Privacy Policy
How Syntra Grid collects, uses, stores and protects your personal information — on this website, in an enquiry, and across the platforms we build and run for you.
- Effective
- Last updated
- Region
- United Kingdom · UK GDPR
Syntra Grid Ltd — Privacy Policy
Last updated June 2026
The short version
- We collect only the details you choose to share when you contact us or work with us.
- We use them to reply, quote, deliver, host and support your systems — and to meet legal duties.
- We never sell your information, and share it only with providers who help us operate.
- Data inside the platforms we build and run belongs to our clients — we process it on their instructions.
- You can access, correct or delete your data at any time by emailing hello@syntragrid.com.
This summary is provided for convenience. The full policy below is what applies.
Who we are
Syntra Grid Ltd is a software development company registered in England and Wales. We design, build and manage custom digital platforms for businesses, schools and organisations — websites, admin dashboards, customer and staff portals, mobile applications, management systems, AI features, automation, secure payments, messaging, analytics and role-based access.
We also host, maintain, secure and support those systems on an ongoing basis, so our involvement with a client's technology usually continues long after launch.
For the information described in this policy, Syntra Grid Ltd is the data controller — the party that decides why and how your personal information is processed.
What this policy covers
This policy covers the personal information we handle as a business: visitors to our website, people who send us an enquiry, and the contacts we work with during a project or a support engagement.
It does not cover the systems we build and run for our clients. Where a platform we developed holds personal data belonging to a client's students, residents, customers or staff, that client decides how the data is used and their own privacy policy applies. Our role there is set out under client project data below.
Information we collect
When you contact us or use our website, we collect your name, email address, company or organisation name, phone number, project details and anything else you choose to include. We only collect what you give us.
During a live project or support engagement we also hold the working contact details of the people we deal with, correspondence about the work, and the access credentials needed to administer the systems we manage for you.
We collect limited technical information automatically, such as your approximate location, browser and device type, and how you moved through the site. This is used to keep the site working and to understand which pages are useful.
How we use your information
To respond to your enquiry, prepare quotations, deliver and support the work we have agreed, and keep in touch about a live project.
To run the systems we host and maintain for you — monitoring, patching, backups, incident response and the technical support that goes with them.
To operate the business: invoicing, record keeping, improving our services and keeping our infrastructure secure.
To meet our legal and regulatory obligations, including tax and accounting requirements.
We do not use your information to train AI models, and we do not use the content of client systems for anything beyond delivering and supporting that client's work.
Legal basis
Under UK GDPR we rely on one or more of the following. Contract, where processing is necessary to deliver work you have engaged us for. Legitimate interests, in running and improving our business and securing our systems. Legal obligation, where the law requires us to keep or disclose records. Consent, where you have opted in — for example to marketing.
Where we rely on consent, you can withdraw it at any time without affecting anything processed beforehand.
Client project data
When we build, host or maintain a system for a client, that system may hold personal data about the client's own students, residents, customers, members or staff. For that data the client is the controller and we act as a processor, working only on their documented instructions.
Because we provide ongoing hosting and support, that processing relationship continues for the life of the engagement rather than ending at handover. It is governed by the contract and data processing terms agreed with each client, covering confidentiality, security measures, the sub-processors we rely on, breach notification, staff access, and the return or deletion of data when the engagement ends.
Our people access client environments only where a task requires it, under least-privilege access that is reviewed and revoked as roles change.
If you are a student, resident, customer or user of an organisation we have built software for, contact that organisation in the first instance — they hold the relationship with you and can action your rights directly. We will support them in responding.
Data sharing
We do not sell your personal information, and we do not share it for anyone else's marketing.
We share it with service providers who help us operate — cloud hosting, email delivery, analytics, payment processing and accounting — and only to the extent each needs to perform its service. We also share information where we are legally required to, or where it is necessary to establish or defend a legal claim.
Third-party services and sub-processors
Our website, our infrastructure and the platforms we run for clients rely on trusted third parties including cloud hosting, databases, media storage, email and notification delivery, payment providers and analytics. Each processes information only as needed to provide its service, under contractual terms requiring appropriate safeguards.
Where a provider processes client data, it acts as our sub-processor and is covered by the data processing terms agreed with that client. Clients can request the current list of sub-processors for their platform at any time.
International transfers
Some of our providers process information outside the United Kingdom. Where personal information is transferred abroad, we rely on the safeguards recognised under UK data protection law — an adequacy decision covering the destination country, or standard contractual clauses together with the UK International Data Transfer Addendum.
You can ask us which safeguard applies to a particular transfer, and clients can ask where a given platform's data is hosted.
Data security
We apply technical and organisational measures appropriate to the risk — encryption in transit, role-based and least-privilege access, secured infrastructure, separated environments, dependency and platform patching, monitoring, and backups with tested recovery.
Security is part of what we provide on an ongoing basis rather than something checked at launch. Systems we maintain are patched and reviewed continuously for as long as we run them.
No system is perfectly secure. If a breach affects your personal information and is likely to result in a risk to your rights, we will notify you and the Information Commissioner's Office as required. Where a breach affects data we process for a client, we notify that client without undue delay so they can meet their own obligations.
Data retention
We keep personal information only as long as we need it for the purpose it was collected for, or as long as the law requires.
Enquiries that do not become projects are deleted once they are no longer of use. Project and client records are kept for the duration of the engagement and afterwards for the period required by contract and by UK tax and accounting law. Data held inside a client platform is retained according to that client's instructions and returned or deleted when the engagement ends.
You can ask us to delete your information sooner where nothing obliges us to keep it.
Your rights
Under UK GDPR you have the right to access the personal information we hold about you, to have it corrected, to have it erased, to restrict or object to how we process it, to receive it in a portable format, and to withdraw consent where we rely on it.
To exercise any of these, email hello@syntragrid.com. We respond within one month, and we may need to confirm your identity first. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve it with you first.
Changes to this policy
We update this policy when our services, providers or legal obligations change. The current version always sits on this page with the date it was last updated, and we give additional notice where a change is material.
Contact us
Questions about this policy, or about how your personal information is handled, go to hello@syntragrid.com. We are happy to explain any part of it.
Questions about your privacy?
We're happy to explain anything in this policy, or to help you exercise your rights over your data.
hello@syntragrid.comSyntra Grid Ltd · Registered in England and Wales
Last updated · June 2026