Melode Privacy Statement

Melode – Privacy Policy
Synerge Limited
Last updated: 1st July 2026 | Version 1.2
1. IntroductionSynerge Limited ("we", "us", or "our") operates the Melode mobile application (the "App"). This Privacy Policy explains how we collect, use, store, and protect personal data when you use our App, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.This App is a business-to-business (B2B) workplace tool. Access is restricted to individuals employed by, or contracted with, organisations that have a valid licence agreement with us ("Client Organisations"). The App cannot be meaningfully used without an access key provided by your employer or contracting organisation.If you have any questions about this Privacy Policy, please contact us using the details in Section 14.2. Data ControllerThe data controller responsible for your personal data is:Synerge Limited
Royton Medical Centre, Chapel Street, Greater Manchester, OL2 5QL
United Kingdom
Company Registration Number: 14092348
ICO Registration Number: ZB735368
Email: [email protected]
Website: https://melode.uk
Please note that your employer or contracting organisation may also act as a data controller in respect of certain processing activities. We encourage you to review your employer's own privacy policy.3. Personal Data We CollectWe collect and process the following categories of personal data:3.1 Account and Identity Data
Full name
Work email address
Encrypted password (we do not store passwords in plain text)
Employee or contractor identifier (as provided by your organisation)
3.2 Employment and Scheduling Data
Shift assignments and rota information
Availability and leave requests
Training records and completion status
Compliance documentation and acknowledgements
3.3 Technical and Usage Data
Device type, operating system, and unique device identifiers
IP address and approximate location (country/region level)
App version and usage logs
Crash reports and diagnostic data
We do not collect special category data (such as health, biometric, or ethnicity data) unless specifically required and agreed with your Client Organisation, in which case a separate data processing agreement will govern that processing.4. Lawful Basis for ProcessingWe process your personal data under the following lawful bases as defined by UK GDPR Article 6:Contractual necessity (Art. 6(1)(b)): Processing your account data, shift records, and access credentials is necessary to provide the App services.
Legitimate interests (Art. 6(1)(f)): Processing technical and usage data to maintain App security, prevent fraud, and improve service performance.
Legal obligation (Art. 6(1)(c)): Retaining certain records where required by applicable UK law or regulation.
Consent (Art. 6(1)(a)): Where we rely on consent (e.g. optional notifications), you may withdraw consent at any time without affecting prior processing.
5. How We Use Your Personal DataWe use your personal data to:Create and manage your App account and authenticate your identity
Display your shift rota, training schedule, and compliance requirements
Facilitate communication between you and your employer regarding scheduling
Allow your employer to manage workforce planning and compliance reporting
Ensure the security and integrity of the App and its infrastructure
Diagnose technical issues and improve App performance
Comply with legal and regulatory obligations
Notify you of changes to shifts, training, or compliance deadlines (subject to your preferences)
6. Access Control and AuthenticationThe App is not a publicly accessible service. Although the App can be downloaded from the Google Play Store, it is entirely non-functional without a valid access key issued by your Client Organisation. We do not create user accounts on an open self-registration basis.Your employer or contracting organisation is responsible for issuing and revoking access keys. When your employment or engagement ends, your Client Organisation is responsible for notifying us so that access can be revoked promptly.7. How We Share Your Personal DataWe do not sell your personal data. We may share it in the following circumstances:Your Client Organisation: Your employer or contracting organisation has access to your scheduling, training, and compliance data as part of the service. They are an independent data controller for these purposes.
Hosting and infrastructure providers: We use trusted third-party cloud service providers to host the App and its data. These providers act as data processors under contract and are required to maintain appropriate security measures.
Analytics and crash reporting tools: We may use tools such as Firebase or similar services to collect anonymised usage and diagnostic data.
Legal requirements: We may disclose data where required by law, court order, or regulatory authority in the United Kingdom.
8. International Data TransfersAll personal data is stored and processed on servers located within the United Kingdom. We do not routinely transfer personal data outside the UK. Where any third-party service provider processes data outside the UK, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements (IDTAs) or adequacy decisions.9. Data RetentionWe retain your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy or as required by law:Account data: Retained for the duration of your active access, plus 6 months following account closure.
Shift and scheduling records: Retained for 6 years in line with employment record-keeping requirements.
Training and compliance records: Retained for 6 years or as required by relevant sector regulations.
Technical logs: Retained for up to 6 months for security and diagnostic purposes.
On expiry of the retention period, data is securely deleted or anonymised.10. Data SecurityWe implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:Encrypted storage of passwords using industry-standard hashing
TLS/HTTPS encryption for all data in transit
Access controls limiting who within our organisation can access personal data
Regular security reviews and vulnerability assessments
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform affected individuals without undue delay, in accordance with UK GDPR Articles 33 and 34.11. Your Rights Under UK GDPRYou have the following rights in relation to your personal data:Right of access: Request a copy of the personal data we hold about you (Subject Access Request).
Right to rectification: Request correction of inaccurate or incomplete data.
Right to erasure: Request deletion of your data where there is no compelling reason for us to continue processing it.
Right to restrict processing: Request that we limit how we use your data in certain circumstances.
Right to data portability: Receive your data in a structured, commonly used, machine-readable format.
Right to object: Object to processing based on legitimate interests.
Right to withdraw consent: Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month.If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.12. Children's DataThe App is intended solely for use by adults in a professional or employment context. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has inadvertently provided data through the App, please contact us immediately at [email protected].13. Changes to This Privacy PolicyWe may update this Privacy Policy from time to time to reflect changes in the law, our services, or operational practices. We will notify you of significant changes via the App or by email. The "Last updated" date at the top of this document indicates when the most recent revision was made.14. Contact UsFor any questions, concerns, or rights requests relating to this Privacy Policy or our data practices, please contact us:Email: [email protected]
Post: Synerge Limited, Royton Medical Centre, Chapel Street, Greater Manchester, OL2 5QL
Website: https://melode.uk