SYNORA

Privacy Notice

Synora holds information about two very different groups of people: students who chose to sign up, and researchers who did not. This notice covers both, and it is honest about the second because that is the part that matters.

Controller — SKLZ LABS LLC, a limited liability company registered in the Kyrgyz Republic
Service — Synora (synora.app / iskra.marketing/synora)
Contact for privacy, removal and data requests — fxfactor24@gmail.com
Version — 1.0 · Effective — 20 August 2026 · Last reviewed — 20 August 2026
This is a draft prepared from the current build of the system, not legal advice. It describes accurately what the software does, and it cites the instruments that apply. It has not been reviewed by a qualified lawyer, and three obligations identified during drafting are not yet met — they are listed in section 12 rather than hidden. Do not publish this as final until a data protection lawyer in the EU or UK has reviewed sections 3, 4 and 9.
  1. Who we are
  2. If you are a student
  3. If you are a researcher
  4. Our lawful basis
  5. Who we share data with
  6. How long we keep it
  7. Your rights
  8. Getting removed
  9. International transfers
  10. Security
  11. Children
  12. What we have not done yet

1. Who we are

Synora is operated by SKLZ LABS LLC, registered in the Kyrgyz Republic. We are the "controller" of the personal data described here, which means we decide why and how it is processed and we are answerable for it.

Because we are established in the Kyrgyz Republic and offer a service to people in the European Union and the United Kingdom, more than one law applies to us at once:

Where these give you different rights, you get whichever is stronger. Where they set different deadlines, we work to the shortest: the Digital Code requires a reasoned answer within seven working days, which is faster than GDPR's one month, so seven working days is what we aim for on every request from anyone.

2. If you are a student

You gave us this information yourself, and almost all of it is optional.

WhatWhyRequired?
Email addressTo identify your account, let you sign in, and send you a password reset if you ask for one.Yes
PasswordStored only as a scrypt hash. We cannot read your password and neither can anyone who steals our database.Yes
Your nameSo the site can greet you and so a draft email you write reads correctly.No
Research interest, in your own wordsThis is what the matching engine actually reads. Without it, matching does nothing.No
Degree sought, fieldsTo narrow results.No
Nationality, funding position, current qualification, destination countriesOnly to filter scholarships and programmes to ones you are actually eligible for. Telling you about a scholarship you cannot win wastes your time.No
Saved researchers, saved searches, applications you trackTo give them back to you. That is the whole feature.No
The commitment on the sensitive fields. Your nationality, funding position and qualification are, in combination, enough to identify you and to describe how much leverage someone has over you. They are therefore: never shown to a researcher; never sold, rented or shared for marketing; and never included in any statistic we give an institution unless that statistic covers at least twelve students. If you would rather not give them, leave them blank — the rest of Synora works.

What we do not collect

We do not ask for passports, identity documents, financial statements, transcripts or visa records. We do not want them, we have no use for them, and holding them would make us a target. If any page ever asks you for one, it is not us.

What happens when you write to a researcher

Synora writes a draft for you. You send it yourself, from your own email, and that message is not routed through us. We never send a message to a researcher on your behalf — the endpoint that would do it does not exist and returns an explicit refusal. Consequently a researcher only learns who you are when you decide to tell them.

3. If you are a researcher and you never signed up

This section is the notice required by Article 14 of the GDPR. If you have found your name on Synora and want to know what is going on, this is the answer.

What we hold and where it came from

We hold a profile built entirely from OpenAlex, a public bibliographic database of scholarly works. Nothing in it came from you, from your employer, or from any private source. Specifically:

We do not hold your email address, your telephone number, your salary, your students, your grants, or anything you have not published.

What we do with it

We match it against descriptions written by prospective master's and doctoral students, and we show the student why the match was made — which shared field, which shared topic — so they can judge it rather than trust it. That is the entire purpose.

What your profile does not say. Until you claim it, your profile states nothing about whether you supervise students, whether you have capacity, or what you would do for anyone. It cannot: the database physically refuses to store an intention on an unclaimed profile, and every result carries the words "has not joined Synora". We will not put words in your mouth.

Why you were not emailed about this

Article 14 normally requires us to contact you directly. Article 14(5)(b) permits publishing this notice instead where contacting each person would involve a disproportionate effort, and requires us to protect your rights by other means in exchange. We have taken that route, and we think you are entitled to know exactly why rather than being told it is "for operational reasons":

The measures we take instead, which is what the exemption obliges: this public notice; a removal route that needs no account and no login (section 8); no use of your data for marketing; no sale or sharing of it; and a profile that says plainly that you are not a member.

Where this reasoning is weakest, stated plainly. Article 14(5)(b) is strongest when the processing is for scientific research. Synora is a matching service that intends to charge money, and whether that counts as scientific research is genuinely unsettled. A regulator could disagree with us. We have therefore written down the balancing exercise behind this decision and will produce it on request, and if we are told to notify people directly we will.

