Sisotee LogoSisotee.

Chapters

📖 CHAPTER 1 – INTRODUCTION & SCOPE
Chapters ▾

Privacy Policy

Version 1.0•Effective: July 27, 2026

CHAPTER 1 – INTRODUCTION & SCOPE

§1.1 Introduction

Welcome to Sisotee, a cloud-based Software-as-a-Service (SaaS) platform owned and operated by ANABASIS INFRA PRIVATE LIMITED ("Sisotee," "Company," "we," "our," or "us").

Sisotee provides integrated digital solutions for residential, commercial, industrial, mixed-use, institutional, hospitality, and other managed communities. Depending on the subscription and configuration selected by a Community or organization, the Services may include visitor and gate access management, resident management, community ERP, financial management, maintenance billing, facility booking, communication tools, complaint management, vendor management, domestic staff management, parcel tracking, accounting, reporting, analytics, APIs, integrations, automation features, and other related services.

We recognize that privacy is fundamental to the trust placed in us by our users. This Privacy Policy explains how we collect, use, disclose, store, protect, retain, and otherwise process personal information in connection with the Services.

§1.2 Purpose of this Privacy Policy

The purpose of this Privacy Policy is to help you understand:

What information we collect;
How we collect it;
Why we collect it;
How we use it;
1 of 124 --
When we share it;
How we protect it;
How long we retain it;
What rights you may have regarding your personal information; and
How you can contact us with privacy-related questions or requests.

This Privacy Policy is intended to promote transparency regarding our data handling practices while supporting the secure operation of the Services.

§1.3 Scope

This Privacy Policy applies to personal information processed in connection with Sisotee, including information collected through:

The Sisotee mobile applications;
The Sisotee website;
Administrator dashboards;
Security guard applications;
Resident portals;
Visitor management interfaces;
Payment modules;
APIs;
Integrations;
Customer support interactions;
Email communications;
Push notifications;
SMS communications;
WhatsApp communications where enabled;
IoT devices integrated with Sisotee;
Other services offered under the Sisotee brand.

This Privacy Policy also applies to information processed while providing customer support, onboarding, migration, implementation, training, or related business services.

§1.4 Who this Policy Applies To

This Privacy Policy applies to all individuals whose information is processed through Sisotee, including:

Residents;
2 of 124 --
Apartment owners;
Tenants;
Family members added to resident accounts;
Community committee members;
Resident Welfare Associations (RWAs);
Housing societies;
Management companies;
Facility managers;
Property developers;
Security personnel;
Domestic workers;
Drivers;
Vendors;
Service providers;
Delivery personnel;
Visitors;
Guests;
Employees of customer organizations;
Prospective customers;
Website visitors;
API users; and
Other authorized users of the Services.

The specific information processed may vary depending on the role of the individual and the Services used.

§1.5 Relationship with the Terms of Service

This Privacy Policy forms an integral part of the Sisotee Terms of Service.

By accessing or using the Services, you acknowledge that your information will be processed as described in this Privacy Policy.

Where a conflict exists between this Privacy Policy and the Terms of Service regarding the processing of personal information, this Privacy Policy shall prevail to the extent of that conflict.

§1.6 Information Covered

3 of 124 --

This Privacy Policy governs information that can reasonably identify, relate to, describe, or be associated with an identified or identifiable individual, including information that becomes personal information when combined with other data.

This Policy also applies to information relating to devices, accounts, transactions, and usage where such information constitutes personal information under applicable law.

This Policy does not generally apply to information that has been irreversibly anonymized so that it can no longer reasonably identify an individual.

§1.7 Global Operations

Sisotee is currently offered in India and is designed to support future international deployment.

As our Services expand into additional jurisdictions, we may process information in accordance with the privacy and data protection laws applicable to those jurisdictions.

Where required by law, we will implement appropriate safeguards for international transfers of personal information and provide additional disclosures specific to those regions.

§1.8 Our Privacy Principles

We are guided by the following principles:

Lawfulness;
Fairness;
Transparency;
Purpose limitation;
Data minimization;
Accuracy;
Storage limitation;
Integrity;
Confidentiality;
Security by design;
Privacy by design;
Accountability; and
Continuous improvement.

These principles guide the design, operation, and ongoing development of the Services.

4 of 124 --

§1.9 Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

Changes in our Services;
Changes in applicable law;
Regulatory guidance;
Security enhancements;
Operational improvements; or
Changes to our business practices.

Where required by applicable law, we will provide reasonable notice of material changes before they become effective.

The "Effective Date" at the beginning of this Privacy Policy indicates the latest version.

§1.10 Contact Information

If you have questions regarding this Privacy Policy or our privacy practices, you may contact:

ANABASIS INFRA PRIVATE LIMITED Registered Office 13A, BG Tower Chandni Chowk Kanke Road Ranchi – 834008 Jharkhand, India Website https://www.sisotee.com Support Email support.sisotee@anabasis.in Grievance Officer Abha Bhushan Head – Support & Grievance Officer Email: support.sisotee@anabasis.in
Registered Office
Grievance Officer
5 of 124 --

Phone: +91 95235 54222 PRIVACY POLICY Sisotee Version 1.0 Effective Date: [To be inserted upon publication]

CHAPTER 2 – DEFINITIONS

For purposes of this Privacy Policy, the following terms shall have the meanings set out below.

