No production-data access
Build or test with synthetic, anonymised or client-prepared data, then let the client's authorised team deploy or approve the change.
Security & Data Protection
A small workflow build and an ongoing managed service do not need the same access. We agree the access model before work starts.
Working principles
Access should match the systems, permissions and time needed for the agreed work.
Where the platform allows it, we prefer named accounts so activity can be tied to a person.
We use the client's approved identity controls and MFA where the environment supports them.
Passwords, tokens and private keys should not be sent through public website forms or stored in normal project documents or source code.
Development, test and production have different risks. Production access is agreed before it is granted.
Important changes, testing and operating notes are recorded when the work requires it.
Access models
Build or test with synthetic, anonymised or client-prepared data, then let the client's authorised team deploy or approve the change.
Use a named, time-bounded account when live troubleshooting or configuration genuinely needs it.
For managed services, agree the systems, roles, privileged actions, escalation path and review process in advance.
Personal data
For the public website, Syntix is the controller for the inquiry and recruitment data described in the Privacy Notice.
For client work, Syntix may be a processor or subprocessor when it handles personal data on the client's instructions. The applicable agreement sets out what is processed, why, who can access it and what happens when the work ends.
International access
Cross-border access, transfer requirements and country-specific restrictions are covered on the International Delivery page.
Incident handling
We contain the issue, preserve useful evidence, tell the right client contact and follow the incident process agreed for the engagement. Contractual notification duties stay in the contract and the client's incident procedure.
Website infrastructure
The current Syntix website uses Cloudflare for delivery and security. Public inquiry records are stored in a dedicated Syntix company-website Supabase project whose current primary database region is Singapore. Email notifications may be sent through Resend if that feature is configured.
These website providers do not define the architecture or data location of a client environment.
Procurement or security review?