Privacy Policy
Last updated: 9 September 2026
This Privacy Policy explains how SyncXpress collects, uses, stores and protects personal data, both on this website and within the SyncXpress platform. We are committed to protecting your privacy and to complying with the UK GDPR and the EU GDPR.
1. Who we are
SyncXpress ("we", "us", "our") provides a low-code enterprise integration middleware platform. Our registered office is Cannon Bridge House, 25 Dowgate Hill, London, EC4R 2YA, UK.
For any question about this policy or about how we handle personal data, contact privacy@syncxpress.com.
2. Data this website collects
This website is a static site. It sets no cookies, runs no analytics and embeds no third-party trackers, advertising pixels or social media widgets.
The contact form does not submit anything to a server. It validates your input in your browser and then opens your own email application with the message pre-filled, so you remain in control of what is sent and when.
Our web host records standard server logs, which may include your IP address, browser user agent, requested page and timestamp. These are used solely to operate and secure the site, and are retained for a limited period.
3. Data the platform processes
When your organisation uses the SyncXpress platform, SyncXpress may process personal, HR and access-control data as configured by your organisation’s integrations. This can include employee records, attendance data, access events and the identifiers needed to synchronise data between systems.
In this context your organisation is the data controller and SyncXpress acts as a data processor, processing data only on your documented instructions.
4. Lawful basis
We process personal data on the lawful bases of contract performance, legitimate interests, legal obligation and, where applicable, consent. The specific basis depends on the integration and the category of data concerned.
5. Data retention
Retention periods are configurable per integration. Administrators can define how long processed data, execution logs and audit records are kept. Data is deleted or anonymised once the retention period expires.
Enquiries received by email are retained only as long as needed to answer them and to keep a record of our correspondence.
6. Your rights
Under UK and EU data protection law you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure, often called the right to be forgotten
- Right to restrict or object to processing
- Right to data portability
- Right to lodge a complaint with the Information Commissioner’s Office (ICO) or your local supervisory authority
7. International transfers
Where data is transferred outside the UK or the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses, and we ensure a level of protection equivalent to that required by UK GDPR.
8. Security measures
We apply TLS encryption in transit, encryption at rest, encrypted credential storage, secret masking, tenant isolation and role-based access control. Sensitive values are never written to audit logs.
You can read more on our Security page.
9. Changes to this policy
We may update this Privacy Policy from time to time. Any change takes effect when it is published on this page with a revised date.
10. Contact
To exercise your rights or to ask a question about this policy, write to privacy@syncxpress.com or to Cannon Bridge House, 25 Dowgate Hill, London, EC4R 2YA, UK.