SYSTIQOApplied AI & Systems Lab

SYSTIQO Tech LabsPrivacy Policy

Effective date: 17 September 2026

This Privacy Policy explains how personal data is handled in connection with this website and our business relationships. SYSTIQO Tech Labs ("SYSTIQO", "we", "us" or "our") is an Applied AI & Systems Lab that researches, designs, and engineers intelligent systems, providing professional engineering and consulting services.

Introduction

We are committed to handling personal data lawfully, transparently and only to the extent necessary for our business. This Policy has been prepared having regard to the Digital Personal Data Protection Act, 2023 and the rules made under it, the Information Technology Act, 2000 and rules made thereunder, and, where they apply to a particular interaction, the principles of the EU General Data Protection Regulation and the UK General Data Protection Regulation.

References in this Policy to a "Data Principal" (or "data subject") mean the individual to whom personal data relates. References to a "Data Fiduciary" (or "controller") mean the entity that determines the purpose and means of processing.

This Policy describes our current practices. It does not create rights or obligations beyond those provided by applicable law or by a written agreement between you and SYSTIQO.

Scope

This Policy applies to personal data we handle as a Data Fiduciary, namely:

  • Personal data collected through this website, including our contact form and general enquiries.
  • Personal data exchanged in the course of business communications: email, telephone, WhatsApp and other messaging services, and online meeting platforms.
  • Personal data of prospective clients, client personnel, partners and prospective partners, suppliers and job applicants that we process for ordinary business administration.

This Policy does not apply to personal data that we process on behalf of, and under the documented instructions of, a client in the course of delivering services. In that role we act as a Data Processor (or "processor"), and such processing is governed by the agreement between SYSTIQO and that client, not by this Policy. Where a client is the Data Fiduciary, that client's own privacy notice governs the individuals concerned.

This Policy also does not apply to third-party websites or services that we link to. Their own privacy notices govern their handling of your data.

Information We Collect

We collect only information that is reasonably necessary for the purposes described in this Policy. We do not require you to create an account to use this website, and we do not operate public user accounts.

Personal information

  • Name.
  • Business email address.
  • Telephone number.
  • Company or organisation name.
  • Job title or role.
  • Country or region.

On our contact form, only your name, email address and a description of the problem are required. Everything else is optional.

Business information

  • The business problem you describe, what you want to improve, the outcome you are looking for, and the systems or technology you currently use.
  • Documents and other files you choose to send us by email or share during an engagement. This website does not accept file uploads.
  • Proposal requests, statements of work and related commercial correspondence.
  • Job applications, CVs and related correspondence you send us by email.
  • Records of meetings, calls and other communications with us.

Technical information

  • IP address and approximate location derived from it. The IP address of a contact form submission is also used to limit repeated submissions and to detect abuse.
  • Browser type and version, device type and operating system.
  • Form interaction signals, such as how long the contact form was open before it was sent, used only to detect automated spam.
  • Pages viewed, referring URL and interaction data, collected through Google Analytics only if you accept analytics cookies.
  • Server logs generated automatically when this website is accessed.

Please do not send us sensitive personal data, special category data, health data, financial account credentials, government identifiers or third-party personal data unless we have specifically asked for it and agreed how it will be handled. Where you provide personal data about other individuals, for example colleagues named in a project brief, you confirm that you are entitled to share it with us for the purposes described here.

How We Collect Information

  • Directly from you, when you complete our contact form, email or call us, message us on WhatsApp, apply for a role, enquire about our Partner Program, or speak with us on an online meeting platform.
  • Automatically, through server logs when you visit this website, and through cookies and similar technologies as described under Cookies below.
  • From the organisation you represent, where a colleague provides your business contact details in the context of an engagement or enquiry.
  • From publicly available or professional business sources, where we verify or supplement business contact details in a business-to-business context.

Where we rely on your consent, we will ask for it at the point of collection and you may withdraw it at any time as described under Your Rights.

How We Use Information

We use personal data for the following purposes:

  • To respond to enquiries, and to arrange and hold a first conversation about your problem.
  • To send you a one-off email confirming that we received your enquiry.
  • To screen enquiries for spam and abuse, including the automated screening described under AI & Confidential Information.
  • To scope, prepare, negotiate and administer engagements, including paid discovery work, statements of work and contracts.
  • To deliver and support the professional services we have been engaged to provide.
  • To communicate with you about an active or prospective engagement.
  • To assess job applications, and to evaluate and administer partner relationships.
  • To operate, secure, maintain and improve this website.
  • To understand, in aggregate, how visitors use our content, where you have accepted analytics cookies.
  • To maintain ordinary business, accounting and administrative records.
  • To establish, exercise or defend legal claims, and to comply with legal, regulatory and tax obligations.

Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent or, where available, on the basis of a legitimate use recognised under that Act. Where the EU or UK GDPR applies to a particular interaction, we rely on consent, on the necessity of processing for a contract or steps taken at your request prior to entering into one, on our legitimate interests in operating and securing our business, or on compliance with a legal obligation, as appropriate to the purpose.

