SerpY — Smart ERP for Modern Manufacturers
Issued by Synx Automation Private Limited | March 2026
CIN: U62099KL2024PTC087457 | GSTIN: 32ABNCS3504L1Z8
77 Spaces, Kumarapuram, Trivandrum, Kerala – 695011, India
This Data Security Policy ("Policy") describes the technical and organisational security measures implemented by Synx Automation Private Limited ("Synx") to protect all data processed through SerpY ("the Service") at https://www.serpy.in.
This Policy applies to all data stored, transmitted, or processed by Synx on behalf of subscribers and their teams, including job records, inventory data, invoices, customer information, procurement records, and user account data.
The Policy is aligned with the Information Technology Act, 2000, SPDI Rules, 2011, Digital Personal Data Protection Act, 2023, and ISO/IEC 27001 principles.
| Classification | Examples | Protection Level |
|---|---|---|
| Confidential | Customer PII, GSTIN, payment data, credentials | Highest — encrypted at rest and in transit |
| Business Data | Job records, inventory, invoices, schedules | High — subscriber-owned |
| Internal | Usage analytics, operational logs | Standard — restricted to Synx teams |
| Public | Marketing content, feature descriptions | None — freely accessible |
3.1 Cloud Infrastructure
SerpY is hosted on enterprise-grade cloud infrastructure (AWS, Google Cloud, or equivalent) providing:
3.2 Data Encryption
Application controls are maintained against the OWASP Top 10 framework, including protection against SQL injection, XSS, and CSRF. We use automated static analysis and dependency scanning on every release. Periodic third-party penetration tests are conducted.
We implement the Principle of Least Privilege. Multi-Factor Authentication (MFA) is required for all Synx administrative access to production systems. Production deployments require multi-person authorisation.
In the event of a breach, we will isolate affected systems, investigate within 24 hours, and notify affected subscribers within 72 hours where required by the DPDPA 2023 and IT Act.
All third-party vendors with access to subscriber data are engaged under contractual agreements requiring security standards equivalent to or higher than those described in this Policy.
All Synx employees receive data security training and undergo background verification. All company-managed devices are encrypted and subject to remote wipe capability.
Subscribers must maintain credential confidentiality, assign minimum necessary roles, and revoke access promptly when staff leave.
RTO: targeted within 4 hours. RPO: targeted at no more than 24 hours. Redundancy is maintained across multiple availability zones.
Aligned with IT Act 2000, DPDPA 2023, ISO/IEC 27001, and GST Act requirements.
This Policy is reviewed at minimum annually, or following any significant security incident or regulatory change.
Synx Automation Private Limited
Trivandrum, Kerala – 695011, India
Email: legal@synxautomate.com