Legal
Privacy policy
This policy explains what personal information Systemfy Infotech collects, why we collect it, who we share it with, how long we keep it, and how you can have it removed.
Last updated 31 July 2026 · Version 1.0
1. Who this policy covers
This policy applies to Systemfy Infotech (“Systemfy”, “we”, “us”), a software engineering and technology consultancy with its registered office at P 88/5 Helen Keller Sarani, Kolkata, West Bengal 700053, India.
It covers:
- this website, systemfy.tech;
- the products we publish and operate, including MealiePro;
- the mobile applications we publish on the Apple App Store and Google Play;
- correspondence with us by email or post.
Software we build for a client and hand over to them to run is not covered by this policy. In those cases the client operates the system and publishes its own privacy notice.
2. Our role under data protection law
For the products we operate, including MealiePro, Systemfy Infotech is the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 — the equivalent of the “controller” under other data protection laws. We determine how personal data on the platform is handled, retained and secured; we carry the resulting legal obligations; and reporting a personal data breach to the Data Protection Board of India is our responsibility, not that of the organisations using our software.
This is deliberate. A practice or clinic using our platform has no practical way to discharge platform-level obligations such as infrastructure security or breach notification, so we hold them rather than passing them on.
An organisation that uses one of our products — a nutrition practice, clinic or employer — decides which of its own clients it records and what it records about them, and remains responsible for having a lawful basis for doing so and for meeting its own professional and record-keeping obligations. Where it holds copies of records outside our platform, those copies are its responsibility.
If you are a client of a practice that uses one of our products, you do not have to go through that practice to reach us. Write to privacy@systemfy.tech and we will deal with your request ourselves — every right in section 9 can be exercised directly against us.
3. Information we collect
Information you or your organisation provides
- Account information — name, email address, telephone number, the organisation you belong to and your role within it, and an encrypted form of your password. We never store passwords in a readable form.
- Profile and health information — in our practice management products this may include date of birth, gender, height, weight, body measurements, dietary restrictions, allergies, medical conditions, medications, family medical history, uploaded medical or laboratory reports, progress photographs, food and meal logs, wellness check-ins and assessment responses.
- Scheduling and communications — appointments, and messages exchanged between an organisation and its clients inside the product.
- Billing information — the legal name, address and tax registration of a subscribing organisation, and a record of invoices and payments. We do not operate a card payment processor and therefore do not receive or store payment card numbers.
- Correspondence — what you send us when you write for support, including anything you choose to attach.
Information collected automatically
- Usage records — we record that an authenticated user was active on a given day, and a record of actions that change data (who changed what, and when). We use this to understand which features are used, to size capacity, and to investigate disputes about a change to a record.
- Technical and device information — IP address, device and operating system type, application version and browser, together with server logs of requests made.
- Diagnostics — when the software errors, a technical report of the fault is generated so we can fix it.
We do not use advertising trackers, we do not build advertising profiles, and we do not sell personal information. We do not track you across other companies' websites or applications.
4. Health and other sensitive information
Some of our products are used to record health information, which is sensitive personal data and is treated accordingly. It is used solely to deliver the service to the organisation and the individual concerned, is visible only to that organisation and the individual, and is never used for advertising, sold, or shared for any purpose unconnected with providing the software.
Our products enforce strict separation between organisations at the data layer: records belonging to one organisation are not reachable from another, and this separation is covered by automated tests that run on every change to the software.
5. How we use information
- To provide, maintain and secure the products, and to authenticate you.
- To make the features you use work — planning, scheduling, logging, messaging and reporting.
- To send service messages such as appointment reminders, notifications and account or security notices.
- To provide support, and to investigate and fix defects.
- To bill subscribing organisations and to meet our tax and accounting obligations.
- To detect, prevent and investigate abuse, fraud and security incidents.
- To understand aggregate usage so we can improve the software.
We do not use your content to train machine learning models, and we do not permit our vendors to do so.
6. Legal bases for processing
Where data protection law requires us to identify a legal basis, we rely on:
- Performance of a contract — to supply the service you or your organisation has subscribed to.
- Legitimate interests — to secure our systems, prevent abuse, and improve our products, balanced against your interests and rights.
- Consent — for optional features, and for sensitive information where consent is required. Consent can be withdrawn at any time.
- Legal obligation — to keep tax, accounting and statutory records.
