Home / Privacy Policy
effective 8 September 2026

Privacy Policy.

We sell data-protection readiness, so this document is held to the standard we audit our clients against: it says what we actually collect, not what is convenient to claim. Where we collect nothing, we say so plainly.

Who we are

Sungensis Software Solutions Pvt. Ltd. (“Sungensis”, “we”, “us”) is a private limited company registered in India (CIN U72900PN2019PTC185244), at Flat No. 303, SN-120 A+B, Ajinkyatara Apt, PL-545/14B, Sinhagad Road, Parvati, Pune, Maharashtra 411030, India.

For personal data described in this policy, Sungensis acts as the Data Fiduciary (controller) — except where we process data on behalf of a client, in which case that client is the Data Fiduciary and we act as a Data Processor under contract. Both roles are described below.

What this policy covers

  • This website — www.sungensis.com, including the live AI security checker.
  • Business communication — enquiries you send us by email or through the forms on this site.
  • Our services — security testing, auditing, engineering, compliance and messaging-platform engagements delivered to clients.
  • Our WhatsApp Business Platform services — where we onboard and operate messaging platforms for client businesses as a Meta Tech Provider.

This website collects almost nothing

The site loads no analytics, no advertising pixels, and no third-party scripts of any kind. Its Content-Security-Policy restricts scripts to our own domain, which is enforced by your browser rather than promised by us. There are no tracking cookies, and we do not operate a cookie consent banner because there is nothing to consent to.

  • Theme preference — if you switch between light and dark mode, that single choice is stored in your browser's local storage. It never leaves your device and is never sent to us. Clearing your browser data removes it.
  • Server logs — our hosting provider records standard web-server logs (IP address, timestamp, page requested, user agent) for security and troubleshooting. These are generated by the hosting infrastructure, retained on its standard schedule, and not used to build profiles.

The AI security checker

The checker on our AI & automation page inspects the publicly visible security posture of a website address you enter. It reads only what any visitor to that address could see — chiefly HTTP response headers. It does not attempt to log in, exploit, or access anything non-public.

  • What we retain — for each completed check: the hostname you submitted, the resulting grade and score, a count of findings by severity, the time, and whether the AI summary ran.
  • Your IP address is truncated before it is written. We keep only the surrounding network block (the first three octets for IPv4, the first three groups for IPv6) so that we can see repeat usage from one organisation. The full address is never stored in that record.
  • Abuse prevention — to enforce a limit of five checks per hour, we store a one-way SHA-256 hash of your IP address with request timestamps. Entries older than one hour are discarded automatically.
  • The AI runs on our own infrastructure. The language model that writes the summary is self-hosted by Sungensis. Your input is not sent to OpenAI, Anthropic, Google or any other third-party AI provider. By design, the model receives only our internal finding codes — never raw text from the site being checked.
  • Please don't enter personal data. The field is for a website address. Anything else you type is unnecessary and unwanted.

When you contact us

If you email us or use a contact link, we receive what you send — typically your name, email address, company, and the substance of your enquiry. We use it to reply, to scope work, and to keep a record of our dealings with you. We do not sell it, rent it, or add you to a marketing list you did not ask to join.

Client engagements

Delivering security testing, audits or engineering work can expose us to personal data held in a client's systems. In those engagements the client is the Data Fiduciary and we are a Data Processor: we act only on the client's documented instructions, under a written agreement and confidentiality terms.

  • Minimisation — we ask for the least access that allows the work to be done, and prefer test data or redacted extracts where these are sufficient.
  • Findings — where a finding must evidence exposure of real data, we record the minimum needed to prove impact and mark it accordingly.
  • Return and deletion — at the end of an engagement, evidence and client data are returned or destroyed in line with the engagement contract, except where retention is legally required.
  • No secondary use — client data is never used to train models, build products, or for any purpose beyond the engagement.

