Skip to content

Last updated September 2026

Privacy policy

This policy explains what personal data Syntxt collects through this website and our business relationships, why we collect it, how long we keep it and what rights you have.

1. Who we are

Syntxt (“Syntxt”, “we”, “us”) builds underwriting, policy administration, claims administration and rating software for the insurance industry. We operate from the United Kingdom and serve customers in the United Kingdom, Europe, North America, the Middle East and Asia.

For personal data collected through this website and in the course of our own business relationships, Syntxt is the controller.

For personal data contained within a customer’s underwriting, policy or claims data and processed by our platform, our customer is the controller and Syntxt acts as a processor on that customer’s documented instructions, under a separate data processing agreement. This policy does not govern that processing. See section 10.

Questions about this policy, or any request to exercise your rights, can be sent through our contact form.

2. The personal data we collect

Information you give us

  • Your name, work email address, organisation and role, when you submit our contact form.
  • The content of your enquiry, and of any subsequent correspondence with us.
  • Business contact details exchanged in the course of meetings, calls and commercial discussions.

Information collected automatically

  • Standard server and delivery information generated when your browser requests a page, including your IP address, the pages requested, timestamps, referring page and browser and device characteristics. This is processed by our hosting provider to deliver the site, maintain its security and produce aggregate traffic statistics.
  • We use privacy preserving, aggregated site analytics. We do not use advertising technology, cross site tracking or behavioural profiling, and we do not set any non essential cookies. See our cookie policy.

Information we do not want

Please do not send us special category data, personal data relating to insureds or claimants, or confidential customer information through the website contact form. If you do, we will delete it and ask you to use an agreed secure channel instead.

3. Why we use it, and our lawful basis

PurposeLawful basis
Responding to your enquiry and arranging a demonstration or meetingLegitimate interests (responding to a request you made), and steps taken at your request prior to entering a contract
Managing a commercial relationship, contracts and service deliveryPerformance of a contract, and legitimate interests in running our business
Occasional relevant updates about our products to business contactsLegitimate interests, or consent where required. You can opt out at any time and every message includes a means to do so
Site security, abuse prevention and rate limitingLegitimate interests in protecting our systems
Aggregate analytics to understand how the site is usedLegitimate interests in improving our website
Meeting legal, regulatory, accounting and tax obligationsLegal obligation

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and we have concluded that they are not. You may object to that processing at any time. See section 7.

4. Who we share it with

We do not sell personal data, and we do not share it for advertising purposes. We share it only with:

  • Service providers acting on our instructions under written contract: our website hosting and delivery provider, our transactional email provider, our business email and productivity provider, and our analytics provider.
  • Professional advisers such as lawyers, accountants and auditors, where necessary and under a duty of confidentiality.
  • Authorities where we are required to do so by law, regulation or court order.
  • A purchaser or successor in the event of a reorganisation, merger or sale of our business, subject to equivalent protection.

A current list of our sub processors is available on request.

5. International transfers

Our website is served from a global content delivery network, and some of our service providers operate outside the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or the EEA, we rely on an adequacy decision where one applies, or on the UK International Data Transfer Addendum and the European Commission Standard Contractual Clauses, supported by an assessment of the transfer. A copy of the relevant safeguards is available on request.

Customer platform data is a separate matter. Each customer deployment is hosted in the market of the insurer, and customer data is not transferred outside the agreed region other than on the customer’s documented instructions.

6. How long we keep it

  • Enquiries that do not lead to a relationship: up to 24 months from the last contact.
  • Prospect and customer relationship records: for the duration of the relationship and up to 6 years afterwards.
  • Contracts and records with a legal or tax purpose: as required by applicable law, typically 6 to 7 years.
  • Server and security logs: typically up to 30 days, unless retained for the investigation of a specific incident.

7. Your rights

Under the UK GDPR and the EU GDPR you have the right to:

  • be informed about how your personal data is used, which is the purpose of this policy;
  • request a copy of the personal data we hold about you;
  • have inaccurate personal data corrected;
  • request erasure of your personal data in certain circumstances;
  • request that we restrict processing in certain circumstances;
  • receive certain data in a portable format, or have it transmitted to another controller;
  • object to processing carried out on the basis of legitimate interests;
  • object at any time to direct marketing, with no need to give a reason; and
  • withdraw consent at any time, where we rely on consent, without affecting processing carried out beforehand.

To exercise any of these rights, contact us through the contact form. We will respond within one month. We may ask for information to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with our response you may complain to a supervisory authority. In the United Kingdom this is the Information Commissioner’s Office at ico.org.uk. In the European Union it is the supervisory authority of the country in which you live or work. We would appreciate the opportunity to address your concern first.

8. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access control on a least privilege basis, multi factor authentication, secure secret management, logging and monitoring, and a documented incident response process. Our security policy sets these out in more detail.

9. Automated decision making

We do not carry out automated decision making that produces legal effects concerning you or similarly significantly affects you, in respect of the personal data covered by this policy. Within our platform, AI assisted output is presented to a human decision maker and the platform does not automatically accept, decline, price or bind risk.

10. Customer platform data

Where personal data is processed within a Syntxt deployment operated for a customer, the customer is the controller and determines the purposes and means of that processing. Syntxt acts as processor under a data processing agreement which sets out, among other things, that we process only on documented instructions, apply appropriate technical and organisational measures, restrict access to personnel with a business need, do not appoint sub processors without prior authorisation, do not transfer personal data outside the agreed region except in accordance with data protection law and the controller’s instructions, notify the controller promptly and in writing of any personal data breach, assist with data subject requests and regulatory obligations, and delete or return the data at the controller’s election at the end of the engagement. Customer data is never used to train or improve any artificial intelligence model.

If you are an individual whose personal data is held within a customer’s deployment, please direct your request to that organisation, which is the controller. We will support them in responding to you.

11. Children

Our website and products are directed at businesses. We do not knowingly collect personal data relating to children.

12. Changes to this policy

We may update this policy from time to time. The date at the top of the page shows when it was last revised. Where a change is material we will take reasonable steps to bring it to the attention of affected individuals.