Data Deletion Instructions
- Version 1.0
- Last updated: 01/10/2026
1. Purpose
These Data Deletion Instructions describe the procedures under which personal data processed in connection with the services of Synapse 42 and the Kubrik 21 platform may be deleted.
They supplement the General Terms of Use and the Privacy Policy of Synapse 42.
Their purpose is, in particular, to specify the procedures enabling a person to request the deletion of their personal data, the consequences of deleting an account, the situations in which certain data may be retained, as well as the procedures applicable when Kubrik 21 is used by a client company.
Data deletion is carried out in accordance with Regulation (EU) 2016/679 ("GDPR"), other applicable regulations and, where Synapse 42 acts as a processor, the documented instructions of the controller and the applicable contractual provisions.
2. Scope
These instructions apply to personal data processed in connection with the Synapse 42 website, user accounts, Kubrik 21 and associated services.
They may in particular concern data relating to users, consultants, candidates, prospects, client representatives, employees or any other person whose personal data is processed within the Services.
They also apply to data entered into Kubrik 21 by a client when Synapse 42 acts as a data controller.
Where Synapse 42 acts as a processor on behalf of a client, the deletion procedures are determined primarily by the contract and DPA entered into with that client.
3. General principle
Synapse 42 does not retain personal data beyond the period necessary for the purposes for which it is processed, except where additional retention is required or permitted by applicable regulations.
When data is no longer necessary and no obligation justifies its retention, it is deleted or anonymized.
However, the right to erasure provided for by the GDPR, also known as the "right to be forgotten," is not absolute. In certain situations, Synapse 42 may be legally permitted or required to retain certain data despite a deletion request.
4. Who can request data deletion?
Any data subject may request the deletion of their personal data where the conditions provided for by applicable regulations are met.
Where a person has a Kubrik 21 account and the deletion feature is provided directly in their user area, they may use this feature to request or initiate the deletion of data associated with their account.
Where such a feature is not available, the request may be submitted to Synapse 42 in accordance with the procedures described in the section "How can I request the deletion of my data?".
Where data is processed on behalf of a client company, the request should, in principle, be submitted to the relevant data controller. Synapse 42 may then assist that controller in fulfilling the request in accordance with the applicable DPA.
5. Deletion of a user account
When a user requests the deletion of their account, Synapse 42 deletes or anonymizes the data associated with the account to the extent that retention is not necessary.
Deletion may in particular result in the permanent deactivation of access credentials and the deletion of personal information directly associated with the account.
It may also result in the loss of access to documents, histories, preferences or other information accessible exclusively through that account.
Deleting an account does not necessarily mean that all associated data is immediately deleted from all Synapse 42 systems. Certain data may be retained where it is subject to a legal obligation, necessary for the defense of Synapse 42's rights, or covered by backup and Service continuity mechanisms.
6. Deletion of specific data
A person may also request the deletion of certain data without requesting the deletion of their entire account.
The request may in particular concern profile data, contact details, documents, professional information, application data or other personal information.
Where deleting data is compatible with the purposes of processing and applicable obligations, Synapse 42 deletes it from the relevant systems.
Where data cannot be deleted immediately, Synapse 42 explains, where required by applicable regulations, why it must be retained and, where relevant, the applicable retention period or criterion.
7. Documents and files
Kubrik 21 may allow the storage of documents containing personal data, including CVs, contracts, invoices, supporting documents, expense reports, timesheets or administrative documents.
When a document is deleted pursuant to a valid request, Synapse 42 deletes it from the relevant active environments.
However, deleting a document may not result in its immediate erasure from all existing technical copies.
In particular, certain copies may temporarily remain in backups, replication systems, caches or technical logs necessary for the security and continuity of the Services.
These copies are deleted or become inaccessible in accordance with the applicable technical cycles.
8. Data contained in backups
Synapse 42 may retain backups of its systems to ensure continuity of the Services and enable restoration in the event of an incident.
Therefore, when data is deleted from a production environment, it may temporarily remain in an earlier backup.
Backups are not used as routine operational environments, and access to them is limited to authorized persons and processes.
Deleted data is progressively removed from backups in accordance with the applicable rotation and expiration cycle.
The temporary retention of data in a backup does not prevent its deletion from active environments where the conditions for deletion are met.
9. Data subject to a legal retention obligation
Certain data cannot be deleted immediately due to legal or regulatory obligations.
This may in particular concern certain data relating to accounting, invoicing, contracts, tax obligations or evidence of transactions carried out.
In this case, Synapse 42 retains only the data necessary to comply with the relevant obligation and limits its use to the purpose justifying its retention.
When the statutory retention period expires, the relevant data is deleted or anonymized in accordance with the applicable procedures.
10. Data necessary for the defense of rights
Synapse 42 may retain certain data where it is necessary for the establishment, exercise or defense of legal claims.
Such retention is limited to the relevant data and to the period necessary for the purpose concerned.
