Skip to content
Skip to main content

Legal

Privacy Notice

This notice describes how the operator of Syftia ("Syftia", "we", "us") handles personal information when you use the Syftia workforce-management platform. It reflects how the platform currently works and will be updated as the service evolves.

Last updated:

Draft — pending independent legal review

This document reflects how the platform currently works. It has not yet been reviewed by a qualified solicitor and does not constitute legal advice. It will be updated before general availability.

1. Who operates Syftia

Syftia is currently operated by the individual or organisation running the platform (referred to here as "the operator of Syftia"). A registered legal entity will be published on this page once formed. If you need to confirm the current operator for legal correspondence, please use the contact form.

2. Information we collect

We only collect information that the platform actually processes today:

Account and identity

  • Email address, name, chosen role (contractor or company), and authentication credentials.
  • Identity information returned by OAuth providers (Google, Apple) when you choose to sign in with them: your provider user id, email, name and — if you consent at the provider — profile picture.
  • A record that you accepted our Terms of Service and Privacy Notice: which version of each document, the moment you accepted, and the interface language you were using.

Contractor profile

  • Profile details you add: display name, contact details, availability preferences, how you trade (sole trader or your own limited company), and — where you provide them — UTR and VAT registration status.
  • Payment details you enter so companies can pay your invoices (for example account name, sort code and account number, or the payment reference you ask companies to use).
  • Documents and qualifications you upload (for example licences and certificates). Whether a document is verified is set by an authorised reviewer, not by you.
  • Expiry dates you record for those documents. Syftia surfaces them for review; it does not verify licences with any issuing body or check right-to-work status on your behalf.
  • A factual record of your platform activity, such as completed jobs, attendance records, timesheets and invoices. Syftia does not calculate ratings or reputation scores.

Company

  • Company profile details, sites, integrations you enable, and settings you configure.
  • Company memberships and invitations that determine which contractors can see or apply to your jobs.

Jobs, applications and schedule

  • Jobs you publish or apply to, application status, acceptances and rejections.
  • Clock-in and clock-out timestamps, break minutes, early-departure reasons, incident reports, and expenses (including any receipt images you upload).
  • Timesheets generated from your clock-in/out, and invoices generated from approved timesheets. Issued invoices are immutable records and are corrected by issuing new documents, not by editing the original.

Communications

  • Messages you send inside Syftia (direct messages between authorised parties and job conversations for booked contractors), and the metadata needed to deliver and organise them. Message content is stored in readable form.
  • Notifications we send you in-app.

AI Assistant

  • Prompts you send to the in-app AI Assistant and the operational context we look up to answer them.

Product feedback and support

  • Roadmap votes, feature feedback, and messages you send through the contact form.

Technical and security

  • Standard request logs (IP address, user agent, timestamps) generated by our hosting providers, and authentication events.

We do not currently collect background location, advertising identifiers, or payment card details. Syftia does not process payments, so no card or bank authorisation data passes through the platform. Device location is collected — see the next section.

2a. Location information

When you clock in or clock out of a job, Syftia asks your browser for a single location reading at that moment and stores it alongside the attendance record: latitude, longitude, the accuracy reported by your device, and the time of capture. This exists so both parties have an honest record of where an attendance event was recorded.

  • Capture is single-shot and event-driven. We use one reading per clock-in and one per clock-out. We do not track you continuously, do not sample in the background, and do not collect heading or speed.
  • Your browser asks your permission first. If you decline, or your device cannot provide a reading, the attendance event is still recorded and the outcome is stored as declined or unavailable instead of coordinates.
  • The company you performed the job for can see the location outcome for their own attendance records. Coordinates are not shown on invoices and are not shared with other contractors.

3. How we use information

  • Provide the platform: authenticate you, show your jobs, deliver messages, generate timesheets and invoices from your recorded activity.
  • Manage access: enforce company memberships, invitations and job visibility rules so people only see what they are authorised to see.
  • Record legal acceptance: store which version of these documents you accepted and when.
  • Support you when you contact us and investigate reported issues.
  • Keep the service secure: detect abuse, protect accounts, and preserve audit trails required for a workforce platform.
  • Improve the product using aggregate usage and feedback.

4. Lawful bases (UK GDPR)

Where UK GDPR applies, we generally rely on the following lawful bases: contract (to provide the platform you signed up for), legitimate interests (to secure the service, prevent abuse and improve the product in a proportionate way), consent (for optional features such as marketing communications if we introduce them), and legal obligation (for records we are required to keep). This list will be refined with independent legal review before general availability.

5. Controller and processor roles

For your own account and general use of the platform, Syftia acts as the data controller. For information about contractors that a company manages inside the platform (for example applications, timesheets, invoices and messages tied to a company workspace), the company is the controller of that information for its own purposes, and Syftia processes it on their behalf as part of the service. Companies are responsible for their own obligations to their contractors.

6. Who we share information with

  • Companies with whom you have an active application, membership or accepted job — limited to what they need to operate that workflow.
  • Contractors booked on a job, for the job conversation and schedule context.
  • Service providers who host and operate the platform on our behalf and are contractually bound to protect your information.
  • Google or Microsoft, but only where you personally connect a calendar — see the next section.
  • Authorities where we are legally required to disclose information, or to protect the safety of users and the platform.

