Privacy Policy
Introduction
Fyntra Tech Ltd (“Fyntra Tech”, “we”, “our” or “us”) is committed to protecting your privacy and handling personal data fairly, lawfully and transparently. This Privacy Policy explains how we collect, use, store, share and protect personal data when you visit our website, communicate with us, use or enquire about our services, apply for a role, or otherwise interact with us.
For the processing described in this Privacy Policy, Fyntra Tech Ltd is generally the data controller. This means we decide why and how your personal data is processed. In some client engagements, we may act as a processor on behalf of a client. Where that happens, the client’s privacy notice and our contract with that client will govern the relevant processing.
This Privacy Policy applies to www.fyntratech.com and to personal data collected through related contact forms, email communications, business interactions, recruitment activities and social-media engagement.
2. Personal data we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
2.1 Contact and communication data
- your name, email address, telephone number and postal address;
- the company or organisation you work for or represent, your job title and business contact details;
- information contained in messages, enquiries, contact forms, live-chat conversations or other communications you send to us; and
- records of meetings, calls, requests, complaints and customer-support interactions.
2.2 Client, supplier and business-partner data
- information needed to prepare proposals, quotations, statements of work, contracts and invoices;
- project, account and service-delivery information;
- billing, transaction and payment-related records, where relevant;
- identity, role and authority information relating to people who act for a client, supplier or business partner; and
- information required for due diligence, fraud prevention, sanctions, anti-money-laundering or other compliance checks where applicable.
2.3 Recruitment data
- your name, contact details, CV, employment history, education, qualifications and professional experience;
- information supplied in an application, interview, assessment or correspondence;
- references, right-to-work information and other information needed to assess your suitability for a role; and
- any other information you voluntarily provide during recruitment.
2.4 Website and device data
- internet protocol (IP) address, browser type and version, device type, operating system and approximate location;
- pages visited, date and time of access, time spent on pages, referring pages, links clicked and navigation patterns;
- cookie identifiers and similar technical information; and
- security, diagnostic, error and server-log information.
2.5 Marketing, survey and social-media data
- your preferences for receiving marketing communications;
- responses to surveys, event registrations, feedback and promotional activities;
- publicly available information from professional or social-media profiles; and
- information you share when you comment on, message or otherwise engage with our social-media accounts.
2.6 Information from third parties
We may receive business contact data from current or potential clients, suppliers, professional advisers, business partners, recruitment sources, public registers or publicly available professional profiles. This usually includes a person’s name, role, organisation, email address, telephone number and other information needed for a legitimate business interaction.
2.7 Special-category data
We do not intend to collect special-category or highly sensitive personal data through the website unless it is necessary and lawful to do so. This includes information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetics, biometrics used for identification, health, sex life or sexual orientation. Please do not send such information through general website forms or ordinary email unless we specifically ask for it and explain why it is needed.
3. How we collect personal data
We collect personal data:
- directly from you when you complete a form, send an email, request information, enter into a contract, use our services, attend a meeting or apply for a role;
- automatically through cookies, server logs and similar technologies when you use our website;
- from an organisation you work for or represent;
- from service providers or professional advisers acting on our behalf; and
- from public sources, professional networks, social-media platforms or business directories where lawful.
4. Why we use personal data and our lawful bases
We only process personal data where we have a lawful basis. The basis depends on the purpose and circumstances of the processing. We may rely on consent, performance of a contract, steps requested before entering into a contract, compliance with a legal obligation, or our legitimate interests or those of a third party.