Where the context requires otherwise, the singular includes the plural and vice versa.

§2.1 Company

"Company", "Sisotee", "we", "our", or "us" means ANABASIS INFRA PRIVATE LIMITED, including its successors, affiliates, subsidiaries (if any), and authorized service providers acting on its behalf.

§2.2 Platform

"Platform" means the Sisotee ecosystem, including:

Mobile applications;
Web applications;
Resident portals;
Administrator dashboards;
Security applications;
APIs;
Integrations;
Backend infrastructure;
Cloud services;
Software modules; and
Related digital services.
6 of 124 --

§2.3 Services

"Services" means all products, software, features, tools, APIs, integrations, and services made available by Sisotee, whether currently offered or introduced in the future.

§2.4 User

"User" means any individual or organization that accesses or uses the Services, including:

Residents;
Apartment owners;
Tenants;
Committee members;
Community administrators;
Security personnel;
Vendors;
Domestic workers;
Delivery personnel;
Visitors;
Guests;
Employees of customer organizations; and
Other authorized persons.

§2.5 Community

"Community" means any residential, commercial, industrial, institutional, mixed-use, hospitality, township, gated development, office complex, business park, or other property managed using Sisotee.

§2.6 Community Administrator

"Community Administrator" means a person authorized by a Community to manage administrative functions using Sisotee, including resident management, visitor approvals, billing, reporting, and operational activities.

7 of 124 --

§2.7 Resident

"Resident" means an owner, tenant, occupier, or other individual authorized to reside within or use a Community.

§2.8 Visitor

"Visitor" means any person visiting a Community temporarily, including invited guests, relatives, contractors, interview candidates, or other persons granted access.

§2.9 Delivery Personnel

"Delivery Personnel" means any individual delivering goods or services to a Community, including personnel associated with courier companies, e-commerce platforms, restaurants, grocery services, pharmacies, or similar businesses.

§2.10 Vendor

"Vendor" means any contractor, supplier, service provider, maintenance company, consultant, or business providing services to a Community.

§2.11 Domestic Worker

"Domestic Worker" means any individual engaged by a resident or Community to provide household or personal services, including domestic helpers, cooks, drivers, caregivers, gardeners, cleaners, and similar personnel.

§2.12 Personal Data

8 of 124 --

"Personal Data" means any information relating to an identified or identifiable natural person, including information that can directly or indirectly identify an individual, as defined under applicable data protection laws.

Examples include:

Name;
Mobile number;
Email address;
Residential unit details;
Vehicle registration number;
Photographs;
Device identifiers;
Visitor records; and
Other information capable of identifying an individual.

§2.13 Sensitive Personal Data

Where recognized under applicable law, "Sensitive Personal Data" means categories of information requiring enhanced protection.

Depending on the Services used, this may include information such as:

Government-issued identification details (where collected);
Authentication credentials;
Biometric information (where expressly enabled);
Financial account information;
Other categories designated as sensitive under applicable law.

Sisotee processes such information only where permitted or required by law and subject to appropriate safeguards.

§2.14 Processing

"Processing" means any operation performed on information, whether automated or manual, including:

Collection;
Recording;
Organization;
9 of 124 --
Storage;
Use;
Analysis;
Retrieval;
Disclosure;
Sharing;
Modification;
Transmission;
Retention;
Deletion; or
Destruction.

§2.15 Account

"Account" means a registered user profile used to access the Services.

§2.16 Device

"Device" means any hardware used to access Sisotee, including:

Smartphones;
Tablets;
Computers;
Laptops;
Smart displays;
Security terminals;
IoT devices; or
Other compatible equipment.

§2.17 Authentication Information

"Authentication Information" means information used to verify identity or authorize access, including:

Passwords;
Passkeys;
One-Time Passwords (OTPs);
10 of 124 --
Authentication tokens;
Session identifiers;
Multi-factor authentication credentials; and
Other security credentials.

For security reasons, Sisotee does not intentionally store passwords in readable form.

§2.18 Cookies

"Cookies" means small text files or similar technologies placed on a device to recognize users, remember preferences, maintain sessions, enhance security, or improve the Services.

This definition also includes similar technologies such as local storage, software development kit (SDK) identifiers, pixels, and other comparable technologies where applicable.

§2.19 Usage Information

"Usage Information" means technical and operational information generated through use of the Services, including:

Login history;
Session duration;
Device type;
Browser type;
Operating system;
IP address;
Feature usage;
Error logs;
Performance metrics; and
Other diagnostic information.

§2.20 Location Information

"Location Information" means information relating to the geographic location of a device or individual.

Depending on the Services used and the permissions granted, this may include:

11 of 124 --
Approximate location derived from IP address;
GPS location;
Device-generated location information; or
Location associated with a Community or property.

Where required by applicable law or platform permissions, precise location will only be processed with the user's permission.

§2.21 Visitor Information

"Visitor Information" means information relating to visitors entering or attempting to enter a Community, including:

Name;
Mobile number;
Visit purpose;
Host resident;
Entry and exit timestamps;
Vehicle details;
Photographs where enabled;
QR codes;
OTP verification records; and
Other access-related information.

