Privacy Policy
Last Updated: 31st Dec 2024
1. INTRODUCTION
- This privacy policy governs the manner in which M/s. Synerthink Solutions LLP (“Synerthink”, “We”, “Us”, or “Our”) collects, uses, maintains and discloses information collected from users of the https://certifi.biz website (“Website”) and/or application https://play.google.com/store/apps/details?id=com.certifi (“App”) (collectively referred to as “Platforms”). This privacy policy applies to the Platforms and all services offered by Synerthink. You agree to and are bound by the terms and conditions set forth below and in any modified or additional terms that Synerthink may publish from time to time (collectively, the “Privacy Policy”).
2. DEFINITIONS
- “Product(s)“ means and includes any products / services / offers / display items that are uploaded/showcased/displayed on the Platforms and the related description, information, procedure, processes, warranties, delivery schedule, etc.
- “Personal Data“ means any data about an individual who is identifiable by or in relation to such data.
- “Third Parties“ means and includes third-party vendors and/or third-party processors engaged by Synerthink during the course of its business.
- “Applicable Laws“ shall mean, without limitation, all relevant statutes, enactments, ordinances, regulations, rules, guidelines, directives, codes of practice, and other legal requirements, including the Information Technology Act 2000, Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, Directions under sub-space-y-2 (6) of space-y-2 70B of the Information Technology Act, 2000 relating to Information Security Practices, Procedure, Prevention, Response and Reporting of Cyber Incidents for Safe & Trusted Internet dated 28 April 2022, and any other laws, regulations, or directives as may be applicable, amended, substituted, or re-enacted from time to time.
3. SCOPE OF THE PRIVACY POLICY
- This Privacy Policy applies to everyone who visits and/or uses our Platforms, (“collectively referred to as “Users” or “you”). This Privacy Policy does not extend to any websites or applications that may be accessed from the Platforms including, but not limited to any links we may provide to any other websites or applications.
- We follow this Privacy Policy in accordance with the Applicable Laws. For some services offered by us, applications, or events, we may have additional privacy notices. These notices should be read together with this Privacy Policy.
- By using our Platforms, you agree to comply with all Applicable Laws and regulations governing your use of our Platforms and in particular agree to adhere to your duties under the (Indian) Digital Personal Data Protection Act, 2023. You further agree to adhere to the terms and conditions set forth in our Terms of Use, which govern the permissible use of our Platforms. You may access our Terms of Use here.
- All undefined terms used in this Privacy Policy shall have the meaning assigned to them in the Terms of Use.
4. PERSONAL DATA WE COLLECT FROM YOU
- We may collect Personal Data from Users on various occasions, including, but not limited to the following:
- When Users visit our Platforms.
- When Users register on our Platforms, avail our services through our Platforms, and or in connection with other activities, features or resources we make available on our Platform.
- We may collect, use, store and transfer different kinds of Personal Data about you including the below mentioned:
- Name
- Government identification proof
- Financial information
- E-mail address
- Mailing address
- Phone number
- Data collected through cookies, such as the pages you visit, your interests, your internet protocol information, etc.
- We may collect Personal Data from you only if you voluntarily submit such information to us. Users can always refuse to provide Personal Data, except that it may prevent them from engaging in or accessing certain parts or services provided on our Platforms.
- You acknowledge and agree that the provision of our services requires you to provide us the recipient's Personal Data. You further agree to provide such Personal Data only after obtaining the explicit and proper consent from the recipient in accordance with all Applicable Laws. You accept full responsibility for ensuring that the necessary consent has been obtained and agree that we shall not be liable for any claims, damages, or liabilities arising from your failure to obtain such consent or from the use of the Personal Data provided. You shall indemnify and hold harmless us, our affiliates, officers, employees, and agents from any and all claims, actions, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or in connection with your failure to obtain the necessary consent or any violation of Applicable Laws in relation to the collection and processing of Personal Data.
