1. Introduction#
Pavidha Technologies Pvt Ltd ("DECISYN", "we", "us", or "our") operates the SyncHQ Pro platform (the "Services"), an AI-powered contractor management SaaS used by service businesses and their staff. This privacy policy explains how we collect, use, share, retain, and protect personal data when you visit our websites, sign up for an account, use the Services, or otherwise interact with us.
This policy applies to all users of the Services worldwide. Where you are located in the European Economic Area, the United Kingdom, India, California, Canada, or another jurisdiction with specific personal-data protections, additional rights described in Section 8 apply to you.
By using the Services you acknowledge that you have read this policy. If you do not agree with it, please do not use the Services.
2. Information we collect#
We collect personal data in three ways: directly from you when you provide it, automatically when you use the Services, and from a small set of integrated third-party sources.
2.1 Direct collection
When you create an account, configure your company, or operate the Services day-to-day, we collect the following categories of data:
- Account data — name, work email, password hash, role, locale, time zone, and profile picture.
- Business data — company name, address, GSTIN / VAT / EIN, logo, branding colors, working hours, and service areas.
- Customer data — names, contact details, service addresses, communication preferences, and notes you record about your customers.
- Financial data — invoices, estimates, line items, payment status, tax amounts, and (for tenants who enable payments) tokenized payment-method references held by our payment processors. We do not store full card numbers.
- Job data — job descriptions, scheduling, photos uploaded to jobs, checklists, change history, and crew assignments.
- Communication data — content of SMS, WhatsApp, and email messages sent through the platform, plus delivery and read receipts.
- Staff data — staff profiles, skills, certifications, working hours, locations during on-clock periods, and performance metrics.
2.2 Automatic collection
When you use the Services we automatically collect:
- Device data — device type, operating system, browser, screen resolution, and (for PWA installs) installation events.
- Usage data — pages viewed, features used, clicks, time spent in features, and search queries within the app.
- Log data — IP address, request timestamps, request paths, response codes, and user-agent strings. Stored for 90 days.
- Location data — approximate location derived from IP, plus precise GPS coordinates for staff who have explicitly enabled on-clock location tracking via the mobile app.
- Performance data — anonymized telemetry on page load times, render performance, JavaScript errors, and slow database queries.
2.3 Third-party sources
A small number of integrations enrich your tenant data:
- Google Maps Platform — geocoding and route optimization (address → coordinates and back).
- Stripe — payment processing, including tokenized payment-method metadata for tenants who use card payments.
- QuickBooks Online — accounting sync of invoices, customers, and chart of accounts, where you connect your QuickBooks tenant.
- OpenAI — AI feature responses (estimate suggestions, marketing copy, support chat). See Section 5 for what we send.
3. How we use your information#
We use personal data for the following purposes:
- To provide, operate, maintain, and improve the Services.
- To authenticate you and protect your account.
- To deliver service communications you initiate (SMS, WhatsApp, email to your customers and staff) through the platform.
- To process payments and reconcile invoices.
- To provide AI-assisted features (estimate generation, marketing copy, support chat, lead scoring, route optimization).
- To detect, prevent, and respond to fraud, abuse, security incidents, and policy violations.
- To meet legal, regulatory, accounting, and tax obligations.
- To send service updates, security notices, and (with your consent or where lawful) marketing communications about new features.
- To analyze usage and improve product performance in aggregate, anonymized form.
4. Legal basis for processing#
Under the GDPR, the DPDPA, and other applicable frameworks we process personal data on one or more of the following legal bases:
- Contract performance — to provide the Services you have subscribed to, including account creation, feature delivery, billing, and support.
- Legitimate interest — to secure the Services, prevent abuse, improve product quality, and conduct anonymized analytics, in each case balanced against your interests and rights.
- Consent — for optional features (location tracking for staff, marketing emails, optional integrations). Consent can be withdrawn at any time.
- Legal obligation — to comply with tax, accounting, e-invoicing, anti-money-laundering, and lawful enforcement requests applicable in the jurisdictions in which we operate.
