1.  This policy relates to all our processing of personal data. All staff involved in this activity must follow this policy's procedures.

2.  As part of our General Data Protection Regulation (GDPR) obligations - to minimise the risk of breaches and uphold the protection of personal data - we promote privacy and data protection compliance from the early stages of all projects, and then throughout their life-cycles.

3.  The GDPR Owner is responsible for ensuring that appropriate Privacy Notices exist and are appropriately published to enable all data subjects to be aware of these notices and their contents before data is collected. All content will be in plain language.

4. The controller - the person who decides how and why personal data is processed - ensures that appropriate technical and operational measures are in place so that, by default, only personal data which are necessary for each specific purpose of the processing are processed. This applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. Through these measures, the controller ensures that, by default, personal data are not made widely accessible without permission.

5.  Before any personal data are processed, the specific purpose for this processing will be defined and the legal basis for this definition will be recorded to include:

  • Ensuring data subject's consent
  • Contract activity where the data subject is a party
  • Our legal obligations
  • Protecting the rights, freedoms and interests of the data subject
  • Our authority to carry out the processing that is in the public interest
  • Any legitimate interests of the data controller or third party
  • Obligations under UK law

Complaints

In the event that you wish to make a complaint about how personal data is being processed by us (or third parties), or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and our DPO.

Disclosure

We may pass your personal data on to third-party service providers in the course of dealing with you and for the purposes of system support or modification only.  Any third parties that we may share your data with are obliged to keep your details securely and to use them only for agreed purposes.  When they no longer need your data, they will dispose of the details in line with our own procedures. We will not pass any of your sensitive personal data onto a third party unless we are legally required to do otherwise. 

We will not pass on any personal data to any additional third parties without first obtaining your consent.  

Third Party Processors

Our carefully selected partners and service providers may process personal information about you on our behalf as described below:

Digital Marketing Service Providers

We personally appoint digital marketing agents to conduct marketing activity on our behalf, such activity may result in the compliant processing of personal information. Our appointed data processors include:

  1. Prospect Global Ltd (trading as SoPro) Reg. UK Co. 09648733. You can contact SoPro and view their privacy policy here: http://sopro.io. SoPro are registered with the ICO Reg: Z123456 their Data Protection Office can be emailed at: dpo@sopro.io
  2. HubSpot, Inc. You can contact HubSpot and view their privacy policy here: https://legal.hubspot.com/privacy-policy. HubSpot's Data Protection Office can be emailed at: privacy@hubspot.com.
  3. NextRoll Limited. You can contact NextRoll and view their privacy policy here: https://www.nextroll.com/privacy. Their Data Protection Officer can be emailed at: dpo@nextroll.com.

Special Categories

Certain data is classified under the Regulation as 'special categories' (see below).  Synergy Logistics Ltd does not knowing record or collect this information.  If, as the Data Controller, you believe that, as part of your custom setup, we do receive this information, you must notify us immediately.

  • Racial
  • Ethnic origin
  • Political opinions
  • Religious beliefs
  • Philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data
  • Health data
  • Data concerning a natural person's sex life
  • Sexual orientation
  • Other

When You Visit Our Website

You are free to explore the website without providing any Personal Information about yourself. When you visit the website or register for content, we request that you provide Personal Information about yourself, and we collect Navigational Information.

Personal Information

Personal Information refers to any information that you voluntarily submit to us and that identifies you personally, including contact information, such as your name, e-mail address, company name, address, phone number, and other information about yourself or your business. Personal Information can also include information about you that is available on the internet, such as from Facebook, LinkedIn, Twitter and Google, or publicly available information that we acquire from service providers.

Personal Information also includes Navigational Information, which refers to information about your computer and your visits to the Snapfulfil website such as your IP address, geographical location, browser type, referral source, length of visit and pages viewed. Please see the "Navigational Information" section below.

Log Files

When you view content provided by us, we automatically collect information about your computer hardware and software through our marketing automation software provider HubSpot (you may view full details of their Privacy Policy here). This information can include your IP address, browser type, domain names, internet service provider (ISP), the files viewed on our site (e.g. HTML pages, graphics, etc.) operating system, clickstream data, access time and referring website addresses. This information is used by Synergy Logistics Ltd. to provide general statistics regarding the use of the Snapfulfil website. For these purposes, we do link this automatically-collected data to Personal Information such as name, e-mail address, address, and phone number.

Information We Collect from Third Parties

From time to time, we may receive Personal Information about you from third party sources including partners with which we offer co-branded services or engage in joint marketing activities, and publicly available sources such as social media websites.

Compliance with Our Privacy Policy

We use the information we collect only in compliance with this Privacy Policy. Customers who use the Snapfulfil software are obligated through our agreements with them to comply with this Privacy Policy.

We Never Sell Personal Information

We will never sell your Personal Information to any third party.

