Terms and Conditions
Document version 2026-08-02 · Questions? info@synaply.io
Effective Date: August 2nd, 2026
Welcome to Synaply Inc!
This Master User Agreement ("Agreement") governs your use of the services provided by Synaply Inc ("Company," "we," "our," or "us"), including all associated software, platforms, and content (collectively, the "Services"). By signing up, accessing, or using our Services, you agree to be bound by this Agreement.
Please read this Agreement carefully before proceeding.
1. Services and Support
Synaply Inc provides access to software, tools, and platforms designed for your business needs. Support services are outlined in any applicable service plan.
You are responsible for maintaining the confidentiality of your account credentials and all activities occurring under your account. Synaply Inc is not liable for any unauthorized access due to your failure to secure your credentials.
2. Grant of License
2.1 License Grant: Synaply Inc grants you a non-exclusive, non-transferable, revocable license to use the Services for your internal business purposes.
2.2 API Usage: If you access Synaply Inc APIs, you agree to abide by applicable usage limits, security measures, and technical documentation.
2.3 Restrictions:
- Do not sublicense, sell, rent, or lease the Services.
- Do not reverse engineer, disassemble, or otherwise attempt to derive the source code.
- Do not use the Services to create competing products.
- Do not engage in activities that disrupt the Services.
2.4 Responsibilities: You are responsible for ensuring all end users comply with this Agreement.
3. Content Ownership
3.1 User Content: You retain ownership of content and data you submit to the Services ("User Content"). By submitting User Content, you grant Synaply Inc a worldwide, royalty-free license to use, process, and display such content solely to provide the Services. Synaply Inc does not use your User Content to train, fine-tune, or develop generalized or foundation AI or machine-learning models.
3.2 Data Usage and Processing: Synaply Inc processes and stores your data in compliance with applicable data protection laws. See our Privacy Policy for more information.
4. Intellectual Property Rights
4.1 Company Ownership: Synaply Inc retains all rights, title, and interest in the Services, including all associated intellectual property.
4.2 Feedback: If you provide feedback or suggestions, we may use such input without restrictions or compensation.
5. Confidentiality and Data Protection
5.1 Confidential Information: "Confidential Information" includes non-public information shared by either party, such as business, financial, and technical details. Both parties agree to maintain the confidentiality of such information and not disclose it to third parties without prior written consent. The confidentiality obligations will survive termination of this Agreement for a period of three (3) years.
5.2 Data Protection: Synaply Inc implements commercially reasonable measures to protect your data. We will notify you of any data breach affecting your personal data without undue delay and, where required, no later than 72 hours after we confirm it.
5.3 Security Disclaimer: Synaply Inc implements industry-standard security practices to protect your data. However, you acknowledge that no system is completely secure, and Synaply Inc cannot guarantee that unauthorized access or breaches will never occur. To the fullest extent permitted by law, Synaply Inc disclaims any liability for any unauthorized access, breach, or loss of data resulting from circumstances beyond our reasonable control.
6. Payment of Fees
6.1 Fees: You agree to pay all applicable fees as described in the pricing schedule.
6.2 Billing: Payments are processed on a subscription or usage basis, as applicable. Failure to make timely payments may result in suspension or termination of Services.
6.3 Taxes: You are responsible for all applicable taxes.
7. Term and Termination
7.1 Termination by You: You may terminate your account at any time.
7.2 Termination by Us: We reserve the right to terminate or suspend your access to the Services for any violation of this Agreement.
7.3 Effect of Termination: Upon termination, your access to the Services will cease, and any User Content may be deleted. Synaply Inc will delete your data within 30 days unless required by law to retain it.
7.4 Survival: The following sections shall survive termination of this Agreement: 3 (Content Ownership), 5 (Confidentiality and Data Protection), 9 (Warranties and Disclaimers), 10 (Indemnity), and 12 (General Provisions).
8. Right to Reject and Prevent Access to Services
Synaply Inc reserves the right to refuse service, block access, or remove content that violates this Agreement or applicable laws.
