Privacy-Policy

Legal

Privacy Policy & Cookies Policy

Share Your Passion, Inc. (d/b/a SYP AI)

At Share Your Passion, Inc., doing business as SYP AI (“SYP,” “we,” “us” or “our”), we consider the privacy and the security of personal data to be extremely important. This Privacy Policy and Cookies Policy (“Policy”) explains how we collect, use, disclose, transfer and protect personal data in connection with our website at www.getsyp.com (the “Site”), the SYP AI software-as-a-service loyalty, rewards, engagement, publishing and analytics platform (the “Services”), our mobile apps and any other source where this Policy is displayed. It also describes the cookies and similar technologies we use (Section 15) and sets out jurisdiction-specific disclosures required by the laws of the United States, the United Kingdom, Switzerland, the European Union / European Economic Area, the United Arab Emirates, the Kingdom of Saudi Arabia and the Republic of South Africa (Section 17).

Two roles, two relationships. SYP processes personal data (1) for our own purposes as a controller, and (2) under the documented instructions of our business clients (each, a “Client”) as a processor when we process the personal data of their end users, followers, contacts and other individuals on Instagram, Facebook, TikTok and WhatsApp (collectively, “Subscribers”) to provide the Services. This Policy describes our practices as a controller. Where we act as a processor, our handling of personal data is governed by our agreement with the relevant Client and our Data Processing Addendum (“DPA”), and Subscribers should direct privacy requests to the Client that controls their data (see Section 9).

01

Definitions

Terms not defined in this Policy have the meaning given in the applicable data protection law of your jurisdiction.

Personal Data

Any information relating to an identified or identifiable natural person (also called personal information or PII).

Sensitive Personal Data

Personal data requiring special protection under applicable law — including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Under U.S. state laws, may also include precise geolocation, financial account and payment-card data, government identifiers, and children’s data.

Controller

The natural or legal person that determines the purposes and means of the processing of personal data.

Processor

A natural or legal person that processes personal data on behalf of the controller.

Subscriber

An end user, follower, contact or other individual whose personal data a Client imports, uploads, or that we process via authorized Meta, Instagram, TikTok and WhatsApp APIs on the Client’s behalf. “Client Content” means the personal data of Subscribers processed on the Client’s behalf, together with any User Generated Content as defined in our Terms of Service.

02

Scope and Our Role

This Policy applies to personal data we process about: visitors to and users of the Site and mobile apps; prospective clients and event, community or newsletter participants; the personnel, employees and representatives of our Clients and counterparties; and individuals who otherwise communicate with us.

It does not govern personal data we process solely as a processor on behalf of a Client (Client Content and Subscribers), which is addressed in Section 9 and the DPA, nor the independent practices of the third-party platforms with which the Services integrate (Section 19).

This Policy applies globally. Section 17 sets out additional or superseding rights and disclosures for individuals in specific jurisdictions.

03

Personal Data We Collect

The categories of personal data we collect depend on how you interact with us:

  • Account and registration data — name, business name and title, email address, phone number, login credentials, and connected social-media accounts (Instagram, Facebook, TikTok, WhatsApp, payment processors).
  • Billing and transaction data — billing contact, billing address, Subscription Tier, Credit usage, and payment information (processed by third-party payment processors; we retain only truncated card data such as the last four digits and expiration).
  • Contact, business and communications data — full name, title, company, email or other contact details, and the content of information you provide in forms, demo or contact requests, support tickets, emails, and survey or event participation.
  • Usage, log and device data — IP address, browser type and settings, plugins, language preferences, device type, operating system and identifiers, pages and features used, time spent, links clicked, dates and times of access, and referring pages.
  • Cookies and similar technologies data — as described in Section 15.
  • Email performance data — engagement and performance metrics of our newsletters, collected via tracking pixels. You can disable this by turning off images in your email client.
  • Community and event data — data visible in your social profile, comments you post in our groups, registration details for SYP-organized events, and photo/audio-visual content captured at in-person events for promotional purposes (with opportunity to opt out).
  • Inferences — inferences we draw from the above to identify preferences, characteristics, behaviour and attitudes.
Note: Please do not send or disclose Sensitive Personal Data (e.g., social security numbers, racial or ethnic origin, health or biometric data, criminal background) to us via the Site or Services.
04

