Privacy Notice

How SYNKii uses personal information

This Privacy Notice explains what Onlive Productions Limited collects, why it is used, who receives it, how long it is kept and the choices and rights available to teachers, adult learners, parents, guardians and children.

1. Who is responsible for the data?

SYNKii as controller

We decide why and how personal information is used for account registration, subscriptions, security, support, marketplace operation, public profiles, verification, moderation, safety reports, product analytics, legal compliance and our own communications.

SYNKii as processor

For some teacher- or school-managed student records, the teacher, studio or school may decide the purpose and SYNKii may process that information on their instructions. Where required, the organisation and SYNKii must enter a data processing agreement describing instructions, security, subprocessors, rights support, deletion and audit terms.

Role depends on the activity. The same organisation can be controller for one purpose and processor for another. A teacher cannot use their “controller” status to access another teacher’s workspace or override a learner’s rights.

2. Information, purposes and lawful bases

ActivityInformationPurposeMain lawful basis
Accounts and identityName, contact details, credentials, role, age band, guardian relationship, organisation and login/security data.Create and secure accounts, provide role-based access, prevent misuse and support users.Contract; legitimate interests in security and service administration; legal obligation where applicable.
Teacher studio and learningStudent profiles, schedules, notes, tasks, resources, progress, attendance, repertoire, messages and relationship permissions.Deliver studio management, teaching and learning features.Contract; teacher or school instructions where we act as processor; legitimate interests with safeguards.
Subscriptions and invoicesPlan, billing contact, payment status, invoices, tax and transaction references. Payment card data is normally handled by a payment provider.Take subscription payments, issue records, manage renewal and meet accounting duties.Contract; legal obligation; legitimate interests in fraud prevention and debt administration.
MarketplacePublic profile, rates, instruments, availability, location area, enquiries, response data, reviews, rankings and moderation history.Help users discover teachers, operate search, prevent fraud and maintain marketplace quality.Contract; legitimate interests; consent for optional public fields where appropriate.
VerificationEmail/phone status, identity provider result, qualification evidence, DBS or equivalent evidence, review metadata and appeals.Provide precise trust signals, prevent impersonation and investigate false claims.Contract and legitimate interests; additional Article 9 or DPA 2018 Schedule 1 conditions where biometric, special-category or criminal-offence data is processed.
Classroom, recordings and AIAudio, video, screen share, MIDI, transcript, prompts, notes, summaries, settings and technical metadata.Provide lessons, recordings, transcription, summaries, practice tools, support and security.Contract; consent where required for optional recording or biometric features; legitimate interests subject to participant and child safeguards.
Safety, moderation and complaintsReports, messages, content references, evidence, account actions, correspondence and investigation decisions.Protect users, investigate misconduct, handle complaints, preserve evidence and comply with law.Legal obligation; legitimate interests; vital interests in emergencies; legal claims and other applicable conditions.
Product and security analyticsDevice, browser, IP, events, diagnostics, crash data, feature use and cookie choices.Secure, debug and improve the service and measure feature performance.Legitimate interests for essential analytics and security; consent for non-essential cookies or similar technologies.
MarketingEmail address, preferences, engagement and source.Send requested updates and relevant product communications.Consent where required; legitimate interests for limited business-to-business communications, with an opt-out.

3. Where information comes from

From you

Account forms, profiles, uploads, messages, lesson activity, support, reports, settings and payments.

From connected users

A teacher, student, parent, guardian or organisation may provide invitation, relationship, lesson, invoice or safeguarding information about another person where authorised.

From providers and public sources

Payment, identity, communications and security providers may return status information. We may check credential issuers, professional registers or public business information where relevant and lawful.

4. Children’s information and age-appropriate design

High privacy is the default. SYNKii is likely to be used by people under 18, so child design and data use prioritises the child’s best interests, collects only what is needed and explains settings in age-appropriate language.

Guardian-managed onboarding

A teacher may invite a learner, but a child account is activated only after the required parent, guardian or authorised-organisation approval. Adults manage legal acceptance and sensitive settings.

Restricted visibility and discovery

Children do not receive unrestricted teacher search, public profiles, billing, targeted advertising, public location sharing or guardian-only controls. Teacher communications are guardian-visible by default.

No default model training

Private child content, recordings, transcripts and relationship data are not used to train general-purpose AI models by default. Optional adult choices do not silently apply to child accounts.

We provide child-friendly explanations and an easy way to ask for help or report a concern. A child’s rights belong to the child; a guardian may exercise them where legally authorised and appropriate to the child’s maturity and interests.

