Privacy Policy
Last updated: 19 July 2026
1. Introduction
InovoSync Limited ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website inovosync.com (the "Site") or engage our services. Please read this policy carefully. If you do not agree with the terms, do not access the Site.
2. Information We Collect
2.1 Personal Data You Provide
- Name, email, phone, company when you submit the contact form
- Project details, budget, timeline information
- Communication records from email or meetings
2.2 Automatic Data Collection
- IP address, browser type, operating system
- Referring URLs, pages visited, time spent
- Analytics data via PostHog (self-hosted, no third-party tracking)
2.3 Cookies and Similar Technologies
We use essential cookies for site functionality and analytics cookies (with consent) for performance measurement. No advertising cookies. No third-party tracking pixels. See our Cookie Policy for details.
3. How We Use Your Information
- Respond to inquiries and provide service information
- Send relevant technical content (with consent)
- Improve the Site and user experience
- Comply with legal obligations
- Protect our rights and prevent fraud
4. Legal Basis for Processing (GDPR/UK GDPR)
- Legitimate Interest: Responding to business inquiries, site security, analytics
- Consent: Marketing communications, non-essential analytics
- Contract: Pre-contractual discussions for services
- Legal Obligation: Tax, accounting, regulatory compliance
5. Data Sharing and Disclosure
We do not sell your data. We may share information only in these circumstances:
- Service providers (hosting, analytics, email) under data processing agreements
- Legal authorities when required by law
- Business transfers (merger, acquisition) with equivalent protections
- With your explicit consent
6. International Transfers
We operate globally. Your data may be processed in New Zealand, Australia, the UK, EU, or US. Transfers are protected by:
- Adequacy decisions (NZ, UK, EU)
- Standard Contractual Clauses (SCCs) for US processors
- Binding Corporate Rules where applicable
7. Data Retention
- Contact form data: 12 months after last contact
- Analytics data: 26 months (anonymized after 12)
- Contractual records: 7 years per tax law
- Marketing consent: Until withdrawn
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent (where consent is the basis)
- Lodge a complaint with a supervisory authority (e.g., NZ Privacy Commissioner, UK ICO, EU DPA)
To exercise these rights, email privacy@inovosync.com. We respond within 30 days.
9. Security
We implement appropriate technical and organizational measures:
- TLS 1.3 for data in transit
- Encryption at rest (AES-256)
- Access controls, MFA, least privilege
- Regular security testing and patching
- Incident response plan with 72-hour breach notification
No transmission over the internet is 100% secure. We cannot guarantee absolute security.
10. Children's Privacy
The Site is not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.
11. Changes to This Policy
We may update this policy. Material changes will be posted on this page with a revised date. Continued use after changes constitutes acceptance.
13. Contact
Data Protection Officer: privacy@inovosync.com
InovoSync Limited
Lahore, Pakistan