Use of Personal Information

In addition to the uses identified elsewhere in this Privacy Policy, we may use your Personal Information to:

  • Send information or Snapfulfil content to you which we think may be of interest to you by post, email, or other means and send you marketing communications relating to our business;
  • Promote use of our software to you and share promotional information content with you in accordance with your communication preferences;
  • Provide other companies with statistical information about our users – but this information will not be used to identify any individual user;
  • Send information to you regarding changes to our Customer Terms of Service, Privacy Policy (including the Cookie Policy), or other legal agreements
  • Meet legal requirements

Use of Navigational Information

We use Navigational Information, collected via our HubSpot software, to operate and improve our website and marketing processes. We may also use Navigational Information alone or in combination with Personal Information to provide you with personalised information about Snapfulfil.

Customer Testimonials and Case Studies

We post customer testimonials and case studies on our website, which may contain Personal Information. We obtain each customer's consent prior to posting the customer's name and testimonial.

External Websites

Our website provides links to other websites. We do not control, and are not responsible for, the content or practices of these other websites. This Privacy Policy does not apply to these other websites, which are subject to their own privacy and other policies.

Cookies

Synergy Logistics Ltd. and its partners use cookies to analyse trends, administer the website, track users' movements around the website, to gather demographic information as a whole and personalise your marketing experience with us.

How to Access & Control Your Personal Data

At any point while we are in possession of or processing your personal data, you have the following rights:

  • Right of access – the right to request a copy of the information that we hold about you
  • Right of rectification – the right to correct data that we hold about you that is inaccurate or incomplete
  • Right to be forgotten – in certain circumstances, you have the right to ask that the data we hold about you be erased from our records
  • Right to restriction of processing – where certain conditions apply, you have a right to restrict the processing of your data
  • Right of portability – the right to have the data we hold about you transferred to another organisation
  • Right to object – the right to object to certain types of processing such as direct marketing
  • Right to judicial review - in the event that Synergy Logistics refuses your requests under rights of access, we will provide you with a reason as to why

To exercise any of these rights, please contact us at info@snapfulfil.com. We will respond to your request to change, correct, or in a reasonable timeframe and notify you of the action we have taken.

To Unsubscribe from Our Communications

You may unsubscribe from our marketing communications by clicking on the "email preferences" link located on the bottom of our e-mails or by sending us an email at info@snapfulfil.com.

To Opt Out of Cookie Tracking for Advertising

Synergy uses NextRoll to track cookies for interest-based advertising. NextRoll is a member of the Network Advertising Initiative (NAI) and adheres to the NAI Code of Conduct. You may use the NAI opt-out tool here, which will allow you to opt-out of seeing interest-based ads from NextRoll and from other NAI approved member companies. In addition, the NAI opt-out tool allows you to separately opt-out of "audience matched" advertising through the NAI's "Audience Matched Advertising Opt-Out"tool. If you are located in a European Territory affected by GDPR, you may use the EDAA tool to opt out here.

Part A - Snapfulfil Product

In all cases, Synergy Logistics is the Data Processor and the customer is the Data Controller

The Data Controller must ensure that this notice is made available to data subjects prior to collecting/processing their personal data and passing it to Synergy Logistics for Data Processing.  Any Data Controllers who interact with data subjects are responsible for ensuring that this notice is drawn to the data subject's attention and their consent to the processing of their data is secured.

Personal data

The personal data that our customers enter into Snapfulfil vary for each system due to the flexibility of the product.  In all cases the Data Controller should be aware of the Personally Identifiable Information (PII) that is entered into Snapfulfil.

We will process the information you provide in compliance with the EU's General Data Protection Regulation (GDPR). 

  • Personal data type - Usually this includes Names, Addresses, Email and Telephone numbers although this will vary for each customer and our customers should be aware of the data types provided to Snapfulfil.
  • Source - Via manual (typed) entry or an interface (API, CSV, FTP, SFTP) etc.

The personal data entered into Snapfulfil will be used for the following purposes:

  • To allow timely and accurate management of stock from Receipt into the Warehouse right through to Despatch to the end customer or Data Subject.
  • To allow Support of the application in respect of software issues, changes to processes or modifications.

Our legal basis for processing for the personal data:  Pursuit of a contract
Any legitimate interests pursued by us, or third parties we use, are as follows: Contractual obligation

Replication of Data

Synergy maintains additional copies of the Live database and these are described below:

  • Test Database - This is a copy of Live from a point in time to allow customers to perform training and testing of changes in a secure environment without affecting the Live system. 
  • GSS Database - This is a copy of Live from a point in time to allow Synergy employees to perform training and testing of changes requested by the customer in a secure environment without affecting the Live system OR tests/training being performed by the client in the Test Database. 

Both the Test and GSS Databases will be purged of known PII information as soon as is reasonably possible following a copy of Live.   Sometimes the tests being performed may be directly related to PII information, in which case the data will remain until investigations have been completed or the customer asked Synergy Logistics to remove it.