When the reason justifying such retention no longer applies, the data is deleted or anonymized where its retention is no longer necessary for another legitimate purpose.
11. Data necessary for security
Certain technical information may be retained temporarily after an account or other data has been deleted.
This may in particular include security logs, authentication information, technical events or data necessary for incident analysis.
This information may be retained where necessary to detect or prevent fraudulent behavior, analyze a security incident, protect the Services or comply with a legal obligation.
It is retained for a period proportionate to the purpose pursued.
12. Data processed on behalf of a client
Where Synapse 42 provides Kubrik 21 to a client company and acts as a processor, Synapse 42 does not independently decide on the deletion of data processed on behalf of that client.
The client determines the purposes of processing and the rules applicable to data retention.
In this context, deletion requests should, in principle, be submitted to the relevant client.
Where Synapse 42 directly receives a request concerning data that it processes on behalf of a client, it may forward that request to the relevant data controller or provide the assistance stipulated in the DPA.
At the request of the data controller and in accordance with the applicable contractual provisions, Synapse 42 deletes or returns the relevant data.
At the end of a contract, the procedures for returning, exporting and deleting the client's data are those provided for in the applicable contract and DPA.
13. Data relating to consultants and candidates
As Kubrik 21 may be used to manage professional profiles, consultants and candidates, certain data may be retained as part of a recruitment or profile search process.
Where an application or profile is managed directly by Synapse 42, the data subject may request the deletion of their data in accordance with the applicable rules.
Where the profile is managed on behalf of a client, requests must be submitted to the relevant data controller.
Deleting a profile may result in the deletion of professional information and associated documents, except for data whose retention remains necessary to comply with a legal obligation or for another legitimate purpose.
14. Data relating to prospects
Data relating to prospects may be retained for the period necessary to follow up on a potential business relationship.
A person may request at any time, where the applicable conditions are met, the deletion of their data or restriction of its use for marketing purposes.
Where data must be retained for another legitimate purpose, in particular to demonstrate the exercise of a right or comply with a legal obligation, Synapse 42 limits its use to that purpose.
15. Billing and financial data
Certain financial or billing data may be subject to legal retention obligations.
A deletion request therefore does not necessarily result in the immediate deletion of all information contained in an invoice, accounting document or supporting document where its retention is required by applicable regulations.
Where retention is mandatory, Synapse 42 limits the use of such data to what is necessary to comply with the relevant obligation and to defend its rights.
16. Data relating to timesheets and expense reports
Timesheets, expense reports and supporting documents may be associated with contractual, accounting, tax or administrative obligations.
The deletion of such data therefore depends in particular on the person responsible for the processing, the applicable contract and the relevant legal obligations.
Where they are processed on behalf of a client, Synapse 42 applies that client's instructions in accordance with the DPA.
Where they are processed by Synapse 42 for its own purposes, they are retained for the periods necessary for the relevant purposes and applicable legal obligations.
17. Deletion requests related to artificial intelligence features
Where personal data has been processed by an artificial intelligence feature of Kubrik 21, deletion of the source data results, where technically and legally applicable, in its deletion from the relevant operational environments.
Deletion procedures may vary depending on the type of processing and any technical provider used.
Where data is processed by an artificial intelligence service provider on behalf of Synapse 42 or a client, the applicable deletion mechanisms are governed by the contractual commitments entered into with that provider.
Synapse 42 does not intentionally retain a client's personal data in an artificial intelligence model intended for other clients outside the applicable contractual and regulatory conditions.
Where data has been irreversibly anonymized and no longer makes it possible to identify a person, it is no longer considered personal data within the meaning of the GDPR.
18. Anonymization
In certain situations, Synapse 42 may choose to retain information in anonymized form rather than delete it.
Anonymization consists of transforming data in such a way that a person can no longer be identified directly or indirectly by means reasonably likely to be used.
Truly anonymized data no longer constitutes personal data and may therefore be retained subject to compliance with other applicable regulations.
Pseudonymization does not constitute anonymization. Pseudonymized data remains personal data where a person can still be re-identified using additional information.
19. How can I request the deletion of my data?
Where a deletion feature is available in Kubrik 21, the user may submit their request directly from their user area by following the instructions displayed in the application.
Where this feature is not available, the request may be submitted to Synapse 42 using the contact details provided in the Legal Notice or at the dedicated data protection address provided by Synapse 42.
The request must make it reasonably possible to identify the data subject and specify, insofar as possible, the data or processing activities concerned.
In order to prevent any fraudulent deletion or disclosure, Synapse 42 may request additional information to verify the identity of the requester.
20. Processing of the request
Upon receipt of a request, Synapse 42 verifies its admissibility and identifies the data concerned.
Where the request is valid and no exception applies, the data concerned is deleted or anonymized.
Where certain data must be retained, Synapse 42 limits its processing to the purpose justifying such retention and informs the data subject when required by regulations.
Synapse 42 processes requests within the time limits provided for by the applicable regulations.