§2.22 Community Data

"Community Data" means information generated or managed by a Community using Sisotee, including:

Resident directories;
Financial records;
Maintenance records;
Complaints;
Notices;
Facility bookings;
Committee information;
Security logs;
Vendor records; and
Administrative records.
12 of 124 --

Ownership and control of Community Data remain subject to applicable agreements and the Terms of Service.

§2.23 Third-Party Services

"Third-Party Services" means products, software, applications, APIs, websites, cloud providers, payment processors, communication providers, analytics providers, hardware manufacturers, government systems, or other services not owned or operated by Sisotee.

§2.24 Anonymized Information

"Anonymized Information" means information that has been processed so that it can no longer reasonably identify an individual, taking into account available technology and applicable legal standards.

Properly anonymized information is not considered Personal Data under many privacy laws.

§2.25 Aggregated Information

"Aggregated Information" means information combined from multiple users or Communities in a manner that does not reasonably identify any individual.

Aggregated information may be used for:

Statistical analysis;
Service improvement;
Capacity planning;
Research;
Business analytics; and
Product development.

§2.26 Applicable Law

13 of 124 --

"Applicable Law" means all laws, regulations, rules, judicial decisions, governmental orders, and legally binding requirements applicable to the processing of information under this Privacy Policy.

§2.27 Consent

"Consent" means any freely given, specific, informed, and unambiguous indication of a person's agreement to the processing of their Personal Data, where consent is the applicable legal basis under relevant law.

Where applicable law permits another legal basis for processing, Sisotee may rely on that basis instead of consent.

§2.28 Data Breach

"Data Breach" means a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Personal Data.

Not every security event constitutes a Data Breach under applicable law.

§2.29 Artificial Intelligence (AI)

"Artificial Intelligence" or "AI" means machine-learning, generative AI, optical character recognition (OCR), automation, predictive analytics, or similar technologies used within the Services to assist with tasks such as document processing, search, recommendations, summaries, or operational workflows.

Where AI features are offered, they are intended to assist users and should not be relied upon as a substitute for professional judgment or independent verification.

§2.30 Interpretation

Unless the context requires otherwise:

14 of 124 --
References to the singular include the plural and vice versa.
References to one gender include all genders.
"Including", "includes", and "such as" mean "including, without limitation."
Headings are for convenience only and do not affect interpretation.

CHAPTER 3 – INFORMATION WE

COLLECT Sisotee collects information necessary to provide, secure, improve, and support the Services.

The categories of information collected depend on the Services used, your role within a Community, your device settings, and applicable legal requirements.

§3.1 Overview

The information we collect generally falls into the following categories:

Information you provide directly;
Information provided by Communities or other users;
Information generated through your use of the Services;
Information collected automatically from devices;
Information received from third-party services;
Information generated by integrated hardware and software; and
Information created during customer support interactions.

Not every user will provide or generate every category of information described below.

§3.2 Account Information

When you create or manage an account, we may collect:

Full name;
Mobile number;
Email address;
User role;
Username (if applicable);
Profile photograph;
Preferred language;
15 of 124 --
Preferred communication settings;
Community affiliation;
Unit, apartment, office, or property details; and
Other information necessary to create and maintain your account.

§3.3 Identity Verification Information

Where identity verification is offered or required, we may process:

Government-issued identification details;
Identity verification status;
Verification reference numbers;
Verification timestamps;
Authentication records; and
Other information necessary to confirm identity.

Where legally required, identity verification may be performed by authorized third-party providers.

§3.4 Community Information

Communities may provide information relating to:

Community name;
Property address;
Tower or block details;
Unit numbers;
Ownership status;
Tenancy information;
Committee membership;
Resident directories;
Maintenance records;
Facility allocations;
Community rules;
Administrative settings; and
Other operational information.
16 of 124 --

§3.5 Resident Information

Depending on the Community configuration, we may process:

Resident name;
Unit number;
Family member details;
Contact information;
Emergency contacts;
Vehicle details;
Resident identification number;
Occupancy status;
Access permissions; and
Other information provided by the resident or Community.

§3.6 Family Member Information

Residents may voluntarily add information relating to family members residing in the same unit.

This may include:

Name;
Relationship;
Contact details;
Profile photograph;
Access permissions; and
Other information necessary to provide the requested Services.

Residents are responsible for ensuring they have appropriate authority to provide such information.

§3.7 Visitor Information

To facilitate gate access management, we may process:

Visitor name;
Mobile number;
Visit purpose;
Host resident;
Date and time of visit;
17 of 124 --
Entry and exit timestamps;
Vehicle information;
QR codes;
OTP verification records;
Visitor photographs where enabled by the Community;
Gate access status; and
Other access-related information.

Visitor information may be supplied by:

Residents;
Security personnel;
Visitors themselves; or
Authorized third-party integrations.

§3.8 Delivery Personnel Information

Where delivery management features are used, we may process:

Name;
Mobile number;
Employer or delivery platform;
Delivery purpose;
Vehicle details;
Delivery timestamps;
Entry and exit records;
Delivery status;
Verification records; and
Other information reasonably necessary to manage deliveries.

§3.9 Domestic Worker Information

Residents or Communities may provide information relating to domestic workers, including:

Name;
Mobile number;
Nature of work;
Employer (where applicable);
Scheduled working hours;
Access permissions;
18 of 124 --
Attendance records;
Entry and exit logs;
Photographs where enabled; and
Verification status.

The resident or Community providing this information is responsible for obtaining any permissions required by applicable law.

