Privacy Policy
Effective date: 9 August 2026
SYSTIQO Tech Labs ("SYSTIQO", "we", "us" or "our") is an Applied AI & Systems Lab that researches, designs, and engineers intelligent systems, providing professional engineering and consulting services. This Privacy Policy explains how we handle personal data in connection with this website and our business relationships.
Introduction
We are committed to handling personal data lawfully, transparently and only to the extent necessary for our business. This Policy has been prepared having regard to the Digital Personal Data Protection Act, 2023 and the rules made under it, the Information Technology Act, 2000 and rules made thereunder, and — where they apply to a particular interaction — the principles of the EU General Data Protection Regulation and the UK General Data Protection Regulation.
References in this Policy to a "Data Principal" (or "data subject") mean the individual to whom personal data relates. References to a "Data Fiduciary" (or "controller") mean the entity that determines the purpose and means of processing.
This Policy describes our current practices. It does not create rights or obligations beyond those provided by applicable law or by a written agreement between you and SYSTIQO.
Scope
This Policy applies to personal data we handle as a Data Fiduciary, namely:
- Personal data collected through this website, including forms, file uploads and general enquiries.
- Personal data exchanged in the course of business communications — email, telephone, messaging and online meeting platforms.
- Personal data of prospective clients, client personnel, partners, suppliers and applicants that we process for ordinary business administration.
This Policy does not apply to personal data that we process on behalf of, and under the documented instructions of, a client in the course of delivering services. In that role we act as a Data Processor (or "processor"), and such processing is governed by the agreement between SYSTIQO and that client, not by this Policy. Where a client is the Data Fiduciary, that client's own privacy notice governs the individuals concerned.
This Policy also does not apply to third-party websites or services that we link to. Their own privacy notices govern their handling of your data.
Information We Collect
We collect only information that is reasonably necessary for the purposes described in this Policy. We do not require you to create an account to use this website, and we do not operate public user accounts.
Personal information
- Name.
- Business email address.
- Telephone number.
- Company or organisation name.
- Job title or role.
- Country or region.
Business information
- Project requirements, business challenges and objectives you describe to us.
- Technical documentation and other files you choose to upload or send.
- Proposal requests, statements of work and related commercial correspondence.
- Records of meetings, calls and other communications with us.
Technical information
- IP address and approximate location derived from it.
- Browser type and version, device type and operating system.
- Pages viewed, referring URL and interaction data collected through analytics, where enabled.
- Server logs generated automatically when this website is accessed.
Please do not send us sensitive personal data, special category data, health data, financial account credentials, government identifiers or third-party personal data unless we have specifically asked for it and agreed how it will be handled. Where you provide personal data about other individuals — for example colleagues named in a project brief — you confirm that you are entitled to share it with us for the purposes described here.
How We Collect Information
- Directly from you, when you complete a form, upload a file, request a consultation or proposal, or communicate with us by email, telephone or an online meeting platform.
- Automatically, through server logs, cookies and similar technologies when you visit this website, as described under Cookies below.
- From the organisation you represent, where a colleague provides your business contact details in the context of an engagement or enquiry.
- From publicly available or professional business sources, where we verify or supplement business contact details in a business-to-business context.
Where we rely on your consent, we will ask for it at the point of collection and you may withdraw it at any time as described under Your Rights.
How We Use Information
We use personal data for the following purposes:
- To respond to enquiries, consultation requests and proposal requests.
- To scope, prepare, negotiate and administer engagements, statements of work and contracts.
- To deliver and support the professional services we have been engaged to provide.
- To communicate with you about an active or prospective engagement.
- To operate, secure, maintain and improve this website.
- To understand, in aggregate, how visitors use our content.
- To maintain ordinary business, accounting and administrative records.
- To establish, exercise or defend legal claims, and to comply with legal, regulatory and tax obligations.
Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent or, where available, on the basis of a legitimate use recognised under that Act. Where the EU or UK GDPR applies to a particular interaction, we rely on consent, on the necessity of processing for a contract or steps taken at your request prior to entering into one, on our legitimate interests in operating and securing our business, or on compliance with a legal obligation, as appropriate to the purpose.
