Privacy policy
What personal data SYSTMS holds, why, who sees it, how long it is kept and your rights over it.
1. Who we are
SYSTMS provides SYSTMS, software that runs the operations of small and growing businesses: jobs, customers, staff, procedures, calendars, invoicing records and the AI assistants that work across them. In this policy "we", "us" and "our" mean SYSTMS; "you" means anyone whose personal data we handle.
Contact for anything in this policy, including exercising your rights: hello@systms.io.
2. Two different roles
We hold personal data in two capacities, and the difference matters for who you should ask.
- As controller — for our own customers' account and billing details, people who visit this website, people who contact us, and the running of our service (security logs, usage needed to operate it). This policy covers that data in full.
- As processor — for the data a business puts into SYSTMS about its own customers, staff, suppliers and jobs. That business is the controller: it decides what goes in and why, and its own privacy notice applies. We process that data only on its instructions, under our data processing agreement. If you are a customer or employee of a business that uses SYSTMS and want to exercise your rights, contact that business first; we will help it respond.
3. What we collect
When you use SYSTMS
- Account details: name, email address, password (stored by our hosting provider as a salted hash, never in readable form), the businesses you belong to and your role in each.
- Business content entered by you or your colleagues: customers and their contact details, jobs, quotes, invoices records, parts orders, tasks, calendars, leave, staff records, procedures, forms, photos, signatures, notes, emails and messages the business chooses to connect.
- Field data: time clocked on and off jobs and, where the business has turned it on and your device allows it, the location of your device at the moment you clock in or out. Location is not tracked continuously.
- Recordings and transcripts: voice notes you record in the app, and recordings from a connected Pocket recorder, with their transcripts and summaries.
- Connected services: when a business connects Zoho, Google, Microsoft, Notion, Pocket, WhatsApp or a calendar feed, the data it asks SYSTMS to read from or write to that service, and the access tokens that make the connection work.
- Technical data: the minimum needed to run and secure the service — sign-in events, error reports, the browser and device type, IP address as seen by our hosting provider.
When you pay
Payments are taken by Stripe. We receive the plan, status, the last four digits and expiry of the card and the billing name and address; we never see or store the full card number.
When you visit this website or contact us
What you send us (for example a walkthrough request) and the technical data any web server receives. This site uses no advertising or analytics cookies — see the cookie policy.
4. Why we use it, and on what legal basis
| Purpose | Lawful basis (UK GDPR / EU GDPR) |
|---|---|
| Providing SYSTMS to your business, including its AI features | Contract with the business; for business content, the business's instructions under the DPA |
| Creating and securing your account, preventing abuse | Contract; legitimate interests in keeping the service safe |
| Billing and accounting records | Contract; legal obligation (tax records) |
| Service messages (security, changes, billing) | Contract; legitimate interests |
| Fixing faults and improving the service from aggregated, non-identifying usage | Legitimate interests |
| Answering enquiries | Legitimate interests; steps before entering a contract |
| Location at clock-in and clock-out | The business's legitimate interests in accurate time records, as its controller; your device asks your permission first and you can refuse |
We do not sell personal data, and we do not use it for advertising.
5. AI and automated decisions
SYSTMS uses AI models to draft procedures, read documents and emails, suggest schedules, answer questions and run the automations a business sets up. The text sent to a model is only what the task needs. Our AI providers process it to return an answer; under their commercial terms they do not use it to train their models.
SYSTMS does not make decisions with legal or similarly significant effects about individuals by automated means alone. Actions that change records or contact people are either set up in advance by the business or put to a person for approval. AI output can be wrong; the business remains responsible for checking what it relies on.
6. Who we share it with
Only with the service providers that run SYSTMS for us (our sub-processors), the services a business chooses to connect, professional advisers under confidentiality, a buyer of our business if that happens (with this policy continuing to apply), and authorities where the law requires it.
7. International transfers
Some of our providers process data outside the UK and European Economic Area, mainly in the United States. Where they do, the transfer is covered by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework where the provider is certified) or by the ICO's International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed.
8. How long we keep it
- Business content: for as long as the business keeps its account, subject to the retention period it sets in SYSTMS (five years by default). When an account closes, the business can export its data for 30 days, after which it is deleted from the live service; backups are overwritten on our hosting provider's schedule.
- Account details: while your account exists, and deleted within 30 days of closure unless we must keep something longer.
- Billing records: six years, as UK tax law requires.
- Security logs: for as long as our hosting provider keeps them, typically no more than twelve months.
9. How we protect it
Encryption in transit (TLS) and at rest through our hosting provider; access to each business's records restricted to its own members and checked on the server for every read and write; management-only data refused to field and office roles; secrets and connection tokens held server-side and never sent to browsers; staff access to customer data only where needed to support that customer. No system is perfectly secure; if a breach affects your data we will tell those we must, as the law requires.
10. Your rights
You can ask for a copy of your personal data, ask us to correct or delete it, ask us to restrict or stop using it, object to processing based on legitimate interests, and ask for data you gave us in a portable form. Where we rely on consent you can withdraw it at any time. Write to hello@systms.io; we will answer within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
11. Children
SYSTMS is a business tool and is not intended for anyone under 16.
12. Changes
If we change this policy in a way that matters, we will say so in the app or by email before the change takes effect. The date at the top shows when it last changed.