Legal

Privacy Policy

Effective date: 23 July 2026

How we handle personal data for which we are the controller — account, security, and billing data — and the rights you have over it.

Draft for review. This document reflects how Zynth Auth actually operates and the frameworks it aligns to, but it is not legal advice and has not yet been reviewed by counsel. Terms are subject to change before general availability.

This policy applies to Zynth Media's processing of personal data as a controller. Our processing of your end-users' data on your behalf is governed by the Data Processing Addendum.

1. Who we are

Zynth Media ("we", "us") provides Zynth Auth, a multi-tenant identity and access management platform. This policy explains how we handle personal data for which we are the controller — primarily account, security, and billing data for the people who administer a Zynth Auth tenant, and visitors to this website.

Where we process the personal data of your end-users on your behalf (for example, the identities your organization manages in the platform), we act as a processor and those activities are governed by our Data Processing Addendum, not this policy.

2. Data we process

  • Account data — email address, name, and organization name you provide at sign-up.
  • Authentication data — password hashes (Argon2id; we never store plaintext passwords), encrypted MFA secrets, and passkey (WebAuthn) public-key credentials.
  • Security telemetry — IP address, user agent, and authentication/authorization events, used for anomaly detection and the tamper-evident audit log.
  • Billing data — plan and usage counts. Card details are handled by PayPal and never touch our systems.
  • Support communications — the content of messages you send us.

3. How and why we use it

  • To provide and operate the service (performance of our contract with you).
  • To secure the service — detecting brute-force, credential-stuffing, token theft, and other anomalies (our legitimate interest, and yours, in security).
  • To process payments for paid plans (performance of contract).
  • To communicate service, security, and account notices (legitimate interest / legal obligation).
  • To comply with legal obligations, and to establish or defend legal claims.

Under the GDPR our legal bases are contract, legitimate interests, consent (where we ask for it, such as optional analytics), and legal obligation. Equivalent bases apply under the Singapore PDPA and the Philippines Data Privacy Act.

4. Sharing and sub-processors

We do not sell personal data. We share it only with the sub-processors that help us run the service — hosting, transactional email, and payments — each listed with its purpose and location in our Data Processing Addendum. Every outbound connection from the platform is restricted by an egress allowlist, so data cannot flow to a destination we have not vetted.

5. Where your data is processed

The managed offering is hosted in Singapore (APAC region) to support data-residency and sovereignty requirements. Some sub-processors (email, payments, optional social sign-in) operate in the United States; where personal data is transferred internationally we rely on appropriate safeguards such as standard contractual clauses.

If you run Zynth Auth self-hosted, personal data stays entirely within your own infrastructure and this section does not apply.

6. How we protect it

  • Encryption in transit (TLS) and at rest.
  • Strict tenant isolation enforced at the database with Postgres row-level security, not just application code.
  • Fail-closed design — missing keys, unreachable dependencies, or ambiguous authorization result in denial, never insecure degradation.
  • A tamper-evident, hash-chained audit log; least-privilege database roles; and a signed, digest-pinned software supply chain.

7. Retention

We keep personal data only as long as needed for the purposes above or as required by law, and apply configurable retention policies to security and audit data (GDPR Art 5(1)(e) storage limitation). When you close an account, we delete or anonymize associated personal data within a reasonable period, except where retention is legally required.

8. Your rights

Depending on your location, you have rights to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent. Administrators can exercise many of these directly from the in-product Privacy & Data centre (data export and subject-request tools); you can also contact us at any time.

You have the right to lodge a complaint with your data-protection authority (for example, the Singapore PDPC, the Philippines NPC, or your EU/EEA supervisory authority).

9. Cookies and analytics

We use strictly-necessary cookies to keep you signed in (httpOnly, SameSite=Strict). We do not use third-party advertising or cross-site tracking. Any product analytics are first-party, privacy-preserving, and only enabled with your consent.

10. Children

Zynth Auth is a business product and is not directed to children. We do not knowingly collect personal data from children.

11. Changes and contact

We may update this policy; material changes will be posted here with a new effective date. For any privacy question or to exercise a right, contact us at security@zynthmedia.com or sales@zynthmedia.com.

Questions about this document? Contact sales@zynthmedia.com. See all legal documents.