The rest of what Article 14 requires you to be told

ControllerSKLZ LABS LLC, Kyrgyz Republic. Contact: fxfactor24@gmail.com
PurposeMatching published researchers to prospective postgraduate students, and showing the evidence for each match.
Lawful basisLegitimate interests, GDPR Article 6(1)(f). See section 4.
SourceOpenAlex (openalex.org), a publicly accessible bibliographic database. Some records originate with ORCID and with publishers.
RecipientsStudents using the service see your public profile. Our hosting and database providers process it on our instructions. Nobody else.
TransfersSee section 9.
RetentionSee section 6.
Your rightsAccess, rectification, erasure, restriction, portability, and — importantly here — the right to object at any time. See sections 7 and 8.
ComplaintsTo us first, and to your national data protection authority, or the ICO in the UK, whether or not you complain to us.

If you claim your profile

Claiming is done through ORCID. We request the minimum scope — enough to confirm the identifier and your name, nothing else. We never read your ORCID record, and we do not receive your ORCID password. After claiming, anything further on your profile is there because you typed it, and you can change or delete it whenever you like.

4. Our lawful basis

ProcessingBasis
Running your student accountContract — Art. 6(1)(b). We cannot give you an account without it.
Nationality, funding position, qualificationConsent — Art. 6(1)(a). Optional, and withdrawable by clearing the field.
The researcher corpusLegitimate interests — Art. 6(1)(f).
Security, fraud prevention, rate limitingLegitimate interests — Art. 6(1)(f).
Transactional email (password resets)Contract — Art. 6(1)(b).

Our legitimate interest in the corpus is making the process of finding a doctoral supervisor legible to applicants who currently have no way in — an audience that education agents do not serve, because there is no commission on a funded research place. We have balanced that against your interests, and the factors that weighed against us were: you have no existing relationship with us, and you did not expect this. The measures in section 3 are our answer to that. You can require us to reconsider it in your particular case at any time, and you do not have to give a reason.

5. Who we share data with

We do not sell personal data. We have no advertising. We share only with providers who process on our instructions and are contractually bound:

We will disclose data if a competent authority lawfully compels us, and we will tell you unless we are legally forbidden from doing so.

6. How long we keep it

Student accountUntil you delete it. Deletion removes your profile, saved researchers, saved searches and tracked applications, immediately and by database cascade — not by a flag that hides them.
Inactive student accountWe will contact you after two years of no sign-in and delete it if you do not respond.
Researcher profile, unclaimedFor as long as it is in the public bibliographic record and you have not objected. If you object, see section 8.
Researcher profile, claimedUntil you unclaim or delete it.
Password reset tokensSixty minutes, single use. Only a hash is stored, never the token.
Suppression listIndefinitely, and deliberately. If you ask to be removed we must keep a minimal record that you did, or the next data refresh would put you straight back.

7. Your rights

Whoever you are and wherever you are, you can ask us to: give you a copy of what we hold; correct it; delete it; restrict what we do with it; hand it to you in a portable format; and object to it. Where we rely on consent you can withdraw it, and that does not affect anything done before you did.

Write to fxfactor24@gmail.com. We aim to answer within seven working days. We do not charge, and we will not ask you to prove your identity beyond what is necessary — for a researcher asking about their own public profile, usually nothing at all.

You can complain to a supervisory authority without coming to us first: the State Agency for the Protection of Personal Data of the Kyrgyz Republic, your own national authority in the EU, or the Information Commissioner's Office in the UK.

8. Getting removed

One email, no account, no form, no reason required.

Send us the name on the profile from any address, or the link to it. We will remove it from search and from the platform, and we will add the underlying identifier to a suppression list so that the next refresh of the public record cannot recreate it. We will confirm when it is done.

You may also ask only for a correction — a wrong institution, a paper that is not yours, a conflated identity — and we would rather have that than lose you from the index entirely. But it is your call, not ours, and we will not argue with you about it.

9. International transfers

We are in the Kyrgyz Republic; our hosting and email providers are in the European Union and the United States. Data therefore moves across borders in both directions.

Out of Kyrgyzstan, Article 89 of the Digital Code permits transfer to countries the State Agency has designated as offering adequate protection, or under contractual safeguards. The adequacy list has not yet been published, so we rely on the contractual route with each provider.

Out of the EU and UK, we rely on the Standard Contractual Clauses and the UK Addendum with our processors.

10. Security

No system is perfect. If we suffer a breach that is likely to put you at risk, we will tell you and the relevant authority.

11. Children

Synora is for people applying to postgraduate study and is not intended for anyone under 16. We do not knowingly hold data about children. If you believe we do, tell us and we will delete it.

12. What we have not done yet

Three obligations were identified while writing this and are not yet satisfied. Listing them is not a substitute for meeting them, but publishing a notice that quietly implies otherwise would be worse.

ObligationStatus
An EU representative.GDPR Article 27 requires a controller outside the Union to appoint one in a Member State, unless its processing is occasional. Ours is continuous, so the exemption is unlikely to be available.Not appointedRequired before significant EU use.
A UK representative.UK GDPR Article 27, on the same basis.Not appointed
Legal review.Of the Article 14(5)(b) position, and of the legitimate interests assessment behind the corpus.Partly doneWritten and documented internally; not yet reviewed by a qualified lawyer.

Changes to this notice

If we change it materially we will change the version number, date it, and — for logged-in students — say so on the site. Old versions are kept so you can see what changed.