Privacy
Privacy Notice
How Syntix handles personal data when you visit this website, contact us, apply for a role or interact with us in a business capacity.
Last reviewed: 13 August 2026
1. Controller and contact
The controller for the processing described in this notice is Syntix Business Systems & Services (SMC-Private) Limited, trading as Syntix Business Systems.
Registered office: 417 Block A, AWT Phase 2, Shareef Medical Road, Lahore, Punjab, Pakistan.
Email: [email protected]
Phone: +92 304 529 9983
This is an international B2B website. Which privacy rights and regulatory rules apply depends on the individual, the processing activity and the applicable law.
2. Personal data we process
Website and security data. Requests to the website may generate technical information such as IP address, browser and device information, user-agent, request timing, hostname, security events and anti-abuse signals.
Business inquiries. Our inquiry forms currently ask for a name, work email, company name, optional company website and answers describing the business or delivery requirement. The server may also record the source page and browser user-agent for security and operational context.
Business contacts and professional correspondence. If we communicate with a person in their professional capacity, we may process their name, role, company, business contact details, correspondence, meeting notes and the source of those details. Where details were not supplied directly by that person, sources may include their employer's website, professional directories, professional networks, referrals or other legitimately available business sources.
Recruitment. If you apply for a role or contractor opportunity, we may process your contact details, location, availability, work history, skills, application answers and CV, portfolio or professional-profile information that you choose to provide.
Please do not submit passwords, access keys, health information, identity documents, customer secrets or confidential production data through public website forms unless Syntix specifically requests them through an approved secure channel.
3. Why we use personal data and our legal bases
Depending on the context and the law that applies, Syntix may process personal data for the following purposes and legal bases:
- Responding to B2B inquiries, assessing fit, preparing proposals and managing professional relationships: our legitimate interests in operating and developing our business, and steps requested before entering a contract where that basis applies.
- Providing and securing the website, preventing abuse and protecting forms: our legitimate interests in security, service integrity and fraud or bot prevention, together with any rules that permit strictly necessary storage or access technologies.
- Managing signed client or supplier relationships: performance of contractual obligations, legitimate business administration and legal obligations where applicable.
- Recruitment: steps taken at an applicant's request before a possible employment or contractor relationship, legitimate recruitment interests and legal obligations where applicable.
- Business outreach: legitimate interests may support the processing of relevant professional contact data where the applicable data-protection law permits it. This does not override separate electronic-marketing, e-privacy or unfair-competition rules that may require consent or impose additional conditions in a particular country.
- Legal, compliance and dispute purposes: compliance with applicable obligations and our legitimate interests in establishing, exercising or defending legal claims.
Where we rely on consent for a specific activity, you may withdraw that consent for future processing. Withdrawal does not affect processing that was lawful before withdrawal.
4. Website providers and recipients
We disclose personal data only where needed for the relevant purpose, subject to appropriate access and contractual controls. Current website infrastructure may involve:
- Cloudflare for website delivery, security, rate limiting and Cloudflare Turnstile anti-bot checks. Turnstile may process security signals such as IP address, TLS/browser characteristics, user-agent and the sitekey/origin.
- Supabase as the database processor for Syntix company-website inquiry records.
- Resend if website inquiry email notifications are enabled. In that case, the information needed to send the notification is transmitted to Resend.
- Professional advisers, insurers, auditors, authorities or other recipients where reasonably necessary for legal, security or business administration purposes.
We do not sell website inquiry data and do not use it for cross-context behavioural advertising.
5. International processing and transfers
Syntix is established in Pakistan, so information submitted to Syntix may be accessed and handled in Pakistan. The dedicated Supabase project currently used for company-website inquiries has its primary database region in Singapore. Cloudflare operates a global network. If Resend email notification is enabled, Resend states that its primary processing operations take place in the United States.
Where Syntix makes a transfer that is restricted under applicable EU, UK or Swiss data-protection law, we use an applicable transfer mechanism or other lawful safeguard as required. Relevant provider terms currently include the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and Swiss adaptations where those mechanisms apply.
Client project data is not governed only by this website notice. If Syntix processes personal data for a client as a processor or sub-processor, the project contract, data processing agreement and any required international-transfer mechanism define the operational instructions and responsibilities.
6. Retention
We do not keep personal data indefinitely. Our current website-data retention policy is:
- Business inquiries that do not become an active client relationship: normally up to 24 months after the last meaningful interaction, unless a shorter period is appropriate or a longer period is needed for a legal claim or documented business reason.
- Professional prospect/contact records: reviewed for relevance and removed or suppressed when no longer reasonably needed. A minimal suppression record may be retained to honour an objection or opt-out.
- Unsuccessful recruitment applications: normally up to 6 months after the relevant process closes, unless the applicant agrees to a longer talent-pool period or another retention need applies.
- Client, supplier, accounting and legal records: retained separately for the period required by the relevant contract, legal obligations and legitimate record-keeping needs.
- Security and provider logs: retained according to the configured service and provider terms, subject to our data-minimisation and security requirements.
These are Syntix operating periods, not statements that every applicable law prescribes the same duration.
7. Your rights
Depending on the law that applies to you and the legal basis for processing, you may have rights to request access, correction, erasure, restriction, portability, or to object to processing. Where processing is based on consent, you may have the right to withdraw it.
Direct marketing objection: if personal data is used for direct marketing, you may object at any time. Syntix will stop using that personal data for direct marketing and may keep only the minimum information needed to respect the suppression request.
To exercise a right, email [email protected]. We may need proportionate information to verify the request and may refuse or limit a request only where applicable law permits.
8. Complaints and supervisory authorities
You can contact Syntix first at [email protected] so we can investigate a privacy concern.
If applicable law gives you a right to complain to a supervisory authority, you may also contact the relevant authority. For the UK this is the Information Commissioner's Office (ICO). In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). In the EEA you may contact the competent national data-protection authority.
9. Automated decisions, children and sensitive data
Syntix does not use this website to make solely automated decisions that produce legal or similarly significant effects about website visitors or inquiry submitters. This website is intended for professional and business use and is not directed at children.
10. Changes to this notice
We review this notice when our website, providers, markets or processing practices materially change. If a new use of personal data requires additional notice or consent, we will implement that before relying on the new use where applicable law requires it.
Official regulatory references
This notice is maintained against applicable requirements rather than presented as a blanket certification. Relevant official references include the EU General Data Protection Regulation, current UK ICO data-protection guidance and Swiss FDPIC transparency guidance.