6. Data retention#
We retain personal data only as long as needed to deliver the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Once retention expires, data is either deleted or irreversibly anonymized.
| Data category | Retention period |
|---|---|
| Account data | Duration of subscription + 30 days (export grace period) |
| Business and job data | Duration of subscription + 90 days (encrypted backup) |
| Financial records (invoices, payments, tax docs) | 7 years (statutory accounting obligation) |
| Communication logs (SMS / email / WhatsApp delivery records) | 2 years |
| Server logs (IP, request, response) | 90 days |
| Analytics events | 26 months |
| Cookie consent records | 3 years from last consent action |
| Anonymized / aggregated data | Indefinite (no longer constitutes personal data) |
7. Data security#
We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, and destruction. Our current safeguards include:
- Encryption in transit — TLS 1.2 or higher for all client-server traffic.
- Encryption at rest — Bank-level encryption (strong encryption) for database storage and object storage.
- Password protection — Industry-standard salted hashing for user passwords; never stored in plaintext.
- Network controls — Azure Web Application Firewall, rate limiting, intrusion detection.
- Access controls — Principle of least privilege, multi-tenant row-level isolation, MFA for staff access to production systems.
- Monitoring — 24/7 security event monitoring, vulnerability scanning, dependency CVE tracking.
- Backups — Encrypted automated backups retained for 90 days with point-in-time recovery.
If we become aware of a personal data breach affecting you, we will notify you and relevant supervisory authorities in accordance with the timelines required by applicable law (including 72 hours under GDPR and as soon as possible under DPDPA).
8. Your rights#
Depending on your jurisdiction you have specific rights regarding the personal data we hold about you. The table below is a quick reference; the subsections that follow describe each jurisdiction's rights in full.
| Right | DPDPA (India) | GDPR (EEA / UK) | CCPA / CPRA (California) | PIPEDA (Canada) |
|---|---|---|---|---|
| Access / know | ✓ Section 11 | ✓ Art. 15 | ✓ §1798.100, §1798.110 | ✓ Principle 9 |
| Correction / rectification | ✓ Section 12 | ✓ Art. 16 | ✓ §1798.106 | ✓ Principle 9 |
| Erasure / deletion | ✓ Section 12 | ✓ Art. 17 | ✓ §1798.105 | ✓ Conditional |
| Portability | — | ✓ Art. 20 | ✓ §1798.130(a)(2) | — |
| Restrict processing | — | ✓ Art. 18 | ✓ Limit-use of sensitive PI | — |
| Object / opt-out | Consent withdrawal | ✓ Art. 21 | ✓ Opt-out of "sale" / "share" | ✓ Consent withdrawal |
| Withdraw consent | ✓ Section 6(4) | ✓ Art. 7(3) | ✓ Where consent applies | ✓ Principle 3 |
| Grievance / complaint | ✓ Section 13 → Officer → DPB | ✓ Supervisory authority | ✓ AG / CPPA | ✓ OPC |
| Nominate | ✓ Section 14 | — | — | — |
| Non-discrimination | Implicit | Implicit | ✓ §1798.125 | Implicit |
| How to exercise | Settings > Privacy > Data Rights · privacy@servicesynchq.com · 30-day response | |||
8.1 All users — baseline rights
- Right of access — request a copy of your personal data.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion, subject to lawful retention obligations.
- Right to portability — receive your data in a structured, machine-readable format.
- Right to opt out of marketing — unsubscribe from product marketing at any time.
8.2 GDPR (EEA / UK users) — additional rights
- Right to portability — receive personal data you provided in a portable format and have it transmitted to another controller where technically feasible.
- Right to restrict processing — limit our processing while a request is under review.
- Right to object — object to processing based on legitimate interests, including profiling.
- Right to withdraw consent — withdraw any consent previously given, without affecting prior lawful processing.
- Right to lodge a complaint — file a complaint with your local supervisory authority.