| Purpose | How we use the data | Typical lawful basis |
| Responding to enquiries | To respond to messages, provide information, arrange meetings or calls, and take requested pre-contract steps. | Legitimate interests; steps before a contract |
| Providing services | To manage accounts, deliver contracted services, communicate about projects, invoice clients and administer the business relationship. | Contract; legitimate interests |
| Business relationships | To communicate with client, supplier and partner representatives and develop legitimate business opportunities. | Legitimate interests |
| Website operation and security | To provide, maintain, troubleshoot, secure and improve the website and to prevent misuse or fraud. | Legitimate interests; legal obligation where applicable |
| Analytics and non-essential cookies | To understand website use, measure performance and improve user experience where the relevant cookies or technologies are enabled. | Consent; legitimate interests for limited essential diagnostics |
| Marketing | To send service updates, invitations or promotional communications and measure engagement. | Consent or legitimate interests, subject to applicable electronic-marketing rules |
| Recruitment | To assess applications, communicate with candidates, conduct interviews and make recruitment decisions. | Steps before a contract; legitimate interests; legal obligation |
| Legal and regulatory compliance | To keep required records, complete checks, respond to authorities, protect legal rights and handle disputes. | Legal obligation; legitimate interests |
| Corporate transactions | To evaluate or complete a merger, restructuring, investment, sale or transfer of all or part of the business. | Legitimate interests; legal obligation where applicable |
Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights and interests override those interests. Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal.
5. Cookies and similar technologies
Cookies are small text files or similar technologies stored on or accessed from your device. They help websites function, remember choices, measure performance and, where enabled, support advertising or social-media features.
We may use the following categories:
- Strictly necessary cookies: required for security, network management, consent records and core website functions.
- Functionality cookies: remember choices such as language, region or interface preferences.
- Analytics and performance cookies: help us understand how visitors use the website and improve its operation.
- Advertising and social-media cookies: may be used to measure campaigns, limit repeated advertising, personalise content or connect website activity with third-party platforms.
We will not place non-essential cookies or use equivalent non-essential tracking technologies unless you have made an active choice to allow them, where consent is required. You can accept, reject or manage non-essential cookies through the website’s cookie controls. You can also change browser settings, although blocking some cookies may affect website functionality.
The specific cookies, providers, purposes and durations used on the website should be listed in the cookie banner or a separate Cookie Policy. Those controls form part of this Privacy Policy.
6. Direct marketing
We may send relevant business-to-business information about our services, events or updates where permitted by law. Where consent is required, we will obtain it before sending marketing. You may unsubscribe at any time by using the unsubscribe link in a marketing message or contacting [email protected].
We will not use an unsubscribe request to stop communications that are necessary to provide a contracted service, respond to an active request, issue a security notice or meet a legal obligation.
7. Who may receive personal data
We may disclose personal data to the following categories of recipients where necessary:
- hosting, cloud-storage, website-management and cybersecurity providers;
- email, communications, productivity, customer-support and collaboration providers;
- analytics, advertising and social-media providers, but only in accordance with the applicable cookie and consent settings;
- payment, banking, accounting and invoicing providers where relevant;
- recruitment platforms, background-check providers and professional referees where relevant;
- professional advisers, including lawyers, accountants, auditors, consultants and insurers;
- clients, suppliers and business partners where disclosure is necessary for a project or business relationship;
- regulators, courts, law-enforcement bodies, tax authorities and other public authorities where required or permitted by law; and
- potential buyers, investors or advisers in connection with a proposed corporate transaction.
Service providers that process personal data on our behalf are expected to use it only for agreed purposes, protect it appropriately and comply with confidentiality, security and data-protection obligations.
We do not sell personal data as a business commodity. We will not disclose personal data to third parties for their independent direct marketing unless we have a lawful basis and provide any required choice or consent.
8. International data transfers
Some service providers or recipients may process personal data outside the United Kingdom. Where personal data is transferred internationally, we will use a lawful transfer mechanism and appropriate safeguards. Depending on the destination and circumstances, these may include UK adequacy regulations, approved contractual clauses, the UK International Data Transfer Agreement or Addendum, and additional technical or organisational safeguards.
You may contact us for further information about the safeguards relevant to a particular transfer, subject to confidentiality and security limitations.
9. Data retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to meet contractual, accounting, tax, regulatory, security, complaint-handling and legal requirements.
| Record type | Typical approach |
| Website enquiries and general correspondence | Usually up to two years after the last meaningful interaction, unless a longer period is needed for an active matter or legal reason. |
| Marketing records | Until consent is withdrawn, an objection is made, the information is no longer accurate or useful, or the applicable review period expires. Suppression records may be kept to respect opt-outs. |
| Client, supplier and contract records | For the duration of the relationship and afterwards for the period required to manage obligations, financial records, complaints or legal claims. |
| Recruitment records | For the recruitment process and a limited period afterwards, unless a longer period is required by law or the candidate agrees to future opportunities. |
| Cookie and technical records | For the duration stated in the cookie controls or as reasonably required for security, diagnostics and consent evidence. |
| Complaints and legal matters | For as long as needed to investigate, respond, comply with law and establish, exercise or defend legal rights. |
When personal data is no longer required, we will delete it, anonymise it or securely restrict its use, as appropriate.
