1. Who operates Syftia
Syftia is currently operated by the individual or organisation running the platform (referred to here as "the operator of Syftia"). A registered legal entity will be published on this page once formed. If you need to confirm the current operator for legal correspondence, please use the contact form.
2. Information we collect
We only collect information that the platform actually processes today:
Account and identity
- Email address, name, chosen role (contractor or company), and authentication credentials.
- Sign-in today uses your email address and a password. Syftia does not currently offer sign-in with a third-party provider; if we enable one, we will describe the information it returns here before it goes live.
- A record that you accepted our Terms of Service and Privacy Notice: which version of each document, the moment you accepted, and the interface language you were using.
Contractor profile
- Profile details you add: display name, contact details, availability preferences, how you trade (sole trader or your own limited company), and — where you provide them — UTR and VAT registration status.
- Payment details you enter so companies can pay your invoices (for example account name, sort code and account number, or the payment reference you ask companies to use).
- Documents and qualifications you upload (for example licences and certificates). These stay private to you and Syftia platform administration; companies do not receive access to them through Syftia. The information you provide is treated as self-declared and is not independently verified.
- Expiry dates you record for those documents. Syftia surfaces reminders to you from those dates; it does not verify licences with any issuing body or check right-to-work status on your behalf.
- A factual record of your platform activity, such as completed jobs, attendance records, timesheets and invoices. Syftia does not calculate ratings or reputation scores.
Company
- Company profile details, sites, and settings you configure.
- Company memberships and invitations that determine which contractors can see or apply to your jobs.
Jobs, applications and schedule
- Jobs you publish or apply to, application status, acceptances and rejections.
- Clock-in and clock-out timestamps, break minutes, early-departure reasons, incident reports, and expenses (including any receipt images you upload).
- Timesheets generated from your clock-in/out, and invoices generated from approved timesheets. Issued invoices are immutable records and are corrected by issuing new documents, not by editing the original.
Payments
- Payment records for invoices: the identifiers Stripe gives us for a payment attempt and for a connected Stripe account, the amount, the currency, the payment status and the outcome — including failed attempts, refunds, disputes and credit notes.
- For contractors, the Stripe account you connect so companies can pay you, and the payout records Stripe reports for that account (status, amount and dates). Syftia never holds your money.
Communications
- Messages you send inside Syftia (direct messages between authorised parties and job conversations for booked contractors), and the metadata needed to deliver and organise them. Message content is stored in readable form.
- Notifications we send you in-app, by push notification and — for a limited set of operational messages — by email.
- Your notification preferences: which notifications you want, and on which channels.
AI Assistant
- Prompts you send to the in-app AI Assistant and the operational context we look up to answer them.
Product feedback and support
- Roadmap votes, feature feedback, and messages you send through the contact form.
Technical and security
- Standard request logs (IP address, user agent, timestamps) generated by our hosting providers, and authentication events.
We do not currently collect background location or advertising identifiers, and we never receive or store your card details. Card payments are taken on a payment page hosted by Stripe, so card and bank authorisation data goes to Stripe and not through Syftia; we keep only the resulting payment record described above. Device location is collected — see the next section.
2a. Location information
When you clock in or clock out of a job, Syftia asks your browser for a single location reading at that moment and stores it alongside the attendance record: latitude, longitude, the accuracy reported by your device, and the time of capture. This exists so both parties have an honest record of where an attendance event was recorded.
- Capture is single-shot and event-driven. We use one reading per clock-in and one per clock-out. We do not track you continuously, do not sample in the background, and do not collect heading or speed.
- Your browser asks your permission first. If you decline, or your device cannot provide a reading, the attendance event is still recorded and the outcome is stored as declined or unavailable instead of coordinates.
- The company you performed the job for can see the location outcome for their own attendance records. Coordinates are not shown on invoices and are not shared with other contractors.
3. How we use information
- Provide the platform: authenticate you, show your jobs, deliver messages, generate timesheets and invoices from your recorded activity.
- Manage access: enforce company memberships, invitations and job visibility rules so people only see what they are authorised to see.
- Record legal acceptance: store which version of these documents you accepted and when.
- Support you when you contact us and investigate reported issues.
- Keep the service secure: detect abuse, protect accounts, and preserve audit trails required for a workforce platform.
- Improve the product using aggregate usage and feedback.
Optional Syftia updates
If you choose to turn on Syftia updates, we may send you occasional product news, useful tips and offers by email. This is optional and based on your consent. You can turn Syftia updates off at any time in Settings. This does not affect service, security or account emails needed to provide Syftia.
4. Lawful bases (UK GDPR)
Where UK GDPR applies, we generally rely on the following lawful bases: contract (to provide the platform you signed up for), legitimate interests (to secure the service, prevent abuse and improve the product in a proportionate way), consent (for optional Syftia updates emails that you choose to turn on), and legal obligation (for records we are required to keep).
5. Controller and processor roles
For your own account and general use of the platform, Syftia acts as the data controller. For information about contractors that a company manages inside the platform (for example applications, timesheets, invoices and messages tied to a company workspace), the company is the controller of that information for its own purposes, and Syftia processes it on their behalf as part of the service. Companies are responsible for their own obligations to their contractors.
