> For the complete documentation index, see [llms.txt](https://legal.synap.ac/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://legal.synap.ac/privacy-policy.md).

# Privacy Policy

How Synap uses personal information when acting as a controller for its website, business relationships, customer accounts and administration.

LAST UPDATED: 29th September 2026

## 1. About this policy

This Privacy Policy explains how **Synap Learning Limited** uses personal information when we decide why and how it is processed. In data-protection law, this means Synap acts as a **Controller**.

Synap Learning Limited is a company registered in England and Wales under company number 08862590. Our address is Castleton Mill, Castleton Close, Leeds, England, LS12 2DR. You can contact our privacy team at <legal@synap.ac>.

This policy principally applies when you:

* visit a website operated directly by Synap, including [synap.ac](https://synap.ac);
* enquire about, buy, administer or support a Synap subscription;
* act as an account owner, administrator or business contact for a Synap Customer;
* communicate with us about our business, events, partnerships or services; or
* otherwise interact with Synap in a business or professional capacity.

### Candidates and learners

If an organisation has registered you to take an assessment or use a Synap Portal, that organisation normally decides why your candidate information is used and Synap processes it on its behalf. Please read that organisation's privacy notice, the information shown before your assessment and our [Candidate Privacy Notice](https://legal.synap.ac/candidate-privacy-policy).

Our [Data Processing Agreement](https://legal.synap.ac/data-processing-agreement-dpa) governs Synap's processing of Customer Data on behalf of Customers. This Privacy Policy does not replace those arrangements.

A person can fall into more than one category. For example, a Customer administrator who also visits our marketing website is covered by this policy for both activities.

## 2. Information we collect and how we use it

The table below describes our principal Controller activities. The information we receive depends on your relationship with Synap and the services you use.

| Activity                                   | Information and sources                                                                                                                                                                                                                                                             | Purposes                                                                                                                                                                          | Lawful basis                                                                                                                                                                                                                                                        |
| ------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Customer and administrator accounts**    | Name, business email, organisation, job title, account role, authentication and security records, Portal association, service configuration and account activity. We receive this from you, your organisation and our systems.                                                      | Establish and administer the Customer relationship; provide account access; attribute administrative actions; communicate about the service; maintain security and audit records. | Performance of a contract where you contract with us personally; otherwise our legitimate interests in providing and administering the service and the Customer's legitimate interests in managing its account; compliance with legal obligations where applicable. |
| **Sales and business enquiries**           | Name, business contact details, employer, role, correspondence, meeting notes, requirements, opportunity history and communication preferences. We receive this from you, your organisation, referrals, events and professional or publicly available sources.                      | Respond to enquiries; arrange demonstrations and meetings; prepare proposals; develop and manage business relationships; maintain accurate records of communications.             | Steps requested before entering a contract; our legitimate interests in developing and managing our business; consent where required.                                                                                                                               |
| **Service communications and support**     | Contact details, support messages, call or meeting information, case history, technical details and limited extracts needed to investigate an issue.                                                                                                                                | Provide support and training; answer questions; diagnose problems; communicate operational, security and contractual information.                                                 | Performance of a contract; our legitimate interests and those of the relevant Customer in supporting and securing the service; compliance with legal obligations. Customer Data included in a support case remains subject to the DPA.                              |
| **Website and service usage**              | IP address, browser and device characteristics, operating system, referring pages, approximate location derived from IP address, timestamps, pages and features used, cookie identifiers and security events. We collect this from your browser, device and our service providers.  | Operate and secure our websites and services; prevent misuse; diagnose faults; understand performance and use; improve navigation, content and services.                          | Our legitimate interests in operating, securing and improving our services; consent where required for cookies or similar technologies.                                                                                                                             |
| **Billing and commercial administration**  | Customer and billing contact details, subscription, order and invoice information, payment status, transaction references and tax information. Payment-card details are handled by our payment providers; Synap does not ordinarily store full card numbers or card security codes. | Process payments; administer subscriptions; maintain financial records; prevent fraud; manage debt and disputes.                                                                  | Performance of a contract; compliance with tax, accounting and other legal obligations; our legitimate interests in managing payments and preventing fraud.                                                                                                         |
| **Marketing and events**                   | Name, organisation, role, contact details, interests, event participation, engagement with communications and marketing preferences.                                                                                                                                                | Send relevant product and company information; invite contacts to events; measure and improve campaigns; maintain suppression records.                                            | Consent where required; otherwise our legitimate interests in business-to-business marketing and developing our services. You may opt out at any time.                                                                                                              |
| **Feedback, research and testimonials**    | Survey responses, interview notes, feedback and, with permission, your name, role, organisation, image or testimonial.                                                                                                                                                              | Understand and improve our services; conduct research; publish agreed testimonials or case studies.                                                                               | Our legitimate interests in improving our services; consent for publication where appropriate.                                                                                                                                                                      |
| **Security, compliance and legal matters** | Account, device, access, correspondence, transaction, audit and incident information, together with information relevant to a complaint, dispute or legal request.                                                                                                                  | Protect people, systems and information; investigate suspected misuse; establish, exercise or defend legal claims; comply with law and regulatory requirements.                   | Our legitimate interests in protecting our business and users; compliance with legal obligations; establishment, exercise or defence of legal claims.                                                                                                               |