We do not sell personal data, and sending us an enquiry does not add you to a marketing mailing list. We do not use personal data collected through this website for automated decision-making that produces legal or similarly significant effects concerning you. Submissions that show clear signs of automated spam may be recorded in our server logs instead of being delivered to our inbox.

Cookies

This website uses a small number of cookies and similar browser storage technologies, in two groups:

  • Essential and functional: these remember your cookie choice, whether the opening animation has already played in this browser session, and whether you switched on the voice guide. For five minutes after you send the contact form, a cookie also holds your first name so the confirmation page can greet you. None of these tracks you across other websites.
  • Analytics: Google Analytics, which provides aggregate information about how visitors reach and move through the site. It loads only after you select Accept on our cookie notice. If you select Decline, or make no choice, it does not load.

We do not use cookies for advertising or cross-site behavioural advertising.

To change your choice, clear this website's stored data in your browser settings. The cookie notice will appear again on your next visit. Most browsers also let you refuse, restrict or delete cookies. Our Cookie Policy describes each cookie and storage item in more detail.

Third-Party Services

We may use carefully selected third-party service providers to operate our business and this website. These providers act on our instructions and are permitted to use the information we make available to them only for the purpose of providing their service to us.

Categories of provider we may engage include:

  • Cloud hosting and infrastructure providers.
  • Transactional email providers, which deliver enquiry notifications and confirmation emails.
  • Email, communication, messaging and calendaring providers.
  • AI model providers, which screen contact form submissions for spam and, where agreed with a client, are used in delivering an engagement.
  • A text-to-speech provider for the optional voice guide. It receives only the page heading being read aloud, not personal data.
  • Website analytics providers (currently Google Analytics), only where you have accepted analytics cookies.
  • Online meeting and conferencing platforms.
  • Customer relationship management and business administration tools.
  • Development, source control, deployment and monitoring platforms.
  • Invoicing, accounting and payment providers, for paid engagements.
  • Professional advisers, including legal, tax and accounting advisers.

We seek to engage providers that offer contractual commitments on confidentiality and security appropriate to the data involved. The providers we use may change over time. Except where a provider is named above, this Policy is not a representation that any particular provider is or is not currently engaged.

If you contact us through WhatsApp or another third-party messaging service, that service's own terms and privacy policy also apply to the conversation.

Information Sharing

We do not sell, rent or trade personal data. We share personal data only in the following circumstances:

  • With the service providers described above, to the extent necessary for them to provide their service to us.
  • With our professional advisers, where necessary for legal, accounting, audit or insurance purposes.
  • Where you have asked us to, or otherwise consented to the disclosure.
  • Where disclosure is required to comply with applicable law, a binding legal process, or a lawful request from a court, regulator or law enforcement authority.
  • Where necessary to establish, exercise or defend legal claims, or to protect the rights, safety or property of SYSTIQO, our clients or others.
  • In connection with a merger, acquisition, financing or transfer of all or part of our business, in which case we will take reasonable steps to ensure the recipient continues to handle personal data in accordance with this Policy.

Client confidential information is handled as described under AI & Confidential Information below and under the terms of the relevant engagement agreement.

International Transfers

We are based in India. Some of the service providers we use may store or process personal data on infrastructure located outside India, and correspondence with clients or prospective clients located in other countries necessarily involves transfers of business contact information across borders.

Under the Digital Personal Data Protection Act, 2023, personal data may be transferred outside India except to any country or territory that the Central Government restricts by notification. We will comply with any such restriction that applies to us.

Where personal data protected by the EU or UK GDPR is transferred outside the European Economic Area or the United Kingdom, we will use a transfer mechanism recognised under that legislation, such as standard contractual clauses, where one is required.

You may contact us using the details below for further information about the safeguards applicable to a specific transfer.

Data Security

We implement technical, administrative and organisational measures that we consider reasonable and appropriate to the nature of the personal data we handle and the risks involved. Depending on the context, these may include:

  • Encryption of data in transit, and encryption at rest where offered by the underlying platform.
  • Authentication controls, including multi-factor authentication on business-critical accounts.
  • Role-based access control and the principle of least privilege.
  • Use of reputable cloud and software providers rather than self-managed infrastructure where that is the more secure option.
  • Logging and monitoring of access to systems that hold personal data.
  • Backup and recovery procedures appropriate to the systems concerned.
  • Rate limiting and automated spam screening on the contact form.
  • Confidentiality obligations for personnel and contractors, and internal guidance on secure handling of information.

No method of transmission over the internet, and no method of electronic storage, is completely secure. We therefore cannot and do not guarantee absolute security. We do not hold any security or compliance certification, and nothing in this Policy should be read as a claim of certification or accreditation under any standard or framework.

In the event of a personal data breach, we will take steps to contain and assess it, and will notify the Data Protection Board of India and affected individuals to the extent and in the manner required by applicable law.

