Security & trust

Your data. Your control. Your peace of mind.

SyncHQ Pro is built so you can stop worrying about your data — and get back to running your business. Encrypted everywhere. Tenant-isolated by design. Continuously monitored. Aligned with the world's strictest data-protection laws.

GDPR DPDPA 2023 CCPA / CPRA PIPEDA SOC 2 (Q4 2026) ISO 27001 (Q4 2026) HIPAA-ready · BAA on Scale
EU GDPR IN DPDPA SOC 2 ISO 27001

Three things we promise every tenant

No tech jargon. Just what we do for you.

Your data is always encrypted

Whether sitting in our database or moving across the network, every piece of your data is protected by industry-standard encryption — both when in motion and at rest. Even our engineers can't read it casually.

Your tenant is its own world

Your data, your customers, your invoices, your team — completely separated from every other business on the platform. We can't accidentally show your data to anyone else, and they can't see yours.

Every action is recorded for your audit

Who did what, when, and why — captured in a tamper-evident audit trail that's all yours. Perfect for compliance reviews, board reporting, or just answering "who deleted that?" with certainty.

Defense in depth — every layer of your data

Every record your team enters is encrypted before it leaves the browser, stored in your tenant's private vault, and traced end-to-end through an audit log only you can read. Independent assurance (SOC 2 Type II, ISO 27001) is on the roadmap for Q4 2026 — the controls already operate today.

Aligned with the standards your customers, your auditors, and your board expect

We meet the bar set by the world's strictest data-protection regimes and security frameworks.

GDPR
EU / UK General Data Protection Regulation
Aligned today
What it means
Lawful basis · DSAR within 30 days · 72-hour breach notice · DPA Art. 28 pre-signed.
DPDPA 2023
India Digital Personal Data Protection Act
Aligned today
What it means
Section 8 consent · Data principal rights · Indian-language notices · breach to DPB.
CCPA / CPRA
California Consumer Privacy Act
Aligned today
What it means
Right to know · delete · opt-out of sale · "Do Not Sell" link · 45-day response.
PIPEDA
Canada Personal Information Protection Act
Aligned today
What it means
10 fair information principles · meaningful consent · OPC breach notification.
SOC 2 Type II
Service Organization Control 2
Audit scheduled Q4 2026
What it means
5 Trust Services Criteria · Security · Availability · Confidentiality · Processing Integrity · Privacy.
ISO 27001
Information Security Management
Certification in progress
What it means
93-control ISMS · risk-based · continual improvement · global gold-standard.
PCI DSS
Card data is never on our servers
Out of scope
What it means
Stripe / Razorpay PCI Level 1 handle card data · we never store PAN · SAQ-A scope.
HIPAA-ready
BAA available on Scale tier
On request
What it means
BAA available on Scale tier · PHI safeguards · audit log of every PHI access.

The journey of a piece of your data

From the moment your team enters it to the day it's deleted — what happens.

Save Bank-level encryption Fenced off from every other business Tamper-proof trail Daily · PITR
Bank-level encryptionEncrypted at rest
TLS 1.3Encrypted in transit
Tamper-proof auditCryptographic fingerprint chain
Banking-grade isolationevery sensitive data type

Created

Your team enters it through the app or API.

Encrypted

Wrapped in encryption the moment it leaves the browser.

Isolated

Stored in your tenant's space only. No bleed-through.

Audited

Every read, change, delete recorded — for you.

Backed up

Daily, encrypted, restorable to a recent point in time.

What you can count on, today

The commitments you can put in front of your customers, your board, and your auditors.

Your data is yours alone.We never sell your data. We never use it to train any AI model — yours or ours.
You can export it anytime.JSON, CSV, PDF — from self-serve settings, no support ticket needed. 30-day grace period after cancellation.
You know where it lives.All customer data is hosted in our primary region and never moved without notice.
You're notified within 72 hours.If anything affects your data, we tell you fast — required by GDPR, promised by us in every contract.
You'll never lose a day's work.Automatic encrypted backups, restorable to a recent point in time. Tested every quarter.
Your team sees only what they should.Role-based access lets you grant minimum permissions per person. Multi-factor authentication enforceable workspace-wide.
Your customers are protected too.Customer-portal access is single-use, time-limited, and revocable. Customer data-export requests honored within statutory timeframes.
Independent assurance is on the way.SOC 2 Type II and ISO 27001 audits booked for 2026 Q4. The controls already operate; the certificates are the evidence trail.

Built for 5 jurisdictions out of the box

India · UK · EU · KSA · UAE · Canada · Australia · United States — and one to spare for the next region your business expands into.

India GSTUS Sales TaxUK VATEU VATGCC VAT
INIndia

CGST + SGST + IGST routing · IRN e-invoice with 24h cancellation window · HSN/SAC codes · DPDPA 2023.

UKUnited Kingdom

CIS withholding 20% / 30% / 0% by verification status · VAT returns · UK-GDPR · DSAR.

EUEuropean Union

SDI XML e-invoice format (Italy) · reverse-charge VAT routing · GDPR Art. 28 DPA.

SASaudi Arabia (KSA)

ZATCA Phase 1 bilingual invoice (AR/EN) · TLV QR with 5 mandatory tags · Phase 2 ready.

AEUnited Arab Emirates

GCC VAT 5% · bilingual Arabic/English invoices · FTA-compliant tax invoice numbering.

