Privacy Policy
Last updated:
This policy explains what personal data we collect when you use the SupportIQ website and application, why we collect it, who we share it with, and the rights you have over it.
This is a template document. It is provided as a starting point and does not constitute legal advice. Have it reviewed by a qualified legal professional in your jurisdiction before relying on it.
1. Who we are
Skyrion Labs Private Limited ("Skyrion Labs", "we", "us") is a private limited company incorporated in India (CIN U62099UT2026PTC021778) with its registered office in Dehradun, Uttarakhand, India. We operate SupportIQ, an AI-powered customer support platform.
This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights available to you. It applies to our website and to the SupportIQ application.
For personal data that our customers upload or route through SupportIQ in the course of their own support operations, our customer is the data controller (or "data fiduciary" under Indian law) and we act as a processor on their instructions. This policy describes our own processing; our customers’ own privacy notices govern their end users.
2. Personal data we collect
Information you give us
- Account details: name, work email address, company name, and password credentials (stored only as a salted hash).
- Billing details: billing name, address, tax identifiers, and the last four digits and expiry of a payment card. Full card numbers are handled by our payment processor and never stored on our systems.
- Communications: the content of messages you send us through our contact form, by email, or through in-product support.
- Content you upload: help documentation, FAQs, ticket exports and other material you connect as a knowledge source.
Information collected automatically
- Usage data: pages and features accessed, actions taken in the application, and timestamps.
- Device and connection data: IP address, browser type and version, operating system, and referring URL.
- Cookies and similar technologies, as described in the Cookies section below.
Information from third parties
- Authentication data from single sign-on providers, where you choose to sign in that way.
- Data from helpdesk and commerce integrations you explicitly connect, limited to the scopes you authorise.
- Billing status and payment confirmations from our payment processor.
3. How we use personal data
We use personal data to provide and operate the service, and specifically to:
- Create and administer your account, and authenticate your access.
- Deliver the core functionality of SupportIQ, including indexing your connected content and generating answers from it.
- Process payments, issue invoices and manage subscriptions.
- Provide customer support and respond to your enquiries.
- Monitor service health, diagnose faults, and detect abuse, fraud and security incidents.
- Improve the product through aggregated and de-identified usage analysis.
- Send service communications about outages, security matters, billing and material changes to terms. These are operational and cannot be opted out of while you hold an account.
- Send marketing communications, where you have opted in or where permitted by applicable law. You may withdraw consent at any time.
- Comply with legal obligations and enforce our agreements.
Legal bases (where GDPR applies)
- Performance of a contract: operating the service and administering your account.
- Legitimate interests: securing the platform, preventing abuse, and improving the product, balanced against your rights and freedoms.
- Consent: optional marketing communications and non-essential cookies, which you may withdraw at any time.
- Legal obligation: tax, accounting and statutory record-keeping requirements.
4. AI processing and your content
SupportIQ generates answers using retrieval-augmented generation. When a question is asked, the system retrieves relevant passages from the knowledge sources connected to that workspace and passes them, together with the question, to a foundation model hosted by our cloud infrastructure provider under a commercial agreement that prohibits training on our data.
The following commitments apply to content processed through the service:
- We do not use customer content to train foundation models, and we do not permit our model providers to do so.
- Content connected to one workspace is not used to answer questions in another workspace.
- Conversation transcripts are retained so that you can review answer quality, audit escalations and measure performance. You control the retention period on paid plans.
- You may delete a knowledge source or an entire workspace at any time, which removes the associated indexed content from active systems.
Automated answers are generated by a machine learning system and may contain errors. The service provides confidence thresholds, source citations and escalation rules so that a human can review or take over. We recommend keeping human oversight for decisions that materially affect an individual.
6. International data transfers
We host customer data in an Indian data-centre region by default. Certain sub-processors may process data in other jurisdictions, including the European Union and the United States.
Where personal data is transferred out of a jurisdiction that restricts such transfers, we rely on an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses, together with supplementary technical measures including encryption in transit and at rest.
Enterprise customers may request data residency in a specific region as part of their agreement.
7. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Account data is retained for the life of your account and for up to 90 days after closure, to allow for reactivation and dispute resolution.
- Knowledge base content and conversation transcripts are retained according to your workspace settings. Free plans default to 12 months; paid plans allow a configurable period.
- Billing and tax records are retained for the period required by Indian statutory law, currently eight financial years.
- Security and access logs are retained for up to 12 months.
On deletion, data is removed from active systems immediately and purged from encrypted backups within 35 days as those backups age out of rotation.
8. Security
We maintain technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS 1.2 or above, and encryption at rest using managed encryption keys.
- Logical isolation of each customer workspace and its indexed content.
- Role-based access control, with internal access to production data restricted to personnel who require it and logged for audit.
- Multi-factor authentication on internal administrative systems.
- Continuous monitoring of infrastructure health, and automated encrypted backups with a documented recovery process.
No system can be guaranteed completely secure. If we become aware of a personal data breach affecting your data, we will notify you and the relevant supervisory authority without undue delay and in accordance with applicable law.
9. Your rights
Under the GDPR (EU and UK residents)
- Access: obtain confirmation of whether we process your data and a copy of it.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: request deletion, subject to our legal retention obligations.
- Restriction and objection: limit or object to certain processing, including processing based on legitimate interests.
- Portability: receive your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting processing carried out before withdrawal.
- Lodge a complaint with your local supervisory authority.
Under India’s Digital Personal Data Protection Act, 2023
- Access a summary of the personal data being processed and the processing activities undertaken.
- Correction, completion, updating and erasure of your personal data.
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Grievance redressal through the contact point below, before escalating to the Data Protection Board of India.
To exercise any of these rights, email support@skyrionlabs.com. We will verify your identity and respond within the period required by applicable law — generally 30 days. Where you are an end user of one of our customers, please contact that customer directly; we will refer your request to them and assist them in responding.
11. Children’s data
SupportIQ is a business product and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy to reflect changes in our practices, the service, or applicable law. The "last updated" date at the top of this page always reflects the current version.
Where a change is material — for example, a new purpose for processing or a new category of recipient — we will notify account holders by email or through an in-product notice at least 14 days before it takes effect.
Contact
Questions about this document can be sent to support@skyrionlabs.com.
Skyrion Labs Private LimitedDehradun, Uttarakhand, India
CIN: U62099UT2026PTC021778