Privacy Policy
Last updated: September 2026
Effective Date: 1 September 2026
Last Updated: 9 September 2026
Version: 2.0
1. Introduction and Who We Are
This Privacy Policy explains how ZYNTHIO LTD collects, uses, shares and protects personal data in connection with the Zynthio platform, the Zynthio mobile apps, the ZynthioEpos till software, and our websites (together, the "Platform").
Legal entity: ZYNTHIO LTD
Registered in: Scotland, company number SC873700
Registered office: 110 Izatt Avenue, Dunfermline, KY11 3BJ, United Kingdom
ICO registration: ZC228967
Privacy contact:hello@zynthio.co.uk
Zynthio is a multi-tenant hospitality management platform used by restaurants, pubs, hotels and similar businesses. Depending on the modules a customer subscribes to, the Platform supports food safety and HACCP records, checklists and audits, health & safety and accident reporting, HR and employee records, rotas and time & attendance, training, stock and procurement, customer bookings and reviews, EPOS sales reporting and the ZynthioEpos till (including card payments taken at the point of sale).
We are registered with the UK Information Commissioner's Office (ICO) as required by the Data Protection (Charges and Information) Regulations 2018. Our registration reference is ZC228967 and can be verified on the ICO's public register.
2. Our Role: Controller and Processor
Our role under UK GDPR depends on whose data is involved. This distinction matters, because it determines who you should contact to exercise your rights.
2.1 Where Zynthio is the Controller
We act as a data controller for data we decide the purposes of ourselves, namely:
- Data about our own customers and prospects — the business contacts who sign up, buy, or enquire about Zynthio
- Billing and subscription records for our own accounts and tax obligations
- Website visitor data, analytics and marketing data on our public website
- Support correspondence sent directly to us
- Security, fraud-prevention and platform-integrity logs
2.2 Where Zynthio is a Processor
Important for employees of our customers: when your employer uses Zynthio to manage staff records, rotas, clock-ins, training, payroll inputs or compliance evidence, your employer is the data controller and Zynthio is a data processor. We hold and process that data only on your employer's documented instructions. If you want to access, correct or delete your employee record, please contact your employer in the first instance. If you contact us directly, we will pass your request to your employer and support them in responding; we cannot act on it unilaterally.
Data we process as a processor on behalf of our business customers includes employee and HR records, clock-in and rota data, training records, checklist and compliance evidence, accident and incident reports, stock and supplier records, customer booking and review data collected by the customer, and EPOS transaction records.
Our processing obligations in that role are set out in our Data Processing Agreement (see section 12).
3. Personal Data We Collect
3.1 Account and Business Data (Zynthio as controller)
- Account information: name, work email address, phone number, job title, business name and role/permission level
- Business information: trading name, business address, sites, brands and subscribed modules
- Billing information: billing name and address, VAT details, invoice and payment history. Card details are entered directly with our payment provider and are not stored by Zynthio
- Communication data: support tickets, emails, in-app messages and enquiry-form submissions
3.2 Employee and Workforce Data (Zynthio as processor)
Where a customer uses our HR, rota or time & attendance modules, the Platform may hold the following categories of data about that customer's staff, as configured and entered by the customer:
- Identity and contact: name, preferred name, date of birth, home address, personal email and phone, photograph, emergency contact details
- Employment: job title, position, start and end dates, contracted hours, reason for leaving, performance and lifecycle status, free-text management notes
- Payroll and tax: National Insurance number, tax code, student loan plan, payroll ID, salary or hourly rate, pension enrolment and contribution rate, tronc allocations
- Bank details: account name, sort code and account number, held for payroll purposes and encrypted at application level
- Right to work and immigration: nationality, passport number, share code, visa or settled-status details and expiry dates, right-to-work check outcomes, and uploaded copies of right-to-work documents
- Working time: rota and shift data, clock-in and clock-out events including, where the customer has enabled geofenced clock-in, the device's GPS latitude and longitude at the moment of clocking and whether that position fell inside the site geofence
- Absence: holiday balances and requests, and absence records which may include sickness absence
- Training and competency: courses assigned and completed, quiz results, certificates and expiry dates
- Documents: contracts, offer and disciplinary letters, payslips, certificates, starter forms, proof of address and other files uploaded by the customer
- Equality monitoring: where the customer chooses to record it, gender identity, ethnicity and marital status
Special category and sensitive data: some of the above — for example ethnicity, sickness absence, and health information recorded in accident or COSHH incident reports — is special category data under Article 9 UK GDPR. Where Zynthio is the processor, it is the customer's responsibility as controller to identify a valid Article 9 condition and a Schedule 1 Data Protection Act 2018 condition, and to maintain the appropriate policy document. We provide the technical controls; we do not decide what is collected.