§3.10 Vendor Information

We may process information relating to contractors, suppliers, and service providers, including:

Business name;
Contact person;
Mobile number;
Email address;
Services provided;
Billing information;
Tax registration details;
Attendance records;
Access logs; and
Other information necessary for Community operations.

§3.11 Vehicle Information

To facilitate parking and gate management, we may process:

Vehicle registration number;
Vehicle type;
Parking allocation;
Resident association;
Visitor vehicle information;
Entry and exit records;
RFID identifiers (where used);
QR code identifiers;
Other vehicle-related information.
19 of 124 --

§3.12 Payment and Financial Information

Where financial modules are used, we may process:

Maintenance invoices;
Payment status;
Transaction reference numbers;
Billing history;
Refund records;
Ledger information;
Tax information;
Accounting records;
Financial reports; and
Other ERP-related financial information.

Sisotee does not intentionally store complete payment card numbers, CVV values, or other sensitive payment credentials when payments are processed by certified third-party payment providers.

§3.13 Customer Support Information

When you contact Sisotee, we may collect:

Support requests;
Emails;
Chat messages;
Telephone call records where legally permitted;
Attachments;
Screenshots;
Screen recordings voluntarily shared by you;
Diagnostic information;
Bug reports; and
Other information necessary to resolve your request.

§3.14 Communications

We may process communications exchanged through the Platform, including:

Community notices;
Complaint submissions;
20 of 124 --
Discussion posts;
Comments;
Classified listings;
Poll responses;
Announcements;
Administrative communications; and
Other communications facilitated by the Services.

§3.15 Documents and Files

Users may upload:

Identity documents;
Agreements;
Invoices;
Images;
PDFs;
Maintenance records;
Community documents;
Financial records;
Other supported files.

Users remain responsible for ensuring they have the legal authority to upload such materials.

§3.16 Images and Photographs

Depending on the features enabled, we may process:

Profile photographs;
Visitor photographs;
Vehicle photographs;
QR code images;
Uploaded documents;
Images attached to complaints;
Images uploaded to classified listings;
Other images voluntarily provided.

Where Communities integrate CCTV systems, Sisotee may receive metadata or event notifications. Unless expressly configured and supported, Sisotee does not continuously record or monitor CCTV footage.

21 of 124 --

§3.17 Device Information

When you access the Services, we may automatically collect technical information including:

Device model;
Operating system;
Browser type;
App version;
Language settings;
Time zone;
Device identifiers;
Push notification token;
Network information;
Crash diagnostics; and
Performance metrics.

§3.18 Usage Information

We may collect information regarding how the Services are used, including:

Login timestamps;
Logout timestamps;
Session duration;
Features accessed;
Pages viewed;
Buttons clicked;
Search activity;
Navigation paths;
Error events;
Performance statistics; and
Other operational analytics.

This information helps us improve reliability, security, and user experience.

§3.19 Location Information

Depending on your device settings and the permissions you grant, Sisotee may process:

22 of 124 --
Approximate location derived from IP address;
GPS location;
Community location;
Location associated with access events; and
Other location information necessary for specific features.

Where required by law or platform permissions, precise location is collected only with your permission.

You may disable location permissions through your device settings, although some features may no longer function correctly.

§3.20 Authentication and Security Information

To protect accounts and the Platform, we process information such as:

Password hashes;
Passkey credentials;
Multi-factor authentication status;
OTP verification records;
Authentication logs;
Failed login attempts;
Session identifiers;
Security alerts;
Device trust information; and
Risk assessment indicators.

Passwords are stored using industry-standard cryptographic hashing techniques and are not stored in plaintext.

§3.21 Information from Third Parties

We may receive information from third parties including:

Community administrators;
Payment service providers;
Identity verification providers;
SMS providers;
Email providers;
Push notification providers;
23 of 124 --
Government systems, where legally authorized;
Business partners;
Integrated software providers; and
Other authorized sources.

We process such information in accordance with this Privacy Policy and applicable law.

§3.22 API and Integration Data

Where integrations are enabled, Sisotee may receive or exchange information through APIs, including:

Authentication tokens;
Event notifications;
User identifiers;
Visitor approval status;
Payment confirmations;
Accounting data;
ERP information;
System logs; and
Other information necessary for the requested integration.

§3.23 IoT and Access Control Data

Where supported hardware is connected to Sisotee, we may process:

RFID scans;
QR code scans;
Gate events;
Smart lock events;
Boom barrier events;
Biometric verification status (where enabled and lawful);
Device health information;
Hardware identifiers; and
Other operational telemetry.

§3.24 AI and Automation Data

24 of 124 --

Where AI-powered features are used, we may process:

User prompts;
Uploaded documents;
OCR outputs;
AI-generated summaries;
AI-generated recommendations;
Automation requests;
User feedback relating to AI responses; and
Operational metadata necessary to improve AI functionality.

AI-generated outputs may contain inaccuracies and should be reviewed by users before being relied upon.

§3.25 Information We Do Not Intentionally Collect

Unless expressly required for a supported feature or required by applicable law, Sisotee does not intentionally collect:

Payment card CVV values;
Payment card PINs;
Online banking passwords;
One-time banking passwords unrelated to Sisotee transactions;
Personal email passwords;
Social media passwords; or
Other credentials unrelated to providing the Services.