Where a request cannot be fulfilled in whole or in part, the reasons for the refusal are communicated under the conditions provided for by the regulations.
21. Identity verification
Synapse 42 takes reasonable measures to prevent a person from requesting the deletion of a third party's data without authorization.
Where necessary, additional information may be requested in order to verify the identity of the requester.
This information is itself processed only to the extent necessary for the verification and management of the request.
Synapse 42 does not request proof of identity where such verification is not necessary or where identity can reasonably be verified by another means.
22. Deletion and connected services
Kubrik 21 may be connected to third-party services or to the client's information systems.
Deleting data in Kubrik 21 does not automatically guarantee its deletion from third-party systems to which it may previously have been transferred.
Where Synapse 42 controls the processing carried out by the third-party service, it implements appropriate mechanisms to comply with applicable obligations.
Where the third-party service is controlled by the client or another organization, that organization remains responsible for processing carried out within its own system.
The deletion arrangements applicable to third-party services are also subject to their own policies and contractual terms.
23. Deletion of connection data and technical logs
Deleting an account does not necessarily result in the immediate deletion of all associated technical logs.
Certain information may be retained for a limited period where necessary for security, fraud detection, incident resolution, proof of a transaction, or compliance with a legal obligation.
This information is deleted or anonymized at the end of the applicable retention period.
24. Consequences of deletion
Deleting data may result in the permanent loss of certain features or information.
When an account is deleted, the user may, in particular, lose access to their history, documents, settings, or other content associated with the account.
Where deletion concerns data used in a business process, it may also affect features available to other authorized users.
Where deletion is requested by a user of a client organization, it may therefore be subject to the governance rules and responsibilities defined by that organization.
25. Deletion at the end of a client contract
When a contract between Synapse 42 and a client ends, the client's data is processed in accordance with the applicable contractual provisions.
Depending on the agreed terms, the client may, in particular, be given a period in which to retrieve or export its data before deletion.
At the end of the stipulated data return period, Synapse 42 deletes or returns the data in accordance with the client's instructions, subject to legal retention obligations and data that must be retained to establish, exercise, or defend legal claims.
Where Synapse 42 acts as a processor, these arrangements are defined, in particular, in the DPA.
26. Residual data and backups
Certain data may temporarily remain in backups or technical systems after being deleted from active environments.
This data is not used for Kubrik 21's day-to-day operations, and access to it is strictly limited.
It is deleted in accordance with the applicable backup retention cycle.
In the event that a backup is restored, Synapse 42 applies, where necessary, procedures to delete again any data that had been deleted before the restoration.
27. Exceptions to the right to erasure
The right to erasure may be refused or limited where processing remains necessary in the cases provided for by regulations.
This may, in particular, be the case where retention is necessary for compliance with a legal obligation, for exercising the right to freedom of expression and information, for the establishment, exercise, or defense of legal claims, or in any other situation provided for by the GDPR or applicable law.
Where only part of the data must be retained, Synapse 42 deletes data that is no longer necessary and limits retention to the information covered by the exception.
28. Exercise of other rights
This procedure primarily concerns the right to erasure.
A person may also exercise, under the conditions provided for by the GDPR, their rights of access, rectification, restriction, objection, and portability.
The procedures for exercising these rights are detailed in Synapse 42's Privacy Policy.
29. Complaint
If a person considers that their deletion request has not been handled correctly, they may contact Synapse 42 to request a review of their request.
They may also lodge a complaint with the competent supervisory authority.
In Luxembourg, this authority is:
National Commission for Data Protection (CNPD)
15, Boulevard du Jazz
L-4370 Belvaux
Grand Duchy of Luxembourg
Website: cnpd.lu
30. Data protection and security
Deletion operations are carried out within the framework of the technical and organizational measures implemented by Synapse 42 to protect personal data.
Access to functions that allow data to be deleted or restored is limited to authorized persons and systems.
Sensitive operations may be logged to ensure traceability and prevent fraudulent or accidental deletion.
31. Changes to these Instructions
Synapse 42 may amend these Data Deletion Instructions to take into account changes to Kubrik 21, its internal procedures, its technical providers, or the applicable regulations.
The most recent version is published on the Synapse 42 website.
Where a substantial change affects the rights of data subjects, Synapse 42 may implement additional notification measures where appropriate or required by regulations.
32. Contact
For any questions regarding the deletion of personal data or to exercise the right to erasure, data subjects may contact Synapse 42 using the contact details provided in the Legal Notice or use the dedicated data protection address provided by Synapse 42.
Where a request concerns data processed by Synapse 42 on behalf of a client, the data subject may also directly contact the relevant data controller.
33. Entry into force
These Data Deletion Instructions enter into force upon publication.
Publisher identification
Synapse 42 Consulting SARL
113, route d'Esch
L-1471 Hollerich
Grand Duchy of Luxembourg
Additional legal information is available in the Legal Notice.