3.3 Operational and Compliance Records
- Completed checklists, temperature readings, HACCP records, timestamps and the identity of the user who completed each task
- Photographs and files uploaded as evidence, which may incidentally contain images of people
- Accident, incident and near-miss reports, which may include the name and injury details of the person affected
- Audit trails recording which user performed which action and when
- Customer bookings, enquiries and review data where the customer uses those modules
- Loyalty scheme members: where a venue runs a customer loyalty scheme, the name, email address and mobile number a customer gives when joining, their marketing preference, and their points, rewards and visit history. The venue is the controller of this data and Zynthio processes it on the venue's behalf
- Shift notice and cancellation records: when each shift was published to an employee, any later change or cancellation with its reason, and rolling hours worked over a reference period, kept so employers can evidence the notice and guaranteed-hours duties introduced by the Employment Rights Act 2025
- Records captured offline: checklists and temperature readings completed on a device without a connection are stored on that device and sent to us when it reconnects. We keep both the time the record was completed on the device and the time it reached our servers
3.4 EPOS, Till and Payment Data
- Transaction records: items sold, order and table details, totals, discounts, tips, timestamps, terminal and site identifiers, and the staff member who processed the sale
- Payment metadata: payment method, amount, currency, authorisation result, the last four digits of the card, card scheme and a processor reference. See section 6
- Staff till activity: PIN-based operator identification, till clock-ins and cash-up records
- Third-party EPOS integrations: where a customer connects a third-party EPOS such as Toast, we receive sales aggregates and item-level data under that customer's instruction
3.5 Data Collected Automatically
- Device and connection data: IP address, browser type and version, operating system, device type
- Usage data: pages and features accessed, actions taken, session timings, error and diagnostic logs
- Approximate location: derived from IP address on our public website
- Precise location: only where a customer has enabled geofenced clock-in and the user grants location permission (see 3.2)
- Push notification tokens: where a user installs our mobile app and enables notifications
- Cookies and similar technologies: see our Cookie Policy
3.6 Data from Third Parties
- Payment and subscription status from Stripe
- Card authorisation results from the relevant payment processor (Stripe, Dojo or SumUp)
- Sales data from connected EPOS providers, where a customer authorises the connection
- Publicly available review and business-listing data where a customer uses our reviews module
- Identity assertions where a user signs in via a linked Zynthio product
4. How We Use Personal Data
- Service delivery: to provide, host, maintain, support and improve the Platform
- Account management: to create accounts, authenticate users and apply role-based permissions
- Compliance records: to store, display and report on food safety, health & safety and HR records on behalf of our customers
- Payments: to process subscription payments and, for ZynthioEpos, to route card payments to the customer's payment processor
- Communications: to send service, security and billing messages, task reminders and notifications by email and push
- Marketing: to send business-to-business marketing about Zynthio to business contacts, with an opt-out in every message
- Analytics: to understand aggregate use of our website and Platform and improve it
- Security and abuse prevention: to detect, investigate and prevent fraud, unauthorised access and technical faults
- Legal: to comply with law, respond to lawful requests, and establish, exercise or defend legal claims
We do not sell personal data. We do not use customer content or employee data to train artificial intelligence models, and where an AI feature is used to process customer content we require the provider to contract on no-training terms. Our AI features are: Venue Copilot, which answers questions and proposes supplier orders from your own venue data using Anthropic; the allergen matrix and menu tools, which use Anthropic; and delivery-note and supplier-invoice reading, which uses OpenAI. Only the data needed to answer the request is sent, and neither provider retains it for training.
