Business telecoms, done properly · broadband, phone systems, mobile & Wi-Fi

Legal

Data Protection (UK GDPR) Policy

Last updated: 8 August 2026

This policy sets out how Synergy Max Ltd meets its obligations under the UK GDPR and the Data Protection Act 2018. It applies to all personal data we process, and to everyone who processes personal data on our behalf. It sits alongside our Privacy Policy, which is the customer-facing explanation of how we handle personal data.

1. Our commitment

We are committed to protecting the rights and privacy of individuals and to handling personal data lawfully, fairly and transparently. We treat compliance with data protection law as an ongoing responsibility, not a one-off exercise.

2. Scope

This policy applies to all personal data we hold, in any format, relating to our customers, prospective customers, suppliers, employees and any other individuals. It applies to all directors, employees, workers and contractors, and to any third party that processes personal data on our behalf.

3. Data protection principles

We follow the principles set out in the UK GDPR, which require that personal data is:

  • processed lawfully, fairly and transparently;
  • collected for specified, explicit and legitimate purposes and not used incompatibly with those purposes;
  • adequate, relevant and limited to what is necessary;
  • accurate and, where necessary, kept up to date;
  • kept in a form that identifies people for no longer than is necessary;
  • processed securely, protecting against unauthorised processing, loss or damage; and
  • handled in a way that we can demonstrate our compliance (accountability).

4. Roles and responsibilities

The directors of Synergy Max Ltd have overall responsibility for data protection compliance. Everyone who handles personal data on our behalf is responsible for following this policy and our procedures, and for reporting any concern or suspected breach without delay.

5. Lawful basis for processing

We only process personal data where we have a valid lawful basis, such as the performance of a contract, our legitimate interests, compliance with a legal obligation, or consent. We identify and record the appropriate basis before we begin processing, and where we rely on consent we make sure it is freely given and can be withdrawn.

6. Data subject rights

We respect the rights of individuals, including the rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights in relation to automated decision-making. We have procedures in place to recognise and respond to requests to exercise these rights within the timescales required by law.

7. Consent

Where we rely on consent, we ensure it is specific, informed and unambiguous, and given by a clear affirmative action. We keep a record of consent and make it as easy to withdraw as it is to give.

8. Data Protection Impact Assessments

Where a type of processing is likely to result in a high risk to individuals, for example when introducing new technology, we carry out a Data Protection Impact Assessment to identify and reduce that risk before the processing begins.

9. Data security

We use appropriate technical and organisational measures to keep personal data secure, including access controls, secure systems, and staff awareness. Access to personal data is limited to those who need it to carry out their role.

10. Data breach reporting

We have procedures to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will report it to the Information Commissioner’s Office without undue delay and, where required, within 72 hours of becoming aware of it, and we will inform affected individuals where the law requires it.

11. Records of processing

We keep appropriate records of our processing activities, so that we can demonstrate how and why we process personal data and meet our accountability obligations.

12. Third-party processors and due diligence

Where we use third parties to process personal data on our behalf, we carry out appropriate due diligence and put a written contract in place that requires them to protect the data and to process it only on our instructions and in line with data protection law.

13. International transfers

Where personal data is transferred outside the UK or the European Economic Area, we ensure an appropriate level of protection is in place using safeguards recognised under UK data protection law.

14. Training and awareness

We make sure that those who handle personal data understand their responsibilities under this policy and under data protection law, and we keep that awareness up to date.

15. Review

This policy is reviewed regularly and updated to reflect changes in our business, our processing activities and the law. It was last reviewed on the date shown above. If you have any questions, please contact us at support@synergymax.co.uk.