Privacy Notice
How Sync Software collects, uses, shares and protects personal data across our website, web application, iOS and Android apps, portals and APIs. Version 2.0 reflects the launch of the Sync mobile apps and clarifies when we act as a controller and when we act as a processor for our customers.
1. About this Privacy Notice
1.1 This notice (Privacy Notice) explains how we collect, use, store, share and protect personal data when you:
- visit our website at syncsoftware.uk (Website);
- use the Sync Software web application;
- use the Sync Software mobile applications for iOS or Android;
- access a customer portal, subcontractor portal or any other portal we make available;
- use an application programming interface (API) or an integration connected to Sync Software; or
- otherwise interact with us, including as a customer, prospective customer, supplier or other business contact.
1.2 Sync Software is a cloud-based software-as-a-service platform that supports business operations, project management, workflow management, site management, health and safety record keeping and project collaboration. In this Privacy Notice, our Website, web application, mobile applications, portals, APIs, integrations and associated services are together called the Services.
1.3 When providing the Services we may process personal and business information provided directly by users, provided by the organisation through which a user accesses Sync Software, generated through use of the Services, or collected automatically from the device used to access the Services.
1.4 The Services are provided for business use. They are intended for authorised business users and are not directed at children. Customers must not create accounts for children unless we have expressly agreed to it and the use is lawful and appropriate.
1.5 We may update this Privacy Notice from time to time. The effective date and version number at the top of this notice show when it last changed. We may also let users know about significant changes, for example by email or a notice within the Services.
2. Who we are and our role
2.1 We are SYNC SOFTWARE LIMITED, a company registered in England and Wales with company number 14520117. Our registered office is Chancery House, 3 Hatchlands Road, Redhill, Surrey, RH1 6AA, United Kingdom (Sync, we, us or our).
2.2 Our role under data protection law depends on the circumstances in which personal data is processed.
2.3 When we are a controller. We act as a controller where we decide why and how personal data is used. This includes personal data about visitors to our Website, our customers’ account holders and billing contacts, prospective customers, suppliers and other business contacts, and personal data we use for account administration, billing, sales, marketing, customer support, security and the operation of our business.
2.4 When we are a processor. Organisations that subscribe to Sync (Customers) use the Services to collect, record, store and manage personal data about their employees, workers, subcontractors, customers, site visitors and other individuals. For that information (Customer Data), the Customer will generally act as the controller and Sync acts as its processor. We process Customer Data only on the Customer’s documented instructions, under our agreement with that Customer (including our Data Processing Addendum) and applicable data protection law.
2.5 If you use Sync because your employer, a main contractor or another organisation has given you access, that organisation is usually responsible for how your information is used within its account. Questions or requests about that information are best directed to that organisation. If you contact us, we may need to refer your request to them.
3. How to contact us
3.1 If you have any questions about this Privacy Notice or how we use personal data, please contact us:
- Email: [email protected] (please include “Privacy” in the subject line)
- Phone: 020 4553 5333
- Post: Sync Software Limited, Bank Chambers, 2 Church Street, Reigate, Surrey, RH2 0AN
- Online: our contact page
4. Whose personal data we process
4.1 Depending on how Customers use the Services, personal data may relate to:
- customers and prospective customers, and their staff;
- Customer employees and workers;
- subcontractors and subcontractor personnel;
- engineers and field personnel;
- suppliers, consultants and professional advisers;
- site visitors;
- end customers of our Customers, such as clients who use a customer portal;
- contacts at other organisations; and
- other individuals whose information is entered into the Services by a Customer or its users.
5. The personal data we collect
5.1 Personal data means any information that identifies, or could be used to identify, a living person. The types of personal data we may process include:
- Identity Data: first name, surname, title and other identifying information associated with an account.
- Contact Data: work email address, telephone number and business contact details.
- Account Data: username, organisation, role, permissions, account status and account settings. Passwords are stored only as one-way hashes, so we cannot see or recover them.