5. Lawful Bases for Processing
Where we act as controller, we rely on the following lawful bases under Article 6 UK GDPR:
Where we rely on legitimate interests, we have assessed that our interests are not overridden by the rights and freedoms of the individuals concerned. You may ask us for a summary of that assessment.
Where we act as processor for employee and operational data, the lawful basis is determined by our customer as controller. Typically that will be contract (to administer the employment contract), legal obligation (payroll, right-to-work, working time and food safety record-keeping) and legitimate interests. For special category data, the customer must identify an Article 9 condition — commonly employment, social security and social protection law under Article 9(2)(b) with Schedule 1 Part 1 DPA 2018.
6. Payment Processing and Card Data
6.1 Subscription Payments
Subscription and invoice payments are processed by Stripe. When you pay, your card details are entered into Stripe's hosted payment pages and are transmitted directly to Stripe. Zynthio never receives or stores your full card number, expiry date or security code. We receive only a payment reference, the outcome, and limited card metadata such as brand and last four digits.
6.2 Card Payments Taken at the Till (ZynthioEpos)
Where a customer uses ZynthioEpos to take card payments in venue, payments are captured by a certified payment terminal or payment provider — currently Stripe, with Dojo and SumUp supported — under a merchant agreement between the venue and that provider. The venue is the merchant of record.
Cardholder data: Zynthio does not capture, transmit or store primary account numbers (PANs), magnetic stripe data, chip data, CVV/CVC values or PINs. Cardholder data is captured by the payment terminal or the provider's hosted flow and passes directly to the payment provider. Zynthio's systems receive and store only non-sensitive transaction metadata: amount, currency, timestamp, authorisation result, provider transaction reference, card scheme and the last four digits of the card.
PCI DSS responsibility. Our payment providers are PCI DSS Level 1 compliant. Because ZynthioEpos is designed so that cardholder data does not enter our environment, our PCI scope is limited accordingly; the venue remains responsible for its own PCI DSS obligations as merchant, including terminal handling, physical security and staff procedures. We will provide our current PCI attestation position on request. Payment provider credentials supplied by a customer are stored encrypted at rest and are never returned in API responses.
Payment providers act as independent controllers for their own anti-fraud, regulatory and financial-crime purposes. Their handling of your data is governed by their own privacy notices.
7. Who We Share Data With
We do not sell personal data. We share it only as set out below.
7.1 Sub-processors
We use the following service providers to operate the Platform. Each is bound by a written data processing agreement, may process personal data only on our instructions, and is subject to confidentiality and security obligations.
We maintain a current sub-processor list and will give business customers advance notice of changes in accordance with our Data Processing Agreement. To be notified of changes, email hello@zynthio.co.uk.
7.2 Within Your Organisation
The Platform is multi-tenant and access is role-based. Data entered by or about a user may be visible to that user's employer — for example to site managers, organisation administrators, and HR or payroll staff — according to the permissions the customer configures. Administrators can view audit trails of user activity.
7.3 Professional Advisers and Authorities
We may share data with our accountants, insurers and legal advisers under duties of confidentiality, and with regulators, courts or law enforcement where we are legally required to do so or where necessary to establish or defend legal claims.
7.4 Business Transfers
If ZYNTHIO LTD is acquired, merged, or its assets are sold, personal data may be transferred to the acquiring entity. We will notify affected customers and, where we are the processor, act only on the controller's instructions in relation to their data.