8.3 CCPA (California residents) — additional rights
- Right to know — categories of personal information collected and the purposes of collection.
- Right to delete — request deletion of personal information collected from you.
- Right to opt out of "sale" — although we do not sell personal information, you can confirm and exercise this right.
- Right to non-discrimination — you will not receive degraded service for exercising privacy rights.
8.4 DPDPA (India) — Sections 11–14
- Section 11 — Right to access information — confirmation of processing, summary of data, and identities of recipients.
- Section 12 — Right to correction and erasure — correct, complete, update, or erase personal data.
- Section 13 — Right of grievance redressal — escalate to the Grievance Officer (Section 9 below). 30-day response timeline.
- Section 14 — Right to nominate — nominate another person to exercise rights in the event of death or incapacity.
8.5 PIPEDA (Canadian users) — additional rights
- Right to access — request information about how your data is being used.
- Right to challenge accuracy — request that we correct or amend personal data.
- Right to withdraw consent — withdraw consent subject to legal or contractual restrictions, with reasonable notice.
8.6 How to exercise your rights
You can exercise any of these rights by:
- Emailing privacy@servicesynchq.com, or
- Signing in to your account and navigating to Settings > Privacy > Data Rights.
We will verify your identity before processing the request and respond within 30 days. If we need more time, we will tell you why and how long it will take.
9. Grievance officer#
In accordance with the DPDPA, the IT Rules 2011, and the Intermediary Guidelines 2021, we have appointed a Grievance Officer to address concerns about how we handle personal data.
Grievance Officer
Email: grievance@servicesynchq.com
Response timeline: 30 days from receipt of complaint (DPDPA-mandated).
If you are dissatisfied with the Grievance Officer's response, you may escalate to the Data Protection Board of India or your local supervisory authority.
10. Children's privacy#
The Services are designed for business use by adults. We do not knowingly collect personal information from individuals under the age of 18. If you believe a child has provided us with personal information, please contact privacy@servicesynchq.com and we will delete the information promptly after verification.
11. International data transfers#
DECISYN is headquartered in India and primarily processes data in Microsoft Azure's India region. When personal data is transferred from the EEA or UK to India, or to any sub-processor outside the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) together with supplementary technical and organizational measures (encryption, access control, audit logging) to ensure an essentially equivalent level of protection.
All customer data is hosted in our primary region. We notify you in advance of any change to where your data is stored.
12. DPDPA (India) — full notice#
Scope of this section. The following is SyncHQ Pro's complete Digital Personal Data Protection Act, 2023 notice for Indian Data Principals. It supplements the rest of this Privacy Policy; in case of any conflict regarding Indian Data Principals, this section controls. Last reviewed by counsel: 2026 Q2. Effective date: June 1, 2026. Issuing entity: Pavidha Technologies Pvt Ltd, Dindigul, Tamil Nadu, India.
12.1 About the DPDPA
The Digital Personal Data Protection Act, 2023 ("DPDPA") is India's comprehensive law governing the processing of digital personal data. It establishes rights for Data Principals (the individuals whose data is processed), obligations for Data Fiduciaries (organisations that decide why and how personal data is processed), and a regulator — the Data Protection Board of India ("DPB") — to enforce compliance.
12.2 Our role as Data Fiduciary
Pavidha Technologies Pvt Ltd, headquartered in Dindigul, Tamil Nadu, India, operates the SyncHQ Pro platform. When you sign up directly with us, DECISYN is the Data Fiduciary for your personal data.
When your employer or service provider invites you into a SyncHQ Pro workspace as a staff member, the workspace owner is the Data Fiduciary for your data; DECISYN acts as a Data Processor on their behalf and follows their lawful instructions, subject to our security and compliance baselines.
12.3 Personal data we process
The DPDPA applies to all digital personal data. We process the following categories of personal data of Indian Data Principals:
- Identity data — name, work email, mobile number, role.
- Business data — company name, GSTIN, address.
