How SYNE manages, protects and uses data within our SaaS products - for our own personnel, contractors and third parties involved in handling customer data.
This Data Management Policy sets out the principles and procedures governing the management, protection and use of data within SYNE's Software-as-a-Service products. It applies to all SYNE employees, contractors and third parties involved in handling data associated with the Services, and should be read alongside our Privacy Policy and Product Licensing terms.
This policy outlines how data is managed, protected and used within SYNE's SaaS products - including SYNE Climate Risk Management, Enterprise Sustainability, SYNE Trust, SYNE One and SYNE Plus. It governs the conduct of everyone involved in handling customer data on SYNE's behalf, whether an employee, contractor or third-party service provider.
SYNE owns the Software, the underlying platform technology, and our risk methodology and models. Clients retain ownership of the data they submit to the Services - referred to as "Customer Data" in our Product Licensing terms, such as supplier records, emissions data, financial data or program outcome data - and grant SYNE a limited license to process, store and secure it solely to provide, maintain and improve the Services.
Where we generate aggregated or de-identified insights from Customer Data - for example, the sector and peer benchmarks shown in Market Intelligence - those aggregated insights do not identify any individual client's data and remain distinct from a client's own Customer Data.
Purpose. Data collected within the Services is used solely to provide, maintain and improve the functionality of the Services.
Consent. Where a client's use of the Services involves personal data about the client's own employees, suppliers or other individuals, the client is responsible for obtaining any consents or permissions required to collect and process that data within the Services.
Minimisation. We collect and process only the data necessary to fulfil the intended purpose of each product. We avoid collecting data we don't have a defined use for.
Anonymisation & aggregation. Where practicable, we anonymise or aggregate data before using it to improve platform-wide models or benchmarks, consistent with the approach described in our Privacy Policy.
Usage restrictions. Customer Data is not used for any purpose other than those set out in the applicable client agreement, our Product Licensing terms, or this policy - including that we do not sell Customer Data.
Access control. Access to client data is restricted to authorised personnel, granted according to job role and operational necessity.
Encryption. Client data is encrypted in transit and at rest using industry-standard protocols.
Data integrity. We maintain regular backups, data validation checks and access logs to help ensure the integrity of client data.
Security audits. We conduct regular security audits and assessments to identify and address potential vulnerabilities across the platform.
Where SYNE Services connect to independently governed data partners - such as those described on our Partners page - those partners maintain their own security practices for the specific data they supply, alongside the safeguards described here.
Retention period. We retain client data only for as long as necessary to fulfil the purposes described in this policy, in accordance with the applicable client agreement, or as required by law.
Deletion. Upon termination of a client agreement, or upon a valid request, SYNE will securely delete or anonymise client data in accordance with applicable legal requirements and the retention terms set out in our Terms of Use.
Third-party service providers. We may engage third-party providers to help deliver the Services. These providers are contractually required to meet data protection standards consistent with this policy.
Legal compliance. We may disclose client data where required by law or in response to a valid legal request, such as a subpoena or court order, consistent with the disclosures described in our Privacy Policy.
Our practices regarding the collection, use and disclosure of personal data are set out in our separate Privacy Policy. We respect the rights of data subjects in relation to their personal data, including rights to access, correct or request deletion of their data, as described there.
All personnel involved in handling client data receive training on data protection principles, including their responsibilities under this policy and applicable data protection law.
We regularly monitor compliance with this policy and take appropriate action where it is not followed. For personnel, non-compliance may result in disciplinary action up to and including termination of employment or contract.
This policy is reviewed periodically and updated as necessary to reflect changes in technology, business practices or legal requirements. Where changes are material, we will provide notice consistent with the approach described in our Privacy Policy and Terms of Use.
By using SYNE's SaaS products, clients agree to the provisions of this Data Management Policy.
See our licensing terms in Product Licensing, how we handle personal data in our Privacy Policy, or get in touch with a specific question.