- Technical Data: IP address, device type, device identifiers, browser type and version, operating system and platform, application version, time zone, language settings and similar technical information about the device used to access the Services.
- Usage and Audit Data: sign-in and account security events, such as logins, failed logins, password changes and two-factor authentication events, recorded with IP address and browser or device details; login history, features and screens used, records viewed, created or changed, actions performed and timestamps.
- Location Data: location information from your device where you use a location-enabled feature, such as checking in to a site. See section 7.
- Photographs and Videos: images and video you choose to capture or upload through the Services.
- Documents and Files: drawings, attachments, certificates, credentials and other documents uploaded to the Services.
- Project Data: information in projects, tasks, quotations, invoices, purchase orders, variations, programmes and other project records.
- Workforce and Site Data: site attendance, check-ins, inductions, toolbox talks, work records and associated site information.
- Health and Safety Data: information recorded in audits, inspections, incidents, near misses, accident records and other health and safety or compliance records.
- Financial and Transaction Data: billing details, subscription information and payment information. Card details are handled by our payment provider and are not stored by us.
- Support and Communications Data: correspondence with us, support requests, survey responses and feedback.
- Crash and Diagnostic Data: crash reports, error logs, application performance traces and technical diagnostic information, linked to your user ID and organisation so we can investigate problems.
- Notification Data: device tokens used to deliver push notifications, and information about their delivery.
- Marketing and Communications Data: your preferences for receiving marketing from us, and your interaction with our marketing emails and Website.
5.2 Special category data. Some information entered into the Services by Customers may be special category personal data under data protection law, most commonly information about an individual’s health recorded in an accident or incident report. Where we process that information on a Customer’s behalf, the Customer is responsible for ensuring it has an appropriate lawful basis and condition for processing it. We process it as a processor on the Customer’s documented instructions.
6. Where we get personal data from
6.1 We may obtain personal data:
- directly from you, for example when you contact us, book a demo, register for an account or use the Services;
- from the organisation through which you use Sync Software, for example when your employer creates your account or a main contractor records your site attendance;
- from another Customer or authorised user, where they are permitted to provide the information, for example a main contractor inviting a subcontractor to a project;
- from third-party systems connected to Sync Software at a Customer’s request, such as accounting or business software integrations;
- automatically when you use our Website, web application or mobile applications (see sections 7 and 13); and
- from publicly available business sources, such as Companies House or company websites, where appropriate.
7. Mobile applications and device permissions
7.1 Our mobile applications may request access to certain device functions where this is needed for a feature you choose to use. Depending on the features you use, this may include:
- Camera: to take photographs or video as evidence, for audits, inspections, incidents, project records or other attachments.
- Photographs and videos: to choose existing images or video from your device to upload to the Services.
- Location: to support site-related features such as checking in to a site. Location is used only to provide that functionality.
- Notifications: to send you push notifications about activity relevant to you in the Services.
7.2 Permissions are requested only when needed for the relevant feature. You can grant, refuse or withdraw any permission at any time through your device’s settings. Refusing or withdrawing a permission may stop the related feature from working, but will not stop you using unrelated parts of the Services. Withdrawing a permission does not affect processing that took place lawfully before you withdrew it.
7.3 Data the mobile applications collect. To provide the app’s functionality, our mobile applications collect and link to your account: your name, email address and phone number; your user ID; a device ID; precise location when you use a location-enabled feature; photographs and videos you choose to capture or upload; and crash data, performance data and other diagnostic data. This information is used only to provide and support the app’s functionality. It is not used for advertising or to track you across other companies’ apps or websites.
7.4 Where push notifications are enabled, we process a device or application notification token and related technical information in order to deliver notifications. Push notifications are delivered through the platform notification services provided by Apple (for iOS) and Google (for Android).
