Synora holds information about two very different groups of people: students who chose to sign up, and researchers who did not. This notice covers both, and it is honest about the second because that is the part that matters.
Synora is operated by SKLZ LABS LLC, registered in the Kyrgyz Republic. We are the "controller" of the personal data described here, which means we decide why and how it is processed and we are answerable for it.
Because we are established in the Kyrgyz Republic and offer a service to people in the European Union and the United Kingdom, more than one law applies to us at once:
Where these give you different rights, you get whichever is stronger. Where they set different deadlines, we work to the shortest: the Digital Code requires a reasoned answer within seven working days, which is faster than GDPR's one month, so seven working days is what we aim for on every request from anyone.
You gave us this information yourself, and almost all of it is optional.
| What | Why | Required? |
|---|---|---|
| Email address | To identify your account, let you sign in, and send you a password reset if you ask for one. | Yes |
| Password | Stored only as a scrypt hash. We cannot read your password and neither can anyone who steals our database. | Yes |
| Your name | So the site can greet you and so a draft email you write reads correctly. | No |
| Research interest, in your own words | This is what the matching engine actually reads. Without it, matching does nothing. | No |
| Degree sought, fields | To narrow results. | No |
| Nationality, funding position, current qualification, destination countries | Only to filter scholarships and programmes to ones you are actually eligible for. Telling you about a scholarship you cannot win wastes your time. | No |
| Saved researchers, saved searches, applications you track | To give them back to you. That is the whole feature. | No |
We do not ask for passports, identity documents, financial statements, transcripts or visa records. We do not want them, we have no use for them, and holding them would make us a target. If any page ever asks you for one, it is not us.
Synora writes a draft for you. You send it yourself, from your own email, and that message is not routed through us. We never send a message to a researcher on your behalf — the endpoint that would do it does not exist and returns an explicit refusal. Consequently a researcher only learns who you are when you decide to tell them.
This section is the notice required by Article 14 of the GDPR. If you have found your name on Synora and want to know what is going on, this is the answer.
We hold a profile built entirely from OpenAlex, a public bibliographic database of scholarly works. Nothing in it came from you, from your employer, or from any private source. Specifically:
We do not hold your email address, your telephone number, your salary, your students, your grants, or anything you have not published.
We match it against descriptions written by prospective master's and doctoral students, and we show the student why the match was made — which shared field, which shared topic — so they can judge it rather than trust it. That is the entire purpose.
Article 14 normally requires us to contact you directly. Article 14(5)(b) permits publishing this notice instead where contacting each person would involve a disproportionate effort, and requires us to protect your rights by other means in exchange. We have taken that route, and we think you are entitled to know exactly why rather than being told it is "for operational reasons":
The measures we take instead, which is what the exemption obliges: this public notice; a removal route that needs no account and no login (section 8); no use of your data for marketing; no sale or sharing of it; and a profile that says plainly that you are not a member.
| Controller | SKLZ LABS LLC, Kyrgyz Republic. Contact: fxfactor24@gmail.com |
| Purpose | Matching published researchers to prospective postgraduate students, and showing the evidence for each match. |
| Lawful basis | Legitimate interests, GDPR Article 6(1)(f). See section 4. |
| Source | OpenAlex (openalex.org), a publicly accessible bibliographic database. Some records originate with ORCID and with publishers. |
| Recipients | Students using the service see your public profile. Our hosting and database providers process it on our instructions. Nobody else. |
| Transfers | See section 9. |
| Retention | See section 6. |
| Your rights | Access, rectification, erasure, restriction, portability, and — importantly here — the right to object at any time. See sections 7 and 8. |
| Complaints | To us first, and to your national data protection authority, or the ICO in the UK, whether or not you complain to us. |
Claiming is done through ORCID. We request the minimum scope — enough to confirm the identifier and your name, nothing else. We never read your ORCID record, and we do not receive your ORCID password. After claiming, anything further on your profile is there because you typed it, and you can change or delete it whenever you like.
