Privacy Notice
1. Introduction
Welcome to Synergy Safeguarding Ltd. We are committed to protecting your privacy and ensuring that your personal data is handled in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025 and other applicable data protection law.
We are registered as a Data Controller with the Information Commissioner's Office (ICO) under registration number ZB912075.
This privacy notice explains how we collect, use, store, and protect your personal data when you engage with our services, visit our website, or interact with us, including which other organisations are involved in handling that data on our behalf, and where.
2. Who we are
Synergy Safeguarding is a consultancy specialising in safeguarding consultancy, training, and safeguarding governance support. Our registered business address is:
Unit 2 Court Mews
London Road
Cheltenham
GL52 6HS
If you have any questions about this privacy notice or how we handle your data, you can contact us at:
- hazel@synergysafeguarding.co.uk
- Phone
- 07865 057990
3. About Synergy Safe accreditation
Synergy Safe accreditation is issued directly by Synergy Safeguarding Ltd. It is our own accreditation, awarded against our published standard. It is not a mark administered, regulated, or issued by any third-party body.
4. What data we collect
We may collect and process the following types of personal data:
- Identity Data: name, job title, organisation name.
- Contact Data: email address, phone number, postal address.
- Organisational Data: client organisations' accreditation level, status, and key dates. This is information about an organisation, not an individual, and is not personal data in its own right, though where a record includes a named contact, that contact's details are covered by the Identity and Contact Data categories above.
- Technical Data: IP address, browser type, and website usage data.
- Financial Data: payment details (if applicable).
We do not directly collect or hold details of individual staff qualifications, accreditation details, or training records. Where a client organisation chooses to use the Safeguard-Me app as part of their accreditation, that information is collected and held directly by Safeguard-Me under its own privacy terms, not by us.
Where DBS checks form part of an organisation's accreditation, we require the client organisation to evidence that appropriate checks are in place and current for relevant roles. We do not request, collect, or retain copies of individual DBS certificates or other personal check details ourselves.
5. How we use your data
We process personal data for the following purposes:
- To provide safeguarding consultancy and training services.
- To manage accreditation programmes, including maintaining records of client organisations' accreditation status and renewal dates.
- To communicate with clients, contractors, and partners.
- To comply with legal and regulatory obligations.
- To improve our services and website functionality.
We do not sell or share personal data for marketing purposes without explicit consent.
6. Legal basis for processing
Under the UK GDPR, we process personal data based on the following lawful grounds:
- Contractual Necessity: when processing is required to fulfil a contract with you.
- Legal Obligation: when processing is necessary to comply with legal requirements.
- Legitimate Interests: when processing supports our business operations without overriding your rights.
- Recognised Legitimate Interests: a basis introduced by the Data (Use and Access) Act 2025, covering specific purposes including the safeguarding of vulnerable individuals, without requiring a separate balancing test.
- Consent: when you have explicitly agreed to receive communications or participate in activities.
7. Who handles your data
We do not sell your data, and we do not share it for anyone else's marketing. We use a small number of trusted third-party providers to run our website and business operations. Each acts as a data processor on our instructions, bound by a contract that limits them to what we have asked them to do, and none is permitted to use your data for its own purposes. They are:
- Web3Forms delivers messages submitted through our website contact form to our inbox. When you send the form, it receives your name, email address, organisation if you give one, and your message. It is not used for anything else and it does not send you marketing. Data may be processed in the United States. Web3Forms is operated by Web3Creative.
- Vercel Inc. hosts this website, delivers it to your browser and runs the code behind the contact form. Its servers record standard technical information when a page is requested, including your IP address, the page requested and your browser type. Data may be processed in the United States, and potentially other locations via Vercel's global content delivery network.
- GitHub, Inc. stores the source code and content that makes up this website, and the record of changes to it. It holds the words on these pages, not enquiries or client records. Data may be processed in the United States. GitHub, Inc. is a subsidiary of Microsoft.
- Microsoft provides our business email (Microsoft 365), and Microsoft Bookings for Health Check consultations. Data may be processed in the United States and other locations where Microsoft operates data centres.
This list reflects the providers in use as at the date of this notice. If we start using a different or additional provider that handles personal data, we will update this notice accordingly. Beyond these, we disclose personal data only where the law requires it, or where there is a safeguarding duty or a risk to someone's safety that means information must be shared with the police, a local authority or another statutory body.
Delivery partners
In delivering our services, we may also engage specialist partners to carry out specific elements of a client's accreditation or training programme on our behalf, for example delivering training courses, processing DBS or digital safety checks, or providing safeguarding supervision. We only share the data necessary for that specific purpose, and only with partners who are contractually required to protect it to at least the same standard as we do.
Because these partners are chosen per engagement and may change over time, we do not list every one in this notice. If you would like to know which delivery partners are involved in a specific piece of work, please contact us and we will confirm this. The partners we work with most often are listed on our Partners page.
If you would like the current list of our processors, including any added since this notice was last updated, please ask and we will send it to you.
8. International data transfers
Some of the providers listed in Section 7 are based outside the United Kingdom, principally in the United States, which means your personal data may be transferred abroad. This is common for website hosting and email, and it does not reduce your rights.
Where personal data is transferred outside the UK, whether by a listed provider or a delivery partner engaged for a specific piece of work, UK GDPR requires that appropriate safeguards are in place to protect it to a standard that is not materially lower than under UK law. That is the test introduced by the Data (Use and Access) Act 2025, replacing the previous "essentially equivalent" standard.
We rely on recognised safeguards for these transfers, including UK adequacy regulations where they apply, the UK International Data Transfer Agreement and its Addendum to the standard contractual clauses, alongside the providers' own security and compliance measures. You have the right to ask which safeguard applies to a particular provider, and to be given a copy of it. Write to us at the address above and we will provide it.
9. Data retention
We retain personal data only for as long as necessary to fulfil the purposes outlined in this notice or as required by law. After this period, data is securely deleted or anonymised.
Accreditation records for client organisations are retained for the duration of accreditation plus the renewal cycle, and for six years after lapse or completion, to allow us and our clients to evidence accreditation history where needed.
10. Your rights
You have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold. Under the Data (Use and Access) Act 2025, we are only required to carry out a reasonable and proportionate search to respond to this request.
- Correction: request corrections to inaccurate or incomplete data.
- Erasure: request deletion of your personal data (subject to legal obligations).
- Restriction: request limited processing of your data.
- Objection: object to processing based on legitimate interests.
- Data Portability: request transfer of your data to another provider.
- Complain directly to us: a right introduced by the Data (Use and Access) Act 2025, allowing you to raise a data protection complaint with us directly, in addition to your existing right to complain to the regulator.
To exercise any of these rights, contact us at hazel@synergysafeguarding.co.uk. We will acknowledge and respond to your request or complaint promptly.
11. Data security
We implement appropriate technical and organisational measures to protect personal data from unauthorised access, loss, or misuse.
12. Complaints and contact information
If you have concerns about how we handle your data, you can contact us at hazel@synergysafeguarding.co.uk. You also have the right to lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office (ICO), at www.ico.org.uk.
Following the Data (Use and Access) Act 2025, the ICO is being renamed the Information Commission as part of wider reforms to its powers and structure. It continues to operate at ico.org.uk in the meantime.
13. Updates to this privacy notice
We may update this privacy notice periodically, including to reflect changes in the law or in the providers we use. Any changes will be posted on our website, and significant updates will be communicated directly where applicable.