7.5 We collect crash reports, performance information and other diagnostic information, linked to your user ID and organisation, to identify faults, investigate technical issues and keep the Services secure and reliable. We use Sentry for this in our web application and mobile applications. We do not use Sentry’s session replay feature, and it is configured not to collect additional personal data by default.
7.6 Our mobile applications store limited information on your device, such as authentication tokens and application settings, so the application can keep you signed in and work as expected.
7.7 We do not use device permissions, device information, photographs, videos or location information for advertising, behavioural advertising or tracking across other companies’ apps or websites, and we do not sell this information.
7.8 Mobile accounts are created and managed by the organisation you work with. You cannot create a new Sync account from within the mobile applications. See section 17 for how to delete your account.
8. How we use personal data and our lawful bases
8.1 Data protection law requires us to have a lawful basis for each use of personal data. The table below sets out the purposes for which we act as a controller and the lawful bases we rely on.
| Purpose | Lawful basis |
|---|---|
| Creating and administering accounts for Authorised Users, authenticating users, managing permissions and providing access to the Services | Legitimate interests (providing the Services purchased by the Customer, maintaining account security and enabling authorised business users to access the Services) |
| Administering the account of a Customer’s account owner or billing contact, where they are party to our agreement | Contract |
| Billing, payments, invoicing and managing subscriptions | Contract; legal obligation (accounting and tax records) |
| Providing customer support and responding to enquiries | Contract; legitimate interests (helping our customers and users) |
| Protecting the security and integrity of the Services, and detecting, investigating and preventing unauthorised access, fraud, misuse and security incidents | Legitimate interests (keeping the Services and our users safe); legal obligation where relevant |
| Monitoring performance and diagnosing faults, crashes and technical issues | Legitimate interests (keeping the Services reliable) |
| Maintaining logs and audit trails | Legitimate interests (security, accountability and supporting our Customers’ own record keeping) |
| Sending service communications, such as security notices, changes to the Services and changes to our terms | Contract; legitimate interests (keeping users informed) |
| Improving and developing the Services | Legitimate interests (making Sync better for our customers) |
| Business-to-business marketing | Legitimate interests; or consent where the law requires it (see section 14) |
| Website analytics and non-essential cookies | Consent (see our Cookie Policy) |
| Complying with the law and responding to lawful requests from authorities | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
8.2 Customer Data. When we process Customer Data as a processor, we do so on the Customer’s instructions. The Customer, as controller, is responsible for identifying the lawful basis for that processing.
8.3 Legitimate interests. Where we rely on legitimate interests, we have considered whether our use of the information is necessary and balanced it against your rights and freedoms. You can ask us for more information about this balancing and you have the right to object (see section 16).
8.4 Consent. Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
8.5 If you do not provide information. Where we need personal data to provide the Services or perform a contract, failing to provide it may mean we cannot provide the Services to you.
8.6 Automated decision-making. We do not carry out solely automated decision-making using personal data that produces legal effects or similarly significant effects on individuals. If this changes we will update this Privacy Notice and provide the information the law requires.
9. Access to Customer Data by Sync personnel
9.1 Authorised Sync personnel may access information held within a Customer’s account where reasonably necessary to:
- provide technical support requested by a Customer or user;
- investigate faults, incidents or unexpected behaviour;
- maintain, operate and secure the Services;
- investigate suspected misuse or security incidents;
- carry out maintenance, data migration or technical administration;
- comply with a Customer’s lawful instructions; or
- comply with applicable legal or regulatory obligations.
9.2 Access is restricted to authorised personnel who have a legitimate business need and who are bound by confidentiality and data protection obligations. We do not access Customer Data for unrelated purposes, and we do not sell Customer Data.
10. Who we share personal data with
10.1 We share personal data, or allow access to it, only where necessary and with the following categories of recipients:
- Our personnel: employees, contractors and authorised workers who need access to provide, operate, secure or support the Services and who are subject to confidentiality obligations.
- Hosting and infrastructure providers: organisations that provide cloud hosting, storage, databases, networking, content delivery and backup services.