5. PURPOSES FOR COLLECTING YOUR PERSONAL DATA
- Synerthink may collect and use Users personal information for the following purposes:
- As part of our service:
- The internet protocol (IP) address from where the User may access the system for making the agreement is recorded for addressing any future dispute.
- Personal Data of the User, such as the name, e-mail address, phone number are collected for creating digital proof of delivery certification.
- Financial information is collected to verify the identity and facilitate payments and security purposes.
- IP address of the system used by the User to access the Platforms are recorded for creating digital proof of existence certificate.
- The information collected as mentioned above in paragraph 5.1(a)(i) and paragraph 5.1(a)(ii) shall only be used for complaint resolution and for performance improvement
- The communication intended to be processed for certification is collected from registered Users and is stored in our systems for forward transmission and delivery certification
- Recipient’s Personal Data will be used for generating the certificate and will be used as a part of mandatory information in order to make a proof of delivery having legal sanctity.
- To personalize user experience: We may use Personal Data in an aggregate form to understand how our Users use the services and resources provided on our Platforms.
- To improve our Platforms: We may use the feedback you provide to improve our products and services.
- To send periodic e-mails: We may use the e-mail address stored in our systems to send User information and updates pertaining to their services. It may also be used to respond to their inquiries, questions, and/or other requests. If User decides to opt-in to our mailing list, they will receive e-mails that may include news regarding Synerthink, updates, related service information, etc. If at any time the User would like to unsubscribe from receiving future e-mails, we include detailed unsubscribe instructions at the bottom of each e-mail or User may contact us via our Website.
- To run a promotion, contest, survey or other Website feature: To send Users information they agreed to receive about topics we think will be of interest to them.
6. CHANGE IN PURPOSE FOR COLLECTING PERSONAL DATA
- We will only use your Personal Data for the purposes for which we collected it. If we need to use your Personal Data for another purpose, we will tell you about it and explain why we are doing it. We may also ask for your permission, depending on the applicable laws.
- We may also process your Personal Data for certain legitimate purposes as per Applicable Laws.
7. WEB BROWSER COOKIES
- As you interact with our Platforms, we will automatically collect technical data about your device, browsing actions and patterns. We collect this Personal Data by using cookies. The Personal Data collected by using cookies is used to customize the Platforms and enhance the value of the features offered through our Platforms. To learn more about cookies and how we use them, see our Cookie Policy.
8. STORAGE AND RETENTION OF YOUR PERSONAL DATA
- All the Personal Data provided by you will be uploaded to secure servers in India that are controlled by us. We may also use third party processors to store Personal Data collected from you.
- All readable data of the communications made by the User will not be retained (and will be deleted) from Synerthink’s systems after two days (A+2 days) of generation of the Certificate. For clarity, “A+2 days” means the date on which the Certificate is generated (“A”), plus an additional two full calendar days. For instance, if the Certificate is generated on December 10 at 18:00 hours, the data will be retained until 23:59 hours on December 12 and then deleted. Users are advised to download their Certificates and associated data within this timeframe unless they have opted for extended retention options.
- The generated certificates are stored only in non-readable format (HASH) for future cross verification of issued certificates by the User.
- We may also anonymise your Personal Data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
- We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
- Typically, we determine the appropriate retention period for Personal Data by considering the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements.
9. HOW WE PROTECT YOUR INFORMATION
- Synerthink treats all Personal Data it receives from you as confidential and does not use the Personal Data for any purpose other than in accordance with this Privacy Policy. We have security measures in place to protect your Personal Data from unauthorized access, use, or disclosure.
- We regularly review our security measures to make sure they are keeping your Personal Data safe. However, no security measures are perfect.
- We implement reasonable security practices and procedures and have a comprehensive documented information security programme and information security policies that contain managerial, technical, operational and physical security control measures that are commensurate with respect to the information being collected and the nature of our business. We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorized access, alteration, disclosure or destruction of your personal information, username, password, transaction information and data stored on our Platforms and servers.
- Sensitive and private data exchange between the Platforms and its Users happens over an SSL secured communication channel and is encrypted and protected with digital signatures.