We may combine information collected through these activities where the purposes are compatible. If we intend to use personal information for a materially different purpose, we will provide appropriate information before doing so.

## 3. Information from other sources

In addition to information provided directly by you, we may receive personal information from:

* your employer or another Synap Customer;
* colleagues who identify you as a relevant contact or authorised user;
* payment, identity, communications and account-management providers;
* event organisers, referral partners and professional advisers;
* publicly available company websites and professional profiles; and
* security, fraud-prevention and technical service providers.

We do not treat publicly available information as exempt from data-protection requirements.

## 4. When information is required

Some information is required to enter into or administer a contract, create a secure account, process payment or comply with law. If it is not provided, we may be unable to create the account, provide the requested service, process an order or meet a legal requirement.

Other information, including optional profile fields, survey responses and most marketing preferences, is voluntary. We will identify material consequences at the point of collection where they may not be obvious.

## 5. Cookies and similar technologies

We use cookies and similar storage or access technologies to operate our websites and services, keep users signed in, protect accounts, remember settings and understand usage. We may also use analytics or advertising technologies on our marketing website.

Where consent is required, non-essential technologies are not used until the relevant choice has been made. You can change your choices through the available cookie controls. Our [Cookie Policy](https://legal.synap.ac/cookie-policy) provides further information.

Candidate exam portals do not use advertising cookies. Their essential and functional technologies are explained in the Candidate Privacy Notice and Cookie Policy.

## 6. How we share personal information

We may share personal information with:

* companies that provide hosting, communications, analytics, customer-support, customer-relationship, billing, payment, security and professional services to Synap;
* the Synap Customer or organisation with which your account or business contact is associated;
* advisers, auditors, insurers, banks and prospective investors or purchasers subject to appropriate confidentiality arrangements;
* regulators, courts, law-enforcement bodies and other recipients where disclosure is required or permitted by law; and
* a successor or relevant participant in a merger, acquisition, financing, reorganisation or sale of all or part of our business.

We require service providers to protect personal information and use it only for the agreed purpose. Our [Subprocessors List & Management Policy](https://legal.synap.ac/subprocessors-list-and-management-policy) also identifies important platform and business-service providers. Not every provider listed there is a Subprocessor for every activity.

We do not sell personal information for money. We do not use candidate assessment, proctoring or identity information for Synap's own targeted advertising.

## 7. International transfers

Our marketing website and principal EU platform workloads are hosted in Ireland. Synap also operates a United States platform stack, and some service providers or their personnel process information in the United States or other countries.

Where applicable law restricts an international transfer, we use an available lawful mechanism. Depending on the transfer, this may include:

* UK or EU adequacy arrangements;
* an applicable Data Privacy Framework certification, including the UK Extension where relevant;
* the EU Standard Contractual Clauses with the UK Addendum where required;
* the UK International Data Transfer Agreement; or
* another mechanism permitted by applicable law.

We also assess providers and apply contractual, technical and organisational safeguards appropriate to the processing. Contact <legal@synap.ac> if you would like further information about the safeguards relevant to a particular transfer.

Customer Data transfers are governed more specifically by the DPA and Subprocessor page.

## 8. Retention

We keep personal information only for as long as reasonably necessary for the relevant purpose, including to provide services, maintain security and audit records, comply with legal obligations and establish or defend legal claims.

