Privacy Policy
Last updated: 22 September 2026
1. Who we are
G-SYNQ is a marketing automation agency based in the Philippines. We build lead follow-up, booking and customer relationship management (CRM) systems for businesses, including property agents in Singapore.
G-SYNQ is a business name used by Frenz Adrian Miravalles Sarabia, who operates it from the Philippines and is responsible for the personal data G-SYNQ collects ("G-SYNQ", "we", "us").
We handle personal data in line with the Philippines' Data Privacy Act of 2012 and, where we collect personal data from people in Singapore, Singapore's Personal Data Protection Act 2012 (PDPA).
This policy explains what personal data we collect, why, who we share it with, and how you can access or correct your data or withdraw your consent.
2. Two roles we play
When you enquire about our services, or we contact you about them, we decide what data is collected and why. This policy governs that data in full.
When we build and run a system for a client, we may handle personal data about that client's own enquiries and customers, such as property buyers and sellers, inside a sub-account we manage for them. In that case the client is responsible for the data, and we process it only on their instructions, as a data intermediary. Where a client uses Facebook or Instagram lead form ads, this can include sending updates on how their leads progress to the client's own Meta advertising account, with contact details hashed, on the client's instructions. Questions about that data should go to the client concerned. If you contact us instead, we will pass your request to them. Section 12 explains how we protect that data.
3. What personal data we collect
Depending on how you interact with us, we may collect:
- Contact details: your name, email address and phone number.
- Professional details: your agency, your Council for Estate Agencies (CEA) registration number where you are a Singapore property agent, and how you practise.
- Business details: how enquiries reach you, roughly how many you receive, how you follow them up, and the tools you use.
- Your review answers: what you tell us through our lead response review form.
- Communications: emails you send us, and notes from calls with you.
- Booking details: appointments you book with us, and anything you tell us when booking.
- Consent records: what you agreed to, how, and when.
- Visit source: which link or campaign brought you to our page, recorded when you submit a form.
- Public business information: information you or your business have made public, such as your website, public listings or business profile, which we may review when preparing a review or proposal for you.
We do not ask for your NRIC, passport or other government-issued identification numbers.
4. How we collect it
We collect personal data when you:
- submit our lead response review form;
- book a call through our online calendar;
- email us, or reply to an email from us;
- speak with us on a call.
If we contacted you first, we obtained your business contact details from publicly available sources, such as your website, public listings or professional registers, or from business contact lists provided to us by a business partner.
5. Why we use it
We use your personal data to:
- respond to your enquiry;
- prepare and send your lead response review;
- arrange and hold a call with you;
- prepare a proposal, and provide the services you engage us for;
- set up and manage your system, and manage our agreement with you, including billing;
- send you messages about your enquiry, review, booking or service, such as appointment confirmations and reminders;
- send you emails about our services where the law allows, always with a clear way to opt out (see Section 6);
- improve our services;
- comply with our legal obligations.
We will not use your personal data for any other purpose without telling you and, where the law requires, getting your consent.
6. Opting out and withdrawing consent
You can stop hearing from us at any time by:
- clicking the unsubscribe link in any marketing email from us;
- replying "unsubscribe" to any email from us; or
- emailing our Data Protection Officer (Section 14).
When you opt out, we stop all marketing messages to you across every channel, and we mark your record so you are not contacted again by mistake. We usually act immediately, and always within 10 business days. Withdrawing consent may mean we can no longer respond to an enquiry or provide a service; if so, we will tell you. Withdrawal does not affect anything we did lawfully before it.
7. Calls, text messages, WhatsApp and the Do Not Call Registry
We do not call, text or send WhatsApp messages to Singapore telephone numbers unless you asked us to contact you that way or gave clear consent for it. Consent to one channel is not consent to another, and we treat each separately.
Marketing emails we send to Singapore addresses are marked as advertisements and include a working unsubscribe.
8. Who we share it with
We do not sell your personal data.
We share it only with service providers who help us run our business, and only as far as they need it:
- HighLevel, our CRM, booking, workflow and email system;
- Google, for email, calendar, video calls and document storage;
- Supabase, the database where we keep business contact and review records;
- Cloudflare, which runs our domain and routes our email;
- email verification providers, which check that an email address is valid before we send to it;
- AI service providers, such as Anthropic and OpenAI, which help us research, prepare reviews and draft communications.
When we run a system for a client (Section 2), we may also send that client's lead progress to Meta Platforms (Facebook and Instagram) for the client's own advertising, only on the client's instructions.
We may also disclose personal data where the law requires it, for example to a regulator or law enforcement agency.
9. Transfers outside your country
G-SYNQ operates from the Philippines, and several of our service providers store or process data in other countries, including the United States. When personal data is transferred outside Singapore or the Philippines, we use providers whose terms include data protection commitments, so the data is protected to a standard comparable to the law that applies to it.
10. How long we keep it
We keep personal data only as long as we need it for the purposes in Section 5, or as the law requires.
- If you become a client, we keep your data for the length of our agreement, and afterwards for as long as we need it for legal, tax or accounting reasons.
- If you enquire, or we contact you, but you do not become a client, we delete or anonymise your data 24 months after our last contact with you.
- Opt-out and consent records may be kept longer, so that we can make sure you are not contacted again and can show that we respected your choice.
11. Cookies and tracking on our website
Our landing page does not use advertising or analytics cookies. It records which link or campaign brought you to the page only when you submit a form. If that changes, we will update this policy before it does.
12. How we protect it
We take reasonable security measures to protect personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These include limiting access to the people who need it, using password-protected systems with individual accounts, and working only with established service providers.
The same measures apply to personal data we handle for clients in their sub-accounts (Section 2). We use that data only to run the client's system, and never for our own purposes.
No method of transmission or storage is completely secure. If a data breach is likely to cause significant harm, we will notify the relevant regulator and the people affected, as the law requires.
13. Your rights
You can ask us:
- for a copy of the personal data we hold about you, and how it has been used or disclosed;
- to correct personal data that is inaccurate or incomplete;
- to delete personal data we no longer have a lawful reason to keep; or
- to stop using your personal data for marketing.
Email our Data Protection Officer (Section 14). We may need to verify your identity first. We will respond as soon as reasonably possible. If we need more than 30 days, we will tell you when to expect a reply.
14. Contact our Data Protection Officer
For any question about this policy, or to make a request, contact:
Frenz Adrian Sarabia, Data Protection Officer
G-SYNQ
Email: frenz.sarabia@g-synq.com
If you are not satisfied with our response, you may contact the National Privacy Commission of the Philippines (www.privacy.gov.ph) or, if you are in Singapore, the Personal Data Protection Commission of Singapore (www.pdpc.gov.sg).
15. Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last updated. Material changes will be posted on this page.