Privacy Policy
Privacy Policy
Syntara Systems Ltd
Last updated: [26/06/2026]
We're Syntara Systems Ltd (“Syntara Systems”, “we”, “us”, “our”), and we take your privacy seriously. This policy explains what personal data we collect, why, how we look after it, and what rights you have over it under the UK GDPR and the Data Protection Act 2018.
We are registered with the Information Commissioner's Office (ICO), registration number ZC180194.
We are also registered for VAT in the United Kingdom. Our VAT number is GB 522 8544 90.
1. Who we are
Syntara Systems Ltd is a company registered in England and Wales (company number 17289563), with its registered office at Bromileys, Belmont Road, BL7 8BQ, Bolton. We help small and medium-sized businesses find and fix operational inefficiencies, building custom software and automation — sometimes using artificial intelligence, sometimes not, depending on what genuinely solves the problem.
Most of the time we're the Data Controller — responsible for data we collect ourselves, like enquiries through our website. But when we build and host an automated system for a client that processes that client's own customer data, we're acting as a Data Processor instead, under a separate Data Processing Agreement with that client. This policy is about the first kind — not about how a client's own customers' data is handled.
2. Contact us
If you have any questions about this policy or how we handle personal data, contact us at:
Email: hello@syntarasystems.co.uk · Post: Bromileys, Belmont Road, BL7 8BQ, Bolton
3. Personal data we collect
We collect personal data in the following ways:
Website visitors — when you visit syntarasystems.co.uk, we may collect basic technical data (IP address, browser type, pages visited) via standard website analytics, where applicable.
Our website's FAQ widget — the chat-style assistant on our website is not an AI chatbot and does not hold a conversation. It simply offers a set of topics to choose from and, where relevant, opens a pre-filled email to the right team inbox (general enquiries, sales, or support) once you select one. We don't store or log which buttons you click within the widget itself — nothing is recorded until you actually choose to send an email, at which point ordinary email data handling applies, as described in the ‘Enquiries and bookings’ point below.
Our contact form — if you submit the contact form on our website, we collect whatever you enter into it (typically your name, email address, and message) so we can reply. This is sent directly to the relevant Syntara Systems inbox depending on what you've asked about.
Enquiries and bookings — when you contact us, request an audit, or book a call, we collect your name, business name, email address, phone number, and any details you choose to share about your business.
Clients — once you engage our services, we collect business contact details, billing information, and information about your operations necessary to deliver the agreed services.
Client customer data — where a client engages us to build and host an automated system that processes their own customers' personal data (for example, an automated review request or scheduling system), we process that data strictly as a Data Processor, on the client's documented instructions, under a separate Data Processing Agreement. This Privacy Policy does not govern that processing — the relevant client's own privacy policy applies to their customers.
4. How we use your personal data
Purpose
Legal basis
Respond to enquiries and book audits
Legitimate interest in operating our business / steps to enter a contract
Deliver contracted services to clients
Performance of a contract
Send invoices and manage payment
Performance of a contract / legal obligation
Send occasional updates about our services
Legitimate interest, or consent where required — you may opt out at any time
Maintain business records for accounting and tax purposes
Legal obligation
5. Who we share your data with
We don't sell personal data, and we keep the number of people who see it as small as possible. The main categories we share with, only where genuinely needed, are:
Our server hosting provider, which keeps the systems we build running securely
Software and processing tools needed to power a specific system we've built — sometimes a third-party AI provider, sometimes entirely our own custom-written code with no outside party involved — always only the minimum data needed for that system to work
Our messaging provider, where a system needs to send a text or WhatsApp message on a client's behalf
Google Workspace, for our own business email and document storage
Our accountant and any other professional advisers, where reasonably necessary
Regulators or law enforcement, if we're legally required to
6. International data transfers
Some of the service providers listed above are based outside the UK and European Economic Area, including in the United States. Where this is the case, we ensure an appropriate safeguard is in place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or reliance on a recognised adequacy decision.
7. How long we keep your data
Data type
Retention period
Enquiries that do not become clients
12 months from last contact, then deleted
Client contract and billing records
7 years from end of engagement, to meet HMRC requirements
Client operational data processed under a DPA
As specified in the relevant client's Data Processing Agreement, and deleted within 10 business days of contract end unless otherwise required by law
8. Your rights
Under UK GDPR, you have the right to:
Access the personal data we hold about you
Correct inaccurate personal data
Request erasure of your personal data, in certain circumstances
Object to or restrict certain processing
Request a copy of your data in a portable format
Withdraw consent at any time, where processing is based on consent
Complain to the Information Commissioner's Office (ico.org.uk) if you believe we have not handled your data properly
To exercise any of these rights, contact us using the details in section 2. We will respond within one month.
9. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted access controls, two-factor authentication, and restricted access limited to our directors. Further detail is available on request.
10. Cookies
Our website may use essential cookies necessary for its operation and, where used, analytics cookies to understand site usage. Where analytics or non-essential cookies are used, you will be asked for consent via a cookie banner. You can manage cookie preferences through your browser settings at any time.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this document shows when it was last revised. Material changes will be notified to active clients directly.
