Privacy policy
How SayNeel Technologies Private Limited collects, uses, shares and protects personal data.
On this page
- Who this policy applies to
- Information we collect
- How we use information
- Legal basis and consent
- Children's data
- Sharing and disclosure
- Storage location and transfers
- How long we keep information
- Security practices
- Your rights
- Cookies and analytics
- Client data we process on instruction
- Accessibility
- Changes to this policy
- How to contact us
1. Who this policy applies to
This policy explains how SayNeel Technologies Private Limited ("SayNeel", "we", "us") handles personal data. It covers:
- Visitors to this website;
- People who contact us by email or telephone about services, careers, investment or partnerships;
- Users of products published by SayNeel, including BalSaathi, to the extent that a product-specific privacy notice does not apply;
- Representatives of our clients, suppliers and partners.
Where we build or operate software for a client, that client is normally the entity that decides why and how personal data is processed. In those cases we act on their instructions and their privacy notice governs the processing. Section 12 explains this in more detail.
BalSaathi has its own in-product privacy notice and consent flow covering health and children's data. Where the two documents differ in respect of BalSaathi, the in-product notice prevails.
2. Information we collect
2.1 Information you give us
- Contact details — name, email address, telephone number, organisation and role, when you email or call us.
- Enquiry content — whatever you choose to tell us about your project, organisation or requirements.
- Recruitment information — CV, education and employment history, portfolio links and any other material you send when applying for a role.
- Newsletter subscription — your email address, if you ask to be added to our mailing list.
This website does not contain a contact form. Information reaches us only when you deliberately send an email, place a call, or otherwise contact us.
2.2 Information collected automatically
- Technical data — IP address, browser type and version, operating system, device type, referring page and pages viewed, recorded in standard web server logs by our hosting provider.
- Preference data — your light or dark theme choice, stored in your browser's local storage on your own device. This never leaves your device and is not readable by us.
2.3 Information we do not collect on this website
- We do not run advertising networks or behavioural advertising trackers on this website.
- We do not sell personal data to anyone, in any circumstances.
- We do not use social media tracking pixels on this website.
- We do not collect payment card details through this website.
3. How we use information
| Purpose | Information used |
|---|---|
| Replying to your enquiry and discussing a possible engagement | Contact details, enquiry content |
| Preparing proposals, contracts and invoices | Contact and organisation details |
| Delivering and supporting services we have been engaged to provide | Contact details, project information |
| Assessing job applications and running our hiring process | Recruitment information |
| Sending our newsletter, where you have asked for it | Email address |
| Keeping the website secure, available and free of abuse | Technical data |
| Meeting legal, tax, accounting and regulatory obligations | Transaction and contact records |
We do not use your information to make decisions about you by automated means alone.
4. Legal basis and consent
We process personal data in accordance with the Digital Personal Data Protection Act, 2023 and other applicable Indian law. Our processing rests on one of the following:
- Your consent — for example, when you subscribe to the newsletter. Consent may be withdrawn at any time and withdrawal is as easy to exercise as giving consent was.
- Certain legitimate uses recognised in law — for example, responding to an enquiry you voluntarily sent us for that purpose, or processing an application for employment.
- Performance of a contract — where processing is necessary to deliver services you or your organisation has engaged us to provide.
- Legal obligation — where a statute, regulator or court requires us to retain or disclose information.
5. Children's data
This website is not directed at children and we do not knowingly collect personal data from children through it.
Our BalSaathi product does process data relating to children, because that is its purpose. Where it does, we apply the strictest handling standard we operate anywhere:
- Data relating to a child is processed only with verifiable consent from a parent or lawful guardian, obtained in language they understand.
- Consent is granular: separate categories of use and sharing are consented to separately, and each can be withdrawn independently.
- We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and BalSaathi carries no behavioural advertising at all.
- Children's data is not sold, rented or made available for any commercial purpose unrelated to the child's care.
- Access is limited to those with a defined role in the child's care or programme, for the period of that role only, and every access is logged.
The full detail, including how consent is captured and withdrawn, is set out in the BalSaathi in-product privacy notice.
6. Sharing and disclosure
We share personal data only in the following circumstances:
- Service providers who process data on our behalf under written contract — cloud hosting, email, and business software providers. They may use the data only to provide the service to us.
- Professional advisers — lawyers, auditors and accountants, under professional duties of confidence.
