LEGAL / PRIVACY NOTICE

Privacy Policy

We are a security and privacy consultancy, so we hold ourselves to the standard we ask of clients: collect little, protect it well, delete it on time.

Last updated: 5 September 2026

1. Who we are

SYIT ("we", "us") is a cybersecurity and data privacy consultancy serving startups and individuals. For any privacy question, write to privacy@syit.io.

2. What we collect

  • Contact details you give us — name, email, company and the message you submit through our contact form or by email.
  • Engagement information — information you share with us during an assessment, such as system descriptions, configurations and findings.
  • Basic technical data — server logs such as IP address, browser type and pages requested, used to keep this website available and secure.

We do not sell personal data, and we do not use it for advertising profiling.

3. Why we use it

  • To reply to your enquiry and provide the services you asked for.
  • To perform a contract with you, including reporting and remediation support.
  • To meet legal, accounting and security obligations.
  • To protect this website against abuse and attacks (legitimate interest).

4. Cookies and analytics

This website uses only the cookies strictly necessary to serve pages. If we add analytics or any non-essential cookie in future, we will ask for consent first and update this notice.

5. How long we keep data

Enquiries that do not become engagements are deleted within 12 months. Engagement records, including technical findings, are retained for up to 3 years for legal and professional-liability reasons, then deleted or anonymised. Server logs are kept for up to 90 days.

6. Sharing and processors

We share personal data only with service providers needed to operate — for example email hosting, cloud hosting and accounting — under written agreements that restrict their use of it. We disclose information to authorities only where legally required.

7. Confidentiality of engagement data

Security findings are highly sensitive. They are stored encrypted, accessible only to the consultants working on your engagement, and are never used as public case studies without your written permission.

8. International transfers

Where data is processed outside your country, we rely on appropriate safeguards such as standard contractual clauses with our providers.

9. Your rights

Depending on where you live (including under the EU/UK GDPR and India's Digital Personal Data Protection Act), you may ask us to: access a copy of your data; correct it; delete it; restrict or object to processing; withdraw consent; or receive it in a portable format. You may also complain to your local data protection authority.

To exercise any right, email privacy@syit.io. We respond within 30 days.

10. Security

We use encryption in transit and at rest, multi-factor authentication, least-privilege access and endpoint hardening on every device that touches client data.

11. Children

Our services are not directed at children. We do not knowingly collect data from anyone under 18 without a parent or guardian's involvement.

12. Changes

We will update this page when our practices change and revise the date above. Material changes affecting existing clients are communicated by email.

13. Contact

Questions about this notice? Get in touch or read our terms & conditions.