Legal

GDPR Compliance

Last updated: July 15, 2026

Our Commitment

Sinora AI is committed to protecting the privacy and personal data of all individuals, in compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR.

Data Processing Roles

Data Controller

Our customers are Data Controllers for the personal data of their end users — website visitors, customers, and leads.

Data Processor

Sinora AI acts as a Data Processor for customer conversations and knowledge base content stored on our platform.

Lawful Basis for Processing

Contractual Necessity

To provide the Sinora AI platform to our customers

Legitimate Interests

To improve our services and ensure platform security

Consent

For optional communications such as marketing emails

Legal Obligation

To comply with applicable laws and regulations

Your Data Subject Rights

Right of Access — request a copy of your data
Right to Rectification — correct inaccurate data
Right to Erasure — request deletion of your data
Right to Restriction — limit how we process your data
Right to Portability — receive data in a portable format
Right to Object — object to certain processing

To exercise any of these rights, email gdpr@sinorai.com. We respond within 30 days.

International Data Transfers

Data is stored on servers located in the European Union (EU) and the United States. For transfers outside the EU, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.

Data Protection Measures

AES-256 encryption at rest
TLS 1.3 encryption in transit
Multi-factor authentication
Regular security audits
Data minimization by design
Automated retention policies
Staff data protection training
Access controls with RBAC

Data Breach Notification

In the event of a personal data breach, we will notify affected customers within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

Data Protection Officer

Email: dpo@sinorai.com