Synapse 42

Privacy Policy

  • Version 1.0
  • Last updated: 01/10/2026

1. Purpose of this policy

This Privacy Policy describes how Synapse 42 processes personal data in connection with its activities and digital services, particularly through the Kubrik 21 platform.

Its purpose is to inform data subjects clearly and transparently about the personal data that may be collected, the purposes and legal bases of the processing, the recipients of the data, any processors and international transfers, the applicable retention periods, the security measures implemented, and the rights available to data subjects.

This policy applies to Synapse 42's public website, the Kubrik 21 platform and its various user areas, forms and services accessible online, communications with Synapse 42, as well as processing carried out in connection with Synapse 42's commercial, administrative and professional relationships.

Certain Kubrik 21 features may be operated on behalf of Synapse 42 clients. In this context, the purposes of the processing may be determined by the relevant client and the applicable arrangements may be specified in a data processing agreement ("DPA") or any other appropriate contractual document.

This Privacy Policy supplements the General Terms of Use, the Legal Notice, the Cookie Policy and, where applicable, the SaaS agreements, service agreements and data processing agreements entered into with Synapse 42 clients.


2. Data controller

Unless otherwise stated in this policy or in a specific agreement, the data controller is:

Synapse 42 Consulting SARL

113, route d'Esch
L-1471 Hollerich
Grand Duchy of Luxembourg

Full legal information concerning the entity operating each service is available in the Legal Notice.

Depending on the nature of the processing and the service concerned, another entity within the Synapse 42 group may be involved. Where necessary, the respective responsibilities of the entities concerned are specified in the applicable contractual documents or information notices.


3. Data controller and processor

Synapse 42's status under the GDPR depends on the context in which personal data is processed.

3.1. Synapse 42 as data controller

Synapse 42 acts as data controller when it determines the purposes and essential means of the processing itself.

This applies in particular to the management of its own website, prospects and clients, consultants and staff, job applications, user accounts, communications, as well as the security and improvement of its own services.

In these situations, Synapse 42 determines the purposes for which the data is processed and assumes the corresponding obligations under the applicable regulations.

3.2. Synapse 42 as processor

Kubrik 21 is also designed to enable client companies to manage their own data and business processes.

When a client uses Kubrik 21 to process personal data for which it determines the purposes and essential means, the client generally acts as the data controller and Synapse 42 acts as the processor.

This may include, in particular, data relating to consultants, candidates, employees, staff, prospects, clients or other persons whose data is entered into Kubrik 21 by the client.

In this situation, Synapse 42 processes the data in accordance with the documented instructions of the data controller and the provisions of the applicable agreement or DPA.

The client remains responsible, in particular, for the lawfulness of the collection and processing of the data, defining the purposes, informing data subjects where this obligation rests with the client, the relevance of the data transmitted, and determining the retention periods applicable to its own processing activities.

The GDPR notably requires that the relationship between a data controller and its processor be governed by an agreement defining the essential characteristics of the processing.


4. Data subjects

The processing carried out by Synapse 42 may concern different categories of persons depending on the services used.

These may include, in particular, website visitors, Kubrik 21 users, consultants, candidates, staff, employees, representatives of clients or prospects, suppliers, partners and business contacts.

When Kubrik 21 is used by a client company, data relating to persons who do not themselves have an account may also be processed on the platform. This may include, in particular, the client's consultants, candidates, employees, staff, client representatives or prospects.

In the latter situation, Synapse 42 may act as a processor on behalf of the relevant client.


5. Categories of personal data processed

Synapse 42 applies the principle of data minimization and endeavors to process only information necessary for the purposes pursued.

Depending on the service used and the context of the processing, the data may include identification data such as surname, first name, title, a photograph when provided, a user identifier or any other information necessary for the professional identification of a person.

Contact details may also be processed, including an email address, telephone number, postal address or professional contact details.