9. Warranties and Disclaimers
9.1 Services Provided "As-Is": The Services are provided on an "as-is" and "as-available" basis without warranties of any kind, either express or implied.
9.2 No Guarantee: Synaply Inc does not warrant that the Services will be error-free, uninterrupted, or meet your expectations.
9.3 Limitation of Liability: To the maximum extent permitted by applicable law, Synaply Inc's total liability under this Agreement, whether in contract, tort (including negligence), or otherwise, shall not exceed the total fees paid by you for the Services during the twelve (12) months preceding the event giving rise to the claim. In no event shall Synaply Inc be liable for any indirect, incidental, consequential, special, or punitive damages, or any loss of profits, revenue, data, or business opportunities, even if advised of the possibility of such damages.
9.4 Beta Features: From time to time, Synaply Inc may release beta features for testing purposes. Such features are provided "as-is" without warranties and may be removed at any time.
9.5 Permission-Aware Indexing, ACL Freshness, and Allocation of Responsibility:
(a) How permission mirroring works. The Services build a private, per-tenant search index and knowledge graph derived from content in the third-party source systems you connect on a read-only basis. The index is designed to mirror the access-control lists and permissions ("Permissions") of those source systems, so that each user is presented only with content that user is already entitled to access in the source. The connected source system remains the authoritative system of record for Permissions; Synaply reflects, and does not replace, your source-system access controls.
(b) Effort standard. Synaply Inc will use commercially reasonable efforts — meaning those measures a prudent provider of comparable enterprise-search services would reasonably take, weighing technical feasibility and cost — to mirror source Permissions accurately. Synaply Inc does not guarantee, and expressly disclaims any warranty of, perfect, complete, error-free, or instantaneous Permission mirroring.
(c) ACL freshness and source-connector dependency. When you or your administrators revoke, modify, or otherwise change Permissions in a connected source system, the Services propagate that change to your index using the mechanisms each source system and connector makes available. Where a source connector supports real-time change notifications (webhooks), Synaply Inc applies Permission changes on a near-real-time basis. Where a connector does not support such notifications, Synaply Inc relies on periodic synchronization (polling), and Permission changes may not take effect until the next synchronization cycle. Synaply Inc uses commercially reasonable efforts (as defined in Section 9.5(b)) to propagate Permission and access-control changes ("ACL Freshness") as quickly as the connected source systems and connectors allow. You acknowledge and accept that the speed and completeness of ACL Freshness are inherently limited by the capabilities of each source system and connector, which are outside Synaply Inc's control; that Permission changes may be delayed; and that content may remain accessible in the index for a period after a change is made at the source, until propagation completes.
(d) Customer responsibility. You are responsible for configuring and maintaining Permissions correctly in your source systems and within the Services. Content that is exposed because a source-system Permission was configured to allow access — including over-permissive settings that the Services faithfully mirror — is not a defect in the Services. You are responsible for reviewing your source-system Permissions and for the acts, omissions, and configuration of your administrators and authorized users.
(e) Acknowledgment and assumption of residual risk. You acknowledge that (i) Permission changes may take time to propagate and access may not be updated instantaneously; (ii) any derivation, inference, or synthesis performed by the knowledge graph or AI features operates on content you are already permitted to access; and (iii) no security or access-control system is perfectly secure. You accept these residual risks — including the risk of delayed ACL Freshness described in Section 9.5(c) — as a condition of accessing and using the Services. You confirm this acknowledgment by accepting this Agreement when prompted.
