Privacy Policy
Last updated: May 10, 2026
This Privacy Policy explains how Syrix Ltd, doing business as Syrix (“Syrix,” “we,” “our,” or “us”), collects, uses, shares, stores, and protects personal data when you visit our website, contact us, create an account, connect a protected environment, or use the Syrix platform and related services.
Syrix provides a cloud security platform for Microsoft 365 environments, including security posture management, configuration monitoring, automated and guided remediation, access governance, connected app visibility, security logging, audit evidence, compliance support, and related features.
This Privacy Policy is intended to help customers, users, website visitors, partners, and prospects understand how we process personal data. Where we process personal data on behalf of a customer, we do so under the applicable customer agreement and data processing terms.
Syrix is designed for business use. It is not intended for personal, household, or consumer use.
1. Scope of this Privacy Policy
This Privacy Policy applies to:
- Visitors to our website and landing pages.
- People who contact us, request a demo, join a beta, subscribe to updates, or communicate with us.
- Users of the Syrix platform, including customer administrators, partner administrators, MSP users, and other authorized users.
- Personal data processed through the Syrix platform in connection with a customer’s Microsoft 365 tenant or other protected environment.
This Privacy Policy does not apply to third-party websites, services, platforms, or applications that we do not control, even if they are linked from our website or integrated with our services.
2. Our role: controller and processor
Depending on the context, Syrix may act either as a data controller or as a data processor.
When Syrix acts as a controller
Syrix acts as a controller when we determine how and why personal data is processed, such as when we process:
- Website visitor data.
- Demo, beta, or contact form submissions.
- Customer account and billing contact details.
- Marketing communications and opt-out preferences.
- Platform account administration data.
- Security and operational data needed to protect, operate, and improve Syrix.
When Syrix acts as a processor
Syrix generally acts as a processor when we process personal data contained in a customer’s protected environment, including Microsoft 365 tenant data, on behalf of that customer and according to its instructions.
In that context, the customer is responsible for determining the purposes and legal basis for processing personal data in its environment. Syrix processes that data to provide the services requested by the customer, including monitoring, evaluation, remediation, logging, access governance, compliance evidence, and related support.
Where required, our processing of customer tenant data is governed by a Data Processing Addendum or similar contractual terms.
3. Information we collect
We collect different categories of information depending on how you interact with Syrix.
3.1 Website, contact, and marketing data
When you visit our website, contact us, request information, join a beta, subscribe to updates, or otherwise communicate with us, we may collect:
- Name.
- Business email address.
- Company or organization name.
- Job title or role.
- Phone number, if provided.
- Message content and communication history.
- Demo, beta, or sales inquiry details.
- Marketing preferences.
- Website usage data, such as pages viewed, referral source, browser type, device type, and approximate region derived from technical information.
3.2 Account and platform user data
When a customer, partner, or user creates or uses a Syrix account, we may collect:
- User name and business email address.
- Organization or customer account name.
- Role, permissions, and account type.
- Login and authentication events.
- Product usage activity.
- Settings, preferences, and notification choices.
- Subscription, plan, billing, and payment-related information.
- Support requests and related communications.
Payment information may be processed by third-party payment providers. Syrix does not intentionally store full payment card details unless explicitly stated in connection with a particular payment process.
3.3 Customer security and Microsoft 365 tenant data
When a customer connects Microsoft 365 or another protected environment to Syrix, we may process data needed to provide the Syrix services. This may include:
- Tenant and protected-environment metadata.
- Microsoft 365 configuration settings.
- Entra ID users, guests, groups, roles, role assignments, and administrator metadata.
- Authentication and access configuration metadata.
- Conditional Access, MFA, password, and identity security settings.
- Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, Power BI/Fabric, and related Microsoft 365 security configuration metadata.
- External sharing, guest access, file-sharing, link-sharing, and permission metadata.
- Connected applications, OAuth grants, service principals, consent records, app permissions, publisher information, and app activity metadata.
- Audit logs, security logs, sign-in logs, alert metadata, and activity signals relevant to detection, posture evaluation, access governance, remediation, or compliance evidence.
- Remediation previews, approvals, suppressions, rollback records, recovery history, policy decisions, and administrator actions.
- Compliance mapping, evidence records, access review records, attestations, and audit-ready export data.
Syrix is designed to process security metadata, configuration data, access metadata, and operational evidence. Syrix does not intentionally access or process the content of emails, documents, chat messages, or files unless this is necessary for a specific feature enabled by the customer and disclosed in the applicable service documentation or agreement.