In connection with Kubrik 21, professional data may be processed, including job title, employer, company, role held, skills, qualifications, certifications, professional experience, information contained in a CV, availability, work location or information relating to assignments.

When the corresponding features are used, Kubrik 21 may also process information relating to assignments, such as the client concerned, role, start and end dates, applicable fee or rate, location, required skills, allocation or assignment status.

Certain features also allow administrative and financial information to be managed. This may include contractual information, bank details where their processing is necessary, invoices, expense reports, supporting documents, reimbursement information, data necessary for billing or certain information relating to remuneration.

When the relevant features are enabled, data relating to professional activity may also be processed, including timesheets, periods worked, numbers of hours, activities performed, approvals or comments.

Documents submitted through Kubrik 21 may contain personal data. These may include CVs, contracts, invoices, expense reports, supporting documents, administrative documents, documents relating to remuneration or any other document necessary for the operation of the service.

Finally, Synapse 42 may process technical data necessary for the operation and security of the Services. This may include IP addresses, technical identifiers, information relating to the browser and operating system, characteristics of the device used, connection dates and times, technical logs, security events, or information relating to authentication and errors.


6. Special categories of personal data

Kubrik 21 is not intended to allow the free and uncontrolled collection of special categories of personal data within the meaning of the GDPR.

In particular, users must not enter data relating to health, political opinions, religious or philosophical beliefs, trade union membership, biometric or genetic data, sex life or sexual orientation in fields or documents that are not intended for this purpose.

Where the operation of a service exceptionally requires the processing of a special category of data, such processing must be based on an appropriate legal basis and be subject to suitable protective measures.


7. Purposes of processing

Personal data is processed only for specified, explicit and legitimate purposes.

In connection with Kubrik 21, it may notably be used to create and manage user accounts, authenticate users, administer their rights and permissions, provide the platform's features, and enable access to the information and documents they are authorized to access.

The data may also be used to manage consultants, prospects, clients and assignments, as well as to manage skills, CVs, applications, timesheets, expense reports, invoices, administrative documents and other information necessary for professional activities.

In the context of the client relationship, the data may be used to perform contracts, respond to requests, provide support, manage incidents, monitor service delivery and communicate with the relevant contacts.

Data relating to prospects may be used to identify and qualify business opportunities, organize communications, follow up with contacts and prepare commercial proposals.

In the context of recruitment or professional profile management, the data may be used to analyze CVs, identify skills, search for profiles matching specific needs, manage applications and communicate with candidates.

Certain data may also be processed to enable billing, accounting, payment, expense reimbursement, administrative management and compliance with applicable tax, social security or regulatory obligations.

Technical data may be used to ensure the security of accounts and infrastructure, prevent fraudulent access, detect abnormal behavior, analyze incidents, ensure the traceability of operations, and protect the integrity and availability of the Services.

Finally, within the limits permitted by regulations, certain data may be used to improve the performance, usability, security and quality of the Services and to develop new features.

Where possible and appropriate, Synapse 42 gives preference for this purpose to the use of aggregated, anonymized or pseudonymized data.


8. Legal bases for processing

The processing of personal data carried out by Synapse 42 is based on one of the legal bases provided for by the GDPR, depending on its purpose and context.

Where processing is necessary for the performance of a contract or to take pre-contractual measures, Synapse 42 may process the data on this basis. This includes, in particular, creating an account, providing Kubrik 21, managing an assignment, handling a client request, billing or support.

Certain data may be processed in order to comply with a legal obligation to which Synapse 42 is subject, particularly in accounting, tax, social security or regulatory matters.

Synapse 42 may also rely on its legitimate interests where processing is necessary for the pursuit of a legitimate interest and the rights and freedoms of the data subjects do not override that interest. This may include, in particular, IT security, fraud prevention, improvement of the Services, client relationship management, certain professional marketing activities or the defense of Synapse 42's rights.

