Last updated September 2026
Privacy policy
This policy explains what personal data Syntxt collects through this website and our business relationships, why we collect it, how long we keep it and what rights you have.
1. Who we are
Syntxt (“Syntxt”, “we”, “us”) builds underwriting, policy administration, claims administration and rating software for the insurance industry. We operate from the United Kingdom and serve customers in the United Kingdom, Europe, North America, the Middle East and Asia.
For personal data collected through this website and in the course of our own business relationships, Syntxt is the controller.
For personal data contained within a customer’s underwriting, policy or claims data and processed by our platform, our customer is the controller and Syntxt acts as a processor on that customer’s documented instructions, under a separate data processing agreement. This policy does not govern that processing. See section 10.
Questions about this policy, or any request to exercise your rights, can be sent through our contact form.
2. The personal data we collect
Information you give us
- Your name, work email address, organisation and role, when you submit our contact form.
- The content of your enquiry, and of any subsequent correspondence with us.
- Business contact details exchanged in the course of meetings, calls and commercial discussions.
Information collected automatically
- Standard server and delivery information generated when your browser requests a page, including your IP address, the pages requested, timestamps, referring page and browser and device characteristics. This is processed by our hosting provider to deliver the site, maintain its security and produce aggregate traffic statistics.
- We use privacy preserving, aggregated site analytics. We do not use advertising technology, cross site tracking or behavioural profiling, and we do not set any non essential cookies. See our cookie policy.
Information we do not want
Please do not send us special category data, personal data relating to insureds or claimants, or confidential customer information through the website contact form. If you do, we will delete it and ask you to use an agreed secure channel instead.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry and arranging a demonstration or meeting | Legitimate interests (responding to a request you made), and steps taken at your request prior to entering a contract |
| Managing a commercial relationship, contracts and service delivery | Performance of a contract, and legitimate interests in running our business |
| Occasional relevant updates about our products to business contacts | Legitimate interests, or consent where required. You can opt out at any time and every message includes a means to do so |
| Site security, abuse prevention and rate limiting | Legitimate interests in protecting our systems |
| Aggregate analytics to understand how the site is used | Legitimate interests in improving our website |
| Meeting legal, regulatory, accounting and tax obligations | Legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and we have concluded that they are not. You may object to that processing at any time. See section 7.
4. Who we share it with
We do not sell personal data, and we do not share it for advertising purposes. We share it only with:
- Service providers acting on our instructions under written contract: our website hosting and delivery provider, our transactional email provider, our business email and productivity provider, and our analytics provider.
- Professional advisers such as lawyers, accountants and auditors, where necessary and under a duty of confidentiality.
- Authorities where we are required to do so by law, regulation or court order.
- A purchaser or successor in the event of a reorganisation, merger or sale of our business, subject to equivalent protection.
A current list of our sub processors is available on request.
5. International transfers
Our website is served from a global content delivery network, and some of our service providers operate outside the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or the EEA, we rely on an adequacy decision where one applies, or on the UK International Data Transfer Addendum and the European Commission Standard Contractual Clauses, supported by an assessment of the transfer. A copy of the relevant safeguards is available on request.
Customer platform data is a separate matter. Each customer deployment is hosted in the market of the insurer, and customer data is not transferred outside the agreed region other than on the customer’s documented instructions.
6. How long we keep it
- Enquiries that do not lead to a relationship: up to 24 months from the last contact.
- Prospect and customer relationship records: for the duration of the relationship and up to 6 years afterwards.
- Contracts and records with a legal or tax purpose: as required by applicable law, typically 6 to 7 years.
- Server and security logs: typically up to 30 days, unless retained for the investigation of a specific incident.
7. Your rights
Under the UK GDPR and the EU GDPR you have the right to:
- be informed about how your personal data is used, which is the purpose of this policy;
- request a copy of the personal data we hold about you;
- have inaccurate personal data corrected;
- request erasure of your personal data in certain circumstances;
- request that we restrict processing in certain circumstances;
- receive certain data in a portable format, or have it transmitted to another controller;
- object to processing carried out on the basis of legitimate interests;
- object at any time to direct marketing, with no need to give a reason; and
- withdraw consent at any time, where we rely on consent, without affecting processing carried out beforehand.
To exercise any of these rights, contact us through the contact form. We will respond within one month. We may ask for information to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.
If you are not satisfied with our response you may complain to a supervisory authority. In the United Kingdom this is the Information Commissioner’s Office at ico.org.uk. In the European Union it is the supervisory authority of the country in which you live or work. We would appreciate the opportunity to address your concern first.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access control on a least privilege basis, multi factor authentication, secure secret management, logging and monitoring, and a documented incident response process. Our security policy sets these out in more detail.
9. Automated decision making
We do not carry out automated decision making that produces legal effects concerning you or similarly significantly affects you, in respect of the personal data covered by this policy. Within our platform, AI assisted output is presented to a human decision maker and the platform does not automatically accept, decline, price or bind risk.
10. Customer platform data
Where personal data is processed within a Syntxt deployment operated for a customer, the customer is the controller and determines the purposes and means of that processing. Syntxt acts as processor under a data processing agreement which sets out, among other things, that we process only on documented instructions, apply appropriate technical and organisational measures, restrict access to personnel with a business need, do not appoint sub processors without prior authorisation, do not transfer personal data outside the agreed region except in accordance with data protection law and the controller’s instructions, notify the controller promptly and in writing of any personal data breach, assist with data subject requests and regulatory obligations, and delete or return the data at the controller’s election at the end of the engagement. Customer data is never used to train or improve any artificial intelligence model.
If you are an individual whose personal data is held within a customer’s deployment, please direct your request to that organisation, which is the controller. We will support them in responding to you.
11. Children
Our website and products are directed at businesses. We do not knowingly collect personal data relating to children.
12. Changes to this policy
We may update this policy from time to time. The date at the top of the page shows when it was last revised. Where a change is material we will take reasonable steps to bring it to the attention of affected individuals.