7. Sharing and disclosure
We do not sell personal information or share it with data brokers. We disclose it only in these circumstances:
- Within your organisation. Records are visible to authorised people at the organisation holding the account, according to the roles it has configured.
-
Service providers acting on our instructions. These are bound
by contract to process information only as we direct, and only to run the
service:
- Hosting and infrastructure — servers and databases operated on our behalf in the European Union.
- Object storage — for files you upload, such as reports and photographs.
- Email delivery — to send service and notification messages.
- Error monitoring — Sentry, for fault diagnostics. It is configured not to transmit personal data by default.
- Artificial intelligence features — where a product offers optional AI-assisted planning, the relevant plan and nutritional details are sent to OpenAI to generate a suggestion. Their terms prohibit using that content to train their models. Do not enter information into these features that you would not wish to send to a third-party provider.
- Legal requirement. Where we are compelled by a valid legal process. We will notify the affected organisation unless prohibited from doing so.
- Business transfer. If our business or a product is transferred, information may transfer with it, subject to this policy. We will give notice before it takes effect.
8. Retention, and deleting your account and data
We keep personal information for as long as the account it belongs to is active, and afterwards only where we have a specific reason to.
Requesting deletion
Write to privacy@systemfy.tech from the email address registered to the account, stating the product and the account concerned. We verify that the request comes from the account holder before we act on it, and we do not charge for this.
What happens
- We acknowledge the request within five business days.
- We delete the account and its associated personal data — profile, health records, logs, uploaded files, messages and progress history — within 30 days of verifying the request.
- Residual copies in encrypted backups are overwritten on the normal backup cycle, within 90 days. They are not accessible for ordinary use in the meantime.
What we must keep
- Financial records — invoices and payment records, retained for eight years as required by Indian tax law. These identify the subscribing organisation, not individual end users.
- Security records — a minimal record of security-relevant events, retained up to 12 months.
- Records your organisation is required to keep. A practice, clinic or employer may be obliged to retain clinical or employment records for a period fixed by its own professional rules, and may hold copies outside our platform. Where that limits what we can delete, we will tell you precisely what is affected and why.
When a subscribing organisation closes its account, its data is retained for 30 days so it can be exported, then deleted.
9. Your rights
Subject to the law applying to you, you may ask us to:
- confirm what personal information we hold about you, and give you a copy;
- correct information that is inaccurate or incomplete;
- delete information, as described in section 8;
- restrict or object to a particular use;
- provide your information in a portable, machine-readable format;
- withdraw a consent you previously gave.
Write to privacy@systemfy.tech. We respond within 30 days. If we cannot act on a request we will tell you why. You do not need to route a request through the organisation whose account you use; where part of your request touches records that organisation holds independently of our platform, we will act on our part and tell you what remains with them.
If you are dissatisfied with our response you may complain to your data protection authority. In India this is the authority constituted under the Digital Personal Data Protection Act, 2023.
10. Security
We protect information with measures appropriate to its sensitivity: encryption in transit using TLS; encrypted storage of credentials; role-based access control within every product; segregation of each organisation's data enforced in the application and verified by automated tests; restricted administrative access on a need-to-know basis; monitoring, logging and regular encrypted backups with tested restores.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant authority without undue delay, and tell you what happened and what to do about it.
11. International transfers
We are established in India. Our production infrastructure is operated in the European Union, so information is transferred outside India in the ordinary course of running the service. Our AI features involve transfer to a provider in the United States. Where we transfer personal information across borders we do so under contractual protections requiring a standard of protection equivalent to that described in this policy.
12. Children
Our products are supplied to organisations and their adult users, and are not directed at children. We do not knowingly collect personal information directly from a child. Where a practice records information about a minor as part of that minor's care, the practice is the controller and is responsible for obtaining parental or guardian consent as its own obligations require. If you believe a child has provided information to us directly, write to privacy@systemfy.tech and we will delete it.
13. Changes to this policy
We may update this policy as our products and obligations change. The date at the top records the current version. Where a change materially affects your rights we will give notice by email or in the product before it takes effect, and we keep prior versions available on request.
14. How to contact us
| Privacy & data requests | privacy@systemfy.tech |
|---|---|
| Security | security@systemfy.tech |
| General | contact@systemfy.tech |
| Post |
Systemfy Infotech P 88/5 Helen Keller Sarani Kolkata, West Bengal 700053 India |