GDPR
Data processing: documents, roles and responsibilities.
This page explains how LOCRAI processes data on the platform — especially the documents you upload and the fields we extract. It does not replace the privacy policy, which covers the website and people who contact us. Technical measures (isolation, encryption, access) are on the security page.
- 01
Controller and processor
On the LOCRAI service the customer is controller of the documents and extracted data. Syncronika Srl acts as processor (GDPR Art. 28) on the customer's behalf. On locrai.com (visits, forms, cookies) Syncronika is controller: details are in the privacy policy.
- 02
What data we process
Uploaded or received files (PDFs, images, XML), document metadata, extracted fields and line items, plus account and organisation data needed to run the service. We process only what is required to deliver the IDP you contracted.
- 03
Why we process it
Purpose: extract, verify and deliver data to your ERP or the APIs you configure. Legal basis: performance of the service contract. We do not use platform documents for marketing.
- 04
Where processing happens
Hosting, storage and AI processing of service documents are entirely in the European Union. Customer files do not leave the EU perimeter for storage or analysis.
- 05
Data Processing Agreement
Business customers are covered by a GDPR Art. 28 DPA, which forms part of the contract. It is available on request, before or when activating the service, at [email protected].
- 06
Retention and deletion
Retention is configurable per organisation. Beyond that window, documents are deleted automatically and permanently. You can request deletion of a single document or an entire organisation.
- 07
Artificial intelligence
AI runs on EU infrastructure and on defined tasks (classification, extraction, interpretation). Service documents are not used to train third-party models.
- 08
People's rights
Access, rectification, erasure, restriction, objection and portability remain available. For data in the platform, the first contact is the controller (the customer who uploaded the documents). For the website, write to [email protected]. You may also lodge a complaint with your supervisory authority.
Questions on processing
Yes. The Art. 28 DPA is part of the contract and can be requested before activation.
Yes. Storage and compute for service documents are in the European Union.
No. Service documents do not train third-party models.
In the privacy policy, with controller, legal bases, sub-processors and rights. This page is the operational picture of processing on the platform.
Need the DPA or a DPO questionnaire?
Write to us: we send the DPA, processing details and what your due diligence requires.
