Your data. Your rights.
Our responsibility.
We handle your information with care. This policy explains what we collect, why, and exactly what you can do about it.
Last updated: 15 May 2026
1.Who We Are
ROISynth is a digital growth agency ("we", "us", "our") providing web design, SEO, paid advertising, AI automation, and related services to businesses worldwide. Our primary markets are the United States, United Kingdom, United Arab Emirates, and Canada.
For the purposes of data protection law, ROISynth acts as a data controller for the personal information collected through this website (roisynth.com). Contact us at hello@roisynth.com with any privacy enquiries.
2.What Information We Collect
We collect information in the following ways:
Information you provide directly:
Name, email address, phone number, and business details submitted through contact forms, booking tools (Calendly), or WhatsApp
Project briefs, requirements, or files shared as part of an enquiry or client engagement
Account information if you access our client portal
Information collected automatically:
Pages visited, time spent on site, and referring sources (via Google Analytics, when consent is granted)
Your IP address, browser type, device type, and operating system
Cookies and similar tracking technologies (see our Cookies section below)
Information from third parties:
If you connect a third-party account (such as Google Search Console) as part of a service engagement, we receive data you authorise us to access
3.How We Use Your Information
We use your personal information only for legitimate purposes:
- –To deliver our services — managing your project, communicating progress, and invoicing
- –To improve our website — understanding which pages are useful and where visitors drop off
- –To send relevant communications — we may email you about your project or, with your consent, about news and offers you can unsubscribe from at any time
- –To comply with legal obligations — such as tax records and fraud prevention
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
4.Our Legal Basis for Processing (GDPR)
If you are in the UK or European Economic Area, we rely on the following legal bases:
- –Legitimate interests — running and improving our business, fraud prevention, and direct marketing to existing clients
- –Consent — analytics cookies and any marketing emails where we have asked your permission
- –Legal obligation — keeping financial records as required by law
6.Who We Share Data With
We share personal data with the following categories of third-party service providers, only to the extent necessary:
- –Google — analytics (Google Analytics), advertising measurement (Google Ads), and workspace tools
- –Clerk — authentication for the client portal
- –Sanity — content management system for our blog and studio
- –Supabase — database infrastructure for the client portal
- –Resend — transactional email delivery
All processors are required to handle your data securely and in compliance with applicable law. We do not authorise them to use your data for their own purposes.
7.How Long We Keep Your Data
We keep personal data only as long as necessary:
- –Client project data — 7 years (to comply with financial record-keeping obligations in UK/US)
- –Analytics data — 14 months (Google Analytics default, subject to your consent)
- –Marketing preferences — until you unsubscribe or withdraw consent
You can request deletion of your data at any time (see Your Rights below).
8.Your Rights
Depending on your location, you have rights over your personal data:
- –Rectification — ask us to correct inaccurate data
- –Erasure — ask us to delete your data ("right to be forgotten")
- –Restriction — ask us to pause processing while a dispute is resolved
- –Portability — receive your data in a machine-readable format
- –Object — object to processing based on legitimate interests or for direct marketing
- –Withdraw consent — where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, email us at hello@roisynth.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (in the UK: the ICO at ico.org.uk; in the US: your state attorney general).
9.International Transfers
ROISynth serves clients globally. Some of the third-party processors listed above are based in the United States. Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place — including Standard Contractual Clauses or adequacy decisions — to protect your data to the same standard as within your jurisdiction.
10.Children's Privacy
Our website and services are not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11.Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the bottom of this page. Material changes will be notified to active clients by email.
Privacy questions?
If you have any questions about this policy or want to exercise your rights, email us directly. We respond within 30 days.
hello@roisynth.com