Users should never share such information through Sisotee.

§3.26 Accuracy of Information

Users and Communities are responsible for ensuring that the information they provide is:

Accurate;
Complete;
Lawfully obtained; and
Kept reasonably up to date.

Sisotee does not independently verify all information submitted to the Platform.

25 of 124 --

CHAPTER 4 – HOW WE COLLECT

INFORMATION Sisotee collects information from multiple sources in order to provide, maintain, secure, improve, and support the Services. The categories and methods of collection depend on the features used, the role of the individual, Community configurations, and applicable legal requirements.

§4.1 Overview

We may collect information:

Directly from you;
From your Community;
From other authorized users;
Automatically through your use of the Services;
From integrated hardware and software;
From third-party service providers;
From business partners;
From publicly available sources where permitted by law; and
From lawful governmental or regulatory sources where applicable.

We do not knowingly collect information through unlawful or deceptive means.

§4.2 Information You Provide Directly

You may voluntarily provide information when you:

Register an account;
Join a Community;
Complete your profile;
Add family members;
Register vehicles;
Invite visitors;
Pre-approve guests;
Schedule deliveries;
Submit complaints;
Book facilities;
Participate in discussions;
26 of 124 --
Respond to polls;
Upload documents;
Upload photographs;
Contact customer support;
Send feedback;
Report bugs;
Use AI-powered features; or
Otherwise interact with the Services.

You may choose not to provide certain information; however, some features may not function correctly without it.

§4.3 Information Provided by Communities

Communities using Sisotee may provide information relating to their residents and operations, including:

Resident directories;
Ownership records;
Tenant information;
Unit allocations;
Vehicle records;
Maintenance billing;
Committee memberships;
Facility access permissions;
Visitor policies;
Security settings; and
Other operational information.

Communities are responsible for ensuring they have the legal authority to provide such information.

§4.4 Information Provided by Other Users

Other authorized users may provide information relating to you, including:

Visitor invitations;
Family member details;
Emergency contact information;
Domestic worker registrations;
27 of 124 --
Vendor registrations;
Complaint references;
Community communications; and
Facility booking information.

The individual submitting such information is responsible for ensuring that they have the authority or consent required under applicable law.

§4.5 Information Collected During Visitor Registration

Visitor information may be collected through:

Resident invitations;
Security guard entry;
Visitor self-registration;
QR code check-in;
OTP verification;
Reception desks;
Kiosk devices;
Pre-approved visitor workflows; or
Other supported access methods.

Depending on Community settings, visitor information may be collected before, during, or after a visit.

§4.6 Information Collected During Delivery Management

Where delivery management is enabled, information may be collected from:

Residents;
Security personnel;
Delivery personnel;
Delivery platforms;
QR codes;
OTP verification;
Entry logs;
Exit confirmations; and
Other supported integrations.
28 of 124 --

§4.7 Information from Domestic Worker and Vendor

Registration Residents or Communities may register:

Domestic workers;
Drivers;
Caregivers;
Gardeners;
Maintenance contractors;
Vendors;
Suppliers; and
Other service providers.

The registering party is responsible for ensuring that such registration complies with applicable law.

§4.8 Information Collected Automatically

When you use the Services, certain technical information may be collected automatically, including:

Device identifiers;
IP address;
Browser type;
Operating system;
Application version;
Language settings;
Time zone;
Session identifiers;
Feature usage;
Error reports;
Performance metrics; and
Security logs.

This information helps us operate, secure, and improve the Services.

§4.9 Cookies and Similar Technologies

29 of 124 --

Our websites and web applications may use:

Cookies;
Local storage;
Session storage;
Pixels;
SDKs;
Device identifiers; and
Similar technologies.

These technologies help us:

Authenticate users;
Maintain sessions;
Improve security;
Remember preferences;
Measure performance;
Analyze usage; and
Improve user experience.

Additional information is provided in the Sisotee Cookie Policy.

§4.10 Mobile Device Permissions

Depending on the features you use and your device settings, the Sisotee mobile application may request permission to access:

Camera;
Photo library;
Microphone;
Location;
Notifications;
Contacts (where a feature specifically requires it);
Storage or files; and
Other permissions supported by your operating system.

Permissions are requested through your device's operating system and can generally be managed through your device settings.

Some features may not function properly if required permissions are denied.

30 of 124 --

§4.11 Location Information

Where enabled and permitted by you, Sisotee may collect location information from:

GPS services;
Mobile operating systems;
Wi-Fi-based location;
IP address;
Bluetooth-based proximity features (where supported); or
Other location technologies.

We collect precise location only where required for a feature and permitted by applicable law.

§4.12 Authentication Information

Authentication information is collected when you:

Sign in;
Verify your identity;
Complete OTP verification;
Register a passkey;
Use multi-factor authentication;
Reset your password;
Approve trusted devices; or
Perform other security-related actions.

Authentication records help protect your account and detect unauthorized access.

§4.13 Information from Payment Service Providers

Payment-related information may be received from authorized payment providers, including:

Payment status;
Transaction identifiers;
Settlement confirmations;
Refund status;
Payment timestamps;
Failure notifications; and
Other transaction metadata.
31 of 124 --

Sensitive payment credentials remain under the control of certified payment providers and are not intentionally stored by Sisotee except where necessary and permitted by applicable law.