10. Your data-protection rights
Subject to applicable law and any relevant exemptions, you may have the following rights in relation to your personal data:
- Access: request confirmation that we process your data and obtain a copy of it.
- Rectification: ask us to correct inaccurate data or complete incomplete data.
- Erasure: ask us to delete personal data in certain circumstances.
- Restriction: ask us to restrict processing in certain circumstances.
- Objection: object to processing based on legitimate interests and object at any time to direct marketing.
- Data portability: receive certain data in a structured, commonly used and machine-readable format and ask for it to be transferred where applicable.
- Withdrawal of consent: withdraw consent at any time where processing is based on consent.
- Automated decisions: obtain safeguards in relation to certain decisions made solely by automated means that produce legal or similarly significant effects.
To exercise a right, email [email protected] or write to Fyntra Tech Ltd at 65 London Wall, London, United Kingdom, EC2M 5TU. Please describe your request clearly. We may ask for information to verify your identity and, where someone acts for you, evidence of their authority.
We will respond within the period required by law. Rights are not absolute, and we may refuse or limit a request where the law permits. Where this happens, we will explain the reason unless legally prevented from doing so.
11. Data-protection complaints
If you are concerned about how we have handled personal data, please contact [email protected] and state that you are making a data-protection complaint. Include enough information for us to understand the issue and locate the relevant records.
We will maintain a process for receiving and handling data-protection complaints. We will acknowledge a complaint within the period required by applicable law, make appropriate enquiries, keep you informed where necessary and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection supervisory authority. We encourage you to contact us first so that we have an opportunity to address the concern.
12. Automated decision-making
We do not currently make decisions about website visitors, enquirers or applicants solely by automated means where the decision produces legal effects or similarly significant effects. If this changes, we will provide the information and safeguards required by law before carrying out the relevant processing.
13. Data security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, misuse, alteration, disclosure or destruction. Measures may include access controls, confidentiality obligations, encryption where appropriate, secure configuration, backups, monitoring, staff awareness and procedures for responding to suspected incidents.
Access to personal data is limited to people and service providers that need it for legitimate business purposes. They must handle it securely and in accordance with applicable duties.
No method of transmission or storage is completely secure. If a personal-data breach creates a legal obligation to notify affected people or a supervisory authority, we will make the required notification.
14. Children’s privacy
Our website and business services are not directed to children. We do not knowingly collect personal data from children through the website. If you believe a child has provided personal data to us without appropriate permission, contact [email protected] so that we can investigate and take appropriate action.
15. Third-party websites and services
The website may contain links to websites, platforms or services operated by third parties. Their privacy practices are controlled by their own notices. We are not responsible for their content or handling of personal data, and you should review the relevant privacy information before providing personal data.
16. Additional information for California residents
This section applies only where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to Fyntra Tech Ltd and to the relevant personal information.
California residents may have rights to request information about categories and specific pieces of personal information collected, request correction or deletion, request information about disclosure, opt out of a sale or sharing where applicable, limit certain uses of sensitive personal information where applicable, and receive equal service without unlawful discrimination for exercising privacy rights.
We do not sell personal information for monetary consideration. If any use of advertising or analytics technology is treated as a sale or sharing under California law, the relevant website controls will provide any legally required opt-out mechanism. Requests may be submitted through [email protected]. We may need to verify the requester’s identity and authority before completing a request.
17. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our services, technologies, business practices or legal obligations. The updated version will be posted on the website and the “Last updated” date will be changed. Where required, we will provide additional notice before a material change takes effect.
18. Contact us
If you have any questions or requests regarding this Privacy Notice or the processing of your personal data by us, you can contact us through e-mail: [email protected]
This Privacy Notice may be changed. We will provide the updated version on our website