Privacy Policy
Your privacy matters to us. This policy explains what personal data Syntrix collects, why we collect it, and the rights you have under UK data protection law.
Last updated: 17 July 2026
1. Who we are
Syntrix (“we”, “us”, “our”) provides WiFi security audits and website penetration testing services to clients in the United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Syntrix is the data controller for the personal data described in this policy.
If you have any questions about this policy or how we handle your data, contact us at syntrixkal@gmail.com.
2. The data we collect
Depending on how you interact with us, we may collect:
- Contact details — your name, email address and phone number, provided when you make an enquiry or book a service.
- Engagement details — information about the network, premises or web application you ask us to assess, and the scope agreed in your authorisation.
- Assessment data — technical findings, configurations and evidence generated during an audit or penetration test.
- Correspondence — the content of emails and messages you send us.
3. How we use your data
We process your personal data to:
- respond to enquiries and provide quotes;
- deliver the services you have engaged us to perform;
- produce and share your security reports;
- manage payments, records and our legitimate business operations;
- comply with our legal and regulatory obligations.
4. Lawful bases
We rely on the following lawful bases under UK GDPR:
- Contract — to take steps at your request and deliver the services you have booked.
- Legitimate interests — to respond to enquiries, maintain records and run our business securely.
- Consent — where you have explicitly agreed, for example to non-essential communications. You may withdraw consent at any time.
- Legal obligation — where processing is required to comply with the law.
5. Confidentiality of findings
Security findings are highly sensitive. We treat all assessment data as strictly confidential, share it only with you (or people you authorise), and never disclose vulnerabilities publicly. Evidence is stored securely and access is limited to those who need it to deliver your service.
6. Sharing your data
We do not sell your personal data. We may share it with trusted service providers who help us operate (such as email or secure storage providers), all bound by appropriate confidentiality and data-protection obligations, or where we are legally required to do so.
7. Data retention
We keep personal data only for as long as necessary. Reports and engagement records are typically retained for up to five years to support follow-up work, retests and our legal obligations, after which they are securely deleted. You may request earlier deletion where no legal obligation requires us to retain the data.
8. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure of your data (“right to be forgotten”);
- restrict or object to processing;
- data portability;
- withdraw consent where processing is based on consent.
To exercise any of these rights, email syntrixkal@gmail.com. We will respond within one month.
9. Security
As a security company, protecting data is at the core of what we do. We apply appropriate technical and organisational measures — including encryption, access controls and secure handling procedures — to protect personal data against loss, misuse or unauthorised access.
10. Complaints
If you are unhappy with how we have handled your data, please contact us first so we can put things right. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
11. Changes to this policy
We may update this policy from time to time. The latest version will always be published on this page with a revised “last updated” date.