The period depends on the nature of the information and our relationship with you. In particular:

* active Customer and administrator account information is generally kept for the duration of the relationship and a reasonable period afterwards;
* contracts, invoices and core transaction records are generally retained for at least the period required by applicable tax, accounting and company law, ordinarily six years;
* sales, support and business correspondence is retained according to its continuing relevance, contractual requirements and applicable limitation periods;
* marketing information is retained while it remains relevant, unless you opt out; we may retain a minimal suppression record to respect an opt-out;
* security logs and incident records are retained according to risk, investigation and assurance requirements; and
* cookie and similar-technology periods are described in the Cookie Policy or relevant control.

We delete or anonymise information when it is no longer needed. Residual copies in protected backups are overwritten through the applicable backup cycle and are not used for ordinary business purposes.

## 9. Security

We use technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction. These include access controls, encryption in transit and at rest, monitoring, staff confidentiality and documented security procedures.

Synap maintains ISO 27001 certification. Further information is available in our [Security Policy](https://legal.synap.ac/security-policy).

No online system is completely secure. Please contact us promptly if you believe personal information connected with Synap may be at risk.

## 10. Automated decision-making

Synap does not ordinarily use the personal information covered by this Policy to make solely automated decisions that have legal or similarly significant effects on website visitors, business contacts or Customer administrators.

Product features that assist a Customer with assessment, proctoring or identity review concern Customer Data and are explained through the Candidate Privacy Notice, the Customer's own notices and information shown before the feature is used.

If we introduce significant automated decision-making for a Controller activity, we will provide meaningful information about the information used, the rationale and likely consequences, together with applicable safeguards and rights.

## 11. Your rights

Depending on where you live and the applicable law, you may have rights to:

* obtain information about our use of your personal information and request access to it;
* ask us to correct inaccurate or incomplete information;
* ask us to delete information;
* restrict or object to particular processing;
* receive certain information in a portable format;
* withdraw consent, without affecting earlier lawful processing;
* object to direct marketing at any time; and
* complain to a data-protection regulator.

These rights are not absolute and may depend on the processing and lawful basis. We may ask for information reasonably necessary to verify your identity and locate the relevant records.

To exercise a right, email <legal@synap.ac>. Where a request concerns Candidate or other Customer Data controlled by a Synap Customer, we will direct or forward the request to that Customer as appropriate.

You may unsubscribe from marketing emails using the link in the message. We may still send necessary service, security or contractual communications.

### Complaints

You can make a privacy complaint by emailing <legal@synap.ac> with the subject **Privacy complaint**. We will acknowledge a complaint within 30 days, investigate it appropriately and respond without undue delay.

You may also complain to the UK Information Commissioner's Office through [ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/) or to another competent supervisory authority, including in the country where you live or work.

## 12. Additional information for United States residents

Privacy laws in certain US states may provide additional rights where they apply to Synap's processing. These may include rights to confirm whether information is processed, access, correct, delete or obtain a copy of it, opt out of certain sales, sharing, targeted advertising or profiling, and appeal a refusal of a request.

Synap does not sell personal information for money. Some advertising or analytics disclosures on our marketing website may be treated as a “sale”, “sharing” or targeted advertising under particular state laws even where no money changes hands. Where applicable, you may use our cookie controls or contact <legal@synap.ac> to exercise an opt-out. Where required, we will treat a recognised opt-out preference signal as a request for the browser or device sending it.

We will not discriminate against you for exercising an applicable privacy right. An authorised agent may make a request where permitted by law, subject to reasonable verification of the authority and request.

Synap does not currently offer a financial incentive in exchange for personal information.

## 13. Children

Our corporate and marketing services are directed principally to organisations and business users, not children. A Customer may use the Synap platform to provide assessments or learning activities to a child, but the Customer controls that candidate processing and must provide age-appropriate information and safeguards. The Candidate Privacy Notice provides a general explanation of Synap's role.

If you believe a child has provided personal information directly to Synap for our own marketing or business purposes without appropriate authority, contact <legal@synap.ac>.

## 14. Changes to this policy

We review this Policy regularly and may update it to reflect changes in our services, practices or legal obligations. We will update the date above and, where a change is material, provide an appropriate additional notice.

## 15. Contact

**Synap Learning Limited**\
Company number: 08862590\
Castleton Mill, Castleton Close\
Leeds, England, LS12 2DR\
Email: <legal@synap.ac>
