Privacy Policy
Effective date: 18 August 2026   |   Last updated: 18 August 2026   |   Version 1.0

This Privacy Policy explains how Intellabel collects, uses, shares, and protects personal data, and the rights you have over that data. It applies to our website, our subscription services, and any related support and communications (together, the "Services").

Intellabel is established in India and complies with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Because our customers are located worldwide, this policy is also written to meet the requirements of the EU and UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and comparable laws in other jurisdictions. Where the law of your country grants you stronger protection than this policy, that law prevails.

1. Who we are

Data Fiduciary / Controller: SUNIX AI PRIVATE LIMITED, CIN U72900KA2021PTC153777 registered at 2B-132, WEWORK SALARPURIA SYMBIOSIS, AREKERE, BANGALORE, INDIA 560076] ("Intellabel", "we", "us").

Sensitive data. We do not intentionally collect special category or sensitive personal data (such as health, biometric, racial or ethnic origin, religious belief, or political opinion) about our account holders. Please do not submit such data to us through support channels.

Sources. Most data comes directly from you when you register, subscribe, or contact support. Some technical data is generated automatically when you use the Services. Where you sign up through a reseller or partner, we may receive your contact and billing details from them.

3. How we use personal data

  • - To create, secure, and administer your account and provide the Services.
  • - To process payments, issue invoices, apply the correct tax treatment, and collect amounts due.
  • - To provide customer support and respond to your requests.
  • - To send service and administrative messages, including security alerts, billing notices, and changes to our terms. You cannot opt out of these while you hold an account.
  • - To send product news and marketing, where you have consented or where permitted by law. You can unsubscribe at any time.
  • - To monitor, secure, and improve the Services, diagnose faults, and develop new features.
  • - To detect, investigate, and prevent fraud, abuse, and security incidents.
  • -  o comply with legal, tax, accounting, and regulatory obligations, and to establish, exercise, or defend legal claims.

We do not use your personal data or your customer content to train machine learning models for use outside your own account without your explicit, separate consent. We do not make decisions producing legal or similarly significant effects about you by solely automated means.

4. Customer content and our role as processor

"Customer Content" means the data you and your authorised users upload to, store in, or generate through the Services, including personal data about your own users, employees, clients, or contacts.

  • - You remain the controller of Customer Content. You decide what is collected, why, and for how long.
  • - You are responsible for having a lawful basis to collect it and for providing the required notices to the individuals concerned.
  • - We process Customer Content only to deliver the Services, to comply with your documented instructions, and where required by law.
  • - We do not access Customer Content except as needed to provide support you have requested, maintain security, or comply with a legal obligation.
  • - We will assist you, at your reasonable cost, in responding to individuals exercising their rights and in carrying out data protection impact assessments.
  • - On termination, we return or delete Customer Content in line with Section 8.
  • Data Processing Agreement. If you require a Data Processing Agreement incorporating the EU Standard Contractual Clauses or the UK International Data Transfer Addendum, contact support@intellabel.com. Our standard DPA is available on request and, once executed, forms part of your agreement with us.

5. Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on the following bases:

  • - Performance of a contract — to provide the Services you have signed up for and to bill you.
  • - Legal obligation — to meet tax, accounting, anti-money-laundering, and record-keeping requirements.
  • - Legitimate interests — to secure and improve the Services, prevent fraud, and communicate with business customers, balanced against your rights.
  • - Consent — for optional cookies and for marketing where consent is required. You may withdraw it at any time.
  • Where the DPDP Act applies, we process personal data on the basis of your consent or as a "legitimate use" permitted under that Act, including where you have voluntarily provided data for a specified purpose. Our consent notices are provided in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.

6. Who we share data with

We share personal data only with the categories of recipients below, under contracts that restrict their use of it. The named providers are indicative and must be confirmed before publication.