3.4 Support and diagnostic data
When you request support or when we troubleshoot the service, we may process:
- Support ticket content.
- Contact details.
- Account and tenant identifiers.
- Error reports.
- Diagnostic logs.
- Configuration and usage information needed to understand and resolve the issue.
We ask users not to submit sensitive personal data in support requests unless necessary for the support issue.
3.5 Cookies and similar technologies
We may use cookies, pixels, local storage, and similar technologies to:
- Operate the website and platform.
- Maintain sessions and authentication.
- Remember preferences.
- Understand website and product usage.
- Measure marketing effectiveness.
- Improve user experience and security.
Where required by law, we will request consent before using non-essential cookies. You can manage cookies through your browser settings and, where available, through our cookie preference tools or cookie notice.
If we use analytics, advertising, or other non-essential cookies, we will provide additional information through a cookie notice or cookie policy and, where required, a consent mechanism.
4. How we use information
We use personal data for the following purposes:
- To provide, operate, secure, and maintain the Syrix platform.
- To connect to and evaluate customer-protected environments.
- To identify security gaps, misconfigurations, access risks, connected app risks, and compliance-related gaps.
- To provide automated remediation, guided remediation, approval workflows, rollback, and recovery features.
- To generate security logs, audit logs, access review records, compliance evidence, reports, and exports.
- To authenticate users and manage accounts, roles, permissions, and subscriptions.
- To provide customer support and respond to inquiries.
- To communicate about the service, including administrative messages, security notices, product updates, and support responses.
- To improve the website, platform, features, reliability, performance, security, and user experience.
- To send marketing communications where permitted by law, subject to opt-out rights.
- To detect, prevent, investigate, and respond to fraud, abuse, security incidents, unauthorized access, and violations of our terms.
- To comply with legal, regulatory, tax, accounting, contractual, and audit obligations.
5. Legal bases for processing
Where applicable data protection law requires a legal basis for processing personal data, we rely on one or more of the following legal bases:
- Contract: to provide the Syrix services, manage accounts, process subscriptions, and support customers.
- Legitimate interests: to operate, secure, improve, and market our services; prevent abuse; understand product usage; and communicate with business contacts.
- Consent: where required for certain cookies, marketing communications, or optional features.
- Legal obligation: to comply with applicable legal, tax, accounting, regulatory, or security obligations.
- Customer instructions: where we process customer tenant data as a processor on behalf of a customer.
6. Microsoft 365 and third-party integrations
When you authorize Syrix to connect to Microsoft 365 or another third-party environment, Syrix uses the authorized APIs, administrative interfaces, permissions, and integrations to provide the services requested by the customer.
Depending on the features enabled and permissions granted, Syrix may read, evaluate, store, and act on relevant security, identity, configuration, access, audit, sharing, application, and compliance metadata. Where a remediation or enforcement action is available, Syrix may perform the action automatically or after approval, depending on customer configuration, product settings, and applicable policy logic.
Customers are responsible for ensuring that they have the right to authorize Syrix to access and process data from their protected environments and for configuring permissions appropriately.
7. How we share information
We do not sell personal data.
We may share personal data in the following circumstances:
Service providers and subprocessors
We may share data with trusted service providers and subprocessors that help us operate, secure, deliver, support, and improve Syrix. These may include providers of:
- Cloud hosting and infrastructure.
- Data storage and databases.
- Authentication and identity services.
- Email delivery and communications.
- Payment processing and billing.
- Analytics and product telemetry.
- Customer support tools.
- Logging, monitoring, security, and error tracking.
- Professional services such as legal, accounting, and compliance support.
These providers are authorized to process data only as needed to provide services to Syrix and are subject to contractual confidentiality, security, and data protection obligations.
Customers and authorized users
When personal data relates to a customer account or protected environment, it may be visible to the customer’s authorized administrators, partner administrators, MSP users, or other authorized users according to the customer’s configuration and permissions.
Business transfers
If Syrix is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, personal data may be disclosed or transferred as part of that transaction, subject to appropriate protections.
Legal, security, and compliance reasons
We may disclose information if we believe it is necessary to:
- Comply with applicable law, regulation, legal process, or governmental request.
- Enforce our agreements and policies.
- Protect the rights, property, safety, or security of Syrix, our customers, users, or others.