- Application monitoring and diagnostic providers: organisations that help us monitor performance and diagnose crashes and errors in the Services.
- Communications providers: organisations that deliver transactional emails, such as account invitations, password resets and notifications.
- Push notification services: Apple and Google, to deliver push notifications to mobile devices.
- Payment providers: organisations that process subscription payments and billing information.
- Website, analytics and marketing providers: organisations that help us run our Website, understand how it is used (with your consent) and manage customer relationships and marketing.
- Integrations chosen by a Customer: third-party software a Customer chooses to connect to Sync, such as accounting or business software. Information is exchanged with that software on the Customer’s instructions.
- Other organisations using Sync, where a Customer shares information with them: for example, when a main contractor shares project information with a subcontractor or client through a portal, on that Customer’s instructions.
- Professional advisers: lawyers, accountants, auditors and insurers, where reasonably necessary.
- Authorities and regulators: where disclosure is required or permitted by law.
- Corporate transactions: a prospective or actual buyer, investor or successor if our business or assets are sold, transferred or reorganised, subject to appropriate confidentiality protections.
10.2 The service providers that process Customer Data on our behalf are listed in our Subprocessor List.
10.3 Where third-party service providers process personal data on our behalf, we require them by contract to process it only for the agreed purposes, keep it confidential and provide protection for it consistent with applicable data protection law.
10.4 If we are asked to provide personal data in response to a court order or legal request (for example from the police), we will consider the request carefully before responding.
10.5 We do not sell personal data.
11. International transfers
11.1 Our primary application infrastructure, and the Customer Data stored in the Services, is hosted in the United Kingdom.
11.2 Some of our service providers, for example those providing email delivery, crash and diagnostic reporting (European Union), payment processing, push notifications and Website analytics, may process limited personal data outside the United Kingdom.
11.3 Where personal data is transferred outside the United Kingdom, we make sure an appropriate legal mechanism is in place, such as UK adequacy regulations, the International Data Transfer Agreement or Addendum approved under UK law, or another transfer mechanism permitted by applicable data protection law.
12. How we keep personal data secure
12.1 We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful access, alteration, disclosure, loss or destruction. These include authentication and access controls, encryption where appropriate, infrastructure and network security, monitoring and security logging, backup arrangements and internal security procedures.
12.2 Access to personal data is limited to users, personnel and service providers who need it for an authorised purpose.
12.3 No system can be guaranteed to be completely secure. If a personal data breach occurs and we are the controller, we will notify the Information Commissioner’s Office and affected individuals where the law requires. Where we are the processor, we will notify the relevant Customer without undue delay and support them in responding.
12.4 If you notice any unusual activity on your account or believe you have found a security vulnerability, please tell us at [email protected].
13. Cookies and similar technologies
13.1 Our Website uses cookies and similar technologies. Non-essential cookies are only set with your consent. For details, and to change your choices, see our Cookie Policy.
13.2 Our web application and mobile applications use storage technologies that are strictly necessary to provide the Services you request, for example to keep you signed in and secure your session. They are not used for advertising.
14. Marketing
14.1 We send relevant business marketing about Sync to corporate business contacts where the law permits it and where we have a lawful basis, usually our legitimate interests in promoting our Services to businesses.
14.2 Where the law requires consent, including for certain electronic marketing to sole traders and some partnerships, we will obtain consent before sending it.
14.3 Every marketing email includes a way to unsubscribe. You can also opt out at any time by contacting us. Opting out of marketing does not affect service communications we need to send you about your account or the Services.