Finally, certain processing is based on the consent of the data subject where consent is required or constitutes the legal basis selected by Synapse 42. This may include, in particular, certain categories of cookies or certain marketing communications.

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.


9. Artificial intelligence

Kubrik 21 may incorporate features based on artificial intelligence, machine learning or automated information processing technologies.

These technologies may notably be used to automatically analyze CVs or documents, extract and normalize information, identify skills, detect certain anomalies, generate summaries, assist with drafting, facilitate profile searches, or match profiles with assignments.

The results generated by these technologies are intended as assistance tools. They may contain errors, be incomplete or fail to take certain contextual factors into account.

Users must therefore verify the generated results before using them in connection with a decision or action that may have a significant impact on a person.

Where an artificial intelligence feature is used as part of processing carried out on behalf of a client, Synapse 42 processes the data in accordance with the instructions of the data controller and the terms set out in the applicable DPA.


10. Automated decision-making and profiling

Certain Kubrik 21 features may perform automated analyses or generate recommendations concerning profiles, documents, skills or assignments.

Unless specifically stated otherwise, these features do not constitute solely automated decision-making that produces legal effects or similarly significant effects within the meaning of Article 22 of the GDPR.

In particular, recommendations or analyses generated by Kubrik 21 do not, on their own, constitute a decision concerning hiring, dismissal, remuneration, assignment or any other decision producing legal or professional consequences.

Where a feature may fall within the scope of the provisions relating to automated decision-making, Synapse 42 and, where applicable, the relevant data controller implement the safeguards required by the applicable regulations.


11. Sources of data

Personal data may be collected directly from the data subject, particularly when they create an account, complete their profile, submit a request or provide a document.

It may also be provided by an organization using Kubrik 21, including an employer, a client or a platform administrator.

In some cases, data may come from third-party systems connected to Kubrik 21, partners, suppliers or documents provided in connection with professional activities.

Certain professional information may also come from publicly available sources where its collection and use are legally permitted.

Where data is not collected directly from the data subject, the information obligations provided for by the GDPR are applied in accordance with the circumstances of the processing.


12. Data recipients

Personal data is accessible only to persons and entities that need it for the relevant purposes.

Depending on the context, it may be accessible to authorized Synapse 42 staff, authorized administrators of a client, authorized Kubrik 21 users, as well as technical service providers involved in providing the Services.

Synapse 42 may notably use providers of cloud infrastructure, hosting, backup, monitoring, security, authentication, messaging, analytics or artificial intelligence services.

Data may also be disclosed to public or administrative authorities where such disclosure is required by applicable regulations or necessary for the exercise of a right.

Access rights are defined according to the principles of need-to-know and, where appropriate, least privilege.


13. Processors

Synapse 42 may use technical service providers to provide, maintain and secure Kubrik 21 and its associated services.

These service providers may operate in areas including hosting, cloud infrastructure, backup, monitoring, security, authentication, email delivery, support or artificial intelligence.

Where a service provider processes personal data on behalf of Synapse 42, it is subject to the applicable contractual and regulatory data protection obligations.

Where Synapse 42 itself acts as a processor on behalf of a client, it applies the provisions set out in the DPA entered into with that client, particularly regarding the use of sub-processors.

The list of the main processors used for the relevant services may be provided to clients in accordance with the applicable contractual provisions.


14. Hosting and infrastructure

Kubrik 21 may be hosted on cloud infrastructure operated by specialized providers.

Synapse 42 implements measures designed to ensure the security and resilience of this infrastructure, including through access control mechanisms, encryption where appropriate, backup, logging, monitoring, identity management and protection against unauthorized access.

Data location may depend on the service used, the environment concerned, and the infrastructure provider.

Information relating to the providers and hosting locations applicable to a client may be specified in the contractual documentation, the DPA, or the security documentation made available by Synapse 42.


15. International transfers

Synapse 42 gives preference, where possible, to processing data within the European Economic Area.

