Data Privacy & Retention Policy
Updated August 2026
esynergy Solutions Limited (“esynergy”, “we”, “us” or “our”) is committed to protecting and respecting your privacy.
This Data Privacy and Retention Policy explains how we collect, use, store, share and protect personal information, the lawful bases on which we process it, how long we retain it and the rights available to individuals in relation to their personal data.
We process personal data in accordance with applicable UK data protection legislation, including:
- the UK General Data Protection Regulation (“UK GDPR”);
- the Data Protection Act 2018;
- the Data (Use and Access) Act 2025; and
- the Privacy and Electronic Communications Regulations 2003 (“PECR”), where
We are committed to the principles of UK data protection law and will ensure that personal data is:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes;
- adequate, relevant and limited to what is necessary;
- accurate and, where necessary, kept up to date;
- kept for no longer than is necessary;
- processed securely, with appropriate protection against unauthorised or unlawful processing and against accidental loss, destruction or damage; and
- processed in a manner that demonstrates accountability and compliance with data protection
For the purposes of applicable data protection legislation, the data controller is:
esynergy Solutions Limited
New London House 6 New London Street London
EC3R 7LP
Our Data Protection Contact is the Head of Contracts and Compliance and can be contacted at:
Who we are and what we do
esynergy is a technology consultancy. We build and support products, platforms and services that accelerate digital business outcomes for our clients.
We have our head office in London, England and operate primarily within the United Kingdom.
We work with employees, independent professional associates, clients, suppliers, professional partners and other organisations to deliver technology consultancy and related services. We also support professional communities through activities which may include events, meetups, training and other business and professional development initiatives.
We may collect and process personal data relating to:
- prospective and current associates and other independent professionals;
- prospective and current employees, consultants and temporary workers;
- prospective and current client contacts;
- supplier and business partner contacts;
- individuals who attend our events or engage with our professional communities;
- referees for associates or employees; and
- other individuals with whom we have a legitimate business
We collect personal information where reasonably necessary to carry out our business activities and provide our services.
Information you give to us, or that we collect about you
We may collect information that you provide to us directly, including information provided:
- through our website;
- when you submit a CV or professional profile;
- when you register with us or through a compliance or onboarding system;
- by telephone, email, social media or other correspondence;
- when you enquire about or provide services;
- when you attend an event, meetup or conference;
- when you participate in surveys, discussions or other professional activities; or
- when you enter into or are being considered for a business or contractual relationship with
Depending on our relationship with you, the information we collect may include:
- your name;
- home or business address;
- personal or business email address;
- telephone number;
- employment or professional history;
- curriculum vitae;
- professional qualifications and experience;
- professional profiles available in the public domain, such as LinkedIn;
- photographs where relevant;
- information required to verify your identity;
- right to work information;
- references;
- screening, vetting and compliance information;
- security clearance information where relevant;
- financial and payment information where you or your organisation provides services to us;
- company and professional contact details;
- information relating to contracts, assignments, engagements or services; and
- other information reasonably necessary for our business relationship with
Where we need to process special category personal data or information relating to criminal convictions or offences, we will only do so where permitted by law and where an appropriate condition for processing applies.
Information we collect when you visit our website
When you visit our website, certain technical information may be collected automatically. This may include:
- your Internet Protocol (IP) address;
- browser type and version;
- device and operating system information;
- information about how you interact with our website;
- pages visited and time spent on those pages;
- referral information;
- website performance and error information; and
- other technical information generated through cookies or similar
We may use third-party services and technologies in connection with our website which process information on our behalf or for their own stated purposes.
Further information about our use of cookies and similar technologies is available in our Cookie Notice.
Information we obtain from other sources
We may obtain personal information about you from other sources, including:
- LinkedIn and other professional networking sites;
- corporate websites;
- job boards and online CV databases;
- recruitment or professional service providers;
- business contacts;
- personal recommendations and referrals;
- clients and suppliers;
- events, meetups and conferences;
- screening and vetting providers;
- credit reference agencies where appropriate;
- publicly available sources; and
- other organisations where there is a lawful basis for sharing information with
Where we obtain your personal data from a source other than you, we will provide you with the privacy information required by applicable data protection law within the required period, unless an exemption applies or you already have that information.
Purposes of processing and our lawful bases
We may process personal information for the following purposes:
- to communicate with you;
- to respond to enquiries;
- to assess whether an individual or organisation may be suitable to provide or receive services;
- to introduce or propose independent professionals or other individuals to clients where appropriate;
- to manage consultancy engagements and delivery services;
- to negotiate, enter into and administer contracts;
- to manage onboarding, screening, vetting and compliance requirements;
- to verify identity, qualifications, experience and eligibility to work;
- to administer payments and financial arrangements;
- to comply with tax, accounting, audit and regulatory obligations;
- to manage client, associate, supplier and partner relationships;
- to maintain business records;
- to operate, secure and improve our systems and website;
- to manage events, training and professional communities;
- to communicate relevant business opportunities, services or events;
- to protect our business, systems, staff, clients, associates and other stakeholders;
- to prevent and detect fraud or other unlawful activity; and
- to establish, exercise or defend legal
Depending on the circumstances, we rely on one or more of the following lawful bases.