CACanada

GST/HST/PST/QST by province · PIPEDA · breach notification to OPC · French-language invoices.

AUAustralia

GST 10% · ABN withholding 49% when no ABN · Privacy Act 1988.

USUnited States

State sales-tax routing · 50-state holiday calendars · CCPA / CPRA · HIPAA BAA on Scale tier.

One tax engine. Every jurisdiction. Right the first time.

Tax routing, e-invoicing, withholding, and QR-code compliance — built into every invoice your team raises.

Intra-state vs Inter-state routing

Same-state job? CGST + SGST. Different state? IGST. The engine picks the right tax based on supplier and place-of-supply addresses.

India · GST

India IRN e-invoice generation

IRN-ready invoice format with signed QR for invoices > ₹5cr aggregate turnover · 24h cancellation window enforced.

India · IRN

UK CIS automatic deduction

20% / 30% / 0% verification status applied per subcontractor · CIS deduction on invoices return ready · gross-status registers track expiry.

UK · CIS

KSA ZATCA TLV QR code

5 mandatory tags (seller name, VAT, timestamp, total, VAT amount) encoded as TLV · bilingual Arabic/English layout · cryptographic stamp Phase 2 ready.

KSA · ZATCA

Speaks your team's language. Reads in your customer's.

Every label, every notification, every PDF — in 6 languages, including full right-to-left layout for Arabic.

EN
English

Your data. Your control.

ES
Español

Tus datos. Tu control.

FR
Français

Vos données. Votre contrôle.

AR
العربية (RTL)

بياناتك. تحت سيطرتك.

HI
हिन्दी

आपका डेटा। आपका नियंत्रण।

TA
தமிழ்

உங்கள் தரவு. உங்கள் கட்டுப்பாடு.

Your business data is fenced off from every other business — at the database itself.

Banking-grade tenant separation. Your customer list stays locked away from every other business on the platform — enforced at the database for every read, every write, every join, with no application-layer escape hatch.

  • Isolation enforced deep in the database on every request.
  • Every request scoped to your business on 100% of routes — not just trusting the app.
  • Super-admin actions audit-logged with impersonation trail.
  • Continuously tested run in CI on every commit — zero leak budget.
  • HSN code lookup + B2B GST invoice flows respect tenant boundary.
A Acme HVAC Business A ISO B Bright Plumb Business B ISO C CivilCo Ltd Business C ISO + more businesses... Database-level tenant isolation

Trust looks different in different industries

Composite scenarios from how operators across our regions actually use SyncHQ Pro safely.

India · Procurement

"We needed our vendor bank details safe."

A 50-staff HVAC operator in Bangalore was nervous about storing supplier account numbers in a SaaS — concerned about breach exposure and audit findings under DPDPA 2023.

Outcome: Account numbers are encrypted at rest; masked in lists; full reveal requires role permission and is audit-logged. The finance head gets the audit trail; the techs never see the masked field at all.
UK · GDPR

"A customer asked for their data — all of it."

A London-based plumbing firm received their first GDPR Article 15 access request. They had 30 days. No process. No tooling.

Outcome: Built-in customer data export delivered everything — invoices, jobs, communications, photos — as a single ZIP, ready to send. The whole thing took 12 minutes, not 12 days.
UAE · Audit

"Our auditors wanted to see who changed what."

A Dubai general contractor's annual VAT audit asked for evidence that invoices weren't being back-dated or modified after issue.

Outcome: The tamper-evident audit log showed every invoice action with user, timestamp, and change reason. The auditor signed off in one meeting.

What you might be wondering

Real questions we get from buyers' procurement and security teams.

Where is my data stored?

By default, in our primary data centre in India. We do not move your data to another region without notifying you in advance.

Do you use my data to train AI models?

No. Our contracts with AI providers explicitly forbid training on our customers' data, and we operate a workspace-level "AI Training Opt-Out" toggle that's on by default for every new tenant. Your business never trains a model — yours or anyone else's.

What happens if there's a security incident?

If we determine an incident affected your data, you'll be notified within 72 hours — required under GDPR, contractual for all customers. You receive the incident details, the affected data scope, the remediation status, and a post-incident report once the investigation closes.

Can I have a Data Processing Agreement (DPA)?

Yes. A pre-signed DPA aligned with GDPR Art. 28 and DPDPA Section 8 is available to every customer. For HIPAA-adjacent use, we offer a Business Associate Agreement (BAA) on the Scale tier. Email legal@servicesynchq.com.

What if I want to leave SyncHQ Pro?

Your data is exportable as JSON, CSV, or PDF — anytime, from self-serve settings. After cancellation we keep your data accessible for 30 days, then permanently delete or anonymise it within 90 days. Statutory financial records are retained for the legally required period.

What about the customer data I store in your platform?

You are the controller for your customers' data; we are the processor. We honour data-subject requests at your direction. Your customers' portal access is single-use, time-limited (1-30 days, configurable), and revocable from your admin panel.

How can I see what my team has done?

Owners and Admins can view the audit log for the workspace any time from Settings > Audit log. Every privileged action — user creation, role change, sensitive-data reveal, deletion — is recorded with the actor, timestamp, and (where applicable) reason.

Found something? Tell us — we'll thank you.

If you believe you've found a security vulnerability, please email security@servicesynchq.com. We acknowledge within 24 hours, treat reports in confidence, and credit researchers. Safe-harbour applies for good-faith research.

security@servicesynchq.com