(f) Disclaimer, allocation, and limitation. Except to the extent caused by Synaply Inc's own gross negligence or willful misconduct, and to the fullest extent permitted by applicable law, Synaply Inc shall not be liable for any unauthorized access to, disclosure of, or exposure of content (an "Access Exposure") arising from or relating to Permission mirroring, ACL Freshness or propagation delay, synchronization latency, source-system or source-connector limitations, source-system configuration, or access-control derivation. Any liability that does arise — including for an Access Exposure caused by a defect in the Services themselves — is subject to Section 9.3 (Limitation of Liability), including the aggregate liability cap and the exclusion of indirect, incidental, consequential, special, and punitive damages. This Section allocates risk between commercially sophisticated business parties and does not apply to consumers. Nothing in this Agreement excludes or limits: (i) liability that cannot lawfully be excluded or limited, including for gross negligence, willful misconduct, or fraud, or for death or personal injury caused by negligence; (ii) any data subject's statutory right to compensation under Article 82 of the EU/UK GDPR, which arises independently of this Agreement; or (iii) a consumer's private right of action under California Civil Code § 1798.150 for a qualifying data breach. Synaply Inc acts as a processor in respect of connected-source personal data that it indexes and processes on your instructions. The parties' respective roles and obligations are set out in the Data Processing Addendum referenced in Section 12.10, which governs in the event of any conflict with this Section. For clarity, the allocation of responsibility in this Section 9.5 concerns only the mirroring of your source-system Permissions. As used here, "tenant isolation" means Synaply Inc's logical segregation of each customer's data into a separate per-tenant index as described in the Privacy Policy, and does not extend to Permission mirroring, ACL Freshness, or access-control derivation. This Section 9.5 does not disclaim liability for a failure of tenant isolation, or of the security of Synaply Inc's own infrastructure, caused by a defect in the Services; any such liability remains subject to Sections 9.1, 9.3, and 9.5(h). Where an Access Exposure has both a source-system or Permission-mirroring cause and a tenant-isolation or infrastructure cause, liability is determined by the predominant cause. Nothing in this sentence is a warranty, representation, or guarantee of any security outcome.
(g) Breach notification. An Access Exposure that constitutes a personal-data breach under applicable law will be handled under Synaply Inc's breach-notification obligations in Section 5.2 and any applicable Data Processing Addendum, notwithstanding the allocation of responsibility in this Section 9.5.
(h) Security program; SOC 2. Synaply Inc maintains an information-security program and undergoes an annual SOC 2 Type 2 examination; the report is available to customers on request under a non-disclosure agreement. This description and any such report are provided for information only, reflect controls as of the applicable examination period, and do not constitute a warranty, representation, or guarantee of any security outcome; the Services remain provided on an "as-is" and "as-available" basis under Section 9.1.
10. Indemnity
You agree to indemnify and hold Synaply Inc, its affiliates, directors, employees, and agents harmless from any claims, losses, or damages arising out of your breach of this Agreement or misuse of the Services.
11. Third-Party Integrations
Synaply Inc may integrate with or allow access to third-party services, tools, or applications ("Third-Party Services"), including AI assistants and other clients you choose to connect to Synaply (for example, through the Model Context Protocol). Your use of such Third-Party Services is subject to their own terms and conditions, and Synaply Inc is not responsible for their availability, performance, or functionality. Synaply Inc assumes no liability for any data shared with or processed by Third-Party Services — including any use a third-party AI provider makes of such data to operate, provide, or improve its own models or services — and you are encouraged to review their terms and privacy practices carefully before connecting to or using them. Synaply Inc does not use your data to train, fine-tune, or develop AI or machine-learning models, but makes no representation regarding the practices of any Third-Party Service.
11.1 Connected Services and Google User Data: Synaply lets you, or your organization's administrator, connect third-party services such as Google Workspace so that Synaply can build a private, permission-aware search index over your own organization's content. You represent that you are authorized to connect each account and to grant Synaply read-only access to its data, including via Google Workspace domain-wide delegation where applicable. Synaply accesses connected data on a read-only basis only and does not create, modify, or delete content in any connected service. Synaply's access to and use of Google user data is governed by our Privacy Policy and complies with the Google API Services User Data Policy, including its Limited Use requirements; such data is never sold, never used for advertising, and never used to train generalized or foundation AI/ML models. You may disconnect a service at any time; on disconnection or request, Synaply deletes the associated indexed data within 30 days.
