How we collect, use and protect personal data in connection with SYNE's website, platform and related services.
Welcome to SYNE. The protection of personal data is important to us, and this Privacy Policy explains how we collect, use, share and protect personal data in connection with SYNE's website, platform and related products and solutions (together, the "Services"), and the choices and rights you have in relation to that data.
This Policy applies to Registered Users of the Services and to Visitors browsing publicly available pages such as Insights, the Blog and our product pages. It should be read alongside our Terms of Use and Cookie Policy.
To create an account, you or your organisation's administrator provides personal data such as given name, surname, work email address and, optionally, a phone number. If your organisation subscribes to a paid Service, we collect billing contact details and payment information, processed through our payment provider. Standard business verification (such as confirming your organisation's identity for billing and compliance purposes) may also be required before certain paid Services can be activated.
Registered Users ("Members") access the platform on behalf of their organisation to view risk scores, manage disclosures, originate green finance, trace supply chains or measure impact, depending on their subscription. Publicly available content on our Services - including product pages, Insights, the Blog and Developer Hub documentation - can be viewed by non-registered visitors ("Visitors") without creating an account.
We use the term "Designated Countries" to refer to countries in the European Union (EU), the European Economic Area (EEA), the United Kingdom and Switzerland. This Policy applies to any Member or Visitor of our Services.
Your account profile includes information such as your name, role, contact details and the organisation you are associated with. Unlike a public social network, your account profile is not published to the general public or to other organisations using SYNE - it is visible only within your own organisation's account and, where relevant, to SYNE personnel supporting your account.
Please do not include sensitive personal data in free-text fields (such as notes or comments) that isn't necessary for the purpose you're using the Services for.
When you use the Services, you or your organisation submit data such as supplier records, emissions and ESG data, financial and loan data, or program outcome data ("Customer Data"). We also log platform activity - such as which features you use, searches you run, and reports you generate - to operate, secure and improve the Services.
Customer Data is used solely to provide the Services to your organisation. We do not publish Customer Data externally, sell it, or share it with marketing partners. Where aggregated or de-identified data is used to improve platform-wide benchmarks (for example, the sector and peer comparisons shown in Market Intelligence), it is not shared in a form that identifies your organisation without your consent. Further detail on how Customer Data is handled is set out in our Terms of Use.
Where our Services connect to independently governed data partners (such as those described on our Partners page), those partners process data under their own privacy and governance practices for the specific data they supply.
We use cookies and similar technologies to recognise you and your device, keep you signed in, and understand how the Services are used so we can improve them. We also log usage data - such as pages viewed, searches performed and reports generated - using log-ins, cookies, device information and IP addresses. Further detail is available in our Cookie Policy.
How we use your personal data depends on which Services your organisation subscribes to and how you use them. In general, we use personal data to: provide and personalise the Services; process transactions and billing; communicate with you about the Services; maintain security and prevent fraud or misuse; and improve our products, including with the help of automated systems and aggregated usage insights.
SYNE is not a public professional network. Collaboration features - such as shared reports, internal comments on a risk record, or task assignments within SYNE One - are visible only to authorised users within your own organisation's account, subject to the permissions your administrator configures. We do not support public "following," profile discovery across organisations, or public sharing of Customer Data.
We contact you by email, in-app notification or other means described in your account settings to communicate about the availability of the Services, security matters, or other service-related issues. We may also send product updates, invitations to research from SYNE Institute, and relevant recommendations from our team. You can adjust your marketing communication preferences at any time; you cannot opt out of service, security or legal notices necessary to operate your account.
We may disclose personal data where required by law or legal process, or where we have a good-faith belief that disclosure is reasonably necessary to: investigate, prevent or address suspected illegal activity; enforce our agreements; investigate or defend against third-party claims; protect the security or integrity of the Services; or protect the rights and safety of SYNE, our customers, personnel or others. Where legally permitted, we attempt to notify affected customers of legal demands for their data.
We generally retain personal data for as long as your organisation's account remains active, or as needed to provide the Services, and for any additional period required by contract, tax, regulatory or legal obligations. Where we retain information after these purposes end, we do so in de-personalised or aggregated form where practicable.
Depending on your location, you may have the right to: access the personal data we hold about you; correct or update inaccurate data; request deletion of your data; restrict or object to certain processing; and request a portable copy of data you provided to us. Many of these can be actioned directly through your account settings; for others, please contact us using the details below, and we will respond in accordance with applicable law.
Residents of the Designated Countries and other regions may have additional rights under local law, described further in Section 15 below.
SYNE is a business-to-business platform intended for use by professionals acting on behalf of an organisation. The Services are not directed at, and are not intended for use by, anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@syne.com and we will take reasonable steps to delete it.
If your organisation closes its SYNE account, your personal data will generally stop being accessible within the Services shortly after closure, and we will delete or de-personalise account data within the timeframe set out in your order form, or within a reasonable period thereafter absent a specific contractual term. We may retain data beyond this period where reasonably necessary to comply with legal obligations, resolve disputes, maintain security, prevent fraud, or enforce our agreements.
We use technical and organisational safeguards designed to protect personal data, including encryption in transit, access controls and regular monitoring for vulnerabilities. No system can be guaranteed fully secure, and we cannot warrant the absolute security of information transmitted to us. We use personal data, including certain communications, for security purposes and to investigate suspected fraud or violations of our Terms of Use.
Data protection law in the EEA and UK requires a "lawful basis" for processing personal data. Depending on the context, our lawful bases include:
Performance of a contract: processing needed to deliver the Services under your organisation's agreement with us.
Legal compliance: processing required by law, such as tax or financial services record-keeping obligations.
Legitimate interests: processing we carry out for reasonable business purposes that do not override your rights - for example, maintaining platform security, preventing fraud, and understanding how the Services are used so we can improve them.
Residents of the EEA and UK have the right to obtain confirmation of, and access to, the personal data we hold about them, and to request its correction, deletion or restriction in appropriate circumstances. You may also object to certain processing or withdraw consent where applicable, without affecting processing already carried out lawfully. To exercise these rights, contact us at privacy@syne.com. You also have the right to lodge a complaint with your local supervisory authority, though we encourage you to contact us first so we can try to resolve your concern directly.
We may update this Policy from time to time. Where changes are material, we will provide notice through the Services or by other reasonable means, such as email, before the change takes effect. We encourage you to review this page periodically.
If you have questions or concerns about this Policy, please contact us at privacy@syne.com or via our Contact Us page. If contacting us does not resolve your concern, you may have further options available under the law of your jurisdiction.
See the contract terms governing use of the Services in our Terms of Use, or get in touch with a specific question.