Privacy Policy
How we collect, use, store, and protect your personal data. Your privacy matters to us — this policy explains your rights and our obligations under UK data protection law.
Last updated: 8 March 2026
How we collect, use, store, and protect your personal data. Your privacy matters to us — this policy explains your rights and our obligations under UK data protection law.
Last updated: 8 March 2026
SinonTech Ltd ("Company", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website (sinontech.co.uk), use our client portal, engage our managed IT services, or interact with us in any other way.
SinonTech Ltd is the data controller for the personal data described in this policy. We are registered in England and Wales.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We may collect and process the following categories of personal data:
When you contact us via our website, email, or phone, we may collect your name, email address, phone number, company name, and the content of your enquiry.
When you become a client, we collect your name, email address, company name, business address, phone number, and billing information necessary to provide our services and manage your account.
If you use our client portal (Lodge), we store your login credentials (username and securely hashed password), session data, and records of quotes, invoices, and product licences associated with your account.
We may collect technical information about your visits to our website, including your IP address, browser type and version, operating system, referral source, pages visited, and duration of visit. This data is collected through cookies and similar technologies as described in our Cookie Policy.
We use personal data for the following purposes:
We process personal data on the following legal bases under UK GDPR:
We do not sell, rent, or trade your personal data to any third party.
We may share your personal data with the following categories of recipients, only where necessary:
We do not transfer personal data outside the United Kingdom or European Economic Area (EEA) unless adequate safeguards are in place, such as Standard Contractual Clauses approved by the Information Commissioner's Office (ICO).
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
When personal data is no longer required, it is securely deleted or anonymised.
Under UK GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you (a "Subject Access Request").
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
You have the right to request that we delete your personal data, subject to legal retention requirements.
You have the right to request that we restrict the processing of your personal data in certain circumstances.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
To exercise any of these rights, please contact us at info@sinontech.co.uk. We will respond to your request within one month. If you have given consent for any specific processing, you may withdraw that consent at any time.
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it, including:
While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to continuous improvement of our security practices.
Our security software products (Umbra SIEM, SinonSentinel, SecureMinds AI, SinonForge, SinonStore, and SinonMeet) are designed to run entirely on infrastructure controlled by the Client.
When you deploy our Products on your own infrastructure, SinonTech does not process, access, or have any visibility of the data stored within those Products.
In this scenario, you (the Client) are the data controller for all data processed within the Products. SinonTech has no role as a data processor for self-hosted deployments unless you explicitly grant us access for support purposes, in which case a Data Processing Agreement will apply.
This is a core principle of our approach to data sovereignty: your data stays on your infrastructure, under your control, at all times.
Our Website, Services, and Products are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that data promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Any changes will be posted on this page with an updated "Last updated" date.
We encourage you to review this policy periodically. For significant changes, we may notify existing clients directly.
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a complaint about how we handle your data, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113
If you have any concerns about how we handle your personal data, we are here to help.
Phone: 0141 536 0433
Email: info@sinontech.co.uk