WhatsApp Business Platform services

Sungensis is a verified Meta Tech Provider. We build and operate WhatsApp Business Platform solutions for client businesses using Meta's official Cloud API. Onboarding is currently assisted by our team; self-service onboarding through Meta's Embedded Signup will be offered in future. In this capacity we are a technology provider acting for our client; the client business is the Data Fiduciary for the conversations it holds with its own customers.

  • What is processed — business account and profile details of our client, and, in the course of operating the platform, the phone numbers and message content exchanged between that client and its customers.
  • Why — solely to configure, operate, support and troubleshoot the messaging platform we have been engaged to run.
  • What we never do — we do not use message content or contact lists for our own marketing, do not sell or share them with data brokers, and do not use them to train AI models.
  • Meta's role — messages are transmitted through Meta's WhatsApp Business Platform and are subject to Meta's own terms and privacy policies. Our use of data received through Meta's APIs complies with the Meta Platform Terms and Developer Policies.
  • End users — if you are a customer messaging a business we support, that business is responsible for its conversation with you. Please direct requests about your data to that business; we will assist it in responding.
  • Deleting WhatsApp platform data — how to request deletion of data processed through our WhatsApp Business Platform services is published at wa.sungensis.com/sungensis/data-deletion.

Who else can see data

We keep the list of third parties deliberately short. We disclose personal data only to:

  • Infrastructure providers that host this website and our email, acting on our instructions.
  • Meta Platforms, where messaging services are delivered through the WhatsApp Business Platform.
  • Authorities, where we are legally compelled — and then only to the extent required.

We do not sell personal data. We do not share it for advertising or profiling.

How long we keep it

  • Checker records — the operational log described above is retained while it remains useful for demand analysis and abuse prevention, and is rotated as it grows.
  • Rate-limit hashes — automatically discarded after one hour.
  • Enquiries — kept for as long as needed to respond and to maintain a record of our business dealings.
  • Client engagement data — per the engagement contract, then returned or destroyed.
  • Statutory records — where Indian company, tax or contract law requires a minimum retention period, we observe it.

How we protect it

We are a security company and hold our own systems to the standard we test for others: encryption in transit (HTTPS with HSTS), least-privilege access, a strict Content-Security-Policy, self-hosted fonts and scripts so no third party observes your visit, and server-side configuration files kept outside the web root. No system is perfectly secure, but we do not ask you to take our word for it — the posture of this site is externally verifiable, and our own checker will grade it for you.

Your rights

Under India's Digital Personal Data Protection Act, 2023, and comparable laws where they apply to you, you may:

  • Access — ask what personal data of yours we hold and how it is processed.
  • Correct — have inaccurate or incomplete data corrected or completed.
  • Erase — ask us to delete data we no longer have a lawful reason to keep.
  • Withdraw consent — where processing rests on your consent, withdraw it at any time; this does not affect processing already carried out.
  • Complain — raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied.
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of death or incapacity.

Where we hold the data as a processor for a client, we will refer your request to that client and support them in answering it.

Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data of children. If you believe a child's data has reached us, tell us and we will delete it.

International transfers

We are based in India and our website is hosted on infrastructure that may process data outside India. Where messaging services are involved, data is processed by Meta on its global infrastructure. Transfers are made only to the extent necessary to deliver the service and subject to the restrictions applicable under Indian law.

Changes to this policy

If we change how we handle personal data, we will update this page and revise the effective date at the top. Material changes affecting existing clients will be communicated directly.

Contact and grievances

For any privacy question, to exercise a right, or to raise a grievance:

  • Emailsales@sungensis.com
  • Post — Grievance Officer, Sungensis Software Solutions Pvt. Ltd., Flat No. 303, SN-120 A+B, Ajinkyatara Apt, PL-545/14B, Sinhagad Road, Parvati, Pune, Maharashtra 411030, India.

We aim to acknowledge privacy requests within 72 hours and to resolve them promptly. If we cannot satisfy you, you may complain to the Data Protection Board of India.