§4.14 Information from Communication Providers

To deliver communications, Sisotee may receive information from:

SMS providers;
Email service providers;
Push notification providers;
WhatsApp service providers;
Voice communication providers (where supported); and
Other messaging platforms.

Such information may include delivery status, message identifiers, timestamps, and diagnostic information.

§4.15 Information from APIs and Integrations

Where authorized by users or Communities, Sisotee may receive information through integrations with:

Accounting systems;
ERP software;
Payment systems;
Identity verification services;
Access control systems;
Property management software;
CRM systems;
Business automation platforms;
Government-authorized systems; and
Other compatible services.

Only the information reasonably necessary for the requested integration will be processed.

§4.16 Information from IoT Devices

Where integrated hardware is deployed, Sisotee may receive operational information from:

32 of 124 --
RFID readers;
QR scanners;
Smart locks;
Boom barriers;
Intercom systems;
Biometric devices (where enabled and lawful);
Attendance devices;
Access terminals;
Sensors; and
Other compatible IoT devices.

The availability and accuracy of such information depends on the proper operation of the integrated hardware.

§4.17 Information Generated by AI Features

Where AI-powered features are used, information may be generated from:

User prompts;
Uploaded documents;
OCR processing;
Search queries;
Automation requests;
User corrections;
Feature interactions; and
Operational metadata.

AI-generated information is processed to provide the requested functionality, improve service quality, detect misuse, and maintain system performance, subject to applicable law.

§4.18 Information from Customer Support

When you request assistance, we may collect information through:

Email correspondence;
Live chat;
Support tickets;
Telephone calls (where legally permitted);
Remote troubleshooting sessions;
Diagnostic logs;
33 of 124 --
Screen recordings voluntarily shared by you;
Screenshots;
Error reports; and
Other communications relating to your request.

This information is used solely to investigate, resolve, and improve customer support.

§4.19 Information from Public Sources

Where permitted by applicable law, we may receive limited information from publicly available sources, such as:

Official business registries;
Public government records;
Corporate websites;
Public directories; or
Other publicly accessible sources.

We do not collect information from public sources for purposes incompatible with this Privacy Policy.

§4.20 Information from Government Authorities

Where required or permitted by applicable law, we may receive information from:

Courts;
Regulatory authorities;
Law enforcement agencies;
Government departments; or
Other competent public authorities.

Such information will be processed only for lawful purposes.

§4.21 Fraud Prevention and Security Information

We may collect information relating to suspected fraud, abuse, or security incidents, including:

Login anomalies;
34 of 124 --
Unusual access patterns;
Device risk indicators;
Security alerts;
Abuse reports;
Spam detection signals;
Account compromise indicators; and
Other information reasonably necessary to protect the Services.

§4.22 Business Transfers

If Sisotee is involved in a merger, acquisition, restructuring, financing transaction, or sale of assets, relevant information may be collected, reviewed, or transferred as part of due diligence or transaction completion, subject to confidentiality obligations and applicable law.

Users will be informed where required by applicable law.

§4.23 Information We Do Not Intentionally Collect

Unless expressly required for a supported feature or required by law, Sisotee does not intentionally collect:

Personal banking passwords;
Payment card PINs;
Full CVV values;
Passwords for third-party accounts unrelated to Sisotee;
Personal social media passwords; or
Other confidential credentials unrelated to providing the Services.

Users should never submit such information through the Platform.

§4.24 Accuracy and Lawful Collection

Users and Communities are responsible for ensuring that information provided to Sisotee:

Is accurate;
Is current to the best of their knowledge;
Has been collected lawfully; and
May be processed in accordance with this Privacy Policy and applicable law.
35 of 124 --

Sisotee may request updates or corrections where information appears incomplete, inaccurate, or inconsistent.

CHAPTER 5 – WHY WE PROCESS

INFORMATION Sisotee processes Personal Data only for lawful, specified, and legitimate purposes. The purposes described below explain why we process information and how such processing supports the operation, security, improvement, and legal compliance of the Services.

Not every purpose described in this Chapter applies to every user. The purposes depend on the Services used, your role, Community configuration, and applicable law.

§5.1 Providing the Services

We process Personal Data to provide the Services requested by you or your Community, including:

Creating and maintaining user accounts;
Managing Communities;
Providing resident services;
Operating ERP modules;
Enabling visitor management;
Managing gate access;
Supporting financial operations;
Providing administrative tools; and
Delivering other subscribed features.

§5.2 Account Registration and Authentication

We process information to:

Register users;
Verify identity;
Authenticate login attempts;
Manage passwords and passkeys;
Enable multi-factor authentication;
36 of 124 --
Detect unauthorized access;
Maintain account security; and
Prevent account misuse.

§5.3 Community Administration

We process information to help Communities:

Maintain resident directories;
Manage ownership and tenancy records;
Configure access permissions;
Assign administrative roles;
Manage committee operations;
Maintain facility records;
Coordinate community activities; and
Operate the Community efficiently.

Sisotee provides the technology platform; Communities remain responsible for their administrative decisions.

§5.4 Visitor and Gate Access Management

One of Sisotee's core purposes is facilitating secure and efficient access management.