Legitimate interests
We may process personal data where this is necessary for our legitimate interests or those of another organisation, provided those interests are not overridden by the rights and freedoms of the individual.
Our legitimate interests include:
- operating and developing our technology consultancy business;
- identifying and engaging suitably qualified professionals;
- delivering services to our clients;
- maintaining relationships with clients, associates, suppliers and business partners;
- maintaining appropriate business and professional records;
- protecting our systems, information and business interests;
- developing and improving our services;
- communicating relevant business and professional opportunities; and
- maintaining professional communities and
Where required, we assess whether our interests are proportionate and whether individuals would reasonably expect the processing to take place.
Contract
We process personal information where necessary to:
- take steps at your request before entering into a contract; or
- perform a contract to which you are a
This may include contracts with individuals, consultants, associates, suppliers, clients or other business contacts.
Legal obligation
We process personal information where necessary to comply with legal or regulatory obligations. This may include requirements relating to:
- taxation;
- financial record keeping;
- employment;
- immigration and right to work;
- fraud prevention;
- screening or regulatory obligations; and
- responding to lawful requests from courts, regulators or public
Consent
We will rely on consent where consent is the appropriate lawful basis for a particular processing activity.
Where we rely on consent, we will make clear what you are consenting to and you may withdraw that consent at any time.
Withdrawal of consent does not affect the lawfulnessof processing carried out before consent was withdrawn.
We may also seek your agreement before taking particular operational steps, such as sharing your professional profile or CV with a specific client, even where the underlying processing is carried out under another lawful basis.
Other uses of personal information
We may also use personal information:
- to notify you of changes to our services;
- to administer our website and business systems;
- for troubleshooting, testing, research, analysis and statistical purposes;
- to maintain the security of our website and systems;
- to improve the content and functionality of our services;
- to measure the effectiveness of our communications and marketing where applicable; and
- to provide information about services, opportunities or events which may reasonably be of interest to
Where direct marketing rules require consent, we will obtain consent before sending the communication. You may object to direct marketing at any time.
Automated decision-making
We do not currently make decisions about individuals which have legal or similarly significant effects solely by automated means.
We may use technology to search, organise or identify information using criteria determined by people, but material decisions are subject to human involvement.
If our use of automated decision-making changes, we will update this notice and comply with the safeguards required by applicable data protection law.
Cookies
Our website uses cookies and similar technologies.
Some cookies are necessary for the operation and security of the website. Others may be used for analytics, functionality or other purposes.
Where consent is required by law, we will obtain consent before placing or using the relevant cookies or technologies.
Further information is available in our Cookie Notice.
Sharing your personal information
We only share personal information where there is a legitimate business need or other lawful basis for doing so.
Depending on the circumstances, we may share personal information with:
- clients;
- associates and independent professionals;
- suppliers and professional service providers;
- companies providing technology, hosting, CRM or business systems;
- screening and vetting providers;
- compliance providers;
- payment and financial service providers;
- accountants, auditors, insurers, brokers and professional advisers;
- event and communications providers;
- analytics and website service providers;
- companies within our corporate group, where applicable;
- public authorities, regulators or law enforcement bodies where required by law; and
- other third parties where reasonably necessary to perform a contract, comply with a legal obligation or protect our legitimate
Where we appoint an organisation to process personal information on our behalf, we require appropriate contractual and security arrangements to protect that information.
We may also disclose personal information:
- where required to comply with a legal obligation;
- to establish, exercise or defend legal rights;
- to protect the rights, property or safety of esynergy, our staff, clients, associates, suppliers or others;
- in connection with the prevention or detection of fraud or other unlawful activity; or
- in connection with a proposed sale, purchase, restructuring or transfer of all or part of our business or
International transfers of personal information
Some of the organisations and technology providers we use may process or store personal information outside the United Kingdom.
Where personal information is transferred outside the UK and the transfer is subject to UK data protection restrictions, we will ensure that an appropriate lawful transfer mechanism is in place.
Depending on the destination and circumstances, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- another recognised appropriate safeguard; or
- an applicable statutory exception where its use is
Whererequired, we will also carry out an appropriateassessment of theprotection availablefor thetransferred information.
