Synexian logo SYNEXIAN — LEGAL-02 ← All documents

Privacy Policy

Who We Are & What This Covers

This Privacy Policy is published by Synexian Labs Private Limited ("Synexian", "we", "us"), a company incorporated in India with its registered office at 703, 7th Floor, Palm Court, Mehrauli Gurgaon Road, Sector 16, Industrial Estate, Gurgaon, Haryana, 122007. It explains how we collect, use, share, store, and protect personal data through synexian.com and through direct contact with us.

We publish it under the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and we follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, under which Synexian is the Data Fiduciary for this data. Where the EU or UK General Data Protection Regulation applies to you, Synexian is the controller. Data we process inside client engagements is governed by our Data Processing Terms and the signed agreement for that engagement.

In plain wordsThis page covers the website and your conversations with us, under Indian law first. Client project data is governed by its own contract.

What We Collect and Why

Every item of personal data we collect, what we use it for, and when:

Personal dataPurposeWhen we collect it
Your name, email address, message, and anything else you choose to writeReplying to your enquiry and preparing proposalsWhen you send us a message or email us
Your name, email address, chosen time, and notesScheduling and holding the call you bookedWhen you book through the "Connect" pop-up, served by Google Calendar
Your CV, contact details, and application notesAssessing your application for a roleWhen you apply for a job
IP address, page requested, date and time, browser user agent, and referring pageOperating and securing the website, blocking abusive traffic, and investigating incidentsAutomatically, on every visit
Browser and device signalsTelling people from bots before a contact message is sent (Cloudflare Turnstile)When you start using the contact form
Pages viewed, scroll depth, button clicks, FAQ opens, whether the contact form was started or sent (never what you wrote), and cookie identifiersUnderstanding which content is useful, and measuring whether our advertising leads to enquiriesOnly after you choose "Accept all" in the cookie banner
Your cookie choice and when you made itRemembering that choiceWhen you use the cookie banner; stored in your own browser

The contact form does not submit anything to our servers: its "send" step opens your email application, and we receive only what you choose to send. Our fonts load from Google Fonts, which receives your IP address with each font request.

We do not ask for sensitive personal data such as passwords, financial information, health information, or biometric information. Please do not send it to us.

In plain wordsEach row says what we get, why, and when. Analytics and advertising data only exist if you say yes.

Who We Share It With

We do not sell personal data, and we do not use your personal data to train AI models. We share it only with service providers that process it on our behalf, under contracts requiring them to follow our instructions and protect it:

  • Google: website hosting and logs (Google Cloud), business email (Google Workspace), call booking (Google Calendar), fonts (Google Fonts), Google Tag Manager, and, with consent, Google Ads.
  • GoDaddy: business email hosting.
  • Cloudflare: domain name service and the Turnstile security check on the contact form.
  • Microsoft: Clarity analytics, with consent.
  • Meta, LinkedIn, and X: advertising measurement, with consent.

Some of these providers store or process data outside India, for example in the United States. Indian law permits this transfer except to countries the Central Government restricts, and for GDPR data we rely on safeguards such as standard contractual clauses. We may also disclose personal data to government agencies or courts where Indian law requires it, including to CERT-In.

In plain wordsA short list of well-known providers helps us host, email, book calls and, with your yes, measure. Nobody buys your data, and no model learns from it.

How Long We Keep It

  • Messages, bookings, and proposals: while our conversation or engagement is active, then for as long as Indian company and tax law require us to keep business records, which can be up to eight years.
  • Job applications: twelve months after the role is filled, unless you ask us to delete yours sooner or agree to be considered for future roles.
  • Server and security logs: one year, as required to detect and investigate security incidents under CERT-In's directions and the DPDP Rules.
  • Cookie data: your cookie choice stays in your browser until you change it or clear your browser storage. Cookie lifetimes are in the Cookie Policy.

When the purpose is served, or you withdraw consent, we erase the personal data unless a law requires us to keep it longer.

In plain wordsEnquiries stay while we work together and as long as business law says. CVs expire after a year. Security logs are kept one year because the law asks for it.

How We Protect It

We maintain reasonable security practices and procedures, including encrypted connections for the whole website, a web application firewall and rate limiting in front of it, least-privilege access to systems and inboxes protected by multi-factor authentication, and access logs that let us detect and investigate misuse. We apply the same security discipline to our own systems that we build into client systems.

In plain wordsThe security we sell is the security we use.

If Something Goes Wrong

If a personal data breach occurs, we act to contain it and inform affected people without delay, explaining what happened, the likely consequences, and what they can do. We report cyber incidents to CERT-In within six hours of becoming aware of them, and we notify the Data Protection Board of India within seventy-two hours as the DPDP Rules require. Where the GDPR applies, we notify the relevant supervisory authority within its deadlines.

In plain wordsIf your data is affected, you hear it from us quickly and with facts, and so do the authorities.

Your Rights

Under Indian law you have the right to:

  • Access a summary of the personal data we hold about you, how we process it, and who we have shared it with.
  • Correct, complete, or update personal data that is inaccurate or incomplete, and review what you have given us.
  • Erase personal data we no longer need to keep.
  • Withdraw consent at any time.
  • Nominate another person to exercise your rights if you die or become unable to.
  • Raise a grievance with our Grievance Officer, and then complain to the Data Protection Board of India.

If the GDPR applies to you, you also have rights to data portability, to object to or restrict processing, and to complain to your local data protection authority.

To make a request, email admin@synexian.com with the subject "Privacy request", from the email address you used with us, and tell us which right you want to exercise. We may ask for details to confirm your identity. We respond within one month. Please give us accurate information and use these channels in good faith.

In plain wordsSee it, fix it, delete it, withdraw it, or name someone to act for you. One email starts it, and you get an answer within a month.

Grievance Officer

Questions, concerns, or complaints about how we handle personal data can be sent to our Grievance Officer:

Grievance Officer, Synexian Labs Private Limited
703, 7th Floor, Palm Court, Mehrauli Gurgaon Road, Sector 16, Industrial Estate, Gurgaon, Haryana, 122007
Email: admin@synexian.com

We acknowledge every grievance and resolve it within one month of receiving it. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.

In plain wordsA named contact at a real address answers privacy complaints within a month.

Children

This website and our services are intended for businesses and adults. Under Indian law a child is anyone under eighteen, and we do not knowingly collect personal data from a child without verifiable consent from a parent or lawful guardian. If you believe a child has sent us personal data, contact our Grievance Officer and we will delete it.

In plain wordsThis site is for businesses and adults. If a child's data reaches us by mistake, we delete it.

Language, Changes & Contact

This policy is written in English. On request, we will provide it in any language listed in the Eighth Schedule to the Constitution of India.

When this policy changes, the version and date at the top change with it, and where a change needs fresh consent we ask for it. Contact: Synexian Labs Private Limited, 703, 7th Floor, Palm Court, Mehrauli Gurgaon Road, Sector 16, Industrial Estate, Gurgaon, Haryana, 122007, admin@synexian.com.

In plain wordsNeed this in another Indian language? Ask. The date at the top is honest, and a person answers every question.
The Rest of the Drawer

Other Legal Documents

A Clause Unclear? Just Ask.

We would rather explain a term before you sign than argue about it after. Questions about this document get a plain answer from a human.