1. Who we are
SYSTEM2 (PRIVATE) LIMITED, trading as Sys2, is a software studio based in Sri Lanka. We design and operate software services, including Sage, a business messaging and customer-service platform used by independent businesses.
For personal data collected through this website, sales conversations, contracts, and our own business operations, SYSTEM2 (PRIVATE) LIMITED acts as the data controller. When a client business uses Sage to communicate with its customers, that business normally decides why and how customer data is processed. In that context, the client business is the controller and SYSTEM2 (PRIVATE) LIMITED acts as its processor or service provider, subject to our agreement with that business.
SYSTEM2 (PRIVATE) LIMITEDNo. 19, Fatima Circular Road, Kapuwatte, Ja Ela
Sri Lanka
Email: privacy@replace-before-publishing.invalid
2. Scope of this policy
This policy applies when you:
- visit the Sys2 website;
- contact us or ask about an engagement;
- enter into or administer a contract with us;
- use a Sys2 service, including the Sage dashboard; or
- communicate on WhatsApp with a business that uses Sage to manage customer messages, bookings, or support.
This policy does not replace the privacy notice of a client business. If you are a customer of a business using Sage, that business is your main point of contact about why it uses your data. You may also contact us using the process below.
3. Personal data we process
Depending on how you interact with us, we may process:
- Contact and identity data: name, business name, job title, email address, phone number, WhatsApp identifiers, and account identifiers.
- Business and contract data: project briefs, correspondence, proposals, agreements, billing records, and service instructions.
- Account data: dashboard email address, password hash, role, login session data, device label, and authentication records.
- WhatsApp and customer-service data: message content, message identifiers, sender type, phone number or business-scoped user identifier, message timestamps, language, opt-in or opt-out status, conversation status, and escalation history.
- Media and booking data: images and captions you send, plus booking details such as the service, date, time, customer name, and booking reference.
- Client configuration and knowledge: business profile information, service descriptions, prices, opening hours, policies, uploaded knowledge, message templates, WhatsApp Business Account details, and encrypted access credentials.
- Technical and security data: IP address, browser or device details, request metadata, logs, failure records, webhook events, and account-quality events.
We receive this data directly from you, from a client business, from Meta and WhatsApp, from your use of our services, or from systems used to deliver and secure those services.
4. Why we process personal data
We process personal data only for defined purposes, including to:
- respond to enquiries and assess potential engagements;
- enter into, perform, and administer contracts;
- provide, operate, support, and improve our services;
- receive, route, and respond to customer-service messages on a client business's instructions;
- create bookings, manage message templates, and support human staff takeover;
- honour opt-outs and enforce messaging and service-window rules;
- authenticate users and keep accounts, systems, and data secure;
- diagnose failures, prevent abuse, maintain service reliability, and keep audit records;
- meet legal, regulatory, tax, accounting, and contractual obligations; and
- establish, exercise, or defend legal claims.
Our legal basis depends on the context. It may be your consent, steps requested before entering a contract, performance of a contract, compliance with law, or our legitimate interests in operating and securing our business and services. When we act for a client business, we process customer data on that business's documented instructions and the business is responsible for establishing an appropriate legal basis.
If personal data is required to create an account, perform a contract, process a booking, or respond to a message, we may be unable to provide that function if the data is not supplied.
5. Automated assistance and artificial intelligence
Sage uses automated systems to identify the language and scope of a request, retrieve relevant information supplied by the client business, draft a response, check the response against safety and scope rules, and decide when to ask for human help. Client staff can take over a conversation. Requests outside the client business's scope are declined or escalated.
WhatsApp Business Solution Data is not used to create, develop, train, or improve any general-purpose machine learning or artificial intelligence model. We require production model providers to process data only to provide the requested service and with provider training disabled. We do not use WhatsApp data to build profiles about individual WhatsApp users, sell advertising, or make decisions that produce legal or similarly significant effects about them.