We do not sell personal data. We do not use personal data collected through this website for automated decision-making that produces legal or similarly significant effects concerning you.
Cookies
This website uses cookies and similar technologies. The categories that may apply are:
- Essential — required for the website to load, function and remain secure. These cannot be switched off through our interface.
- Functional — remember choices you make, such as display preferences, to improve your experience.
- Performance — help us understand loading and reliability issues so we can address them.
- Analytics — provide aggregate information about how visitors reach and move through the site.
We do not use cookies for third-party advertising or cross-site behavioural advertising.
Most browsers allow you to refuse, restrict or delete cookies through their settings. Blocking non-essential cookies will not prevent you from browsing this website, although some features may behave differently. Where required by applicable law, we will seek your consent before setting non-essential cookies.
Third-Party Services
We may use carefully selected third-party service providers to operate our business and this website. These providers act on our instructions and are permitted to use the information we make available to them only for the purpose of providing their service to us.
Categories of provider we may engage include:
- Cloud hosting and infrastructure providers.
- Email, communication and calendaring providers.
- Website analytics providers.
- Online meeting and conferencing platforms.
- Customer relationship management and business administration tools.
- Development, source control, deployment and monitoring platforms.
- Payment processors and accounting providers, where relevant to a commercial engagement.
- Professional advisers, including legal, tax and accounting advisers.
We seek to engage providers that offer contractual commitments on confidentiality and security appropriate to the data involved. The identity of the providers we use may change over time; this Policy is not a representation that any particular provider is or is not currently engaged.
Information Sharing
We do not sell, rent or trade personal data. We share personal data only in the following circumstances:
- With the service providers described above, to the extent necessary for them to provide their service to us.
- With our professional advisers, where necessary for legal, accounting, audit or insurance purposes.
- Where you have asked us to, or otherwise consented to the disclosure.
- Where disclosure is required to comply with applicable law, a binding legal process, or a lawful request from a court, regulator or law enforcement authority.
- Where necessary to establish, exercise or defend legal claims, or to protect the rights, safety or property of SYSTIQO, our clients or others.
- In connection with a merger, acquisition, financing or transfer of all or part of our business, in which case we will take reasonable steps to ensure the recipient continues to handle personal data in accordance with this Policy.
Client confidential information is handled as described under AI & Confidential Information below and under the terms of the relevant engagement agreement.
International Transfers
We are based in India. Some of the service providers we use may store or process personal data on infrastructure located outside India, and correspondence with clients or prospective clients located in other countries necessarily involves transfers of business contact information across borders.
Under the Digital Personal Data Protection Act, 2023, personal data may be transferred outside India except to any country or territory that the Central Government restricts by notification. We will comply with any such restriction that applies to us.
Where personal data protected by the EU or UK GDPR is transferred outside the European Economic Area or the United Kingdom, we will use a transfer mechanism recognised under that legislation, such as standard contractual clauses, where one is required.
You may contact us using the details below for further information about the safeguards applicable to a specific transfer.
Data Security
We implement technical, administrative and organisational measures that we consider reasonable and appropriate to the nature of the personal data we handle and the risks involved. Depending on the context, these may include:
- Encryption of data in transit, and encryption at rest where offered by the underlying platform.
- Authentication controls, including multi-factor authentication on business-critical accounts.
- Role-based access control and the principle of least privilege.
- Use of reputable cloud and software providers rather than self-managed infrastructure where that is the more secure option.
- Logging and monitoring of access to systems that hold personal data.
- Backup and recovery procedures appropriate to the systems concerned.
- Confidentiality obligations for personnel and contractors, and internal guidance on secure handling of information.
No method of transmission over the internet, and no method of electronic storage, is completely secure. We therefore cannot and do not guarantee absolute security. We do not hold any security or compliance certification, and nothing in this Policy should be read as a claim of certification or accreditation under any standard or framework.
In the event of a personal data breach, we will take steps to contain and assess it, and will notify the Data Protection Board of India and affected individuals to the extent and in the manner required by applicable law.
Data Retention
We retain personal data only for as long as there is a legitimate business or legal reason to do so. In determining retention, we consider:
- Whether the purpose for which the data was collected has been fulfilled.
- Whether an active or prospective engagement, contract or negotiation is ongoing.
