SOKERENA UAB (registration code 308066941, Laisvės pr. 60, LT-05120 Vilnius, Lithuania) — referred to here as "AiSynth" — is the data controller for personal information processed via https://aisynth.cloud. This notice explains how we handle personal data under the EU General Data Protection Regulation (GDPR) and equivalent local rules.
What we collect
We process the following categories of personal data: (a) account information — the name and email address you register with, and a salted hash of your password; (b) provider and connector credentials that you supply so your patches can reach external services — held in encrypted form; (c) billing information, where the actual card details are processed by our payment provider and never stored on our systems; (d) the content you put into the studio and what comes out of it — the patch configurations you build, the prompts and files you submit, the outputs each pass produces; (e) operational telemetry — passes dispatched, tokens reserved, debited and released, ledger entries, REST-API activity, IP addresses, browser and device signals. Cookies are covered separately in the Cookie Policy. Please keep sensitive personal data (health, biometric, government identifiers and similar special-category information) out of the material you feed into patches.
Why we process it
• To operate the studio and deliver the results of your passes — performance of the contract between us.
• To take payment and keep accounting records — performance of the contract and compliance with legal obligations.
• To provide support, secure the platform, investigate abuse and improve reliability — our legitimate interests.
• For non-essential cookies and any direct marketing — on the basis of your consent, which you may withdraw at any time.
We do not use your inputs, your outputs or your pipeline data to train our own AI models.
Who we share it with
To run a pass, we transmit the necessary inputs to the AI providers and connected services that the pass calls — either the shared providers we operate the studio through, or the accounts you have linked yourself. Beyond that, personal data is shared only with the vendors that help us run the platform: hosting infrastructure, email delivery, analytics, customer support and payment processing, all bound by contractual data-processing terms. We do not sell personal data. We disclose data to public authorities only where we are legally required to, and where possible we push back on overly broad requests.
International transfers
Some of our processors are located outside the European Economic Area. Where personal data is transferred to a third country, we rely on the safeguards permitted by GDPR — most commonly the European Commission's Standard Contractual Clauses, or a valid adequacy decision for the destination country.
How long we keep it
Account records are retained while your account is active and for a short wind-down period afterwards. Ledger and invoicing records are kept for the period required by tax and accounting law in Lithuania (typically up to ten years). Operational telemetry and support logs are kept only for as long as they remain useful for security and troubleshooting, and are otherwise deleted or aggregated.
Security
We use encryption in transit and at rest, encrypted storage for provider secrets and connector credentials, role-based access controls, key rotation, and monitoring for unusual activity. No system is impenetrable — where a personal data breach affects you and the law requires notification, we will notify you and the competent regulator within the statutory time limits.
Your GDPR rights
You have the right to access your personal data, to have it corrected, to have it deleted, to restrict or object to particular processing activities, to receive a portable copy, and to withdraw any consent you have given (without affecting the lawfulness of processing before withdrawal). Write to [email protected] with your request; we aim to reply within one month of receipt, as GDPR requires. You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI, https://vdai.lrv.lt) or with the supervisory authority of the EU member state where you live or work.
Children
AiSynth is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided data to us, contact [email protected] and we will remove it.
Changes to this notice
We update this notice as the service and the applicable rules evolve. The "last updated" date on the cover reflects the current version, and material changes will be flagged in the studio in advance.
Contact
SOKERENA UAB · Company code 308066941 · Laisvės pr. 60, LT-05120 Vilnius, Lithuania · +370 666 11579 · [email protected]