6. How we share personal data
We may disclose personal data only as needed to:
- the client business whose WhatsApp account and customer service you are using, including its authorised owners and staff;
- Meta and WhatsApp, to send and receive messages and administer WhatsApp Business Accounts;
- infrastructure and database providers, including Cloudflare, Fly.io, Supabase, and Redis Cloud;
- model and data-processing providers, including OpenRouter, the selected model provider, and Voyage AI, where their services are needed to process a request;
- professional advisers, auditors, insurers, and payment or accounting providers;
- authorities or other recipients where disclosure is required by law or is necessary to protect rights, safety, security, or legal claims; and
- a buyer or successor in connection with a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and data-protection measures.
We do not sell personal data. We do not share WhatsApp Business Solution Data for another party's own advertising, profiling, or model-training purposes. Service providers are required by contract to process personal data for the contracted service, protect it, and comply with applicable law.
7. International processing
Some service providers may process personal data outside Sri Lanka. This may include the United States and other countries where Meta, WhatsApp, Cloudflare, Fly.io, Supabase, Redis Cloud, OpenRouter, the selected model provider, or Voyage AI operate. Where required, we use contractual commitments and other safeguards intended to protect personal data during cross-border processing. Contact us if you want more information about safeguards relevant to your data.
8. Retention
We keep personal data only for as long as needed for the purpose described in this policy, to follow a client business's documented instructions, and to meet legal, security, accounting, dispute-resolution, and contractual requirements. We use the following criteria when setting a retention period:
- the duration of the account, engagement, or client contract;
- the period for which conversation history is needed to provide customer service;
- the sensitivity and volume of the data;
- security, fraud-prevention, audit, and backup requirements; and
- applicable limitation, tax, accounting, and regulatory periods.
When data is no longer required, we delete it or anonymise it. A client business may set a shorter retention period for data we process on its behalf. Residual copies may remain in protected backups until the backup is overwritten, unless we must preserve specific information by law or for an active legal claim.
9. Security and tenant separation
We use technical and organisational measures designed to protect personal data against unauthorised access, use, alteration, disclosure, loss, or destruction. These measures include access controls, encrypted transport, password hashing, signed sessions, encrypted WhatsApp access credentials, webhook signature verification, role-based permissions, tenant-scoped data access, message deduplication, and operational monitoring.
Each client business has a separate tenant identity. Application data access is scoped to that tenant so one client's staff cannot use the normal service interfaces to access another client's information. No internet service is completely secure, so we cannot guarantee absolute security.
10. Cookies and website analytics
The public Sys2 website does not currently use advertising cookies or behavioural analytics. The Sage dashboard uses strictly necessary authentication and security technology to keep users signed in and protect requests. If we introduce non-essential analytics or marketing cookies, we will update this policy and request consent where required.
11. Your choices and rights
Subject to applicable law and the role in which we process your data, you may ask to:
- confirm whether we process your personal data and obtain access to it;
- correct or complete inaccurate data;
- erase personal data in circumstances provided by law;
- withdraw consent where processing is based on consent;
- object to or ask us to stop certain processing;
- request review of a solely automated decision where applicable; or
- complain to the relevant data-protection authority.
To exercise a right, email privacy@replace-before-publishing.invalid with the subject “Privacy request”. We may ask for information needed to verify your identity and locate the relevant data. If your request concerns a client business, we may refer the request to that business or assist it in responding. We will respond within the period required by applicable law.
You may also contact the Data Protection Authority of Sri Lanka at dpa.gov.lk. If we refuse a request, we will explain the reason where the law allows and identify any available appeal or complaint process.
12. Children
Our website and business services are not directed to children. Client businesses must not use Sage to collect children's personal data unless they have an appropriate legal basis, provide any required notice, and obtain any required parent or guardian authorisation. If you believe a child's data has been processed improperly, contact us.
13. Changes to this policy
We may update this policy when our services, providers, or legal obligations change. We will publish the revised policy on this page and change the effective date. If a change materially affects how we use personal data, we will provide additional notice where reasonably practicable or legally required.
14. Contact
Questions, complaints, and privacy requests can be sent to privacy@replace-before-publishing.invalid.