6. Who we share information with
- Companies with whom you have an active application, membership or accepted job — limited to what they need to operate that workflow.
- Contractors booked on a job, for the job conversation and schedule context.
- Service providers who host and operate the platform on our behalf and are contractually bound to protect your information.
- Stripe, our payment provider, when a company pays an invoice by card or a contractor connects a Stripe account to receive payment. Stripe handles the card payment on its own hosted page and under its own terms.
- Authorities where we are legally required to disclose information, or to protect the safety of users and the platform.
We do not sell personal information.
6b. Access by Syftia administrators
Accounts holding the Syftia platform administrator role can access operational records — including message content — where it is necessary to investigate a report, resolve a support issue, comply with a legal obligation, or protect the safety and integrity of the platform. Administrators can also send you a direct message inside the product. We mention this explicitly because messages are not end-to-end encrypted and cannot be hidden from platform administrators.
7. International transfers
Some service providers process data outside the UK. Where they do, we rely on appropriate safeguards recognised under UK GDPR (such as the UK International Data Transfer Addendum). The confirmed list of providers and regions will be published alongside our subprocessor list.
8. How long we keep information
We keep account, job, timesheet and invoice records for as long as your account is active and for a reasonable period afterwards to meet audit, dispute-resolution and legal-record requirements. Contact-form submissions are retained for support and abuse-prevention purposes. Specific retention periods will be published once confirmed. Issued invoices, approved pay decisions and attendance records are deliberately immutable, so they are retained even where other profile information is removed. You can request deletion of your account at any time (see "Your rights").
9. How we protect information
Access to your data is protected by industry-standard authentication, encrypted transport (HTTPS), row-level access rules in our database, role-based authorisation for internal features, and separation between company workspaces so one company cannot read another's data.
To be precise about encryption: traffic between your device and Syftia is encrypted in transit, our hosting and database providers apply their own storage-level protections, and any third-party credentials Syftia holds are encrypted at rest. Beyond that, Syftia does not add application-level encryption to your content, and messages are not end-to-end encrypted: authorised parties and platform administrators can read them.
No system is perfectly secure, and we make no certification claims — we do not hold ISO 27001, SOC 2 or Cyber Essentials. If we obtain such certifications, we will state so here with the issuing body and date.
10. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to certain processing of your personal information, and the right to data portability. To exercise any right, use the contact form and select "Privacy or data request". We may need to verify your identity before acting on a request. Companies whose data we process on their behalf will normally handle those requests directly with their contractors.
Being straightforward about how this works today: there is no self-service export or delete button in the product. Requests are handled manually by the operator of Syftia, and we aim to respond within one month as UK GDPR requires. Some records — issued invoices, approved pay decisions and attendance history — must be retained for audit and dispute-resolution reasons even after an account is closed, so a deletion request may result in your profile being removed while those financial records are kept.
11. Cookies and similar technologies
Syftia stores only what it needs to run, plus preferences you chose yourself. Storage required to run the platform:
- An authentication session, stored in your browser's local storage by our authentication provider, so you stay signed in.
- Short-lived storage that carries an invite through sign-up or sign-in, so joining a company does not break part-way.
- If you turn on push notifications, the permission and subscription your browser holds. You can revoke it in your browser settings.
Preferences remembered on the device you are using:
- Your chosen interface language, stored locally and in a
syftia.localecookie so pages open in the language you picked. - Whether you last used the month, week or list calendar view, and how you arranged your availability screen.
- A job you were writing but had not published, kept locally so closing the tab does not lose your work.
We do not run advertising trackers, and we do not load third-party analytics or marketing scripts that would require a consent banner — so there is nothing here to accept or decline. If we introduce optional analytics or marketing technologies, we will add a granular cookie-consent control at that point. Signed in, you can see this same list, check which version of these documents you accepted, and clear the preferences your device remembers under Settings → Privacy & data.
12. Children
Syftia is intended for adults using the platform in a work context. It is not directed to children. If we become aware that a child has created an account, we will delete it.
13. AI Assistant
Syftia contains an in-app AI Assistant that is not part of the standard product experience and is not linked from the product navigation. If you use it, your prompts and the operational context we retrieve to answer them are processed by our AI provider. We do not use your Syftia data to train third-party foundation models, and no AI feature makes decisions about your pay, applications, approvals or invoices. The AI Assistant can make mistakes — please verify important decisions before acting on them.
14. Language of this notice
The Syftia interface is available in English, Spanish, French and Simplified Chinese. This notice and our Terms of Service are published in UK English only, and the English text is the version that applies. We would rather tell you that than offer a machine translation of a legal document.
15. Changes to this notice
We will update this notice as the platform evolves. The "Last updated" date at the top reflects the most recent change. For material changes we will surface a notice inside the app before the changes take effect.
16. Complaints and contact
If you have a concern, please contact us first via the contact form. If you are in the UK and remain unsatisfied, you have the right to complain to the Information Commissioner's Office (ico.org.uk). Once Syftia is registered with the ICO, our registration number will be published here.
