Privacy Policy

Last updated: September 2026

Effective Date: 1 September 2026

Last Updated: 9 September 2026

Version: 2.0

1. Introduction and Who We Are

This Privacy Policy explains how ZYNTHIO LTD collects, uses, shares and protects personal data in connection with the Zynthio platform, the Zynthio mobile apps, the ZynthioEpos till software, and our websites (together, the "Platform").

Legal entity: ZYNTHIO LTD

Registered in: Scotland, company number SC873700

Registered office: 110 Izatt Avenue, Dunfermline, KY11 3BJ, United Kingdom

ICO registration: ZC228967

Privacy contact:hello@zynthio.co.uk

Zynthio is a multi-tenant hospitality management platform used by restaurants, pubs, hotels and similar businesses. Depending on the modules a customer subscribes to, the Platform supports food safety and HACCP records, checklists and audits, health & safety and accident reporting, HR and employee records, rotas and time & attendance, training, stock and procurement, customer bookings and reviews, EPOS sales reporting and the ZynthioEpos till (including card payments taken at the point of sale).

We are registered with the UK Information Commissioner's Office (ICO) as required by the Data Protection (Charges and Information) Regulations 2018. Our registration reference is ZC228967 and can be verified on the ICO's public register.

2. Our Role: Controller and Processor

Our role under UK GDPR depends on whose data is involved. This distinction matters, because it determines who you should contact to exercise your rights.

2.1 Where Zynthio is the Controller

We act as a data controller for data we decide the purposes of ourselves, namely:

2.2 Where Zynthio is a Processor

Important for employees of our customers: when your employer uses Zynthio to manage staff records, rotas, clock-ins, training, payroll inputs or compliance evidence, your employer is the data controller and Zynthio is a data processor. We hold and process that data only on your employer's documented instructions. If you want to access, correct or delete your employee record, please contact your employer in the first instance. If you contact us directly, we will pass your request to your employer and support them in responding; we cannot act on it unilaterally.

Data we process as a processor on behalf of our business customers includes employee and HR records, clock-in and rota data, training records, checklist and compliance evidence, accident and incident reports, stock and supplier records, customer booking and review data collected by the customer, and EPOS transaction records.

Our processing obligations in that role are set out in our Data Processing Agreement (see section 12).

3. Personal Data We Collect

3.1 Account and Business Data (Zynthio as controller)

3.2 Employee and Workforce Data (Zynthio as processor)

Where a customer uses our HR, rota or time & attendance modules, the Platform may hold the following categories of data about that customer's staff, as configured and entered by the customer:

Special category and sensitive data: some of the above — for example ethnicity, sickness absence, and health information recorded in accident or COSHH incident reports — is special category data under Article 9 UK GDPR. Where Zynthio is the processor, it is the customer's responsibility as controller to identify a valid Article 9 condition and a Schedule 1 Data Protection Act 2018 condition, and to maintain the appropriate policy document. We provide the technical controls; we do not decide what is collected.

3.3 Operational and Compliance Records

3.4 EPOS, Till and Payment Data

3.5 Data Collected Automatically

3.6 Data from Third Parties

4. How We Use Personal Data

We do not sell personal data. We do not use customer content or employee data to train artificial intelligence models, and where an AI feature is used to process customer content we require the provider to contract on no-training terms. Our AI features are: Venue Copilot, which answers questions and proposes supplier orders from your own venue data using Anthropic; the allergen matrix and menu tools, which use Anthropic; and delivery-note and supplier-invoice reading, which uses OpenAI. Only the data needed to answer the request is sent, and neither provider retains it for training.

5. Lawful Bases for Processing

Where we act as controller, we rely on the following lawful bases under Article 6 UK GDPR:

Where we rely on legitimate interests, we have assessed that our interests are not overridden by the rights and freedoms of the individuals concerned. You may ask us for a summary of that assessment.

Where we act as processor for employee and operational data, the lawful basis is determined by our customer as controller. Typically that will be contract (to administer the employment contract), legal obligation (payroll, right-to-work, working time and food safety record-keeping) and legitimate interests. For special category data, the customer must identify an Article 9 condition — commonly employment, social security and social protection law under Article 9(2)(b) with Schedule 1 Part 1 DPA 2018.

6. Payment Processing and Card Data

6.1 Subscription Payments

Subscription and invoice payments are processed by Stripe. When you pay, your card details are entered into Stripe's hosted payment pages and are transmitted directly to Stripe. Zynthio never receives or stores your full card number, expiry date or security code. We receive only a payment reference, the outcome, and limited card metadata such as brand and last four digits.

6.2 Card Payments Taken at the Till (ZynthioEpos)

Where a customer uses ZynthioEpos to take card payments in venue, payments are captured by a certified payment terminal or payment provider — currently Stripe, with Dojo and SumUp supported — under a merchant agreement between the venue and that provider. The venue is the merchant of record.

Cardholder data: Zynthio does not capture, transmit or store primary account numbers (PANs), magnetic stripe data, chip data, CVV/CVC values or PINs. Cardholder data is captured by the payment terminal or the provider's hosted flow and passes directly to the payment provider. Zynthio's systems receive and store only non-sensitive transaction metadata: amount, currency, timestamp, authorisation result, provider transaction reference, card scheme and the last four digits of the card.

PCI DSS responsibility. Our payment providers are PCI DSS Level 1 compliant. Because ZynthioEpos is designed so that cardholder data does not enter our environment, our PCI scope is limited accordingly; the venue remains responsible for its own PCI DSS obligations as merchant, including terminal handling, physical security and staff procedures. We will provide our current PCI attestation position on request. Payment provider credentials supplied by a customer are stored encrypted at rest and are never returned in API responses.

Payment providers act as independent controllers for their own anti-fraud, regulatory and financial-crime purposes. Their handling of your data is governed by their own privacy notices.

7. Who We Share Data With

We do not sell personal data. We share it only as set out below.

7.1 Sub-processors

We use the following service providers to operate the Platform. Each is bound by a written data processing agreement, may process personal data only on our instructions, and is subject to confidentiality and security obligations.

We maintain a current sub-processor list and will give business customers advance notice of changes in accordance with our Data Processing Agreement. To be notified of changes, email hello@zynthio.co.uk.

7.2 Within Your Organisation

The Platform is multi-tenant and access is role-based. Data entered by or about a user may be visible to that user's employer — for example to site managers, organisation administrators, and HR or payroll staff — according to the permissions the customer configures. Administrators can view audit trails of user activity.

7.3 Professional Advisers and Authorities

We may share data with our accountants, insurers and legal advisers under duties of confidentiality, and with regulators, courts or law enforcement where we are legally required to do so or where necessary to establish or defend legal claims.

7.4 Business Transfers

If ZYNTHIO LTD is acquired, merged, or its assets are sold, personal data may be transferred to the acquiring entity. We will notify affected customers and, where we are the processor, act only on the controller's instructions in relation to their data.