We process information to:

Register visitors;
Verify visitor identity where applicable;
Process visitor approvals;
Generate QR codes and OTPs;
Record entry and exit events;
Maintain access logs;
Notify residents of visitor arrivals;
Manage delivery access;
Track domestic staff attendance;
Operate smart gate integrations; and
Support Community security workflows.
37 of 124 --

§5.5 Vehicle and Parking Management

We process vehicle-related information to:

Register authorized vehicles;
Manage parking allocations;
Facilitate gate access;
Verify vehicle entry;
Record parking activity;
Manage visitor parking; and
Improve Community traffic management.

§5.6 Community ERP Operations

Where ERP features are enabled, we process information to:

Manage maintenance charges;
Generate invoices;
Record payments;
Maintain ledgers;
Prepare financial reports;
Track expenses;
Manage vendors;
Process purchase requests;
Maintain accounting records;
Support audits; and
Operate Community financial management systems.

§5.7 Payment Processing

We process payment-related information to:

Process maintenance payments;
Verify transactions;
Generate receipts;
Process refunds where applicable;
Maintain transaction history;
Detect payment fraud;
Reconcile accounts;
38 of 124 --
Comply with financial regulations; and
Support customer inquiries.

Payment processing may involve independent payment service providers.

§5.8 Customer Support

We process information to:

Respond to support requests;
Investigate reported issues;
Resolve technical problems;
Diagnose software defects;
Improve customer service;
Communicate updates; and
Maintain support records.

Support interactions may be reviewed internally for quality assurance and training, subject to applicable law.

§5.9 Communications

We process information to send communications including:

OTPs;
Login alerts;
Visitor notifications;
Delivery notifications;
Maintenance reminders;
Payment confirmations;
Community announcements;
Security alerts;
Service updates;
Product notices;
Customer support communications; and
Other transactional messages.

Where permitted by law and your preferences, we may also send product updates or promotional communications.

39 of 124 --

You may opt out of marketing communications where applicable, although you cannot opt out of essential service communications necessary to operate your account or the Services.

§5.10 Complaint Management

We process complaint-related information to:

Record complaints;
Route complaints to authorized Community personnel;
Track complaint status;
Facilitate communication between residents and Communities;
Generate reports; and
Improve Community administration.

Sisotee does not adjudicate complaints unless expressly stated.

§5.11 Community Features

We process information necessary to operate:

Community discussions;
Notices;
Polls;
Classified listings;
Announcements;
Facility bookings;
Resident directories;
Community events; and
Other collaboration features.

§5.12 AI and Automation Features

Where AI-powered functionality is available, we may process information to:

Generate summaries;
Extract information from uploaded documents using OCR;
Assist with searches;
Improve document organization;
40 of 124 --
Automate repetitive tasks;
Generate recommendations;
Enhance productivity;
Improve service quality; and
Develop future AI capabilities.

AI-generated responses are intended to assist users and may contain inaccuracies. Users remain responsible for reviewing AI-generated outputs before relying upon them.

§5.13 Analytics and Service Improvement

We process information to better understand how the Services are used, including to:

Measure feature adoption;
Improve usability;
Identify performance issues;
Optimize workflows;
Develop new features;
Improve accessibility;
Enhance reliability; and
Make informed product decisions.

Where feasible, we use aggregated or anonymized information for analytics.

§5.14 Security

We process information to protect:

Users;
Communities;
Visitors;
Sisotee;
Infrastructure;
Accounts; and
Integrated systems.

Security-related processing may include:

Monitoring suspicious activity;
Detecting malware;
41 of 124 --
Preventing unauthorized access;
Identifying compromised accounts;
Investigating security incidents;
Protecting against cyberattacks; and
Maintaining system integrity.

§5.15 Fraud Prevention

We process information to detect, investigate, prevent, and respond to:

Fraud;
Identity theft;
Payment fraud;
Unauthorized access;
Fake accounts;
Abuse of Community features;
Spam;
Automated attacks;
API misuse; and
Other unlawful or harmful activities.

§5.16 Legal Compliance

We process information where necessary to comply with applicable legal obligations, including:

Tax laws;
Financial regulations;
Court orders;
Lawful requests from competent authorities;
Record retention requirements;
Regulatory investigations;
Compliance audits; and
Other legal obligations.

§5.17 Enforcement of Terms

We may process information to:

42 of 124 --
Investigate violations of the Terms of Service;
Protect intellectual property;
Resolve disputes;
Enforce contractual rights;
Protect users and Communities; and
Defend legal claims.

§5.18 Business Operations

We process information for legitimate business operations, including:

Internal administration;
Financial planning;
Capacity planning;
Service monitoring;
Disaster recovery;
Business continuity;
Risk management;
Compliance management; and
Internal reporting.

Where possible, we use aggregated or anonymized information for these purposes.

§5.19 Research and Product Development

We may process information to:

Improve existing products;
Develop new Services;
Evaluate feature requests;
Conduct product testing;
Measure performance;
Improve AI models;
Enhance security systems; and
Conduct internal research.

Where appropriate, research activities may use anonymized or aggregated information instead of directly identifiable Personal Data.

43 of 124 --

§5.20 Corporate Transactions

If Sisotee undergoes a merger, acquisition, investment, restructuring, financing, or sale of assets, information may be processed as reasonably necessary to evaluate, negotiate, complete, or integrate the transaction, subject to confidentiality obligations and applicable law.