We do not sell personal information. A confirmed list of subprocessors will be published on this page as part of the pre-launch legal review.

6a. Calendar integrations you connect

Syftia can write your Syftia jobs into a personal Google Calendar or Outlook calendar. This only happens if you connect that calendar yourself and turn sync on.

  • When sync is on, we send Google or Microsoft the details needed to create the calendar entry: job title, start and end times, time zone, and the site or location text. Once sent, that data is held in your calendar under Google's or Microsoft's own terms and privacy notices, not ours.
  • We store the access and refresh credentials the provider issues. Those credentials are encrypted at rest.
  • You can disconnect at any time in Settings. Disconnecting stops future sync; entries already written into your calendar remain there until you remove them.

6b. Access by Syftia administrators

Accounts holding the Syftia platform administrator role can access operational records — including message content — where it is necessary to investigate a report, resolve a support issue, comply with a legal obligation, or protect the safety and integrity of the platform. Administrators can also send you a direct message inside the product. We mention this explicitly because messages are not end-to-end encrypted and cannot be hidden from platform administrators.

7. International transfers

Some service providers process data outside the UK. Where they do, we rely on appropriate safeguards recognised under UK GDPR (such as the UK International Data Transfer Addendum). The confirmed list of providers and regions will be published alongside our subprocessor list.

8. How long we keep information

We keep account, job, timesheet and invoice records for as long as your account is active and for a reasonable period afterwards to meet audit, dispute-resolution and legal-record requirements. Contact-form submissions are retained for support and abuse-prevention purposes. Specific retention periods will be published once confirmed. Issued invoices, approved pay decisions and attendance records are deliberately immutable, so they are retained even where other profile information is removed. You can request deletion of your account at any time (see "Your rights").

9. How we protect information

Access to your data is protected by industry-standard authentication, encrypted transport (HTTPS), row-level access rules in our database, role-based authorisation for internal features, and separation between company workspaces so one company cannot read another's data.

To be precise about encryption: traffic between your device and Syftia is encrypted in transit, our hosting and database providers apply their own storage-level protections, and credentials for calendar integrations are encrypted at rest by Syftia. Beyond that, Syftia does not add application-level encryption to your content, and messages are not end-to-end encrypted: authorised parties and platform administrators can read them.

No system is perfectly secure, and we make no certification claims — we do not hold ISO 27001, SOC 2 or Cyber Essentials. If we obtain such certifications, we will state so here with the issuing body and date.

10. Your rights

Under UK GDPR you have the right to access, correct, delete, restrict or object to certain processing of your personal information, and the right to data portability. To exercise any right, use the contact form and select "Privacy or data request". We may need to verify your identity before acting on a request. Companies whose data we process on their behalf will normally handle those requests directly with their contractors.

Being straightforward about how this works today: there is no self-service export or delete button in the product. Requests are handled manually by the operator of Syftia, and we aim to respond within one month as UK GDPR requires. Some records — issued invoices, approved pay decisions and attendance history — must be retained for audit and dispute-resolution reasons even after an account is closed, so a deletion request may result in your profile being removed while those financial records are kept.

11. Cookies and similar technologies

Syftia currently uses only strictly necessary storage on your device:

  • An authentication session, stored in your browser's local storage by our authentication provider.
  • Your chosen interface language, stored locally so the app opens in the language you picked.
  • A sidebar_state cookie remembering whether the navigation sidebar is expanded.
  • Short-lived local storage used to carry sign-up intent (such as chosen role and legal acceptance) across a sign-in redirect.

We do not run advertising trackers, and we do not load third-party analytics or marketing scripts that would require a consent banner. If we introduce optional analytics or marketing technologies, we will add a granular cookie-consent control at that point.

12. Children

Syftia is intended for adults using the platform in a work context. It is not directed to children. If we become aware that a child has created an account, we will delete it.

13. AI Assistant

Syftia contains an in-app AI Assistant that is not part of the standard product experience and is not linked from the product navigation. If you use it, your prompts and the operational context we retrieve to answer them are processed by our AI provider. We do not use your Syftia data to train third-party foundation models, and no AI feature makes decisions about your pay, applications, approvals or invoices. The AI Assistant can make mistakes — please verify important decisions before acting on them.

14. Language of this notice

The Syftia interface is available in English, Spanish, French and Simplified Chinese. This notice and our Terms of Service are published in UK English only, and the English text is the version that applies. We would rather tell you that than offer a machine translation of a legal document. Translations by a qualified translator will be published as part of the pre-launch legal review.

15. Changes to this notice

We will update this notice as the platform evolves. The "Last updated" date at the top reflects the most recent change. For material changes we will surface a notice inside the app before the changes take effect.

16. Complaints and contact

If you have a concern, please contact us first via the contact form. If you are in the UK and remain unsatisfied, you have the right to complain to the Information Commissioner's Office (ico.org.uk). Once Syftia is registered with the ICO, our registration number will be published here.

Questions about this document?

You can contact us with any questions or requests.