However, some of Synapse 42's providers may be established outside the European Economic Area or process certain data from a third country.

When personal data is transferred to a third country within the meaning of the GDPR, Synapse 42 implements a transfer mechanism recognized by the applicable regulations.

Depending on the circumstances, this may include an adequacy decision by the European Commission, standard contractual clauses, or additional measures intended to ensure an appropriate level of protection.

International transfers applicable to the processing activities concerned are documented to the extent required by regulations.


16. Data security

Synapse 42 implements technical and organizational measures appropriate to the risks presented by the processing of personal data.

These measures include, in particular, authorization and access management, secure communications, event logging, infrastructure monitoring, backups, vulnerability management, security updates, incident management procedures, as well as business continuity and recovery measures.

Where appropriate, Synapse 42 also implements encryption or pseudonymization mechanisms.

Security measures are regularly adapted based on changes in risks, available technologies, and regulatory requirements.

Despite the measures implemented, no IT system can be considered entirely risk-free. Synapse 42 therefore cannot guarantee absolute data security.


17. Personal data breaches

Synapse 42 has procedures designed to identify, analyze, and address incidents that may compromise the security of personal data.

When Synapse 42 acts as a data controller, it determines the appropriate measures in accordance with GDPR requirements and, where required, makes notifications to the competent supervisory authority and informs the data subjects.

When Synapse 42 acts as a processor, it informs the relevant data controller in accordance with the applicable DPA and GDPR requirements.


18. Retention periods

Synapse 42 retains personal data only for as long as necessary for the purposes for which it is processed, subject to legal retention obligations and legitimate needs relating in particular to evidence and the defense of its rights.

The retention period depends on the nature of the data and the context of the processing.

Data relating to user accounts is generally retained for the duration of the account's use. After its deactivation or deletion, certain information may be retained for an additional period where necessary for legal, contractual, security, or evidentiary purposes.

Data relating to prospects is retained for the period necessary to follow up on the potential business relationship, and then for an additional period where regulations or Synapse 42's legitimate interests justify it.

Data relating to clients and contractual relationships is retained for the duration of the relationship and then for the periods necessary to comply with legal obligations, including accounting and tax obligations, as well as to defend Synapse 42's rights.

Application data and CVs are retained for the period necessary to process the application and, where legally justified and appropriate, for an additional period to allow the application to be considered for future opportunities.

Technical data and security logs are retained for a period proportionate to the purposes of security, diagnostics, fraud prevention, and incident management.

Accounting, tax, or contractual documents are retained for the periods required by applicable regulations.

At the end of the applicable retention periods, data is deleted or anonymized when further retention is no longer necessary.


19. Data deletion

Data subjects may request the deletion of their personal data under the conditions provided for by the GDPR.

However, deleting an account or data does not necessarily mean that all associated information is immediately deleted from all systems.

Certain data may need to be retained to comply with a legal obligation, fulfill a contractual obligation, establish or defend a legal claim, ensure the security of the Services, or fulfill another legally justified purpose.

Data contained in backups may also be deleted according to the normal backup rotation cycle, subject to the security and continuity requirements of the Services.

The practical procedures for deleting data are detailed in the Data Deletion Instructions published by Synapse 42.


20. Cookies and similar technologies

Synapse 42's website and Kubrik 21 may use cookies and similar technologies.

Some cookies are necessary for the technical operation of the service, particularly to provide authentication, maintain a session, remember certain settings, or ensure security.

Other cookies or technologies may be used for audience measurement, analytics, improving the user experience, or other purposes that, depending on the circumstances, require the user's prior consent.

Where consent is required, it is obtained through a mechanism that allows the user to accept or reject the different categories of cookies and subsequently modify their choices.

Detailed information regarding cookies is provided in Synapse 42's Cookie Policy.


21. Audience measurement and website analytics

Synapse 42 may use audience measurement and analytics tools to understand how its website is used and improve its services.