  • - Cloud hosting and infrastructure — Amazon Web Services
  • - Payment processing — Razorpay
  • - Email and communications — MailerSend
  • - Analytics and product telemetry — Inbuilt Intellabel Service
  • - Customer support tooling — Microsoft
  • - Professional advisers — auditors, accountants, tax advisers, and lawyers, bound by professional confidentiality.
  • - Authorities — regulators, tax authorities, courts, and law enforcement, where legally required. We review every request and challenge those that are overbroad or unlawful, and notify you unless prohibited.
  • - Corporate transactions — an acquirer or successor in a merger, acquisition, or restructuring, subject to this policy continuing to apply.
  • We give at least 30 days' notice before adding a new sub-processor that handles Customer Content, and you may object on reasonable data protection grounds.

7. International transfers

We are based in India and use service providers in several countries, so your data may be transferred across borders. Where data leaves the EEA, the UK, or Switzerland, we rely on one or more of the following safeguards:

  • - European Commission Standard Contractual Clauses, and the UK International Data Transfer Addendum for UK transfers.
  • - An adequacy decision covering the destination country, where one exists.
  • - Supplementary technical and organisational measures, including encryption in transit and at rest, following a transfer impact assessment.
  • Under the DPDP Act, we may transfer personal data outside India except to any country the Central Government restricts by notification. A copy of the relevant transfer safeguards is available on request to support@intellabel.com.

8. How long we keep data

  • - Account data — for the life of your account and 24 months after closure, to handle disputes and reactivation requests.
  • - Invoices and tax records — 5 years, or longer where Indian tax and companies legislation or the law of your country requires it.
  • - Customer Content — available for export for 30 days after termination, then deleted from live systems within 60 days and from backups within [90] days.
  • - Support tickets — 2 years from closure of the ticket.
  • - Security and access logs — 12 months, unless retained longer for an active investigation.
  • - Marketing records — until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again.

Where we no longer need data but cannot delete it immediately, we isolate it and restrict processing until deletion is possible.

9. Security

We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access controls and least-privilege administration, multi-factor authentication for staff, network segregation, logging and monitoring, regular patching and vulnerability scanning, background-checked personnel under confidentiality obligations, vendor due diligence, and tested backup and recovery procedures. [Certifications: ISO 27001:2022]

No system is completely secure. If a personal data breach occurs, we will notify the affected individuals and the relevant authorities without undue delay and within the timelines set by applicable law — including intimation to the Data Protection Board of India and affected Data Principals under the DPDP Rules, and notification within 72 hours under the GDPR where the breach is reportable. If you are a customer whose Customer Content is affected, we will notify you promptly so you can meet your own obligations.

10. Your rights

Subject to the law that applies to you, you have the following rights:

How to exercise them. Email support@intellabel.com or use the controls in your account settings. We will verify your identity before acting and respond within 30 days, or sooner where the law requires. There is no charge unless a request is manifestly unfounded or excessive. If your data is held by us as a processor on behalf of one of our customers, we will refer your request to that customer and support them in responding.

US state privacy rights. Residents of California and other US states with comparable laws have the rights to know, delete, correct, and opt out of sale or sharing. Intellabel does not sell personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of. You may use an authorised agent to submit a request.

11. Cookies and similar technologies

We use strictly necessary cookies to run the Services and keep you signed in; these do not require consent. We use analytics and preference cookies only where you consent through our cookie banner, and you can change or withdraw that choice at any time via Cookie settings. We honour Global Privacy Control and similar browser signals where the law requires. Full details are in our Cookie Notice at our website www.intellabel.com

12. Children

The Services are intended for businesses and for individuals aged 18 and over. We do not knowingly collect personal data from children. Under the DPDP Act, processing a child's personal data requires verifiable parental consent and we do not engage in tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us with personal data, contact support@intellabel.com and we will delete it.

13. Changes to this policy

We may update this policy as our Services or the law change. Material changes will be announced by email or in-product notice at least 30 days before they take effect, and the revised version will be posted here with a new effective date. Continued use of the Services after the effective date means you accept the updated policy.

14. Contact and complaints

Privacy enquiries: support@intellabel.com

Grievance Officer (India, required under the DPDP Act): Details available on dpdpa.com website where you can raise a grievance.