How We Collect Personal Data

  • Directly from you — when you register, subscribe, complete a form, contact us, sign a DPA or other document, or use the Site or Services.
  • Automatically — through cookies, server logs and similar technologies when you use the Site, mobile apps or Services.
  • From integrations you authorize — such as Meta, Instagram, Facebook, TikTok, WhatsApp and payment processors, when you connect your accounts to the Services.
  • From third parties — such as payment processors, analytics and advertising partners, professional networks (e.g., LinkedIn), event co-hosts and partners, and publicly available sources.
  • From our communities — when you join our Facebook, Instagram, TikTok or other social media groups or accounts, and from event registration data provided by co-hosting partners.
05

How and Why We Use Personal Data

As a controller, we use personal data to:

  • Operate the Services — provide, operate, maintain, secure and administer the Site, the Services and your Account, and communicate with you about them (announcements, technical notices, security alerts, support). This includes billing and contractual obligations.
  • Provide the Services — process Client Content on behalf of a Client (see DPA).
  • Communicate and inform — respond to inquiries, support requests and feedback, and send SYP-related marketing and informational communications where permitted, always with the ability to opt out.
  • Conduct events — send reminders, logistical updates and post-event follow-up, and (where opted in) information about future events.
  • Capture event photography — photograph and record attendees at in-person events for promotional purposes, with an opportunity to opt out.
  • Inform you about career opportunities — where you have opted in, send information about open roles relevant to your background.
  • Analyze and improve the Services — produce aggregated or de-identified analytics, benchmarks and product-improvement insights.
  • Comply with law — including sanctions, accounting and tax obligations, legal processes, audits and responses to lawful government requests.
  • Negotiate, enter and perform agreements — with our counterparties and their representatives.
  • Compliance and safety — enforce our terms; protect rights, privacy, safety or property; detect and deter fraudulent, harmful or illegal activity.
06

Legal Bases for Processing

Where EU GDPR, UK GDPR, Swiss revFADP, UAE Federal Decree-Law No. 45/2021 or Saudi PDPL applies, we rely on one or more of the following lawful bases:

  • Performance of a contract (Art. 6(1)(b) EU/UK GDPR) — where processing is necessary to provide the Site, Services or Account, or to take steps at your request before entering into a contract.
  • Legitimate interests (Art. 6(1)(f) EU/UK GDPR) — to communicate about and improve our Services, secure our systems, conduct events, run our business, prevent fraud and defend legal claims, balanced against your rights and freedoms. Our legitimate interests balancing test is available on request.
  • Consent (Art. 6(1)(a) EU/UK GDPR) — for certain cookies, direct electronic marketing and other processing where consent is required. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Compliance with a legal obligation (Art. 6(1)(c) EU/UK GDPR) — to meet tax, accounting, employment, anti-money-laundering, sanctions or other legal requirements.
  • Vital interests, public interest and other bases — in the limited cases where applicable law provides for them.

Under the Saudi PDPL and UAE PDPL, consent is generally the default lawful basis; we rely on additional statutory bases (performance of contract, legal obligation, protection of vital interests, or legitimate interest as narrowly defined) where permitted by law. Under POPIA (South Africa), we process personal information only where one of the justifications in section 11 applies — including the data subject’s consent, performance of a contract, compliance with a legal obligation, protection of a legitimate interest of the data subject, performance of a public-law duty by a public body, or the legitimate interests of the responsible party or a third party — and we comply with the further conditions on processing set out in Chapter 3 of POPIA.

07

How We Share Personal Data

We do not sell personal data for monetary consideration. As explained in Section 15, certain advertising or analytics cookies may constitute a “sale” or “sharing” under the CCPA/CPRA and equivalent U.S. state laws — you can opt out as described in Sections 15 and 17.1. We disclose personal data only as follows:

