Privacy Policy.
This policy explains how SYNE Ratings collects, uses, shares and protects personal information across our websites, ratings services, and recruitment process, and how you can exercise your rights over that information.
Fourteen sections, start to finish.
Introduction & Scope
02Data Controller Information
03Information We Collect
04How We Use Your Information
05Legal Basis for Processing
06Data Sharing & Disclosure
07International Data Transfers
08Data Retention
09Your Rights
10Cookies & Tracking
11Data Security
12Children's Privacy
13Changes to This Policy
14Contact Us
What this policy covers.
This Privacy Policy applies to personal information collected by SYNE Ratings through our websites (including this site), our rating and data products, our recruitment process, and any other interaction you have with us - including submitting a contact form, being contacted as part of a rating engagement, or applying for a role.
It does not apply to information we process on behalf of a client as part of a commissioned rating where that client is itself the data controller - in those cases, the client's own privacy notice governs, and this policy applies only to SYNE's role as a processor under our engagement terms with that client.
Who is responsible for your information.
The SYNE group entity responsible for your personal information depends on where you are located and which service you're using. Each entity acts as the data controller for information it collects directly.
What we collect, and where it comes from.
Website visitors
When you browse our websites, we automatically collect technical information such as your IP address, browser type, device information, pages visited, and referring URL, typically through cookies and similar technologies described in Section 10.
Contact forms and enquiries
When you submit a form on our site - including the Contact Us form - we collect the information you provide, such as your name, work email, company, the nature of your enquiry, and any message content.
Rated entities and their representatives
Where we rate a company, project, supplier or government, we collect business contact information for the individuals involved in that engagement, including names, job titles, and business email addresses, along with the disclosure information submitted as part of the rating process.
Job applicants
When you apply for a role through our Careers pages, we collect the information included in your application - such as your name, contact details, CV or resume, and any information you choose to share during an interview process.
Event and webinar registrants
When you register for a webinar or event, we collect your name, email address, and any information provided as part of registration or during a live Q&A session.
What your information is used for.
- To respond to enquiries submitted through our Contact Us form or by email
- To deliver, administer and communicate about a commissioned rating, dataset, or advisory engagement
- To process job applications and manage recruitment
- To register attendees for webinars and events, and to send related materials or recordings
- To send methodology updates, research, or event invitations, where you have opted in to receive them
- To maintain the security, performance and functionality of our websites
- To comply with our legal and regulatory obligations, including under the EU ESG Ratings Regulation and equivalent regimes
Why we're allowed to process your information.
Where UK GDPR, EU GDPR, or an equivalent regime applies, we rely on one or more of the following legal bases for each processing activity described in Section 4:
- Consent - for marketing communications and non-essential cookies, which you can withdraw at any time
- Contract - to perform a rating, data licensing, or advisory engagement you or your organisation has commissioned
- Legitimate interests - to respond to enquiries, maintain website security, and improve our services, balanced against your rights
- Legal obligation - to comply with regulatory requirements applicable to SYNE as a ratings provider
Who we share information with.
We do not sell personal information. We may share it with:
- Other SYNE group entities, to coordinate a multi-jurisdiction rating engagement or provide a consistent service globally
- Service providers who support our operations, such as hosting, email delivery, and customer relationship management platforms, under contractual confidentiality and data protection obligations
- A client who has commissioned a rating, where the information relates to that specific engagement
- Regulators or public authorities, where required by law or to comply with a valid legal process
- A successor entity, in the event of a merger, acquisition, or sale of assets, subject to equivalent privacy protections
How we handle cross-border transfers.
As a group operating across the United Kingdom, Australia, New Zealand, India, Canada and the United States, personal information may be transferred between these jurisdictions in the course of delivering our services. Where a transfer is made from a jurisdiction with data transfer restrictions to one without an adequacy decision, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or an equivalent mechanism recognised in the relevant jurisdiction.
How long we keep your information.
We retain personal information for as long as necessary to fulfil the purpose it was collected for, including any legal, accounting, or regulatory reporting requirements. As a general guide:
- Contact form and enquiry data is retained for up to 24 months from your last interaction, unless you request earlier deletion
- Rating engagement records are retained in line with our regulatory recordkeeping obligations, typically for a minimum of 5 years following the end of an engagement
- Job applicant data is retained for up to 12 months following the conclusion of a recruitment process, unless you consent to a longer period for future opportunities
- Website analytics data is retained in aggregated or pseudonymised form beyond the periods set out in Section 10
What you can ask us to do.
Depending on where you're located, you may have some or all of the following rights over your personal information.
- Access - request a copy of the personal information we hold about you
- Rectification - ask us to correct inaccurate or incomplete information
- Erasure - ask us to delete your personal information, subject to certain legal exceptions
- Restriction - ask us to limit how we use your information while a request is resolved
- Portability - request your information in a structured, machine-readable format
- Objection - object to processing based on legitimate interests, including for direct marketing
- Withdraw consent - withdraw previously given consent at any time, without affecting processing already carried out
To exercise any of these rights, contact us using the details in Section 14. We will respond within the timeframe required by applicable law, typically within one month of a verified request.
How we use cookies.
We use cookies and similar technologies to operate our website, remember your preferences, and understand how our site is used. This includes:
- Essential cookies - required for the website to function, such as session and security cookies
- Analytics cookies - help us understand aggregate visitor behaviour, so we can improve our content and site structure
- Preference cookies - remember choices you've made, such as display or accessibility settings
You can control or disable cookies through your browser settings. Disabling essential cookies may affect the functionality of our website.
How we protect your information.
We maintain technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction, including encryption in transit, access controls, and regular review of our security practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Our services are not directed at children.
Our websites and services are intended for business use and are not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us using the details in Section 14 and we will take steps to delete it.
How we handle updates.
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. We will post the updated policy on this page with a revised "Last updated" date, and where changes are material, we will provide more prominent notice.
How to reach us about privacy.
If you have questions about this Privacy Policy, or wish to exercise any of the rights described in Section 9, contact our privacy team at privacy@syneratings.com, or use the general Contact Us form and note that your enquiry relates to privacy.
If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority - for example, the UK Information Commissioner's Office (ICO) if you're located in the United Kingdom.
Have a question about your data?
Our privacy team is available to help with access requests, corrections, or general questions.