Who we are
NandySys (“we,” “us,” “our”) provides lead-management, CRM implementation, and related business-process services to mutual fund distributors, loan DSAs, and insurance distribution agencies. This policy explains how we collect, use, store, and protect personal data when you visit this website or engage us for services.
What We Collect
**Information you provide directly:** name, company name, phone/WhatsApp number, email address, country, and any business-process details you share during a conversation, form submission, or engagement.
– **Information collected automatically:** standard website analytics data (pages visited, browser type, general location at country/city level) via cookies and similar technologies — see our Cookie Policy for full detail.
– **Information handled during an engagement:** if you engage us for services, we may process business data you provide for the purpose of the engagement — for example, an existing lead list you ask us to import and organize. This data belongs to you; see Data Security & Handling for how it’s treated.
Why We Collect It
We process personal data for the following purposes, and only for these purposes:
– To respond to enquiries and communicate with prospective and existing clients
– To deliver services under a signed engagement
– To improve this website and our services
– To meet legal and regulatory obligations
Legal Basis for Processing
Where required by applicable law, we rely on: your consent (for marketing communications and non-essential cookies); the necessity of processing to take steps at your request before entering into an agreement, or to perform a signed agreement; and our legitimate interest in operating and improving our business, balanced against your rights.
Who We Share Data With
We do not sell personal data. We may share data with:
– Technology platform providers used to deliver services (for example, Zoho or Freshworks), strictly as needed to deliver the engagement
– Independent technical delivery partners engaged under written confidentiality obligations
– Professional advisers (legal, accounting) where necessary
– Regulators or authorities, where required by law
International Data Transfers
We are based in India. If you are located in the UAE, another GCC country, or the UK, your data may be transferred to and processed in India. Where such transfers occur, we take reasonable steps to apply data protection principles consistent with the law of your location, including purpose limitation, security safeguards, and honoring data subject rights regardless of where the data is processed.
How Long We Keep Data
We retain personal data only as long as necessary for the purpose it was collected, for the duration of an active engagement plus a reasonable period afterward for legal, accounting, or dispute-resolution purposes, or as required by applicable law — after which it is deleted or anonymized.
Your Rights
**If you are in India (under the DPDP Act, 2023):** You have the right to obtain a summary of the personal data we process about you and the processing activities involved, the right to correction and completion of inaccurate or incomplete data, the right to erasure of data that is no longer necessary for the purpose collected, the right to a readily available means of grievance redressal, and the right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
**If you are in the UAE or elsewhere in the GCC (under applicable data protection law, including the UAE PDPL):** You have the right to be informed about how your data is processed, the right to access your data, the right to request correction, the right to request erasure, the right to restrict or object to processing (including for marketing purposes), and the right to data portability.
**If you are in the UK (under UK GDPR and the Data Protection Act 2018):** You have the right to access, rectify, erase, or restrict processing of your data, the right to data portability, the right to object to processing, and the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data has been mishandled.
To exercise any of these rights, contact us at **hello@nandysys.com**. We will respond within a reasonable time and in line with the timelines required under applicable law.
Complaints
If you have a concern about how we’ve handled your data, please contact us first at hello@nandysys.com so we can try to resolve it directly. If you remain unsatisfied, you have the right to escalate to the relevant supervisory authority in your jurisdiction (for example, the Data Protection Board of India, the UAE Data Office, or the UK Information Commissioner’s Office).
Children’s Data
Our services are directed at businesses and business owners, not children. We do not knowingly collect personal data from individuals under 18.
Changes to This Policy
We may update this policy from time to time. The date of the last update will be shown at the top of this page. Material changes will be communicated to active clients directly.
Contact
For any privacy-related query: **hello@nandysys.com**