- Customer & staff data — names, contact details, addresses, work history, performance metrics (where applicable).
- Financial data — invoices, payments, tokenized payment-method references.
- Communication data — content of SMS / WhatsApp / email sent through the platform.
- Location data — IP-derived approximate location, plus precise GPS for staff who explicitly enable on-clock tracking.
- Device & usage data — device type, browser, pages viewed, telemetry.
See Section 2 for the complete enumeration across all jurisdictions.
12.4 Lawful basis under Sections 6 & 7
The DPDPA permits processing of personal data only with consent (Section 6) or for certain "legitimate uses" (Section 7). We rely on:
- Section 6 — Consent for marketing emails, optional analytics, optional location tracking, and any processing outside the strict needs of the contract.
- Section 7(a) — Voluntary provision for personal data you provide for a specified purpose (e.g., creating an account, configuring your workspace).
- Section 7(b) — Compliance with judgments / law for legal-process responses.
- Section 7(g) — Employment-related for processing of staff personal data necessary for employment.
- Section 7(i) — Public interest in legitimate business activity for security, fraud prevention, and platform stability.
You may withdraw consent at any time via Settings > Privacy > Consent management. Withdrawal does not affect lawful processing before withdrawal but stops future processing where consent is the basis.
12.5 Purposes of processing
- Provide, operate, maintain, and improve the platform.
- Authenticate users and protect accounts.
- Deliver service communications (SMS / WhatsApp / email) you initiate.
- Process payments and reconcile invoices.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal, tax, accounting, and regulatory obligations applicable in India.
- Provide AI-assisted features only as the user initiates and only with the inputs required by that feature.
12.6 Retention and erasure
Personal data is retained only as long as needed for the purposes set out above, or as required by Indian law (e.g., 7-year retention for financial records under tax law). The retention schedule in Section 6 applies.
Under Section 8(7) of the DPDPA, personal data must be erased once the specified purpose is no longer being served, unless retention is required by law. On account deletion you may request immediate erasure subject only to statutory retention obligations.
12.7 International transfers (Section 16)
Section 16 of the DPDPA empowers the central government to restrict cross-border transfers of personal data by notification. Until a restriction is notified, transfers are permissible.
SyncHQ Pro primarily processes data in Microsoft Azure's India region. Limited transfers occur to the following sub-processors located outside India, each under a Data Processing Agreement aligned with the Standard Contractual Clauses (SCCs):
| Sub-processor | Region | Purpose |
|---|---|---|
| OpenAI | USA | AI feature responses (anonymised prompts only) |
| Anthropic | USA | AI feature responses (anonymised prompts only) |
| Stripe | USA / global | Card payments |
| Twilio | USA / global | SMS & voice notifications |
| Google Maps Platform | USA / global | Geocoding & route optimisation |
| Vercel | USA / global | Marketing website CDN edge |
All customer data is hosted in our primary region; we notify you in advance of any change. Razorpay (UPI / India-domestic payments) operates entirely within India.
12.8 Sections 11–14 — Data Principal rights
Section 11 — Right to information. You have the right to obtain from us:
- Confirmation of whether we are processing your personal data;
- A summary of the personal data we are processing about you;
- The identities of all Data Fiduciaries and Data Processors with whom we have shared your data, along with a description of the categories shared;
- Any other information related to such processing as may be prescribed.
Submit your request via Settings > Privacy > Data rights or by emailing privacy@servicesynchq.com. We respond within 30 days.
Section 12 — Right to correction and erasure. You have the right to request the correction, completion, updating, or erasure of your personal data. We will:
- Correct or update inaccurate or incomplete data within 30 days.
- Erase data we no longer need, unless retention is required by law.
- Notify our sub-processors of any correction or erasure that affects them.
Some data must be retained for statutory reasons (e.g., tax records). In those cases we restrict further processing and erase as soon as the statutory period ends.