- Whether retention is required by applicable law, including tax, accounting and corporate record-keeping requirements.
- Whether the data may be needed to establish, exercise or defend a legal claim, having regard to applicable limitation periods.
Where the purpose has been served and no legal or contractual requirement to retain the data remains, we delete it, or anonymise it where deletion is not technically practicable, using measures appropriate to the sensitivity of the data.
Retention periods for personal data that we process on behalf of a client, in our capacity as a Data Processor, are governed by the relevant engagement agreement.
Your Rights
Subject to the conditions and exceptions in applicable law, you may have the following rights in relation to personal data we hold about you as a Data Fiduciary:
- Access — to obtain a summary of the personal data we process about you and the processing activities undertaken.
- Correction — to have inaccurate or misleading personal data corrected, and incomplete data completed or updated.
- Erasure — to have personal data erased where it is no longer necessary for the purpose for which it was collected and no legal requirement to retain it applies.
- Withdrawal of consent — where we rely on your consent, to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer respond to your enquiry.
- Nomination — under the Digital Personal Data Protection Act, 2023, to nominate another individual to exercise your rights in the event of your death or incapacity.
- Grievance redressal — to raise a grievance with us about our handling of your personal data.
Where the EU or UK GDPR applies to a particular interaction, you may additionally have the right to restrict or object to certain processing, the right to data portability, and the right to lodge a complaint with your local supervisory authority. The Digital Personal Data Protection Act, 2023 does not itself provide a general right to data portability.
To exercise any of these rights, contact us at hello@systiqo.com. We may ask for information reasonably necessary to verify your identity before acting on a request. We will respond within the timelines prescribed by applicable law. We do not charge a fee for exercising these rights, other than where applicable law permits a charge for a manifestly unfounded or excessive request.
If you are not satisfied with our response, you may escalate the matter. In India, you may raise a complaint with the Data Protection Board of India in accordance with the Digital Personal Data Protection Act, 2023. In the EEA or the UK, you may complain to your local supervisory authority.
Where we hold your personal data only as a Data Processor on behalf of a client, we will direct your request to that client, who is responsible for responding to it.
Children's Privacy
This website and our services are directed at organisations and business professionals. They are not directed at children, and we do not knowingly collect personal data from children through this website.
Under the Digital Personal Data Protection Act, 2023, a child is an individual who has not completed eighteen years of age. We do not knowingly process the personal data of a child without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
If you believe a child has provided us with personal data, please contact us at hello@systiqo.com and we will take appropriate steps to delete it.
AI & Confidential Information
We are an applied AI firm and we may use AI-assisted tools in the course of delivering services, including where you send us project material, prompts or documents.
- Client and prospect information shared with us is treated as confidential and is used only for the purpose for which it was provided and for the engagement to which it relates.
- We do not use client data to train foundation models or any other machine learning model without the client's explicit agreement.
- Where a third-party AI service is used in delivering an engagement, we seek to use it on terms that do not permit the provider to use the submitted content to train its models, and we will agree the tools and boundaries with the client where the engagement requires it.
- AI-generated output is treated as a draft. Work product that is delivered to a client is subject to human review appropriate to its risk and purpose.
- We do not use AI to make automated decisions about individuals that produce legal or similarly significant effects.
We apply reasonable safeguards to confidential information, but we do not promise absolute confidentiality or absolute security. Where an engagement requires specific confidentiality, data handling or AI usage terms, those are agreed in the engagement agreement or a separate non-disclosure agreement, which takes precedence over this Policy in respect of that engagement.
Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, our service providers, or applicable law. The effective date at the top of this page indicates when the current version took effect.
Where a change is material, we will take reasonable steps to bring it to your attention. Where applicable law requires your consent for a change, we will obtain it before the change applies to you.
Contact Information
For questions about this Policy, about how we handle personal data, or to exercise your rights or raise a grievance, contact us at:
- SYSTIQO Tech Labs
- 806A, 8th Floor, Levana Cyber Heights, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh, India
- Email: hello@systiqo.com
- Phone: +91 94500 99351
- Privacy queries and grievances: hello@systiqo.com
We aim to acknowledge privacy enquiries promptly and to resolve grievances within the timelines prescribed by applicable law.