Privacy Policy
Who We Are & What This Covers
This Privacy Policy is published by Synexian Labs Private Limited ("Synexian", "we", "us"), a company incorporated in India with its registered office at 703, 7th Floor, Palm Court, Mehrauli Gurgaon Road, Sector 16, Industrial Estate, Gurgaon, Haryana, 122007. It explains how we collect, use, share, store, and protect personal data through synexian.com and through direct contact with us.
We publish it under the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and we follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, under which Synexian is the Data Fiduciary for this data. Where the EU or UK General Data Protection Regulation applies to you, Synexian is the controller. Data we process inside client engagements is governed by our Data Processing Terms and the signed agreement for that engagement.
What We Collect and Why
Every item of personal data we collect, what we use it for, and when:
| Personal data | Purpose | When we collect it |
|---|---|---|
| Your name, email address, message, and anything else you choose to write | Replying to your enquiry and preparing proposals | When you send us a message or email us |
| Your name, email address, chosen time, and notes | Scheduling and holding the call you booked | When you book through the "Connect" pop-up, served by Google Calendar |
| Your CV, contact details, and application notes | Assessing your application for a role | When you apply for a job |
| IP address, page requested, date and time, browser user agent, and referring page | Operating and securing the website, blocking abusive traffic, and investigating incidents | Automatically, on every visit |
| Browser and device signals | Telling people from bots before a contact message is sent (Cloudflare Turnstile) | When you start using the contact form |
| Pages viewed, scroll depth, button clicks, FAQ opens, whether the contact form was started or sent (never what you wrote), and cookie identifiers | Understanding which content is useful, and measuring whether our advertising leads to enquiries | Only after you choose "Accept all" in the cookie banner |
| Your cookie choice and when you made it | Remembering that choice | When you use the cookie banner; stored in your own browser |
The contact form does not submit anything to our servers: its "send" step opens your email application, and we receive only what you choose to send. Our fonts load from Google Fonts, which receives your IP address with each font request.
We do not ask for sensitive personal data such as passwords, financial information, health information, or biometric information. Please do not send it to us.
Consent and Legal Grounds
We collect analytics and advertising data only with your consent, given through the cookie banner. You can withdraw that consent at any time, as easily as you gave it, with Manage cookie preferences on our Cookie Policy. Withdrawal does not affect processing that happened before it.
Messages, bookings, and job applications are data you give us voluntarily for a specified purpose, and we use them only for that purpose. We keep technical logs because the law requires it and to keep the website secure.
If the GDPR applies to you, our legal bases are your consent for analytics and advertising, the steps you ask us to take before a contract for replies, bookings, and proposals, our legitimate interest in running a secure website, and our legal obligations.
Who We Share It With
We do not sell personal data, and we do not use your personal data to train AI models. We share it only with service providers that process it on our behalf, under contracts requiring them to follow our instructions and protect it:
- Google: website hosting and logs (Google Cloud), business email (Google Workspace), call booking (Google Calendar), fonts (Google Fonts), Google Tag Manager, and, with consent, Google Ads.
- GoDaddy: business email hosting.
- Cloudflare: domain name service and the Turnstile security check on the contact form.
- Microsoft: Clarity analytics, with consent.
- Meta, LinkedIn, and X: advertising measurement, with consent.
Some of these providers store or process data outside India, for example in the United States. Indian law permits this transfer except to countries the Central Government restricts, and for GDPR data we rely on safeguards such as standard contractual clauses. We may also disclose personal data to government agencies or courts where Indian law requires it, including to CERT-In.
How Long We Keep It
- Messages, bookings, and proposals: while our conversation or engagement is active, then for as long as Indian company and tax law require us to keep business records, which can be up to eight years.
- Job applications: twelve months after the role is filled, unless you ask us to delete yours sooner or agree to be considered for future roles.
- Server and security logs: one year, as required to detect and investigate security incidents under CERT-In's directions and the DPDP Rules.
- Cookie data: your cookie choice stays in your browser until you change it or clear your browser storage. Cookie lifetimes are in the Cookie Policy.
When the purpose is served, or you withdraw consent, we erase the personal data unless a law requires us to keep it longer.
How We Protect It
We maintain reasonable security practices and procedures, including encrypted connections for the whole website, a web application firewall and rate limiting in front of it, least-privilege access to systems and inboxes protected by multi-factor authentication, and access logs that let us detect and investigate misuse. We apply the same security discipline to our own systems that we build into client systems.
If Something Goes Wrong
If a personal data breach occurs, we act to contain it and inform affected people without delay, explaining what happened, the likely consequences, and what they can do. We report cyber incidents to CERT-In within six hours of becoming aware of them, and we notify the Data Protection Board of India within seventy-two hours as the DPDP Rules require. Where the GDPR applies, we notify the relevant supervisory authority within its deadlines.
Your Rights
Under Indian law you have the right to:
- Access a summary of the personal data we hold about you, how we process it, and who we have shared it with.
- Correct, complete, or update personal data that is inaccurate or incomplete, and review what you have given us.
- Erase personal data we no longer need to keep.
- Withdraw consent at any time.
- Nominate another person to exercise your rights if you die or become unable to.
- Raise a grievance with our Grievance Officer, and then complain to the Data Protection Board of India.
If the GDPR applies to you, you also have rights to data portability, to object to or restrict processing, and to complain to your local data protection authority.
To make a request, email admin@synexian.com with the subject "Privacy request", from the email address you used with us, and tell us which right you want to exercise. We may ask for details to confirm your identity. We respond within one month. Please give us accurate information and use these channels in good faith.
Grievance Officer
Questions, concerns, or complaints about how we handle personal data can be sent to our Grievance Officer:
Grievance Officer, Synexian Labs Private Limited
703, 7th Floor, Palm Court, Mehrauli Gurgaon Road, Sector 16, Industrial Estate, Gurgaon, Haryana, 122007
Email: admin@synexian.com
We acknowledge every grievance and resolve it within one month of receiving it. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
Children
This website and our services are intended for businesses and adults. Under Indian law a child is anyone under eighteen, and we do not knowingly collect personal data from a child without verifiable consent from a parent or lawful guardian. If you believe a child has sent us personal data, contact our Grievance Officer and we will delete it.
Language, Changes & Contact
This policy is written in English. On request, we will provide it in any language listed in the Eighth Schedule to the Constitution of India.
When this policy changes, the version and date at the top change with it, and where a change needs fresh consent we ask for it. Contact: Synexian Labs Private Limited, 703, 7th Floor, Palm Court, Mehrauli Gurgaon Road, Sector 16, Industrial Estate, Gurgaon, Haryana, 122007, admin@synexian.com.
Other Legal Documents
A Clause Unclear? Just Ask.
We would rather explain a term before you sign than argue about it after. Questions about this document get a plain answer from a human.