Syntara Systems Ltd
Last updated: [26/06/2026]
We’re Syntara Systems Ltd (“Syntara Systems”, “we”, “us”, “our”), and we take your privacy seriously. This policy explains what personal data we collect, why, how we look after it, and what rights you have over it under the UK GDPR and the Data Protection Act 2018.
We are registered with the Information Commissioner’s Office (ICO), registration number ZC180194.
1. Who we are
Syntara Systems Ltd is a company registered in England and Wales (company number 17289563), with its registered office at Bromileys, Belmont Road, BL7 8BQ, Bolton. We help small and medium-sized businesses find and fix operational inefficiencies, building custom software and automation — sometimes using artificial intelligence, sometimes not, depending on what genuinely solves the problem.
Most of the time we’re the Data Controller — responsible for data we collect ourselves, like enquiries through our website. But when we build and host an automated system for a client that processes that client’s own customer data, we’re acting as a Data Processor instead, under a separate Data Processing Agreement with that client. This policy is about the first kind — not about how a client’s own customers’ data is handled.
2. Contact us
If you have any questions about this policy or how we handle personal data, contact us at:
Email: hello@syntarasystems.co.uk · Post: Bromileys, Belmont Road, BL7 8BQ, Bolton
3. Personal data we collect
We collect personal data in the following ways:
Website visitors — when you visit syntarasystems.co.uk, we may collect basic technical data (IP address, browser type, pages visited) via standard website analytics, where applicable.
Our website’s FAQ widget — the chat-style assistant on our website is not an AI chatbot and does not hold a conversation. It simply offers a set of topics to choose from and, where relevant, opens a pre-filled email to the right team inbox (general enquiries, sales, or support) once you select one. We don’t store or log which buttons you click within the widget itself — nothing is recorded until you actually choose to send an email, at which point ordinary email data handling applies, as described in the ‘Enquiries and bookings’ point below.
Our contact form — if you submit the contact form on our website, we collect whatever you enter into it (typically your name, email address, and message) so we can reply. This is sent directly to the relevant Syntara Systems inbox depending on what you’ve asked about.
Enquiries and bookings — when you contact us, request an audit, or book a call, we collect your name, business name, email address, phone number, and any details you choose to share about your business.
Clients — once you engage our services, we collect business contact details, billing information, and information about your operations necessary to deliver the agreed services.
Client customer data — where a client engages us to build and host an automated system that processes their own customers’ personal data (for example, an automated review request or scheduling system), we process that data strictly as a Data Processor, on the client’s documented instructions, under a separate Data Processing Agreement. This Privacy Policy does not govern that processing — the relevant client’s own privacy policy applies to their customers.
4. How we use your personal data
Purpose
Legal basis
Respond to enquiries and book audits
Legitimate interest in operating our business / steps to enter a contract
Deliver contracted services to clients
Performance of a contract
Send invoices and manage payment
Performance of a contract / legal obligation
Send occasional updates about our services
Legitimate interest, or consent where required — you may opt out at any time
Maintain business records for accounting and tax purposes
Legal obligation
5. Who we share your data with
We don’t sell personal data, and we keep the number of people who see it as small as possible. The main categories we share with, only where genuinely needed, are:
Our server hosting provider, which keeps the systems we build running securely
Software and processing tools needed to power a specific system we’ve built — sometimes a third-party AI provider, sometimes entirely our own custom-written code with no outside party involved — always only the minimum data needed for that system to work
Our messaging provider, where a system needs to send a text or WhatsApp message on a client’s behalf
Google Workspace, for our own business email and document storage
Our accountant and any other professional advisers, where reasonably necessary
Regulators or law enforcement, if we’re legally required to
6. International data transfers
Some of the service providers listed above are based outside the UK and European Economic Area, including in the United States. Where this is the case, we ensure an appropriate safeguard is in place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or reliance on a recognised adequacy decision.
7. How long we keep your data
Data type
Retention period
Enquiries that do not become clients
12 months from last contact, then deleted
Client contract and billing records
7 years from end of engagement, to meet HMRC requirements
Client operational data processed under a DPA
As specified in the relevant client’s Data Processing Agreement, and deleted within 10 business days of contract end unless otherwise required by law
8. Your rights
Under UK GDPR, you have the right to:
Access the personal data we hold about you
Correct inaccurate personal data
Request erasure of your personal data, in certain circumstances
Object to or restrict certain processing
Request a copy of your data in a portable format
Withdraw consent at any time, where processing is based on consent
Complain to the Information Commissioner’s Office (ico.org.uk) if you believe we have not handled your data properly
To exercise any of these rights, contact us using the details in section 2. We will respond within one month.
9. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted access controls, two-factor authentication, and restricted access limited to our directors. Further detail is available on request.
10. Cookies
Our website may use essential cookies necessary for its operation and, where used, analytics cookies to understand site usage. Where analytics or non-essential cookies are used, you will be asked for consent via a cookie banner. You can manage cookie preferences through your browser settings at any time.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this document shows when it was last revised. Material changes will be notified to active clients directly.