This Privacy Policy explains how Intellabel collects, uses, shares, and protects personal data, and the rights you have over that data. It applies to our website, our subscription services, and any related support and communications (together, the "Services").
Intellabel is established in India and complies with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Because our customers are located worldwide, this policy is also written to meet the requirements of the EU and UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and comparable laws in other jurisdictions. Where the law of your country grants you stronger protection than this policy, that law prevails.
Data Fiduciary / Controller: SUNIX AI PRIVATE LIMITED, CIN U72900KA2021PTC153777 registered at 2B-132, WEWORK SALARPURIA SYMBIOSIS, AREKERE, BANGALORE, INDIA 560076] ("Intellabel", "we", "us").

Sensitive data. We do not intentionally collect special category or sensitive personal data (such as health, biometric, racial or ethnic origin, religious belief, or political opinion) about our account holders. Please do not submit such data to us through support channels.
Sources. Most data comes directly from you when you register, subscribe, or contact support. Some technical data is generated automatically when you use the Services. Where you sign up through a reseller or partner, we may receive your contact and billing details from them.
We do not use your personal data or your customer content to train machine learning models for use outside your own account without your explicit, separate consent. We do not make decisions producing legal or similarly significant effects about you by solely automated means.
"Customer Content" means the data you and your authorised users upload to, store in, or generate through the Services, including personal data about your own users, employees, clients, or contacts.
Where the GDPR or UK GDPR applies, we rely on the following bases:
We share personal data only with the categories of recipients below, under contracts that restrict their use of it. The named providers are indicative and must be confirmed before publication.
We are based in India and use service providers in several countries, so your data may be transferred across borders. Where data leaves the EEA, the UK, or Switzerland, we rely on one or more of the following safeguards:
Where we no longer need data but cannot delete it immediately, we isolate it and restrict processing until deletion is possible.
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access controls and least-privilege administration, multi-factor authentication for staff, network segregation, logging and monitoring, regular patching and vulnerability scanning, background-checked personnel under confidentiality obligations, vendor due diligence, and tested backup and recovery procedures. [Certifications: ISO 27001:2022]
No system is completely secure. If a personal data breach occurs, we will notify the affected individuals and the relevant authorities without undue delay and within the timelines set by applicable law — including intimation to the Data Protection Board of India and affected Data Principals under the DPDP Rules, and notification within 72 hours under the GDPR where the breach is reportable. If you are a customer whose Customer Content is affected, we will notify you promptly so you can meet your own obligations.
Subject to the law that applies to you, you have the following rights:

How to exercise them. Email support@intellabel.com or use the controls in your account settings. We will verify your identity before acting and respond within 30 days, or sooner where the law requires. There is no charge unless a request is manifestly unfounded or excessive. If your data is held by us as a processor on behalf of one of our customers, we will refer your request to that customer and support them in responding.
US state privacy rights. Residents of California and other US states with comparable laws have the rights to know, delete, correct, and opt out of sale or sharing. Intellabel does not sell personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of. You may use an authorised agent to submit a request.
We use strictly necessary cookies to run the Services and keep you signed in; these do not require consent. We use analytics and preference cookies only where you consent through our cookie banner, and you can change or withdraw that choice at any time via Cookie settings. We honour Global Privacy Control and similar browser signals where the law requires. Full details are in our Cookie Notice at our website www.intellabel.com
The Services are intended for businesses and for individuals aged 18 and over. We do not knowingly collect personal data from children. Under the DPDP Act, processing a child's personal data requires verifiable parental consent and we do not engage in tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us with personal data, contact support@intellabel.com and we will delete it.
We may update this policy as our Services or the law change. Material changes will be announced by email or in-product notice at least 30 days before they take effect, and the revised version will be posted here with a new effective date. Continued use of the Services after the effective date means you accept the updated policy.
Privacy enquiries: support@intellabel.com
Grievance Officer (India, required under the DPDP Act): Details available on dpdpa.com website where you can raise a grievance.