Section 13 — Right of grievance redressal. If you are dissatisfied with how we have processed your personal data or responded to a DPDPA request, you may file a grievance with our Grievance Officer (see 12.12 below). We will acknowledge the grievance within 7 working days and resolve it within 30 days.
Section 14 — Right to nominate. You have the right to nominate another individual who may exercise your DPDPA rights in the event of your death or incapacity. To register a nominee, sign in and go to Settings > Privacy > Nominee, or contact privacy@servicesynchq.com with the nominee's name, relationship, and consent.
12.9 Consent and Consent Manager
Where we rely on consent under Section 6, we obtain it in plain language at the time of collection. You can review and withdraw consent at any time from Settings > Privacy > Consent management.
If the DPDPA Consent Manager framework is operational at your time of use, we will integrate with registered Consent Managers so you can manage consents across the providers participating in the framework.
12.10 Children's data (Section 9)
SyncHQ Pro is designed for business use by adults. We do not knowingly process the personal data of children (under 18). If a child's personal data has been provided to us, contact privacy@servicesynchq.com and we will delete it after reasonable verification.
For tenants who operate services that may involve children's data (e.g., school-uniform services), the tenant — as the Data Fiduciary for that data — must obtain verifiable parental consent before processing.
12.11 Breach notification (Section 8(6))
If we become aware of a personal data breach affecting your data, we will notify both the Data Protection Board of India and you "as soon as practicable" — for SyncHQ Pro that means within 72 hours of confirmation. The notice will include the nature of the breach, the data affected, the steps you can take, and the steps we are taking to mitigate.
12.12 Grievance Officer (India)
In accordance with the DPDPA Section 10 and the IT Rules 2011 / Intermediary Guidelines 2021, DECISYN has appointed a Grievance Officer:
Grievance Officer — DECISYN Privacy Office
First point of contact for all DPDPA grievances. Empowered to investigate, decide, and direct remediation across DECISYN's data-processing operations.
- Email: grievance@servicesynchq.com
- Postal: Pavidha Technologies Pvt Ltd, Dindigul, Tamil Nadu, India
- Response: 30 days (DPDPA-mandated)
- Acknowledge: 7 working days
To file a grievance, email the Grievance Officer with: (1) your name and registered account email; (2) a clear description of the issue; (3) any prior tickets or correspondence; (4) the outcome you are seeking. We will acknowledge within 7 working days and resolve within 30 days. See also our cross-jurisdiction Grievance officer block in Section 9.
12.13 Escalation to the Data Protection Board
If you are dissatisfied with the Grievance Officer's response, or if no response is received within 30 days, you may escalate to the Data Protection Board of India under Section 27 of the DPDPA. The DPB's official notification, contact channel, and complaint form are published by the Government of India on the Ministry of Electronics and Information Technology (MeitY) portal.
12.14 Other Indian laws
In addition to the DPDPA, SyncHQ Pro complies with the following Indian laws and regulations to the extent applicable:
- Information Technology Act, 2000 — including Section 43A (sensitive personal data) and Section 72A (disclosure obligations).
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — including the requirement to publish a privacy policy and obtain consent for processing.
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — including the requirement to designate a Grievance Officer and process complaints within stipulated timelines.
Contacts specific to India:
- Grievance Officer (DPDPA, primary): grievance@servicesynchq.com
- Privacy & data-rights requests: privacy@servicesynchq.com
- Legal: legal@servicesynchq.com
Postal address: Pavidha Technologies Pvt Ltd, Dindigul, Tamil Nadu, India.
14. Changes to this policy#
We may update this privacy policy from time to time. The "Effective date" at the top of this page tells you when the current version became effective. When we make material changes we will notify you by email (to your account email address) and by a prominent notice on the website at least 30 days before the change takes effect. Continued use of the Services after a change becomes effective constitutes acceptance of the updated policy.
15. Contact us#
For any question about this policy, your data, or your rights, please use the most appropriate channel below. We respond within 30 days (faster where required by law).
Postal address: Pavidha Technologies Pvt Ltd, Dindigul, Tamil Nadu, India.