Back to Home

Data Security Policy

SerpY — Smart ERP for Modern Manufacturers

Issued by Synx Automation Private Limited | March 2026

CIN: U62099KL2024PTC087457 | GSTIN: 32ABNCS3504L1Z8

77 Spaces, Kumarapuram, Trivandrum, Kerala – 695011, India

1. Purpose & Scope

This Data Security Policy ("Policy") describes the technical and organisational security measures implemented by Synx Automation Private Limited ("Synx") to protect all data processed through SerpY ("the Service") at https://www.serpy.in.

This Policy applies to all data stored, transmitted, or processed by Synx on behalf of subscribers and their teams, including job records, inventory data, invoices, customer information, procurement records, and user account data.

The Policy is aligned with the Information Technology Act, 2000, SPDI Rules, 2011, Digital Personal Data Protection Act, 2023, and ISO/IEC 27001 principles.

2. Data Classification

ClassificationExamplesProtection Level
ConfidentialCustomer PII, GSTIN, payment data, credentialsHighest — encrypted at rest and in transit
Business DataJob records, inventory, invoices, schedulesHigh — subscriber-owned
InternalUsage analytics, operational logsStandard — restricted to Synx teams
PublicMarketing content, feature descriptionsNone — freely accessible

3. Infrastructure & Hosting Security

3.1 Cloud Infrastructure

SerpY is hosted on enterprise-grade cloud infrastructure (AWS, Google Cloud, or equivalent) providing:

  • Geographically distributed data centres with physical access controls and biometric entry.
  • Automatic, encrypted backups with a Recovery Point Objective (RPO) of 24 hours.
  • Intrusion detection (IDS) and intrusion prevention (IPS) systems.
  • Firewall rules, network segmentation, and DDoS mitigation.

3.2 Data Encryption

  • In Transit: All data transmitted uses TLS 1.2 or higher (HTTPS).
  • At Rest: Sensitive data (PII, financials) is encrypted using AES-256.
  • Database: Production databases are encrypted at the volume level.
  • Backups: All backup data is encrypted prior to storage.

4. Application Security

Application controls are maintained against the OWASP Top 10 framework, including protection against SQL injection, XSS, and CSRF. We use automated static analysis and dependency scanning on every release. Periodic third-party penetration tests are conducted.

5. GST & Invoice Data Security

  • All invoice data in access-controlled databases separate from general data.
  • GSTIN data is validated and stored in encrypted form.
  • Audit trails for all invoice events are maintained for 7 years.

6. Access Control

We implement the Principle of Least Privilege. Multi-Factor Authentication (MFA) is required for all Synx administrative access to production systems. Production deployments require multi-person authorisation.

7. Data Breach Response

In the event of a breach, we will isolate affected systems, investigate within 24 hours, and notify affected subscribers within 72 hours where required by the DPDPA 2023 and IT Act.

8. Third-Party & Vendor Security

All third-party vendors with access to subscriber data are engaged under contractual agreements requiring security standards equivalent to or higher than those described in this Policy.

9. Employee & Internal Security

All Synx employees receive data security training and undergo background verification. All company-managed devices are encrypted and subject to remote wipe capability.

10. Subscriber Responsibilities

Subscribers must maintain credential confidentiality, assign minimum necessary roles, and revoke access promptly when staff leave.

11. Business Continuity & Disaster Recovery

RTO: targeted within 4 hours. RPO: targeted at no more than 24 hours. Redundancy is maintained across multiple availability zones.

12. Compliance Framework

Aligned with IT Act 2000, DPDPA 2023, ISO/IEC 27001, and GST Act requirements.

13. Policy Review

This Policy is reviewed at minimum annually, or following any significant security incident or regulatory change.

14. Contact

Synx Automation Private Limited
Trivandrum, Kerala – 695011, India
Email: legal@synxautomate.com