  • Service providers and processors — vendors that host, support, secure and operate the Site and Services (cloud hosting, payment processing, CRM, email agents, analytics, communications, AI model providers). These third parties may only use personal data to perform tasks in accordance with our agreements.
  • Advertising partners — limited personal data to measure advertising effectiveness and (where permitted) personalize ads. Raw email addresses are never shared; where used, identifiers are hashed (e.g., SHA-256) and transmitted securely.
  • Authorized integrations — Meta, Instagram, Facebook, TikTok, WhatsApp and other platforms you connect, to provide the Services you request.
  • Professional advisors — lawyers, bankers, auditors, accountants and insurers, as needed.
  • Corporate affiliates — in accordance with this Policy. A current list is at getsyp.com/legal/affiliates.
  • Corporate transactions — in connection with a merger, acquisition, financing, reorganization or sale of assets.
  • Legal and safety — to comply with law or valid legal process, enforce our agreements, and protect rights, privacy, safety or property.
  • With your consent or at your direction — in any other case you authorize.
08

Sub-processors, Service Providers and Corporate Affiliates

A current list of sub-processors and service providers, together with our corporate affiliates, is published at getsyp.com/legal/service-providers. Clients receive advance notice of material changes as required by the DPA. We conduct due diligence, impose written data-protection obligations, and remain responsible for their acts and omissions to the extent required by applicable law.

09

Client (Processor) Data and Subscriber Requests

When we provide the Services to a Client, the Client determines the purposes and means of processing Client Content and the personal data of Subscribers. The Client is the controller; SYP acts only as a processor and processes such data under the Client’s documented instructions and the DPA.

We have no direct relationship with Subscribers. The Client is responsible for ensuring it has the appropriate permission and legal basis for us to collect and process personal data about Subscribers, and for informing Subscribers about the collection of personal data by the Services, this Policy and the DPA.

Subscribers: If you wish to exercise privacy rights with respect to data processed through the Services, please contact the Client (the business) that controls your data. If you contact us directly, we will refer your request to the relevant Client.
10

AI Features, Sentiment Analysis and Automated Decision-Making

The Services include AI Features, including AI-powered sentiment analysis, content analysis, and image, video, profile and text analysis. Where a Client uses these features, SYP may process the inputs submitted and the outputs generated (including sentiment scores, classifications and insights derived from social-media content and from public profile information of Subscribers) to provide, maintain, secure and improve the Services and to comply with law.

Additional terms specific to AI Features are set out in the AI Supplementary Terms.

We contractually restrict our AI model providers from using Client inputs or outputs to train or improve their models for general purposes. Sentiment and other AI outputs are automated, probabilistic estimates that may be inaccurate or incomplete and are not advice.

EU AI Act. Where the Services fall within the scope of Regulation (EU) 2024/1689 (the “AI Act”), we act as a “provider” or “deployer” only in the roles allocated by our contract with the Client. Emotion-recognition and biometric-categorization functionality is not used in prohibited contexts under Article 5 of the AI Act.

11

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including for the duration of your relationship with us, and thereafter as necessary to comply with our legal, tax, accounting and contractual obligations, resolve disputes, prevent abuse and enforce our agreements.

Once your Account is deleted or deactivated, we will securely delete or anonymize your personal data unless a longer retention period is required by law or necessary to establish, exercise or defend legal claims.

As a general matter, and subject to any longer period required by law, Client-related personal data is retained for up to three (3) years following the end of the applicable Client agreement, after which it is securely deleted or anonymized. Specific retention periods are set out in our internal retention schedule, available on request from the Data Protection Officer (Section 21).

12

Data Security and Breach Notification

Safeguarding your information. We take reasonable and appropriate administrative, technical and organizational measures to protect personal data. Our security standards include:

  • Payment processing handled by PCI-DSS-compliant providers
  • Data in transit encrypted using TLS 1.2 or higher
  • Data at rest encrypted using AES-256 or equivalent
  • Access controls following least-privilege principles with multi-factor authentication for privileged accounts

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Notice of breach. If a personal data breach materially affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authorities within the timeframes required by applicable law, including:

  • Within 72 hours to EU/UK/Swiss supervisory authorities
  • Without undue delay to the UAE Data Office
  • Within 72 hours to the Saudi Arabia National Data Management Office (SDAIA) for serious breaches
  • As soon as reasonably possible after discovery to the South African Information Regulator, and to affected data subjects as required by section 22 of POPIA (subject to the limited deferral grounds in section 22(3))
  • In accordance with applicable U.S. state and sectoral breach-notification laws
13

International Data Transfers and Data Privacy Frameworks

SYP is based in the United States and uses service providers in the U.S. and other countries. If you are located outside the United States, your personal data may be transferred to, stored and processed in countries whose data-protection laws may differ from those of your country.