  • Disaster Recovery - Live data is replicated in real time for DR purposes to 2 separate instances.  This is a real time copy of the Live system and purges in line with the Live system.

Encryption

Snapfulfil data is encrypted at rest. The data also has restricted access based on user privileges both from an application level and from a direct data access level.

Retention period

We will process personal data for the purge periods set out in the Specification provided by the Synergy Logistics Project Manager.  Once the purge period has been reached, the data will be our Help Centre.

Your customers' Data Subject rights

At any point while we are in possession of or processing your customers (the data subject) personal data, they have the following rights.

  • Right of access – the data subject has the right to request a copy of the information that we hold about them. 
  • Right of rectification – the data subject has the right to correct data that we hold about them that is inaccurate or incomplete.
  • Right to be forgotten – in certain circumstances the Data Subject can ask for the data we hold about them to be erased from our records.
  • Right to restriction of processing – where certain conditions apply the data subject has a right to restrict the processing. This relates to accuracy of data being obtained in a non-authorised manner
  • Right of portability – the data subject has the right to have the data we hold about them transferred to another organisation.
  • Right to object – the data subject has the right to object to certain types of processing such as direct marketing.  However, Synergy Logistics will never use your customer's data for Marketing purposes. 
  • Right to object to automated processing, including profiling – The data subject has the right to be subject to the legal effects of automated processing or profiling. 
  • Right to judicial review - in the event that Synergy Logistics refuses the Data Controllers requests under rights of access, we will provide you with a reason as to why. 

In all of the cases above, Data subjects will be referred to the Data Controller for identity checks.  The Data Controller may then raise a ticket with the Snapfulfil Help Desk to enquire if specific Data Types are still within any of our Live, Test, GSSTEST, Replicated or DR Databases.  If there is a third party involved in the processing of personal data, the requests will be forwarded on.

Part B - Support Services

Personal data

We will process the information you provide in compliance with the EU's General Data Protection Regulation (GDPR). We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary.  We are required to retain information in accordance with the law, such as information needed for income tax and audit purposes. How long certain kinds of personal data should be kept may also be governed by specific business-sector requirements and agreed practices. Personal data may be held in addition to these periods depending on individual business needs.

In order to provide Support Services, we will collect and store any contact details that you or your organisation has provided to us.  The information you provide will be subject to rigorous measures and procedures to minimise the risk of unauthorised access or disclosure. 

  • Personal data type - Usually this includes Name.  All the other data types should be business only, for example: Business Addresses, Business Email and Business Telephone numbers.  An audit of contact numbers within our ticket logging system (Zendesk) has taken place in April and May 2018.
  • Source - Usually this would be via CC in an email or by creating a Zendesk User account.  When a Zendesk Account is created, the user is automatically added to the Support Mailing list.

Support Mailing list

This mailing list only contains important notifications from Support Services, including Support enhancements, additions to the team, uplift/out of support hours notices and other improvements/services related to Service Desk, CST and QA.  

We are committed to ensuring that the information we collect and use is appropriate for this purpose and does not constitute an invasion of your privacy.

The personal data entered by your employees will be used for the following purposes:

  • To allow Support of the applications in respect of software issues, changes to processes or modifications to the application.
  • To notify you of changes to Support Services

You may withdraw consent at any time by contacting our DPO.

Disclosure

The following third parties will receive your personal data for the following purpose(s) as part of the processing activities:

  • Zendesk - Hosting provider for our ticket logging system.
  • Renovotec - RF provider for some customers to enable investigations for specific tickets

Retention period

We will process personal data for the duration of the contract between Synergy Logistics Limited and your organisation.

Your rights as a data subject

At any point while we are in possession of or processing your customers (the data subject) personal data, they have the following rights.

  • Right of access – the data subject has the right to request a copy of the information that we hold about them. 
  • Right of rectification – the data subject has the right to correct data that we hold about them that is inaccurate or incomplete.
  • Right to be forgotten – in certain circumstances the Data Subject can ask for the data we hold about them to be erased from our records.
  • Right to restriction of processing – where certain conditions apply the data subject has a right to restrict the processing. This relates to accuracy of data being obtained in a non-authorised manner
  • Right of portability – the data subject has the right to have the data we hold about them transferred to another organisation.
  • Right to object – the data subject has the right to object to certain types of processing such as direct marketing.  However, Synergy Logistics will never use your customer's data for Marketing purposes. 
  • Right to object to automated processing, including profiling – The data subject has the right to be subject to the legal effects of automated processing or profiling. 
  • Right to judicial review - in the event that Synergy Logistics refuses the Data Controllers requests under rights of access, we will provide you with a reason as to why. 

In all of the cases above, you will be required to provide information for identity checks.  Synergy Logistics will then investigate your request and if there is a third party involved in the processing of personal data, the requests will be forwarded on.