Security and storage of personal information
We use appropriate technical and organisational measures designed to protect personal information against:
- unauthorised or unlawful access;
- alteration;
- disclosure;
- accidental loss;
- destruction; or
Personal information may be stored within secure business systems operated by esynergy or by authorised third-party service providers.
Access to personal information is restricted according to business need and appropriate access controls are used.
Where passwords or other credentials are provided to access our systems or portals, users are responsible for keeping those credentials confidential.
While no method of electronic transmission or storage can be guaranteed to be completely secure, we maintain security measures designed to manage the risks associated with the personal information we process.
Retention of personal information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, regulatory, contractual and business requirements.
The appropriate retention period depends on matters including:
- the nature and sensitivity of the information;
- the purpose for which it is held;
- whether a contractual or professional relationship exists or has existed;
- legal, regulatory, tax and accounting requirements;
- limitation periods relevant to potential legal claims;
- whether the information remains accurate and relevant; and
- our legitimate business
Different categories of personal information may therefore be retained for different periods.
Financial and contractual records
Where payments have been made or received, or where records form part of our financial, tax, contractual or audit records, relevant information will generally be retained for up to seven years or for such longer period as may be required by law or necessary in connection with legal claims.
Thisdoes not mean that every item of personal information relating to an individual will necessarily be retained for the same period.
Information which is no longer required will be deleted, anonymised or otherwise securely disposed of where appropriate.
Professional and associate information
Where we hold information relating to prospective associates, consultants or other professionals, we may retain that information for a reasonable period where we have a legitimate business reason to do so.
Where we rely solely on consent to retain information for future opportunities or services, we will review that consent and the continuing need to retain the information at appropriate intervals.
Where there has been no meaningful interaction or continuing reason to retain information, we will periodically review it and delete or anonymise it where appropriate.
Records following deletion or suppression requests
Where an individual asks us to delete their personal information, we may retain limited information where necessary to:
- record that the deletion request was made;
- ensure that we do not inadvertently re-add the individual to our systems;
- comply with a legal obligation; or
- establish, exercise or defend legal
Where appropriate, such information may be pseudonymised or placed on a suppression record.
Accuracy of your information
We take reasonable steps to ensure that personal information is accurate and kept up to date where necessary.
You can help us by informing us if your contact details or other relevant personal information change. You may request correction of inaccurate or incomplete information at any time by contacting: gdpr@esynergy.co.uk
Your rights
Subject to the conditions and exemptions set out in applicable data protection law, you may have the right to:
- request access to the personal information we hold about you;
- request correction of inaccurate or incomplete personal information;
- request erasure of your personal information where there is no continuing lawful reason for us to process it;
- object to processing based on legitimate interests in certain circumstances;
- object to direct marketing at any time;
- request restriction of processing in certain circumstances;
- request portability of certain personal information in a structured, commonly used and machine-readable format;
- withdraw consent at any time where we rely on consent;
- raise concerns about automated decision-making, where applicable; and
- make a complaint about our handling of your personal These rights are not absolute and may not apply in every circumstance.
For example, we may be required to retain certain information despite a request for deletion where we have a legal obligation or other lawful reason to retain it.
Requests to exercise your data protection rights should be sent to:
We may need to verify your identity before acting on a request.
Data Subject Access Requests
You have the right to request access to personal information that esynergy holds about you.
A Data Subject Access Request (“DSAR”) should be submitted to:
We will respond in accordance with the timescales and requirements set out in applicable data protection legislation.
Complaints about our use of personal information
If you believe that we have not handled your personal information appropriately or have not complied with data protection law, you may raise a complaint with us.
Complaints should be sent to:
We will:
- provide a clear route for you to raise your complaint;
- acknowledge receipt of a data protection complaint within 30 days;
- investigate the complaint appropriately; and
- notify you of the outcome without unjustifiable or excessive
We will keep an appropriate record of complaints and how they have been handled.
You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office (“ICO”).
Further information about the ICO and how to make a complaint is available at:
Links to other websites
Our website may contain links to websites operated by third parties.
Those organisations are responsible for their own privacy practices and privacy notices.
We do not control those websites and recommend that you review the relevant privacy information before providing personal information to them.
Changes to this Data Privacy and Retention Policy
We review this policy regularly and may update it from time to time to reflect:
- changes to our business activities;
- changes in the way we process personal information;
- changes to the systems or services we use;
- legal or regulatory developments; or
- changes to regulatory
The latest version of this policy will be made available on our website or otherwise provided where appropriate.
Where a change materially affects the way we use personal information, we will take reasonable steps to bring that change to the attention of affected individuals where required.
Contact
For questions about this policy, the way esynergy processes personal information, requests to exercise your data protection rights or data protection complaints, please contact:
Data Protection Contact
Head of Contracts and Compliance esynergy Solutions Limited
Email: gdpr@esynergy.co.uk