Where we transfer personal data from the EEA, UK, Switzerland, UAE, Saudi Arabia or South Africa to a country not recognized as providing adequate protection, we rely on appropriate safeguards including:

  • European Commission Standard Contractual Clauses (2021/914) for transfers from the EEA
  • UK International Data Transfer Addendum to the EU SCCs, or the UK International Data Transfer Agreement, for transfers from the UK
  • Swiss FDPIC-approved SCCs for transfers from Switzerland
  • Written binding instruments permitted under UAE PDPL and DIFC/ADGM laws
  • Transfers permitted by Saudi SDAIA implementing regulations
  • For transfers from South Africa, the mechanisms permitted under section 72 of POPIA — including transfers to a recipient country with adequate protection, binding corporate rules or binding agreements, transfers with the data subject’s consent, transfers necessary for the performance of a contract, or transfers for the benefit of the data subject where consent is impracticable
  • Binding Corporate Rules where applicable
  • Supplementary technical, contractual and organizational measures where required

EU-U.S. / UK / Swiss Data Privacy Framework. Where SYP holds an active certification, it adheres to the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework. Unresolved complaints may be referred to ICDR-AAA DPF IRM Service at no cost. SYP is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC). See dataprivacyframework.gov for our certification.

14

Your Privacy Rights, Choices and Response Times

Depending on where you live and our role, you may have rights to:

  • Access, correct, delete, restrict or object to the processing of your personal data
  • Receive a portable copy of your personal data
  • Opt out of marketing, targeted advertising, profiling and the “sale” or “sharing” of personal information
  • Withdraw consent at any time
  • Not be subject to solely automated decisions with legal or similarly significant effects
  • Not be discriminated against for exercising your rights
  • Lodge a complaint with a competent supervisory authority

How to submit a request. Contact us at contact@getsyp.com or use our DSAR tool. You may also manage cookie choices via Section 15 and opt out of marketing emails using the unsubscribe link in any marketing message.

Response times. We will acknowledge receipt within 10 business days. Subject to identity verification, we will respond within 45 calendar days. If we require more time (up to a further 45 days, for a maximum of 90 days), we will inform you in writing.

Non-discrimination. We will not discriminate against you for exercising your privacy rights.

Fees. We do not charge a fee to process a verifiable request unless it is excessive, repetitive or manifestly unfounded. If a fee is warranted, we will provide an estimate before completing your request.

15

Cookies and Similar Technologies

We and our partners use cookies, pixels, SDKs, local storage, tags and similar technologies (collectively, “cookies”) on the Site to enable functionality, remember your preferences, measure performance, and — where permitted — deliver and measure advertising.

Manage your choices at any time through our Cookie Settings tool. Disabling certain cookies may affect how the Site functions.

Consent basis for cookies. In the EEA, UK, Switzerland and jurisdictions with prior-consent requirements, we set non-essential cookies only after you give consent through our cookie banner. In the U.S., non-essential cookies may be used subject to opt-out rights and Global Privacy Control (Section 16).

Category Purpose Can it be disabled?
Strictly Necessary Enable core Site functions such as security, network management and access. The Site cannot function properly without them. Always active
Functional Remember choices and preferences to provide enhanced, personalized features. Yes
Performance / Analytics Help us understand how the Site is used so we can measure and improve performance. Yes
Targeting / Advertising Set by us or our partners to build a profile of your interests and show relevant ads on and off the Site, including via hashed identifiers as described in Section 7. Yes
16

Do Not Track and Global Privacy Control

Because the cookie preference tool is device- and browser-specific, if you delete cookies, change devices, or switch browsers, you will need to reset your preferences.

Our Site does not currently respond to “Do Not Track” browser signals, because no consensus standard governs their implementation. However, we honor the Global Privacy Control (“GPC”) browser signal as a valid request to opt out of targeting/advertising cookies and any “sale” or “sharing” of personal information where required by law.

17

Region-Specific Rights and Disclosures

This Section supplements the rest of the Policy with disclosures required in specific jurisdictions. In case of conflict, this Section prevails for individuals in the relevant jurisdiction.

17.1 United States

This Section applies to residents of U.S. states with comprehensive privacy laws, including California (CCPA/CPRA), Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Nebraska, Kentucky and Indiana.

