Skip to main content
Trust Center

Security, Privacy, and Compliance

How Syncra protects your workspace data and supports your compliance, procurement, and security review processes.

We work directly with IT, legal, and procurement teams. Documentation available on request.

Overview

Trust at a glance

No personal data collected

Power draw measurement only. No names, emails, cameras, badges, or individual tracking.

GDPR-aligned

Privacy-first data model. Data Processing Agreement available on request.

EU data residency

Customer data is processed and stored within the European Union.

Encryption

TLS 1.2+ in transit. AES-256 at rest.

Access controls

Role-based access controls with SSO integration for enterprise deployments.

Incident response

Documented incident response plan with 72-hour breach notification in line with GDPR.

Security documentation

Architecture overview, security policies, and questionnaire responses available under NDA.

Vendor onboarding support

Security questionnaires, DPA review, legal review, and architecture walkthroughs.

Data Protection

What Syncra collects, and what it does not

Syncra sensors measure electrical power draw at the desk level. Occupancy is inferred from anonymous power signals. No personal data is collected at any point in the pipeline.

What we collect

  • Aggregated power draw per outlet (watts)
  • Desk occupancy status (occupied / unoccupied)
  • Timestamps of status changes
  • Device health and connectivity metrics

What we never collect

  • Names, emails, or employee identifiers
  • Camera, video, or audio data
  • Browsing activity or application usage
  • Badge-in / badge-out identity data
  • Location tracking or GPS data

GDPR posture

Syncra's data model is designed around GDPR principles. Because the system captures only aggregated power draw, not information about individuals, it operates under a legitimate interest basis. Individual consent for occupancy sensing is not typically required.

Data minimisation

We practise data minimisation by default. Only the data necessary to deliver workspace insights is collected. Nothing more. A Data Processing Agreement (DPA) is available for all customers on request.

EU data residency

Customer workspace data is processed and stored within the European Union. Data is not transferred outside the EU without explicit agreement.

Security

Platform security

Security is built into every layer of the Syncra platform, from sensor hardware to cloud infrastructure to the end-user dashboard.

Encryption

All data transmitted from Syncra sensors to the cloud uses TLS 1.2+. Data at rest is encrypted using AES-256.

Network isolation

Syncra devices can operate on an isolated VLAN or dedicated IoT network, separate from your corporate infrastructure.

Access controls

The Syncra dashboard enforces role-based access controls. Only authorised personnel can view workspace data. SSO integration is available.

Audit logging

All dashboard access is logged with timestamps, user identifiers, and actions performed. A complete audit trail is available.

Data retention and deletion

Customers control their own data retention policy. Data can be purged automatically after a configurable period. Full deletion is available on request.

Monitoring and review

Ongoing security assessments of infrastructure, codebase, and operational processes. Periodic third-party security testing is part of our programme.

Framework Alignment

Standards we support

Syncra's architecture, data handling, and operational processes are designed to support organisations working within recognised compliance frameworks. Where Syncra is not certified against a standard, the platform is designed to align with its principles and support your compliance efforts.

ISO/IEC 27001

Information Security

Syncra's access controls, encryption, data handling, and security operations are designed to align with ISO/IEC 27001 requirements. Our goal is to protect your workspace data throughout its lifecycle.

ISO 50001

Energy Management

Syncra provides granular, real-time energy consumption data at the desk, zone, and building level. This supports organisations in establishing the monitoring and measurement processes required under ISO 50001 for continual improvement of energy performance.

ISO 45001

Occupational Health and Safety

Syncra continuously monitors the electrical behaviour of connected devices. Anomalous power draw is flagged in real time, helping facilities teams identify potential hazards before they become incidents. This supports electrical safety objectives and reduces reliance on periodic testing alone.

Privacy

Workspace analytics without surveillance

Many workspace tools rely on cameras, badge tracking, or device fingerprinting. Syncra takes a different approach.

How Syncra differs

  • Power draw measurement only. No biometric or visual data.
  • No individual tracking or profiling.
  • Employees do not need to opt in or change behaviour.
  • Data is aggregated at the desk or zone level before reporting.
  • No integration with HR or identity systems.

Employee communication

Syncra is designed to be transparent and non-intrusive. We recommend informing employees that occupancy sensing is in place, and we provide template communication materials to support this.

Because no personal data is captured, most organisations classify Syncra as a facilities management tool rather than an employee monitoring system.

Working With Your Team

Supporting your procurement and security review

We understand that deploying new technology in an enterprise environment involves input from multiple stakeholders. Syncra is set up to work with your procurement, IT, legal, and security teams throughout the evaluation and onboarding process.

  • Security questionnaires

    We can complete standard security questionnaires and custom formats. Typical turnaround is within one week.

  • DPA review

    A Data Processing Agreement is available and can be reviewed with your legal team.

  • Architecture review

    Detailed documentation of our data flow, infrastructure, and security controls is available under NDA.

  • Stakeholder calls

    We are available to join calls with your IT, security, legal, or procurement teams to answer questions directly.

  • Insurance documentation

    Syncra carries professional indemnity and cyber liability insurance. Certificates of insurance are available on request.

  • Incident response plan

    Our documented incident response plan is available for review as part of the onboarding process.

Documentation

Request our security and compliance pack

The following documentation is available to prospective and current customers. Some materials are provided under NDA.

  • Data Processing Agreement (DPA)
  • Security overview document
  • Architecture and data flow documentation
  • Completed security questionnaire (sample or custom)
  • Certificates of insurance
  • Incident response plan summary
  • Additional policies available on request

To request any of these documents, contact us at johnny@syncra.ie.

Ready to start your security review?

We can provide documentation, answer technical questions, complete your security questionnaire, or join a call with your IT, legal, or procurement team.