- Detect, prevent, investigate, or respond to fraud, abuse, security incidents, or technical issues.
8. International data transfers
Syrix and its service providers may process and store data in multiple jurisdictions where we or they operate.
Where personal data is transferred internationally, we use appropriate safeguards as required by applicable law. These safeguards may include data processing agreements, contractual protections, standard contractual clauses, adequacy mechanisms, security controls, or other lawful transfer mechanisms.
Syrix seeks to comply with applicable privacy and data protection laws that apply to its services, including, where relevant, the GDPR, UK GDPR, applicable U.S. state privacy laws, and applicable Israeli privacy law, including the Protection of Privacy Law and related regulations.
Syrix is headquartered in a country recognized by the European Commission as providing an adequate level of data protection.
9. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, as required by law, or as set out in the applicable customer agreement.
Unless a customer agreement, plan, product configuration, legal requirement, or security need requires a different period, our default retention practices are:
- Website and marketing data: retained for up to 24 months after the last meaningful interaction, unless you opt out or request deletion where applicable.
- Account and billing data: retained for the duration of the customer relationship and up to 7 years afterward, where needed for legal, tax, accounting, billing, dispute-resolution, or contractual purposes.
- Customer tenant data used for active posture evaluation: retained while the protected environment remains connected and as needed to provide the service.
- Security logs, remediation records, approval decisions, rollback records, and recovery history: retained for a default period of 12 months.
- Audit logs, access review records, compliance evidence, attestations, and audit-ready export data: retained for a default period of 24 months, with extended retention available on applicable plans or by customer agreement.
- Support data: retained for up to 24 months after the support matter is closed, unless longer retention is needed for security, legal, or account continuity reasons.
- Backups: retained for a limited period according to our backup and disaster recovery practices before being overwritten or deleted.
Customers may configure or purchase longer retention periods where available. Upon termination of a customer account, we will delete or anonymize customer tenant data within a reasonable period, unless retention is required for legal, security, compliance, dispute-resolution, backup, or contractual purposes.
10. Security measures
Syrix is designed to support security-sensitive business environments. We use administrative, technical, and organizational measures intended to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include, as appropriate:
- Encryption in transit and at rest.
- Access controls and least-privilege practices.
- Authentication and authorization controls.
- Logging and monitoring.
- Segregation of customer data.
- Secure development practices.
- Vulnerability management.
- Backup and recovery controls.
- Internal confidentiality obligations.
- Vendor and subprocessor review.
No method of transmission or storage is completely secure. Customers and users are responsible for maintaining the security of their own accounts, credentials, devices, tenant permissions, and administrative configurations.
11. Customer controls
Customers may configure certain Syrix features, including protected environments, remediation settings, notification preferences, access governance workflows, audit evidence, and integrations.
Customers may also request export, deletion, or return of customer tenant data according to the applicable agreement and product capabilities.
Authorized customer administrators are responsible for managing user access to their Syrix account, reviewing permissions, and ensuring that only appropriate users can access customer data.
12. Your privacy rights
Depending on your location and applicable law, you may have rights regarding your personal data, including the right to:
- Access personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of personal data.
- Request restriction of processing.
- Object to certain processing.
- Request portability of personal data.
- Withdraw consent where processing is based on consent.
- Opt out of marketing communications.
- Lodge a complaint with a data protection authority.
To exercise your rights, contact us using the details below.
If your request relates to personal data processed by Syrix on behalf of a customer, we may refer your request to that customer or act according to the customer’s instructions.
We may need to verify your identity before responding to a privacy request.
13. Marketing communications
We may send business, product, or marketing communications where permitted by law. You may opt out of marketing emails by using the unsubscribe link in the email or by contacting us.
Even if you opt out of marketing communications, we may still send non-marketing messages, such as service notices, security alerts, support responses, legal notices, and account-related communications.
14. Children
Syrix is intended for business use and is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided personal data to Syrix, please contact us and we will take appropriate steps to delete the information.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date above. If changes are material, we may provide additional notice, such as by email, platform notice, or website notice.
Your continued use of Syrix after an updated Privacy Policy becomes effective means that the updated policy applies from that date onward.
16. Contact us
For privacy questions, requests, or concerns, contact us at:
Email: privacy@syrix.io
For security-related issues, contact:
Email: security@syrix.io
For data processing or customer agreement matters, contact:
Email: dpa@syrix.io
Legal entity: Syrix Ltd.