Subject to statutory exceptions and verification, you may have the right to:

  • Request disclosure of the categories and specific pieces of personal information collected, sold or shared about you (Requests to Know)
  • Request deletion of personal information collected from you (Requests to Delete)
  • Correct inaccurate personal information
  • Opt out of the “sale” or “sharing” of personal information and of targeted advertising and certain profiling
  • Limit the use of sensitive personal information
  • Designate an authorized agent to make requests on your behalf
  • Not receive discriminatory treatment for exercising your rights
  • Appeal a denial of your request

We do not sell personal information for money. We do not knowingly sell or share the personal information of consumers under 16. To opt out of advertising/analytics cookies, use our Cookie Settings tool, submit a request via getsyp.com/dsar, or broadcast the GPC signal.

California residents may also submit “Shine the Light” requests at contact@getsyp.com (one request per calendar year). Authorized agents may submit requests with proper authorization, including a valid power of attorney under Cal. Prob. Code §§ 4121–4130.

Appeals. If we deny your request, reply to our response or email contact@getsyp.com with the subject “Privacy Appeal.”

17.2 European Economic Area (EEA)

Where EU GDPR applies, you have the right to: access your personal data and receive a copy; rectify inaccurate or incomplete personal data; erase your personal data (right to be forgotten); restrict processing; object to processing based on legitimate interests and to direct marketing at any time; receive your personal data in a portable, machine-readable format; not be subject to solely automated decisions with legal or significant effects (Article 22 GDPR); withdraw consent at any time; and lodge a complaint with your local supervisory authority (edpb.europa.eu).

17.3 United Kingdom

UK residents have the same substantive rights as those in Section 17.2, exercisable in the same manner. We send marketing emails only where we have your consent or a lawful “soft opt-in” under PECR, and you can opt out at any time. You may lodge a complaint with the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom — ico.org.uk — +44 (0)303 123 1113.

17.4 Switzerland

Swiss residents have rights to: receive information about processing; access their personal data; rectification, deletion or destruction; object to processing; restrict processing; data portability; and not be subject to solely automated individual decisions with significant effects. Complaints may be lodged with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland — edoeb.admin.ch.

17.5 United Arab Emirates

Where the UAE Federal Decree-Law No. 45 of 2021 (UAE PDPL) applies, individuals in the UAE have rights to: obtain information about processing; request access, correction or deletion; request restriction or cessation of processing; request transfer of data in machine-readable format; object to processing causing harm or used for direct marketing; and object to automated decisions with legal effects. Complaints may be submitted to the UAE Data Office (Data Office of the Cabinet).

DIFC: If you are in the Dubai International Financial Centre, the DIFC Data Protection Law No. 5 of 2020 (as amended) applies. Complaints may be lodged with the DIFC Commissioner of Data Protection at dp.difc.ae.

ADGM: If you are in the Abu Dhabi Global Market, the ADGM Data Protection Regulations 2021 apply. Complaints may be lodged with the Office of Data Protection at adgm.com.

17.6 Kingdom of Saudi Arabia

Where the KSA Personal Data Protection Law (PDPL, Royal Decree No. M/19) applies, data subjects have the rights to: be informed of the legal basis and purposes of processing; access their personal data and obtain a copy free of charge; request correction, completion or updating of their personal data; and request destruction of their personal data when no longer needed.

Consent is generally required to process personal data unless one of the statutory grounds in Articles 5–6 of the KSA PDPL applies. Sensitive personal data is subject to enhanced protections. Cross-border transfers are subject to the KSA PDPL’s transfer rules. Complaints may be submitted to the Saudi Data & AI Authority (SDAIA) at sdaia.gov.sa.

17.7 Republic of South Africa

This Section applies where the Protection of Personal Information Act, 4 of 2013 (“POPIA”) and its Regulations apply to our processing. Under POPIA, SYP is the “responsible party” for the personal information described in Section 2, and processes such information in accordance with the eight conditions for lawful processing set out in Chapter 3 of POPIA: accountability; processing limitation; purpose specification; further processing limitation; information quality; openness; security safeguards; and data subject participation.

