Security and data handling

Where your data lives, how access is isolated between organizations, and how to delete your account.

Last updated: 2 min read
customer data securitydata privacy support conversationsdelete account datadata residency GDPR

Where your data lives

Production customer data is stored in the EU (AWS eu-central-1, Frankfurt), supporting GDPR data-residency expectations for EU customers.

Encryption

Data is encrypted in transit and at rest.

How organizations stay isolated

Every workspace is a logically isolated organization. Database-level Row-Level Security ensures a user can only read or write data belonging to an organization they're a member of — this isn't just an application-layer check, it's enforced at the database itself. Within an organization, access is further scoped by role (Owner, Admin, Analyst, Guest — see Inviting and managing team members).

Integrations are read-only

Every connected support tool (Zendesk, Intercom, Freshdesk, Freshchat, Gorgias) is authorized for read access only — Synthight cannot reply to your customers or modify records in the source system. See How integrations work.

Certifications

Synthight's infrastructure providers (Supabase, AWS) hold SOC 2, ISO 27001, and related certifications. Synthight's own independent SOC 2 program is on its roadmap and not yet held directly — ask support@synthight.com for the current security overview if this matters for your vendor review.

Deleting your account

Sidebar → Account → Settings → Delete Account. This permanently deletes your personal account and removes your data from Synthight's servers — it requires your password to confirm and can't be undone. This is different from deleting an entire organization; see Company profile settings for that.

Next steps

Frequently asked questions

Where is my data stored, and is it encrypted?
Production customer data is stored in the EU (AWS eu-central-1, Frankfurt), supporting GDPR data-residency expectations, and it's encrypted both in transit and at rest.
Can other organizations on Synthight access my organization's data?
No — database-level Row-Level Security isolates organizations, and it isn't just an application-layer check, it's enforced at the database itself. You can only read or write data belonging to an organization you're a member of.
Can connected tools like Zendesk or Intercom be modified by Synthight?
No. Every connected support tool is authorized for read access only — Synthight can't reply to your customers or modify records in the source system.
Is Synthight SOC 2 or ISO 27001 certified?
Its infrastructure providers, Supabase and AWS, hold SOC 2, ISO 27001, and related certifications. Synthight's own independent SOC 2 program is on its roadmap but not yet held directly — contact support@synthight.com for the current security overview.
How do I permanently delete my account and its data?
Go to Account → Settings → Delete Account and confirm with your password. This permanently deletes your personal account and removes your data from Synthight's servers and can't be undone — it's separate from deleting an entire organization.

Was this article helpful?