SyncMacro, Inc.
Privacy notice.Short, because we collect little.
This site has no accounts, no analytics and no advertising. The only personal data we ask you for is what you type into the contact form — and the only things kept in your browser are your language choice and your answer to the storage banner.
Effective 18 August 2026. We will note material changes here and update this date. This notice is published in English only; the English text is the authoritative one. Ask us through the contact form if you need it in another language.
Who is responsible for your data
The data controller is SyncMacro, Inc., a company registered in the United States.
For anything in this notice — including access, correction or erasure requests — use the contact form and say what you need. We answer within one month, as required.
We have not appointed a Data Protection Officer. Nothing we do meets the threshold in Article 37 of the GDPR that would require one.
What we collect, and when
We ask you for data only when you submit the contact form. Reading the site collects nothing beyond the request log that any web server keeps — see Who receives it below for who keeps it and why.
- You give us. Your name, work email, and message. Optionally your organization, phone number, the type of site you are protecting, what you are asking for — a briefing, pricing, the catalogue, a spec sheet, a job application or something else — and, if you are applying for a role, which one.
- The form adds. The address of the page you submitted from, and the language the page was displayed in.
- Our provider receives. Your IP address, browser type and referring address, which reach Formspark as part of the submission. We do not use these for anything ourselves; they exist for delivery and spam filtering.
We do not collect special-category data, and we ask you not to send it.
One request specific to what we do. This is a public web form, not a secure channel. Please keep detailed site-security information — sensor placements, coverage gaps, guard force posture, floor plans — and any export-controlled or classified technical data out of it. Tell us at a high level what you are trying to protect; we will move to an appropriate channel before anything sensitive is exchanged.
Why we process it, and on what basis
- To answer your enquiry. Where you are asking about a briefing, pricing, the catalogue or a spec sheet, this is Article 6(1)(b) — steps taken at your request before entering a contract. Where it is a general enquiry, it is Article 6(1)(f), our legitimate interest in responding to people who contact our business. You can object to that at any time.
- To consider a job application. Article 6(1)(b), and our legitimate interest in recruiting.
- To keep the form usable. Article 6(1)(f), our legitimate interest — and yours — in a contact channel that is not drowned in automated spam.
Providing your name, email and message is necessary for us to reply. Everything else is optional.
Who receives it
We name our processors rather than referring vaguely to “partners”.
- Formspark receives and stores the submission. Data is held in Ireland, on Amazon Web Services (eu-west-1). Its own sub-processors include Amazon Web Services, OOPSpam (spam detection), Postcraft (notification email rendering) and Sentry (error reporting).
- Vercel hosts this website. Delivering a page means its servers see your IP address and the ordinary request metadata that comes with it — the page requested, the browser, the referring address — in short-lived operational logs kept to serve the site and protect it from abuse. Vercel never sees what you type into the form: your browser posts that straight to Formspark.
- Botpoison (Hyperping ApS) supplies the form’s spam defence. When you press send — and at no other time — your browser solves a short arithmetic puzzle with api.botpoison.com, which sees your IP address and the ordinary request metadata in doing so. It receives none of the content of your message.
- Our email provider delivers the notification to us and carries any reply back to you.
Nothing else is involved. The form has two spam defences: a hidden field that automated submitters fill in and people never see, which stores nothing in your browser and sends nothing anywhere; and the Botpoison puzzle described above, which runs only when you press send. Neither sets a cookie, and neither profiles you. If a submission of yours is ever dropped in error, write to us from your own email and we will pick it up there.
We do not sell your data, share it for advertising, or pass it to anyone else except where the law requires it.
Where it goes
Submissions are stored in Ireland, on infrastructure our form provider operates there. SyncMacro, Inc. is a United States company, so when we read and reply to your message the data is accessed from the United States.
The pages themselves are a separate path. Our host runs a global network and serves them — and keeps the short-lived request log described above — from whichever region is nearest to you. Nothing you type into the form travels that way; it goes straight from your browser to Formspark.
How long we keep it
- Enquiries. We keep them for as long as we are in contact with you about what you asked, and for a reasonable period afterwards in case you come back to us. Then we delete them.
- Job applications. We keep them after the role closes so we can come back to you if something similar opens. Ask us and we will delete them sooner.
- In our form provider. Formspark does not publish a default retention period; we delete submissions from its dashboard on the schedule above.
Cookies and browser storage
This website sets no cookies. There is no analytics, no advertising, no tag manager and no tracking of any kind. Every font, stylesheet, script and image is served from this domain, so reading the site contacts no third party other than the host that serves it. The only requests that ever leave our domain happen when you press send: the spam-defence check with Botpoison, and the submission itself to Formspark. Reading the site makes neither.
Two things are kept in your browser’s local storage, both of them for you (and if your browser blocks that, only for the current session):
- Your language choice, under the key sm-lang, written once you pick a language from the switcher and re-saved on later visits so the choice survives. It holds a two-letter code and nothing else. Until you choose, nothing is written: a page shown in your browser’s own language is not recorded.
- Your storage choice, under the key sm.consent.v1, so we can honour it on your next visit. It holds the preference itself, the moment you made it, and a version number for the format — nothing else.
Both are strictly necessary for something you asked for — there is no way to remember a preference without recording it — and neither identifies you or follows you anywhere. Neither is a cookie: a cookie would be the one cookie this site sets, which would make the statement above false.
We show a banner anyway, so that the analytics choice is yours to make before we would ever add any — and today there is none to enable. You can change your answer at any time from the link in the footer.
Do Not Track. We do not track you across other websites or over time, so there is nothing for a Do Not Track signal to switch off. We do not respond to DNT headers for that reason.
Other parties. No third party collects personal information about your activity on this site, or across other sites, through anything we have put here. Every font, stylesheet, script and image is served from our own domain.
Your rights
If you are in the UK or the EEA you have the right to access your data, correct it, erase it, restrict or object to how we use it, and receive it in a portable form. Where we rely on consent you can withdraw it at any time, without affecting what came before.
Ask through the contact form and we will act on it. If you are unhappy with how we handle it, you can complain to your data protection authority — in the UK, the Information Commissioner’s Office at ico.org.uk; in the EEA, your national supervisory authority.
Automated decisions, and California
We make no automated decisions that produce legal or similarly significant effects about you. Our form provider’s spam filtering can reject a submission it scores as automated, and the hidden field described above will drop one if something — a password manager, say — fills it in for you. If that happens, try again from a different browser, or simply email us. Nothing about you is recorded when it does.
For California residents: we do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
We reply to every inbound from a real organization, usually within two working days.