5. Recordings, transcripts and AI processing

Before recording

The product displays a clear recording indicator, identifies the person who started it and provides settings for consent and access. Teachers and account owners must obtain permissions required for participants and children. Covert recording is prohibited.

Access

Recordings and transcripts are available only to permitted participants and relationship roles. Downloaded copies remain subject to privacy, copyright and safeguarding obligations.

AI providers

Approved providers may receive the minimum input needed to provide transcription, summarisation or related features under contract. We require providers to protect the information and not use private SYNKii content for their own general-purpose model training unless a separate, clearly disclosed arrangement and valid choice applies.

Automated decisions

AI may assist with notes, moderation signals, fraud detection and workflow prioritisation. SYNKii does not make a solely automated decision with legal or similarly significant effects without the safeguards and information required by law.

6. Who receives information

Connected users

Teachers, students, parents, guardians and organisation administrators receive information only according to accepted relationships, account roles and sharing settings.

Service providers

Providers may support hosting, storage, communications, video, AI, identity checks, payments, analytics, support and security. They receive only what is needed and are bound by data-protection and confidentiality terms.

Authorities and transactions

We may share information where required by law, to protect someone, investigate fraud or illegal content, establish legal claims, or in a business sale or reorganisation subject to appropriate safeguards.

Subprocessor register. A current named list of providers, service purposes, processing locations and transfer mechanisms is available from support@synkii.com. We notify controller customers of material changes where contractually required.

International transfers

Where personal information is transferred outside the UK, we use a lawful transfer mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard clauses or another permitted safeguard, together with any required transfer risk assessment and supplementary measures.

7. Retention schedule

We keep information for the shortest period reasonably needed for the stated purpose, taking account of account choices, legal claims, tax, safety, backup and the rights of connected users.

Account and contract

While the account is active, then normally up to six years after closure where needed for contract, consumer, tax or legal-claim records. Optional profile and learning data is deleted or anonymised sooner where it is no longer needed.

Invoices and payments

Normally six years after the relevant financial period or longer only where law, audit or an active dispute requires it.

Recordings and transcripts

Until deleted by an authorised user, the selected storage period expires or the account closes. Unsaved transient processing copies are removed promptly; deleted data may remain in encrypted backups for up to 90 days.

Lesson and relationship records

While the relationship or account is active, then according to user export and archive settings and any controller instructions. Archived records become read-only where appropriate and are not kept indefinitely without a purpose.

Verification

Full identity, qualification or DBS evidence is deleted promptly after review, normally within 30 days, unless a documented legal, fraud or appeal reason requires temporary retention. Minimal verification metadata may be kept while the badge is active and for up to three years afterwards for audit and disputes.

Safety and complaints

Normally up to six years after closure of the matter, or longer where needed to protect a child, comply with law, support an authority or manage continuing risk. Access is strictly limited.

8. Your rights and choices

Data rights

  • Access your personal information.
  • Correct inaccurate or incomplete information.
  • Ask for deletion where applicable.
  • Restrict processing in certain circumstances.
  • Object to processing based on legitimate interests or direct marketing.
  • Receive portable information where applicable.
  • Withdraw consent without affecting earlier lawful use.
  • Ask for human review of qualifying automated decisions.

How to make a request

Email support@synkii.com with “Privacy rights request” in the subject. We may ask for proportionate identity or authority evidence. We normally respond within one month, subject to lawful extensions.

A teacher or school acting as controller may need to handle a request about the records they control, with SYNKii providing processor assistance.

Data-protection complaints

Email support@synkii.com with “Data protection complaint”. We provide a clear route, acknowledge the complaint within 30 days, investigate without undue delay, keep you informed where appropriate and communicate the outcome.

You may also complain to the UK Information Commissioner’s Office. Contacting us first may allow the issue to be resolved more quickly, but it is not a condition of using your regulatory rights.

9. Cookies, security and changes

Cookies and similar technologies

Essential technologies support login, security, preferences and core functionality. This marketing site does not currently use non-essential analytics or marketing cookies. If these are introduced, applicable consent controls will be provided before they are enabled, with a way to withdraw consent.

Security and changes

We use proportionate technical and organisational measures such as encryption in transit, access controls, logging, backups, vulnerability management and incident response. No service is perfectly secure. We will update this notice when processing materially changes and provide additional notice where required.

Privacy request or complaint?

Use the reporting page to request access, correction, deletion or to raise a data-protection complaint.