10. DATA TRANSFERS OUTSIDE INDIA
- We do not transfer any Personal Data outside the territory of India. All Personal Data collected and processed by us will remain stored and maintained within servers located in India, in compliance with Applicable Laws.
- If we transfer Personal Data outside India, we will ensure such transfers follow Applicable Laws
11. YOUR LEGAL RIGHTS
- Under the (Indian) Digital Personal Data Protection Act. 2023, you have the following rights:
- Right to access information: You can ask us for the following information:
- A summary of the Personal Data we have about you.
- What we do with your Personal Data.
- Who we share your Personal Data with.
- What Personal Data we have shared with other organizations.
- Right to correction, completion, and erasure: You have the right to ask us to correct, complete, or erase your Personal Data. This means that you can ask us to:
- Fix any mistakes in your Personal Data.
- Add any missing information to your Personal Data.
- Delete your Personal Data.
- Right to grievance redressal: You have the right to complain to us if you believe we have violated your privacy rights. You may reach out to our Data Grievance Officer at support@synerthinksolutions.com to file a complaint. In the event of you not being satisfied with the resolution provided by our Data Grievance Officer, you may also reach out and complain to the Data Protection Board of India in the manner mentioned in paragraph 12 below.
- Right to nominate:You can choose someone to exercise your privacy rights on your behalf if you are unable to do so yourself. This could be because of death or an inability to exercise your rights due to unsoundness or mind or bodily infirmity.
- Right to appoint consent manager: You can choose to appoint a consent manager i.e., registered with the Data Protection Board of India to give, manage, review or withdraw consent on your behalf.
- Right to withdraw consent: You can withdraw your consent to us processing your Personal Data at any time. We will stop processing your Personal Data once you withdraw your consent. However, withdrawing your consent will not affect any processing that we did before you withdrew your consent. We may also be unable to provide you with certain products or services if you withdraw your consent. We will tell you if this is the case when you withdraw your consent.
- Right to access information: You can ask us for the following information:
- If you wish to withdraw your consent to us processing of your Personal Data, please e-mail us at support@synerthinksolutions.com.
- If you wish to exercise any other rights set out above, please contact us on the address mentioned in paragraph 16 hereinbelow.
- We may need to request specific information from you to help us verify your identity. This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
- The rights set out above are not absolute and are subject to exemptions and limitations as provided under the Applicable Law.
12. RIGHT TO COMPLAINT TO DATA PROTECTION BOARD OF INDIA
- You also have the right to make a complaint at any time to the Data Protection Board of India, which is the supervisory authority for data protection in India on.
13. EXTERNAL LINKS
- Our Platforms may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share Personal Data about you. We do not control these third party websites and assume no responsibility or liability for the actions, products, services, and content of any other third parties. We encourage you to carefully review the legal statements and other conditions of use of for website you access.
14. REFUSAL TO PROVIDE PERSONAL DATA
- Where we need to collect Personal Data by Applicable Laws, or under the terms of any agreement we have with you, and you fail to provide that Personal Data when requested, we may not be able to deliver the functionalities of our Platforms or any part thereof.
15. CHANGES TO THIS PRIVACY POLICY
- We may change this Privacy Policy from time to time. We encourage Users to frequently check this page for any changes to stay informed about how we are helping to protect the personal information we collect, and we will always show the date of the latest modification of the Privacy Policy. You acknowledge and agree that it is your responsibility to review this privacy policy periodically and become aware of modifications.
16. CONTACT OUR DATA PROTECTION OFFICER
- If you have any questions or comments about our policy outlined above, you may contact our Data Protection Officer whose role includes acting as a point of contact for users in relation to concerns around how their data is processed. The contact details are as follows:
- Data Protection Officer
- Email: support@synerthinksolutions.com
17. DISPUTE RESOLUTION
- In the event of any dispute arising out of or in connection with this Privacy Policy, including disputes relating to the interpretation, breach, or enforcement of this Privacy Policy, they shall be resolved in conjunction with the procedures and dispute resolution mechanisms set forth in the Terms of Use.
