steps to contain them. We notify affected customer organisations as soon as practicable after becoming aware of a suspected or confirmed breach affecting their information, and meet any shorter contractual notification period. Where notification is required by applicable law, we notify the relevant privacy regulator and affected individuals as soon as practicable after becoming aware that the breach is notifiable, subject to lawful exceptions. We provide further information as it becomes available rather than waiting for the investigation to finish.

Access, corrections and complaints

You can edit your name in Settings. Sign in to download available account records or submit and track a request. You can also contact us without an account using the form below or email. We may ask for proportionate evidence of identity before releasing or changing personal information. Do not send identity documents with your initial request.

For corrections, identify the record and explain the proposed correction. You can dispute a transcript or generated assessment, request an associated statement if a correction is refused, and ask us to notify recipients of a correction. We do not charge for correction requests. We respond to access and correction requests as soon as reasonably practicable and aim to do so within 20 calendar days. Where the New Zealand Privacy Act applies, we notify you of our decision no later than 20 working days after receiving your request, unless a lawful extension applies. If we extend that deadline, we notify you within the original period, explain the reason and new timeframe, and explain your right to complain. Information approved for release is provided without undue delay.

To complain, describe what happened and the outcome you seek. If we refuse a request, we will explain the reasons and available complaint options. If you are dissatisfied after giving us an opportunity to respond, you may contact the Office of the Australian Information Commissioner for Australian privacy matters, or the New Zealand Office of the Privacy Commissioner for New Zealand privacy matters.

You may ask us to stop using or disclosing your information for direct marketing, and ask where that information came from. Account-security and service messages are handled separately from promotional communications.

Contact the privacy team

We use the information in this form to handle your request. Only authorised Synk staff can review the case. Include a record or session reference where possible; do not include passwords, identity documents or unnecessary sensitive information.

You can also email privacy@synkai.co.