Rights of data subjects. Subject to statutory conditions and exceptions, if you are a data subject in South Africa, you have the right to:

  • Be notified that your personal information is being collected, and that your personal information has been accessed or acquired by an unauthorised person (sections 18 and 22)
  • Request confirmation, free of charge, of whether we hold personal information about you, and to request access to and a description of that information, including the identity of third parties who have or have had access to it (section 23)
  • Request the correction, destruction or deletion of your personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, or that we are no longer authorised to retain (section 24)
  • Object, on reasonable grounds relating to your particular situation, to the processing of your personal information — including at any time to processing for purposes of direct marketing by means other than unsolicited electronic communications governed by section 69 (sections 11(3) and 11(4))
  • Not be subject to a decision based solely on the automated processing of your personal information intended to provide a profile of you that has legal consequences or affects you to a substantial degree (section 71)
  • Submit a complaint to the Information Regulator regarding an alleged interference with the protection of your personal information (section 74)
  • Institute civil proceedings regarding an alleged interference with the protection of your personal information (section 99)

Special personal information and children’s information. We do not process special personal information (as defined in section 26 of POPIA, including information concerning religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, or biometric information) or the personal information of children (as defined in section 34) except where a lawful ground under sections 27 or 35 of POPIA applies, including your express consent.

Direct marketing. In accordance with section 69 of POPIA, we do not send unsolicited electronic direct marketing communications to any data subject who is not already a customer of SYP unless the data subject has given consent. Existing customers may receive direct marketing about our similar products and services and may opt out at any time using the unsubscribe link in any marketing message.

Cross-border transfer. Personal information may be transferred outside South Africa in accordance with section 72 of POPIA and as further described in Section 13 of this Policy.

Information Officer and complaints. Where required, SYP has designated an Information Officer, contactable at contact@getsyp.com. You may submit complaints regarding our processing to the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — inforegulator.org.za — +27 (0)10 023 5200 — POPIAComplaints@inforegulator.org.za.

18

Children’s Privacy

The Site and Services are intended for businesses and individuals who are at least 18 years old. We do not knowingly collect personal data from anyone under 18 as a controller, nor does SYP knowingly solicit personal data from anyone under 18. If you are under 18, you may not attempt to register for the Services or send any information about yourself to us.

If we confirm that we have collected personal data from someone under 18 without verification of parental consent, we will delete that information promptly. We do not sell or share the personal information of individuals we know to be under 16 (as defined under the CCPA/CPRA), and we comply with COPPA where applicable.

If you believe a child has provided us personal data, please contact us at contact@getsyp.com.

19

Third-Party Links and Platforms

The Site and Services may link to or integrate with third-party websites and platforms, including the Meta Platforms (Facebook, Instagram, WhatsApp), TikTok, and payment processors, which operate under their own terms and privacy policies. We are not responsible for the privacy practices or content of those third parties. Please review their policies before providing personal data.

20

Changes to This Policy

We may update this Policy from time to time to reflect legal, technical or business developments. When we update this Policy, we will take appropriate measures to inform you before its entry into force, consistent with the significance of the changes.

We will post the updated Policy on this page and revise the “Last Updated” date above. For material changes affecting our Clients, we will provide advance notice consistent with our agreement with them. Where required by applicable data-protection law, we will obtain your consent to material changes.

Your continued use of the Site or Services after the effective date constitutes acceptance of the revised Policy. Prior versions of this Policy are available on request.

21

Contact Us, Data Protection Officer and Representatives

For questions, concerns or requests regarding this Policy or your personal data, please use the details below.

Data Controller

Share Your Passion, Inc. (d/b/a SYP AI)
151 East 83rd Street, Suite 3A
New York, NY 10028, USA
contact@getsyp.com
DSAR Portal

Data Protection Officer

Where required by law, SYP has appointed a Data Protection Officer.
dpo@getsyp.com

EU / UK / Swiss Representatives

Where Article 27 EU GDPR, Article 27 UK GDPR or Article 14 revFADP apply, SYP will appoint and publish contact details here. In the meantime, requests may be sent to contact@getsyp.com.

UAE / KSA Contacts

For individuals in the UAE (including DIFC and ADGM) or KSA, requests and complaints may be sent to contact@getsyp.com. We will respond within the statutory timeframes.

South Africa — Information Officer

For individuals in the Republic of South Africa, requests, objections and complaints under POPIA may be sent to contact@getsyp.com for the attention of the Information Officer. We will respond within the statutory timeframes.

Scroll to Top