Syntra handles calls, bookings and records on your behalf, so protecting that data is part of the product, not an afterthought. Here is how we keep it safe, and where you can read the detail.
Your data is encrypted in transit (TLS) and at rest. Documents use server-side AES-256 encryption, the same class of protection used by banks.
Data is stored in the region that matches your country. For UK businesses, documents are kept in the UK and do not, by default, leave the UK/EU.
Access to stored documents is recorded in an audit log, so there is a clear trail of who accessed what and when.
Your data, and your customers’ data, is never used to train, fine-tune or evaluate any AI model, ours or a provider’s. This is a firm commitment, not a setting.
Every business’s data is strictly separated from every other’s, and downloads use short-lived, signed links rather than public access.
We are registered with the UK’s Information Commissioner’s Office, and our practices are built around UK GDPR.
You are the data controller. Syntra acts as your processor, handling data only to run the service you have configured, under a written Data Processing Agreement. You decide what it knows, what it keeps, and when to switch it off.
Where you process sensitive information (for example, a clinic capturing patient consent and intake forms), that document storage runs in HIPAA-eligible AWS infrastructure under a signed Business Associate Agreement. Our wider data-protection practices are built around UK GDPR. If you would like our DPA, just ask.