Privacy policy

1. Who we are

SYSTMS provides SYSTMS, software that runs the operations of small and growing businesses: jobs, customers, staff, procedures, calendars, invoicing records and the AI assistants that work across them. In this policy "we", "us" and "our" mean SYSTMS; "you" means anyone whose personal data we handle.

Contact for anything in this policy, including exercising your rights: hello@systms.io.

2. Two different roles

We hold personal data in two capacities, and the difference matters for who you should ask.

3. What we collect

When you use SYSTMS

When you pay

Payments are taken by Stripe. We receive the plan, status, the last four digits and expiry of the card and the billing name and address; we never see or store the full card number.

When you visit this website or contact us

What you send us (for example a walkthrough request) and the technical data any web server receives. This site uses no advertising or analytics cookies — see the cookie policy.

4. Why we use it, and on what legal basis

PurposeLawful basis (UK GDPR / EU GDPR)
Providing SYSTMS to your business, including its AI featuresContract with the business; for business content, the business's instructions under the DPA
Creating and securing your account, preventing abuseContract; legitimate interests in keeping the service safe
Billing and accounting recordsContract; legal obligation (tax records)
Service messages (security, changes, billing)Contract; legitimate interests
Fixing faults and improving the service from aggregated, non-identifying usageLegitimate interests
Answering enquiriesLegitimate interests; steps before entering a contract
Location at clock-in and clock-outThe business's legitimate interests in accurate time records, as its controller; your device asks your permission first and you can refuse

We do not sell personal data, and we do not use it for advertising.

5. AI and automated decisions

SYSTMS uses AI models to draft procedures, read documents and emails, suggest schedules, answer questions and run the automations a business sets up. The text sent to a model is only what the task needs. Our AI providers process it to return an answer; under their commercial terms they do not use it to train their models.

SYSTMS does not make decisions with legal or similarly significant effects about individuals by automated means alone. Actions that change records or contact people are either set up in advance by the business or put to a person for approval. AI output can be wrong; the business remains responsible for checking what it relies on.

6. Who we share it with

Only with the service providers that run SYSTMS for us (our sub-processors), the services a business chooses to connect, professional advisers under confidentiality, a buyer of our business if that happens (with this policy continuing to apply), and authorities where the law requires it.

7. International transfers

Some of our providers process data outside the UK and European Economic Area, mainly in the United States. Where they do, the transfer is covered by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework where the provider is certified) or by the ICO's International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed.

8. How long we keep it

9. How we protect it

Encryption in transit (TLS) and at rest through our hosting provider; access to each business's records restricted to its own members and checked on the server for every read and write; management-only data refused to field and office roles; secrets and connection tokens held server-side and never sent to browsers; staff access to customer data only where needed to support that customer. No system is perfectly secure; if a breach affects your data we will tell those we must, as the law requires.

10. Your rights

You can ask for a copy of your personal data, ask us to correct or delete it, ask us to restrict or stop using it, object to processing based on legitimate interests, and ask for data you gave us in a portable form. Where we rely on consent you can withdraw it at any time. Write to hello@systms.io; we will answer within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

11. Children

SYSTMS is a business tool and is not intended for anyone under 16.

12. Changes

If we change this policy in a way that matters, we will say so in the app or by email before the change takes effect. The date at the top shows when it last changed.