Skip to content
SYGNISYS

Privacy Policy

Last updated: 30 September 2026

This Privacy Policy explains how Sygnisys (pvt) Ltd. (“SYGNISYS”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you visit sygnisys.com (the “Site”) or contact us through it. We process personal data in accordance with the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka (the “PDPA”). For the purposes of the PDPA, SYGNISYS is the controller of the personal data described in this policy.

1. Personal data we collect

Information you give us

When you submit the contact form or an assessment request on the Site, we collect:

  • your name;
  • your work email address;
  • your company or organisation and what you are looking to achieve;
  • for assessment requests, your role (if you give it), a description of the system or area you want assessed and whether it is in production;
  • the page you sent the form from; and
  • any information you choose to include in your message, such as details about your organisation or the challenge you would like to discuss.

Please do not include sensitive personal data (for example, health or financial account information) or confidential third-party information in your message.

Information collected automatically

When you visit the Site, our hosting and security provider automatically processes technical data needed to deliver and protect the Site, such as your IP address, browser type, device information, the pages you request, and the date and time of your visit. When you submit the contact form, we may also use a security check that analyses technical signals from your browser to distinguish people from automated bots.

AI Lens

When you run AI Lens, the text you enter is sent to our AI provider, Anthropic, to generate the analysis shown to you, along with your IP address, which we use only to limit how often the tool can be used. We do not store the text or link it to you, and it is not added to the contact form unless you tick the box to include it. Text that contains an email address, phone number or account number is not sent to the AI provider. Please do not enter personal, sensitive, or confidential information into AI Lens.

Information that stays in your browser

The Site stores a small flag in your browser’s session storage so the opening animation is shown only once per visit. This flag contains no personal data and is deleted when you close the browser tab. We do not use advertising or tracking cookies.

2. How and why we use personal data

  • To respond to your enquiry, including arranging a discovery session and following up on the services you asked about. We process this data with your consent, which you give by submitting the form, and to take steps at your request before entering into a contract with you.
  • To operate, secure, and improve the Site, including preventing spam, abuse, and fraud. We process this data on the basis of our legitimate interest in running a secure and reliable website.
  • To comply with legal obligations, and to establish, exercise, or defend legal claims where necessary.

We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects for you.

3. Who we share personal data with

We share personal data only with service providers that process it on our behalf and under our instructions:

  • Cloudflare, Inc.: website hosting, content delivery, security, and bot protection (Cloudflare Turnstile).
  • Resend: delivery of contact form submissions to our team by email.
  • Anthropic: AI processing of text entered into AI Lens.
  • Our email provider, which stores the enquiry emails we receive and send.

We may also disclose personal data if required by law, regulation, or a valid order of a court or public authority, or in connection with a merger, acquisition, or sale of all or part of our business, in which case the recipient will be bound to protect it in line with this policy.

4. International transfers

Our service providers may process personal data outside Sri Lanka, including in the United States and other countries where they operate. Where we transfer personal data outside Sri Lanka, we do so in accordance with the PDPA and take reasonable steps to ensure that it receives an adequate level of protection, including relying on our providers’ contractual data protection commitments.

5. How long we keep personal data

We keep contact form submissions and related correspondence for as long as needed to respond to and manage your enquiry, and for up to 24 months after our last contact with you, unless you ask us to delete it sooner or we need to keep it longer to meet a legal obligation or resolve a dispute. If you become a client, records relating to our engagement are kept in line with our contractual and legal obligations. Technical logs held by our hosting provider are retained for a limited period in line with its own retention practices.

6. How we protect personal data

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. These include encrypted (HTTPS) connections, restricted access to enquiry data, and reputable service providers with strong security practices. No method of transmission over the internet is completely secure, however, and we cannot guarantee absolute security.

7. Your rights

Subject to the conditions and exceptions set out in the PDPA, you have the right to:

  • request access to, and a copy of, the personal data we hold about you;
  • withdraw your consent at any time, where we rely on consent;
  • request that we correct or complete inaccurate or incomplete personal data;
  • request that we erase your personal data; and
  • request a review of any decision based solely on automated processing that significantly affects you.

To exercise any of these rights, email us at hello@sygnisys.com. We may need to verify your identity before acting on your request, and we will respond within the time required by the PDPA. Withdrawing consent does not affect processing carried out before the withdrawal.

If you are not satisfied with how we handle your request or your personal data, you may lodge a complaint with the Data Protection Authority of Sri Lanka.

8. Children

The Site is intended for business users and is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

9. Third-party links

The Site may link to third-party websites or services. We are not responsible for their privacy practices, and we encourage you to read their privacy policies.

10. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page shows when it was last revised. Where changes are significant, we will take reasonable steps to let you know.

11. Contact us

If you have any questions about this Privacy Policy or how we handle personal data, please email hello@sygnisys.com or write to us at:

Sygnisys (pvt) Ltd.
No 234/4, 1F, Sri Jayawardhanapura Mawatha, Rajagiriya 10100, Sri Lanka

See also our Terms of Service.