Privacy Policy for XYO Enrichment API
This Privacy Policy describes how Syniol Limited ("we", "us", "our") collects, uses, stores, and protects information when you access the XYO Enrichment API, the client portal, and related Services. By registering for an API key or submitting requests to our endpoints, you consent to the practices described below.
Our policy is intentionally concise and can be summarised in the following bullet points. For any questions regarding the processing of your personal data or the data you submit for enrichment, please contact us at hello@syniol.com.
What we collect
- Account data: we request only the email address required to create your account, issue API keys, and communicate service updates. No additional personal identifiers are mandatory.
- Billing data: where API credits or paid plans are purchased, payment is handled by our payment processors. We retain only the invoicing metadata necessary for accounting and tax compliance.
- API request data: the payloads you submit to the XYO Enrichment API endpoints (transactions and related fields) are received, processed, and stored against your account.
- Technical telemetry: we collect endpoint usage, request timestamps, response codes, and rate-limit information for service stability, security, and abuse prevention.
- Analytics: we monitor page views and gather aggregated analytics on the marketing site and client portal through third-party providers, including Google and Microsoft Bing.
How we use your data
- To authenticate API requests, issue and rotate API keys, and meter usage against your pricing tier.
- To enrich the transactions you submit to our endpoints and return the enriched response to your application.
- To improve the accuracy and quality of our enrichment models — transactions submitted for enrichment are retained associated with the account and used for AI/ML learning.
- To detect, prevent, and investigate abuse, fraud, and violations of our Terms of Service.
- To send essential service communications (sign-up confirmation, security alerts, billing notices, and material changes to this policy).
Data retention
- Account email addresses are retained for a minimum of three years after account closure to prevent re-registration abuse. This retention period may be adjusted depending on circumstances and legal obligations.
- Enriched transaction payloads are retained for the lifetime of the account and may continue to be retained in anonymised or aggregated form for AI learning and abuse detection after account closure.
- Technical logs and telemetry are retained for a limited operational window sufficient for diagnostics and security review.
Account deactivation and key revocation
- At present, trial or demo accounts cannot be deactivated directly through the client portal interface.
- If you would like your account deactivated, your API keys revoked, and your email address blocked from future registration, please use the link provided in the sign-in/sign-up confirmation email to report your email address for blocking from our system.
- Revoking access will immediately invalidate any active API keys associated with the account.
Third parties
- The XYO Enrichment API may rely on third-party data sources to produce enriched responses. We do not control those sources and their data is provided through our API on an "as is" basis.
- We share data with our infrastructure, payment, and analytics providers strictly as required to deliver the Service. We do not sell personal data.
- For more information on the broader contractual relationship, please review our Terms and Conditions.
Your rights
- You may request access, correction, or deletion of the personal information we hold about you, subject to legal and operational constraints (for example, records required for abuse prevention and tax compliance).
- Requests should be sent to hello@syniol.com from the email address registered with the account.
This document edited on: Sun May 17 2026