15. How long we keep personal data
15.1 We keep personal data only for as long as necessary for the purposes we collected it for, including to meet legal, accounting and reporting requirements. As a guide:
| Information | How long we keep it |
|---|---|
| Customer account and contract records | For the duration of the relationship, then for as long as needed to meet accounting and legal requirements and to deal with any claims |
| Invoices, payment and tax records | For the period required by tax and company law |
| Support records and correspondence | For the duration of the relationship, then for as long as reasonably needed |
| Enquiries from prospective customers | For as long as reasonably needed to follow up the enquiry, unless a relationship begins |
| Marketing preferences | Until you opt out. We keep a minimal suppression record after that so we do not contact you again |
| Security and audit logs, such as sign-in and account security events | For as long as needed to keep the Services and accounts secure, investigate incidents, prevent fraud and deal with legal claims |
| Website analytics data | In line with the retention settings of our analytics tools |
| Customer Data | As described in 15.3 and 15.4 |
| Backups | Until overwritten through our normal backup cycle |
15.2 How we decide. Where we have not given a fixed period, we decide how long to keep information by considering the purpose we hold it for and whether that purpose can be met another way, legal, tax and accounting requirements, the amount, nature and sensitivity of the information, the risk of harm from unauthorised use or disclosure, the need to deal with complaints or legal claims, and, for Customer Data, the Customer’s instructions.
15.3 Customer Data. Where we act as a processor, Customer Data is kept in line with the Customer’s instructions and our agreement with that Customer. Customers can export their Customer Data while their subscription is active, and for 30 days after a paid subscription ends they may ask us to provide an export. After a subscription ends, access to the account ends and we delete Customer Data from our live systems, normally within 90 days, unless the law requires us to keep it or we have agreed otherwise with the Customer. Copies may remain in secure backups until they are overwritten through our normal backup cycle.
15.4 When a user account is deleted. Personal data associated solely with that user account is deleted or anonymised, except where retention is required by law, is necessary for security or fraud prevention, is needed to establish or defend legal claims, or where the information forms part of business, project, audit, health and safety or other records controlled by the user’s organisation. For example, deleting an engineer’s account does not delete an accident record that belongs to their employer or a main contractor.
16. Your rights
16.1 You have the following rights over your personal data:
- Access: to ask whether we hold your personal data and receive a copy of it.
- Correction: to ask us to correct personal data that is inaccurate or incomplete.
- Deletion: to ask us to delete your personal data where there is no good reason for us to keep it.
- Restriction: to ask us to limit how we use your personal data.
- Objection: to object to our use of your personal data where we rely on legitimate interests, and to object to direct marketing at any time.
- Portability: to ask us to provide personal data you gave us in a structured, machine-readable format, or to send it to another organisation.
- Withdraw consent: where we rely on consent, to withdraw it at any time.
16.2 To exercise any of these rights, email [email protected]. There is normally no charge. We may ask for information reasonably necessary to confirm your identity before we act on a request. We will respond within the time required by data protection law.
16.3 Where we hold your personal data as a processor on behalf of a Customer, we may pass your request to that Customer and act on its instructions.
16.4 Complaints. You have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at ico.org.uk or on 0303 123 1113. We would welcome the chance to help with your concern first, but you do not have to contact us before complaining to the ICO.
17. Deleting your account
17.1 You can ask us to delete your Sync user account and the personal data associated with it. Full details, including what is deleted and what may be kept by your organisation, are on our account deletion page.
17.2 In summary:
- Sync accounts are created and managed by organisations. You can ask your organisation’s Sync administrator to remove you, or deactivate your account yourself in the Sync web application under Account Settings, in the Deactivate tab.
- Deactivating an account stops you signing in straight away, and you will no longer be able to view or download anything from the account. Download anything you need first. To have the personal data associated with your account deleted, email [email protected] from the email address linked to your account.
- A deletion request results in deletion or anonymisation of personal data associated solely with your account, unless we or the organisation controlling the information must or may keep particular information for legal, regulatory, security, fraud-prevention, contractual or record-keeping reasons.
- Where your account is managed by an employer, contractor or other organisation, we may refer the request to that organisation or process it on its instructions.
- Deleting your account does not necessarily delete project, commercial, audit, site, health and safety or other organisational records you contributed to, where those records belong to or are controlled by that organisation.