Privacy
How your data is handled.
Sydex is run by Sam Coggin (sam@sydex.co.uk). If the business incorporates as a limited company, that company becomes the data controller and this policy continues to apply unchanged. This page says, in plain English, what data is collected and what happens to it. Short version: only what is needed to do the work, nothing sold, nothing passed around.
When you ask for a website review
You give a website address, and usually a name and email. That is used to do the review you asked for and to send it to you, and it is kept as part of the enquiry record. The instant health check fetches the website address you enter to run its checks; it stores the address as part of your enquiry, not the contents of your site. Legal basis: taking steps you asked for before a contract. You may get a small number of follow-up emails about your review; every one lets you say stop, and stop means stop.
When you sign a client agreement
The signing page collects your business name, your name, position, email and typed signature, along with the date, time and network address of signing. That is the signed record of the contract. Legal basis: the contract itself.
If you become a client
Your operating system (job book) holds data about your business and your customers. For your customers' personal data, you are the controller and Sydex is your processor: it is processed only to run your system, only on your instructions, kept secure, exported to you on request at any time, and returned then deleted when we part ways. This is written into the client agreement.
Analytics
This site uses Google Analytics to count visits and see which pages get read: pages viewed, rough location, device type. It is configured without advertising features and no analytics data is used to identify you personally. Legal basis: legitimate interest in knowing whether the site works. Details and opt-outs are on the cookies page.
Marketing
There is no newsletter and no marketing list unless you knowingly join one, and if one ever exists, joining will be a clear choice, leaving will be one click, and your address will never be bought, sold or swapped. Enquirers may receive follow-ups about their own enquiry, as above, and nothing else.
The services behind the scenes (subprocessors)
Sydex uses a small set of established providers to run things, each holding only what their job needs:
- Website and systems hosting: the platform that hosts this site and client systems (currently Base44, hosted on major cloud infrastructure).
- Google: business email (Workspace) and analytics.
- Form delivery: the service that relays form submissions to Sydex email (currently FormSubmit).
- GitHub: private storage of website code (code, not personal data).
- GoCardless: Direct Debit collection for clients (they handle bank details; Sydex never sees or stores them).
Some of these providers run on servers outside the UK, including in the United States. Where personal data leaves the UK it travels under recognised safeguards (UK adequacy decisions or the standard contractual clauses in the providers' terms). If a provider changes, this page changes with it.
Payment details
Sydex never sees, takes or stores card numbers or bank details. Direct Debits are set up with GoCardless under their own security and the Direct Debit Guarantee.
AI, honestly
Sydex uses AI tools as part of producing its work. Your data is used to do your work, not to train anybody's models, and nothing confidential is fed to tools that would treat it otherwise.
How long things are kept
- Enquiries that go nowhere: deleted within 12 months.
- Signed agreements and invoices: the relationship plus 6 years (contract and tax rules).
- Client system data: for the life of the care plan, then returned to you and deleted.
- Email correspondence: reviewed and thinned periodically; business records kept as above.
- Analytics: kept on Google's standard retention (14 months), aggregated after that.
- Job applications (if Sydex ever hires): 6 months after the process ends, unless you agree to longer.
Security and if something goes wrong
Data lives with the providers above under their security measures, access is limited to Sam, and accounts use strong authentication. If a breach ever puts your data at risk, you get told promptly and plainly, and the ICO gets told where the law requires it.
Who this site is for
Sydex serves businesses. The site is not aimed at children and no data is knowingly collected from anyone under 18.
Your rights
- Ask what data is held about you, and get a copy.
- Have it corrected or deleted (where there is no legal need to keep it).
- Restrict or object to processing, including anything based on legitimate interest.
- Take your data elsewhere in a usable format.
- Complain to the ICO (ico.org.uk) if you think something is wrong, though a straight answer from Sydex first will usually be faster.
For any of these, one email does it: sam@sydex.co.uk. You get an answer, not a runaround.
When this page changes
This policy gets updated as the business grows: new tools, new services, new providers. The date at the top always tells you when it last changed, and changes never apply backwards to make something already collected fair game for something new.