When these tools require the user's consent, they are activated only after the required consent has been obtained.

The tools used, their purposes, the categories of data collected, and the consent management procedures are described in the applicable Cookie Policy.


22. Commercial communications

Synapse 42 may use the professional contact details of its contacts to provide them with information relating to its services where permitted by applicable regulations.

Where consent is required, commercial communications are sent only after consent has been obtained.

Data subjects may object at any time to the use of their data for direct marketing purposes. Communications strictly necessary for the performance of a contract, the security of an account, or the operation of the Services are not considered commercial communications.


23. Links to third-party services

The website and Kubrik 21 may contain links to websites or services operated by third parties.

When the user accesses these services, the data processing carried out by their operators is subject to their own terms and privacy policies.

Synapse 42 does not control the processing carried out by these third parties and recommends that users review their privacy policies before providing them with personal data.


24. Rights of data subjects

In accordance with the GDPR, data subjects have several rights concerning their personal data, subject to the conditions and exceptions provided for by regulations.

They have, in particular, a right of access, allowing them to obtain confirmation as to whether their data is being processed and, where this is the case, to obtain a copy of that data as well as the information required by regulations.

They also have a right to rectification, allowing them to request the correction of inaccurate or incomplete data.

Under the conditions provided for by the GDPR, they may exercise their right to erasure, also known as the “right to be forgotten.”

They may also request restriction of processing in the situations provided for by the GDPR.

Where the regulatory conditions are met, they have a right to data portability, allowing them to receive certain personal data in a structured, commonly used, and machine-readable format.

They may, under the conditions provided for by regulations, exercise their right to object, particularly to processing based on legitimate interests and, in all cases, to direct marketing.

Finally, where processing is based on their consent, they may withdraw it at any time.

These rights are not absolute and may be subject to the conditions, exceptions, and limitations provided for by the GDPR or any other applicable regulations.


25. Exercising rights

Anyone wishing to exercise their rights may submit a request to Synapse 42 using the contact details provided in the Legal Notice or the dedicated data protection address provided by Synapse 42.

In order to protect personal data against disclosure to an unauthorized person, Synapse 42 may request information to reasonably verify the identity of the requester where necessary.

Requests are processed within the time limits provided for by applicable regulations.

Where Synapse 42 cannot comply with a request, it provides the reasons for its refusal where required by regulations.


26. Exercising rights when a client is the data controller

When a person uses Kubrik 21 as part of a service provided by a Synapse 42 client and that client acts as the data controller, requests concerning data processed on behalf of that client should, in principle, be addressed directly to the client.

Synapse 42 may assist the data controller in handling these requests in accordance with the applicable DPA.

Where the request is submitted directly to Synapse 42, Synapse 42 may forward it to the relevant data controller or inform the requester of the appropriate procedure.


27. Complaint to the supervisory authority

Any data subject who believes that the processing of their personal data constitutes a violation of applicable regulations may lodge a complaint with the competent supervisory authority.

In Luxembourg, the supervisory authority is:

National Commission for Data Protection (CNPD)

15, Boulevard du Jazz
L-4370 Belvaux
Grand Duchy of Luxembourg

Website: cnpd.lu

A data subject may also, where the conditions provided for by the GDPR are met, lodge a complaint with the supervisory authority of their habitual residence, place of work, or the place where the alleged infringement occurred.


28. Minors

Synapse 42's Services and Kubrik 21 are primarily intended for professional users and are not designed for use by children in connection with their personal activities.

Synapse 42 does not seek to intentionally collect personal data concerning children outside situations in which such processing is legally justified.

Where a person believes that data concerning a child has been collected without justification, they may contact Synapse 42 so that the situation can be reviewed.


29. Public data and professional profiles

Certain Kubrik 21 features may allow the management of professional information from publicly accessible sources or provided in the context of a professional relationship.