Data Retention

We retain personal data only for as long as there is a legitimate business or legal reason to do so. In determining retention, we consider:

  • Whether the purpose for which the data was collected has been fulfilled.
  • Whether an active or prospective engagement, contract or negotiation is ongoing.
  • Whether retention is required by applicable law, including tax, accounting and corporate record-keeping requirements.
  • Whether the data may be needed to establish, exercise or defend a legal claim, having regard to applicable limitation periods.

Where the purpose has been served and no legal or contractual requirement to retain the data remains, we delete it, or anonymise it where deletion is not technically practicable, using measures appropriate to the sensitivity of the data.

Retention periods for personal data that we process on behalf of a client, in our capacity as a Data Processor, are governed by the relevant engagement agreement.

Your Rights

Subject to the conditions and exceptions in applicable law, you may have the following rights in relation to personal data we hold about you as a Data Fiduciary:

  • Access: to obtain a summary of the personal data we process about you and the processing activities undertaken.
  • Correction: to have inaccurate or misleading personal data corrected, and incomplete data completed or updated.
  • Erasure: to have personal data erased where it is no longer necessary for the purpose for which it was collected and no legal requirement to retain it applies.
  • Withdrawal of consent, where we rely on your consent, to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer respond to your enquiry.
  • Nomination, under the Digital Personal Data Protection Act, 2023, to nominate another individual to exercise your rights in the event of your death or incapacity.
  • Grievance redressal: to raise a grievance with us about our handling of your personal data.

Where the EU or UK GDPR applies to a particular interaction, you may additionally have the right to restrict or object to certain processing, the right to data portability, and the right to lodge a complaint with your local supervisory authority. The Digital Personal Data Protection Act, 2023 does not itself provide a general right to data portability.

To exercise any of these rights, contact us at hello@systiqo.com. We may ask for information reasonably necessary to verify your identity before acting on a request. We will respond within the timelines prescribed by applicable law. We do not charge a fee for exercising these rights, other than where applicable law permits a charge for a manifestly unfounded or excessive request.

If you are not satisfied with our response, you may escalate the matter. In India, you may raise a complaint with the Data Protection Board of India in accordance with the Digital Personal Data Protection Act, 2023. In the EEA or the UK, you may complain to your local supervisory authority.

Where we hold your personal data only as a Data Processor on behalf of a client, we will direct your request to that client, who is responsible for responding to it.

Children's Privacy

This website and our services are directed at organisations and business professionals. They are not directed at children, and we do not knowingly collect personal data from children through this website.

Under the Digital Personal Data Protection Act, 2023, a child is an individual who has not completed eighteen years of age. We do not knowingly process the personal data of a child without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

If you believe a child has provided us with personal data, please contact us at hello@systiqo.com and we will take appropriate steps to delete it.

AI & Confidential Information

We are an applied AI and systems engineering firm. We use AI where a problem requires it, not by default, and we may use AI-assisted tools in the course of delivering services, including where you send us project material, prompts or documents.

  • Contact form submissions are passed to a third-party AI model, which returns only a label indicating whether a submission looks like spam. A person reads the label alongside the enquiry. The model does not decide whether we reply, and a submission still reaches us if the check is unavailable.
  • Information shared with us under an engagement agreement or a non-disclosure agreement is treated as confidential on the terms of that agreement. Information sent in an enquiry before such an agreement is in place is handled with reasonable care and used only to respond to and evaluate that enquiry, as explained in our Terms & Conditions.
  • We do not use client data to train any machine learning model, including third-party foundation models, without the client's explicit agreement.
  • Where a third-party AI service is used in delivering an engagement, we seek to use it on terms that do not permit the provider to use the submitted content to train its models, and we will agree the tools and boundaries with the client where the engagement requires it.
  • AI-generated output is treated as a draft. Work product that is delivered to a client is subject to human review appropriate to its risk and purpose.
  • We do not use AI to make automated decisions about individuals that produce legal or similarly significant effects.

We apply reasonable safeguards to confidential information, but we do not promise absolute confidentiality or absolute security. Where an engagement requires specific confidentiality, data handling or AI usage terms, those are agreed in the engagement agreement or a separate non-disclosure agreement, which takes precedence over this Policy in respect of that engagement.

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, our service providers, or applicable law. The effective date at the top of this page indicates when the current version took effect.

Where a change is material, we will take reasonable steps to bring it to your attention. Where applicable law requires your consent for a change, we will obtain it before the change applies to you.

Contact Information

For questions about this Policy, about how we handle personal data, or to exercise your rights or raise a grievance, contact us at:

  • SYSTIQO Tech Labs
  • Postal address: see https://systiqo.com/contact
  • Email: hello@systiqo.com
  • Phone: +91 94500 99351
  • Privacy queries and grievances: hello@systiqo.com

We aim to acknowledge privacy enquiries promptly and to resolve grievances within the timelines prescribed by applicable law.

Start a conversationLet's talk