Data Management Policy.
How SYNE Ratings handles the data that underpins every rating - from a rated entity's disclosure submission through to storage, retention and eventual deletion.
How SYNE Ratings handles data, end to end.
This Data Management Policy sets out how SYNE Ratings collects, stores, secures, retains and disposes of the data that underpins our rating products - including data submitted by rated entities, data purchased from third-party providers, and data generated by our own analysts and models. It complements, but is separate from, our Privacy Policy, which addresses personal information specifically.
Who owns what moves through our systems.
Data submitted by a rated entity as part of a disclosure or engagement remains that entity's property. SYNE's rating opinions, scores, and the underlying scoring logic applied to that data are SYNE's own intellectual property. Third-party licensed datasets (such as satellite imagery or market pricing feeds) remain the property of their respective providers and are used by SYNE under license.
What we collect it for.
Data is collected solely for the purpose of producing, maintaining and updating a rating, benchmark or dataset, or for the internal research that supports our methodologies. We do not use a rated entity's confidential disclosure data for any commercial purpose unrelated to the rating engagement without separate consent.
How it's protected while it's with us.
All data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Access to production systems is restricted on a least-privilege basis, logged, and reviewed quarterly. Our information security management system is certified to ISO 27001, and our controls are further described in our Compliance & Certifications page.
How long we keep it, and how it's disposed of.
Rating-supporting data is retained for the duration of an active rating engagement plus seven years, to satisfy regulatory record-keeping obligations applicable to ratings providers. On request, and once retention obligations have lapsed, data is permanently and irrecoverably deleted from production and backup systems within 90 days.
When data leaves SYNE's systems.
We do not sell rated-entity data. Data may be shared with regulators where legally compelled, with sub-processors bound by confidentiality and security terms equivalent to our own, or in aggregated, anonymized form for benchmark or index publication where no individual entity's confidential data can be identified.
Where this meets personal information.
Where the data we manage includes personal information - for example, the business contact details of an individual submitting a disclosure - that information is additionally governed by our Privacy Policy, which takes precedence for anything relating to an identifiable individual.
Keeping our own people accountable.
All SYNE employees and contractors with data access complete mandatory data-handling and information-security training at onboarding and annually thereafter. Analysts handling non-public rated-entity disclosures complete additional confidentiality training specific to our ratings-independence requirements.
How we check this policy is actually followed.
Adherence to this policy is monitored through periodic internal audits and is a standing item for our Compliance function, described further in our regulatory Disclosures. Violations are addressed through our internal disciplinary process and, where required, reported to the relevant regulator.
How this policy changes over time.
This policy is reviewed at least annually and whenever a material change is made to our data infrastructure or applicable regulation. The "last updated" date at the top of this page reflects the most recent revision.
Have a question about how your data is handled?
Our data protection team can walk through retention timelines, sub-processors, or a specific deletion request.