| Processing | Basis |
|---|---|
| Running your student account | Contract — Art. 6(1)(b). We cannot give you an account without it. |
| Nationality, funding position, qualification | Consent — Art. 6(1)(a). Optional, and withdrawable by clearing the field. |
| The researcher corpus | Legitimate interests — Art. 6(1)(f). |
| Security, fraud prevention, rate limiting | Legitimate interests — Art. 6(1)(f). |
| Transactional email (password resets) | Contract — Art. 6(1)(b). |
Our legitimate interest in the corpus is making the process of finding a doctoral supervisor legible to applicants who currently have no way in — an audience that education agents do not serve, because there is no commission on a funded research place. We have balanced that against your interests, and the factors that weighed against us were: you have no existing relationship with us, and you did not expect this. The measures in section 3 are our answer to that. You can require us to reconsider it in your particular case at any time, and you do not have to give a reason.
We do not sell personal data. We have no advertising. We share only with providers who process on our instructions and are contractually bound:
We will disclose data if a competent authority lawfully compels us, and we will tell you unless we are legally forbidden from doing so.
| Student account | Until you delete it. Deletion removes your profile, saved researchers, saved searches and tracked applications, immediately and by database cascade — not by a flag that hides them. |
| Inactive student account | We will contact you after two years of no sign-in and delete it if you do not respond. |
| Researcher profile, unclaimed | For as long as it is in the public bibliographic record and you have not objected. If you object, see section 8. |
| Researcher profile, claimed | Until you unclaim or delete it. |
| Password reset tokens | Sixty minutes, single use. Only a hash is stored, never the token. |
| Suppression list | Indefinitely, and deliberately. If you ask to be removed we must keep a minimal record that you did, or the next data refresh would put you straight back. |
Whoever you are and wherever you are, you can ask us to: give you a copy of what we hold; correct it; delete it; restrict what we do with it; hand it to you in a portable format; and object to it. Where we rely on consent you can withdraw it, and that does not affect anything done before you did.
Write to fxfactor24@gmail.com. We aim to answer within seven working days. We do not charge, and we will not ask you to prove your identity beyond what is necessary — for a researcher asking about their own public profile, usually nothing at all.
You can complain to a supervisory authority without coming to us first: the State Agency for the Protection of Personal Data of the Kyrgyz Republic, your own national authority in the EU, or the Information Commissioner's Office in the UK.
One email, no account, no form, no reason required.
Send us the name on the profile from any address, or the link to it. We will remove it from search and from the platform, and we will add the underlying identifier to a suppression list so that the next refresh of the public record cannot recreate it. We will confirm when it is done.
You may also ask only for a correction — a wrong institution, a paper that is not yours, a conflated identity — and we would rather have that than lose you from the index entirely. But it is your call, not ours, and we will not argue with you about it.
We are in the Kyrgyz Republic; our hosting and email providers are in the European Union and the United States. Data therefore moves across borders in both directions.
Out of Kyrgyzstan, Article 89 of the Digital Code permits transfer to countries the State Agency has designated as offering adequate protection, or under contractual safeguards. The adequacy list has not yet been published, so we rely on the contractual route with each provider.
Out of the EU and UK, we rely on the Standard Contractual Clauses and the UK Addendum with our processors.
No system is perfect. If we suffer a breach that is likely to put you at risk, we will tell you and the relevant authority.
Synora is for people applying to postgraduate study and is not intended for anyone under 16. We do not knowingly hold data about children. If you believe we do, tell us and we will delete it.
Three obligations were identified while writing this and are not yet satisfied. Listing them is not a substitute for meeting them, but publishing a notice that quietly implies otherwise would be worse.
| Obligation | Status |
|---|---|
| An EU representative.GDPR Article 27 requires a controller outside the Union to appoint one in a Member State, unless its processing is occasional. Ours is continuous, so the exemption is unlikely to be available. | Not appointedRequired before significant EU use. |
| A UK representative.UK GDPR Article 27, on the same basis. | Not appointed |
| Legal review.Of the Article 14(5)(b) position, and of the legitimate interests assessment behind the corpus. | Partly doneWritten and documented internally; not yet reviewed by a qualified lawyer. |
If we change it materially we will change the version number, date it, and — for logged-in students — say so on the site. Old versions are kept so you can see what changed.