Forsyt now has a store. Bring your idea and build a Micro SaaS with us, from PRD to launch.

Open the Micro SaaS Store
Privacy Policy

How we collect, use, and protect personal data

Effective: February 2026 · Version: 2.0 · See full security & trust documentation

ISO 27001 Certified · GDPR Compliant

This Privacy Policy explains how Credos Forsyt Private Limited (operating under the brand “Forsyt”; “we”, “us”) collects, uses, and protects personal data when you use our marketing site (forsyt.com), our Revenue OS application, and any related services. Our registered office is in New Delhi, India.

We act in two capacities: as a data controller for marketing-site visitors and lead-form submissions; and as a data processor for the customer pipeline data we process on behalf of paying customers. The EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the Indian Digital Personal Data Protection Act, 2023 (DPDPA) apply where relevant.

1. Who we are & how to reach us

  • Legal entity: Credos Forsyt Private Limited (operating as “Forsyt”)
  • Registered office: New Delhi, India
  • Founder & Data Protection Officer: Udit Pandoh
  • Privacy, DPO & security disclosures: privacy@forsyt.com
  • Commercial & billing: legal@forsyt.com
  • Governing law: India, with exclusive jurisdiction of the courts of New Delhi.

2. What personal data we collect

As a controller (marketing site):

  • Email address (lead-form submissions, newsletter)
  • Name and company (if provided)
  • Marketing-site analytics: pseudonymized page-view events, only after explicit cookie consent
  • Communication metadata (when you email us)

As a processor (Revenue OS application):

  • Names, business email, business phone, job title of your prospects and customers
  • CRM activity events (deal stages, close dates, notes)
  • Call transcripts and email content where shared with the application
  • Application user accounts (your team members) and access logs

We do not solicit or process special category data (health, religion, ethnicity, political views, etc.). If such data appears incidentally in pipeline content, you (the controller) are responsible for instructing us on its handling.

3. Lawful basis for processing

  • Performance of a contract (GDPR Art. 6(1)(b)): for processing pipeline data to deliver the Revenue OS service to paying customers.
  • Legitimate interest (GDPR Art. 6(1)(f)): for security, abuse prevention, fraud detection, and product analytics. Balancing test available on request.
  • Consent (GDPR Art. 6(1)(a)): for marketing emails, non-essential cookies, and product analytics on the marketing site. You can withdraw consent at any time.
  • Legal obligation (GDPR Art. 6(1)(c)): for tax, accounting, and law-enforcement disclosure where compelled.

4. How we use personal data

  • To provide and operate the Revenue OS service
  • To respond to enquiries, demos, and support requests
  • To improve our service through pseudonymized product analytics
  • To send transactional and (with consent) marketing communications
  • To comply with legal obligations

5. Where data is stored & hosted

  • EU / UK customers: AWS Frankfurt (eu-central-1)
  • Indian / APAC customers: AWS Mumbai (ap-south-1)
  • North American customers: AWS Virginia (us-east-1) on request

For EU/UK customers, data does not leave the EEA by default. Any incidental transfer (e.g., engineer access from outside EEA for support) is covered by Standard Contractual Clauses (SCCs) and supplementary technical measures (encryption at rest and in transit, role-based access).

6. Sub-processors

We engage third-party sub-processors to deliver the service. The complete list is published at /sub-processors, including each vendor’s purpose, the data they access, hosting region, and DPA reference. We give 30 calendar days’ advance notice via email and in-app banner before any change to this list.

7. Your rights as a data subject

Wherever applicable law grants you the following rights, we honour them:

  • Right of access (GDPR Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure — “right to be forgotten” (Art. 17)
  • Right to restrict processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object to processing (Art. 21)
  • Right not to be subject to automated decisions (Art. 22)
  • Right to lodge a complaint with your national supervisory authority (Art. 77)

To exercise any of these rights, email privacy@forsyt.com. We acknowledge requests within 5 business days and resolve them within the GDPR’s statutory one-month window. Complex requests may extend up to two further months with notice. If you are unhappy with our response, you may lodge a complaint with your national or regional supervisory authority (for EEA residents) or the Information Commissioner’s Office (for UK residents).

8. Retention

  • Customer pipeline data: retained for the duration of the contract.
  • AI conversation context: in-memory only — discarded at session end.
  • Application logs: retained for as long as operationally needed and then purged.
  • Marketing-site lead data: 3 years from last engagement, or until consent withdrawn.
  • On termination: all customer data deleted from active systems within 30 days. A signed deletion certificate is provided on request.

9. Security

  • AES-256 encryption at rest; TLS 1.3 in transit
  • Role-based access control for all personnel with access to production systems
  • Least-privilege production access with periodic access reviews
  • Audit logging of all access to personal data
  • Continuous backups with point-in-time restore
  • ISO/IEC 27001:2022 certified Information Security Management System

See /security for our complete security and trust documentation.

10. Personal data breaches

In the event of a confirmed personal-data breach, we notify affected customers and relevant supervisory authorities within 72 hours per GDPR Art. 33. We maintain a documented incident-response process and review it as our operations mature.

11. AI & automated decision-making

Forsyt uses Anthropic Claude (Sonnet) for AI Deal Chat reasoning. Anthropic’s commercial terms guarantee zero training on customer prompts or responses. Our backend processes prompts in-memory only — nothing is persisted to Forsyt servers after the response is returned.

Decisions that materially affect a deal (e.g., close-date push, status change) are always reviewed by a human before being written back to your CRM. You have the right not to be subject to a decision based solely on automated processing (GDPR Art. 22).

12. Cookies & tracking

Our marketing site uses essential cookies (always on) and optional analytics cookies (Google Analytics, PostHog). Optional cookies fire only after you give explicit consent via the cookie banner. You can withdraw consent at any time by clearing your browser’s cookies for this site, which re-displays the consent banner.

13. International transfers

Where personal data of EEA / UK / Swiss data subjects is transferred outside those jurisdictions (e.g., to a US-based sub-processor), we rely on Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum. Supplementary technical measures (encryption, access controls, pseudonymization) apply.

14. Children

Forsyt is a B2B service and is not directed at children. Consistent with India’s Digital Personal Data Protection Act, 2023, we treat any individual under 18 as a child and do not knowingly collect personal data from them. If we become aware that we have done so, we delete it immediately.

15. Changes to this policy

We update this policy from time to time. Material changes are notified by email (to customer admins and newsletter subscribers) and via an in-app banner at least 30 days before they take effect. The version history is preserved — previous versions are available on request.

16. Contact

For any privacy, DPO, GDPR, or security-disclosure question, write to privacy@forsyt.com. For commercial or billing matters, write to legal@forsyt.com.


If you cannot resolve a privacy concern with us, you may lodge a complaint with your national supervisory authority for data protection.

We use cookies for analytics to improve your experience. No personal data is sold. Privacy Policy