The fact that information is public does not mean that it may be used without restriction. Any use of personal data remains subject to the principles and obligations provided for by applicable regulations.

Synapse 42 seeks, in particular, to limit the collection and use of data to information relevant to the purposes pursued.


30. Data provided by third parties

When a user provides Synapse 42 with, or enters into Kubrik 21, personal data concerning another person, it is the user's responsibility to ensure that they have the necessary rights, authorizations, or legal bases for such transmission.

This obligation applies in particular to data relating to consultants, candidates, employees, staff members, client representatives, and prospects.

When a client uses Kubrik 21 as a data controller, it is the client's responsibility to comply with its obligations to provide information to the data subjects.


31. Use of data to improve artificial intelligence models

Confidential data entered by a client into Kubrik 21 is not considered freely available data for training artificial intelligence models intended for other clients.

Unless there is a specific agreement or legal basis permitting such use, Synapse 42 does not reuse a client's confidential data to train a model intended for another client.

When an artificial intelligence feature requires a particular use of data, that use is documented and carried out in accordance with the applicable legal basis and the contractual commitments made with the relevant client.

Where possible and appropriate, data used for statistical purposes or for the general improvement of the Services is anonymized, aggregated, or pseudonymized.


32. Decisions concerning individuals

When Kubrik 21 provides recommendations concerning individuals, particularly in connection with searches for consultants or candidates, these recommendations are intended to assist analysis and should not be regarded as final decisions.

Users must take the context into account and verify the available information before making a decision.

Where a decision is likely to have a significant effect on a person, the controller must ensure that the requirements of the GDPR and other applicable regulations are complied with, particularly with regard to transparency, human intervention and the rights of the data subject.


33. Data protection by design and by default

Synapse 42 takes into account the principles of data protection by design and by default in the development of its Services.

This approach is intended in particular to limit data collection to what is strictly necessary, restrict access to authorized persons only, limit retention periods, protect data by default and reduce the risks associated with processing.

These measures are integrated into the design and development of Kubrik 21 to the extent appropriate to the risks and features concerned.


34. Documentation of processing activities

Synapse 42 maintains, where required, documentation relating to its processing of personal data.

This documentation makes it possible, in particular, to identify the purposes of processing, the categories of data and data subjects concerned, the recipients, processors, any international transfers, retention periods and applicable security measures.

Where Synapse 42 acts as a processor, information relating to processing carried out on behalf of a client is documented in accordance with the applicable contract and DPA.


35. Amendment of this policy

Synapse 42 may amend this Privacy Policy to take into account changes in its activities, Kubrik 21, the processing carried out, the providers used or the applicable regulations.

The most recent version is published on the Synapse 42 website.

Where an amendment is substantial and likely to significantly affect the rights of data subjects, Synapse 42 may implement additional information measures where appropriate or required by regulations.


36. Contact

For any questions regarding this Privacy Policy or the processing of personal data, data subjects may contact Synapse 42 using the contact details provided in the Legal Notice.

For requests relating to rights under the GDPR, Synapse 42 may also provide a dedicated data protection email address.


37. Additional documents

This Privacy Policy should be read in conjunction with the following documents where applicable:

  • the Legal Notice;
  • the General Terms of Use;
  • the Cookie Policy;
  • the Data Deletion Instructions;
  • the commercial terms and conditions;
  • the SaaS agreements;
  • the service agreements;
  • the data processing agreements ("DPAs");
  • any service level agreements ("SLAs");
  • and any specific information notice provided to data subjects.

In the event of any conflict between this policy and a DPA entered into with a client, the provisions of the DPA shall prevail for processing carried out on behalf of that client.


38. Entry into force

This Privacy Policy enters into force as of its publication.


Publisher identification

Synapse 42 Consulting SARL

113, route d'Esch
L-1471 Hollerich
Grand Duchy of Luxembourg

Additional legal information is available in the Legal Notice.