11.2 Customer-Provided Credentials and Applications: Some connected services may be enabled using credentials, API keys, OAuth applications, private applications, or access tokens that you create, register, or provide ("Customer Credentials") rather than an application provided by Synaply. Where you choose to use Customer Credentials, you are solely responsible for: (a) creating, configuring, securing at the source, and rotating those credentials and any application you register with the source provider; (b) the scopes, permissions, and level of access you grant through them, including any access that is broader than necessary; (c) that application's registration, scopes, and configuration complying with the source provider's terms, developer or API policies, and applicable law; and (d) revoking them when appropriate. Synaply remains responsible for its own operation of the Services in compliance with the source provider's terms to the extent those terms govern Synaply's conduct as the party making calls through the Customer Credential. You represent that you are authorized to provide each Customer Credential and to grant Synaply access through it; a breach of this representation, and any third-party claim arising from your provision or use of a Customer Credential you were not authorized to provide, is subject to your indemnity obligations in Section 10. Synaply uses Customer Credentials solely to provide the Services on your instructions and continues to apply its standard processor safeguards — including encryption in transit and at rest and per-tenant isolation — to data it processes through them. However, to the fullest extent permitted by applicable law, Synaply is not responsible or liable for your decision to use Customer Credentials, for the configuration, scope, or at-source security of any application or credential you provide, or for any Access Exposure or other exposure resulting from over-broad or mis-scoped permissions you grant, or from credentials you fail to secure at the source or to revoke. You acknowledge and accept these risks as a condition of using Customer Credentials. For clarity, this Section does not disclaim Synaply's obligation to protect Customer Credentials once they are stored within Synaply's systems; Synaply protects stored Customer Credentials using the same safeguards described above, and any liability for a failure of those safeguards caused by a defect in the Services remains subject to Sections 9.1 and 9.3. Nothing in this Section limits liability that cannot lawfully be excluded, including for Synaply's gross negligence, willful misconduct, or fraud, a data subject's right to compensation under Article 82 of the EU/UK GDPR, or a consumer's rights under California Civil Code § 1798.150; any liability that does arise remains subject to the aggregate cap in Section 9.3. This Section does not reduce Synaply's own obligations, as a processor, for the data it processes and the infrastructure it operates.
12. General Provisions
12.1 Governing Law: This Agreement shall be governed by the laws of Ontario, Canada, without regard to conflicts of laws principles.
12.2 Dispute Resolution: Any disputes shall be resolved through binding arbitration in Ontario, Canada, in accordance with the rules of the International Chamber of Commerce (ICC).
12.3 Entire Agreement: This Agreement constitutes the entire understanding between the parties and supersedes all prior agreements.
12.4 Severability: If any provision of this Agreement is found to be unenforceable, the remaining provisions shall remain in full force and effect.
12.5 Waiver: Failure to enforce any provision does not constitute a waiver.
12.6 Assignment: You may not assign your rights or obligations under this Agreement without prior written consent. Synaply Inc may assign this Agreement without restriction.
12.7 Force Majeure: Synaply Inc shall not be liable for delays or failures due to causes beyond its reasonable control, including acts of God, natural disasters, governmental actions, cyberattacks, system-wide internet failures, or other disruptions beyond Synaply Inc's control.
12.8 Compliance with Export Laws: You agree to comply with all applicable export control laws and regulations. You will not use the Services in jurisdictions subject to trade restrictions or sanctions.
12.9 Notices: Synaply Inc may provide notices by email, through the Services, or by posting an updated Agreement on our website.
12.10 Data Processing Addendum: For customers subject to data protection laws, Synaply makes a Data Processing Addendum (DPA) available on request; where executed, the DPA governs the processing of personal data and controls over any conflicting term in this Agreement.
Contact
If you have any questions regarding this Agreement, please contact us at info@synaply.io.
By creating an account and/or using the Services, you acknowledge that you have read, understood, and agree to this Master User Agreement.
© 2026 Synaply Inc. — 62 Carnforth Rd, Toronto, ON, M4A 2K7