- Legal requirement — where disclosure is required by law, regulation, court order or a lawful request from a public authority.
- Business transfer — if the business or part of it is reorganised, merged or acquired, in which case the recipient remains bound by this policy in respect of the transferred data.
We do not sell personal data, and we do not disclose it to advertisers or data brokers.
7. Storage location and transfers
We host our systems in Indian data-centre regions by default. For client and product deployments where data residency is a requirement — including all government work and BalSaathi — data is stored and processed within India.
Some corporate tools we use for general business administration may process limited data outside India. Where that happens, we take reasonable steps to ensure appropriate contractual and security protections are in place, and we do not use such tools for health data, children's data or client production data.
8. How long we keep information
| Category | Retention period |
|---|---|
| Enquiries that do not lead to an engagement | Up to 24 months from last contact |
| Client records, contracts and correspondence | Duration of the engagement plus the period required by tax and company law |
| Financial and statutory records | As required under the Companies Act, 2013 and applicable tax law |
| Unsuccessful job applications | Up to 12 months, unless you ask us to keep them longer for future roles |
| Newsletter subscriptions | Until you unsubscribe |
| Web server logs | Typically 30 to 90 days, per our hosting provider's configuration |
When a retention period ends, data is deleted or irreversibly anonymised.
9. Security practices
We apply the following as standard, both to our own systems and to systems we build:
- Encryption of data in transit (TLS) and at rest;
- Role-based access control and least-privilege access for our own staff;
- Audit logging of access to sensitive records;
- Secrets management, credential rotation and multi-factor authentication on administrative accounts;
- Dependency and container vulnerability scanning in our build pipelines;
- Development practices aligned to the OWASP Application Security Verification Standard;
- Regular backups with tested restoration procedures;
- Confidentiality obligations in every employment and contractor agreement.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to affect you, we will notify you and the relevant authority as required by law, and we will tell you what happened and what we are doing about it.
10. Your rights
Subject to the conditions and exemptions in applicable law, you may:
- Access a summary of the personal data we hold about you and how it is processed;
- Correct data that is inaccurate, and complete data that is incomplete;
- Erase data where it is no longer needed for the purpose it was collected for and no legal obligation requires us to keep it;
- Withdraw consent at any time, where processing is based on consent;
- Nominate another person to exercise these rights on your behalf in the event of your death or incapacity;
- Complain to us, and subsequently to the Data Protection Board of India if you are not satisfied with our response.
To exercise any of these, email privacy@sayneeltech.in. We respond within 30 days, and will tell you if we need to verify your identity first.
Where a request relates to data we process on behalf of a client, we will forward it to that client and assist them in responding.
11. Cookies and analytics
This website does not set advertising or tracking cookies. It stores a single theme preference in your browser's local storage, which stays on your device. Full detail, including what happens if you enable analytics later, is in our Cookie policy.
12. Client data we process on instruction
When we build or operate software for a client, personal data within that system is normally controlled by the client. In that role:
- We process data only on the client's documented instructions;
- We do not use client data for our own purposes, including model training, without explicit written agreement;
- We apply the security measures in section 9 and any additional measures agreed contractually;
- We assist the client in responding to data-principal requests and in meeting their own obligations;
- We engage sub-processors only under written terms no less protective than our own, and we tell the client who they are;
- On termination we return or delete the data as the client directs.
If you are an individual whose data is held in a system we operate for a client, please contact that organisation first. If you cannot identify them, write to us and we will help.
13. Accessibility
We aim to meet WCAG 2.2 Level AA across this website and the products we build. That includes keyboard operability, visible focus indicators, sufficient colour contrast, screen-reader-compatible markup, and respect for reduced-motion preferences.
If any part of this site is difficult for you to use, tell us at contact@sayneeltech.in and we will fix it and give you the information you needed by another route in the meantime.
14. Changes to this policy
We update this policy when our practices or the law change. The date at the top of the page shows when it was last revised. Material changes affecting how we use data you have already given us will be notified directly where we hold contact details for you.
15. How to contact us
For any privacy question, request or complaint:
- Email: privacy@sayneeltech.in
- General enquiries: contact@sayneeltech.in
- Post: SayNeel Technologies Private Limited, Pune, Maharashtra, India
If you are not satisfied with our response, you may complain to the Data Protection Board of India.