§5.21 Emergency Situations

Where permitted by applicable law, we may process or disclose information if reasonably necessary to:

Protect life or physical safety;
Respond to emergencies;
Assist emergency responders;
Prevent serious harm;
Protect Community security; or
Respond to urgent security incidents.

§5.22 Statistical and Aggregated Information

We may generate aggregated or anonymized information for purposes including:

Usage statistics;
Product performance;
Infrastructure planning;
Capacity forecasting;
Market analysis;
Academic or industry research;
Benchmarking; and
Product development.

Where information has been irreversibly anonymized, it no longer identifies an individual.

§5.23 Future Services

As Sisotee evolves, we may process information to provide new products, services, or features consistent with this Privacy Policy.

44 of 124 --

If a new purpose would materially differ from the purposes described here, we will provide additional notice or obtain consent where required by applicable law before processing information for that new purpose.

§5.24 Purpose Limitation

We process Personal Data only for purposes that are:

Lawful;
Fair;
Transparent;
Compatible with the purpose for which the information was collected; and
Otherwise permitted by applicable law.

Where we intend to process Personal Data for a materially different purpose that requires additional legal authorization, we will provide appropriate notice or obtain consent where required.

CHAPTER 6 – LEGAL BASES FOR

PROCESSING Sisotee processes Personal Data only where there is a lawful basis to do so under applicable privacy and data protection laws. The legal basis applicable to a particular processing activity depends on the nature of the Services, your relationship with Sisotee or the Community, and the laws applicable to the processing.

This Chapter explains the legal grounds on which Sisotee relies when processing Personal Data.

§6.1 General Principle

Sisotee processes Personal Data only where processing is:

Authorized by applicable law;
Necessary for providing the Services;
Fair and transparent;
Limited to legitimate purposes; and
45 of 124 --
Consistent with this Privacy Policy.

Different legal bases may apply simultaneously to the same processing activity.

§6.2 Performance of a Contract

We process Personal Data where necessary to perform a contract with you or to take steps at your request before entering into a contract.

Examples include:

Creating user accounts;
Authenticating users;
Managing Communities;
Processing visitor approvals;
Providing ERP functionality;
Managing maintenance billing;
Recording payments;
Operating facility booking systems;
Providing customer support; and
Delivering other Services requested by you or your Community.

Without this processing, many core features of the Services cannot be provided.

§6.3 Compliance with Legal Obligations

We process Personal Data where necessary to comply with legal or regulatory obligations, including obligations relating to:

Taxation;
Accounting;
Financial reporting;
Court orders;
Regulatory investigations;
Lawful governmental requests;
Anti-fraud measures;
Record retention;
Cybersecurity obligations;
Data protection laws; and
Other legal requirements.
46 of 124 --

Where required by law, Sisotee may disclose information to competent authorities.

§6.4 Legitimate Interests

Where permitted by applicable law, Sisotee may process Personal Data where such processing is reasonably necessary for our legitimate interests or those of our customers, provided those interests are not overridden by your rights and freedoms.

Legitimate interests may include:

Operating the Platform;
Improving the Services;
Maintaining security;
Preventing fraud;
Detecting abuse;
Responding to support requests;
Protecting users and Communities;
Conducting internal analytics;
Improving accessibility;
Maintaining business continuity;
Developing new features;
Managing corporate operations; and
Protecting Sisotee's legal rights.

Where required by law, we assess whether our legitimate interests are balanced against the interests and fundamental rights of affected individuals.

§6.5 Consent

Certain processing activities may rely on your consent where required by applicable law.

Examples may include:

Optional location access;
Certain marketing communications;
Optional AI-powered features;
Optional integrations;
Camera access;
Microphone access;
Optional notifications;
47 of 124 --
Processing of specific categories of Personal Data where consent is required.

Where processing is based on consent:

Consent should be freely given;
Consent should be informed;
Consent should be specific where required;
Consent may be withdrawn at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

§6.6 Protection of Vital Interests

Where permitted by applicable law, Sisotee may process Personal Data where reasonably necessary to protect the life, health, or physical safety of an individual.

Examples may include:

Emergency situations;
Security incidents;
Serious threats to life;
Medical emergencies;
Disaster response; or
Other urgent circumstances.

Such processing will be limited to what is reasonably necessary.

§6.7 Public Interest

Where permitted or required by applicable law, Sisotee may process Personal Data for reasons of public interest, including where processing supports:

Public safety;
Law enforcement cooperation;
Judicial proceedings;
Government investigations;
Regulatory compliance; or
Other legally authorized public functions.
48 of 124 --

§6.8 Community Instructions

In many cases, Communities determine how certain Personal Data is processed within Sisotee.

For example, Communities may determine:

Resident records;
Visitor approval workflows;
Domestic worker registrations;
Financial records;
Community notices;
Complaint management;
Facility booking rules; and
Community-specific administrative processes.

Where Communities determine the purposes and means of processing, they are responsible for ensuring that such processing complies with applicable law.

Sisotee processes such information in accordance with applicable agreements, this Privacy Policy, and the lawful instructions of the Community, except where Sisotee has independent legal obligations.

§6.9 Children's Information

Where information relating to minors is processed, Sisotee relies upon the legal authority of:

A parent;
A legal guardian;
A resident authorized to act on the child's behalf; or
Another person legally entitled to provide the information,

unless another lawful basis applies.

Communities and users remain responsible for ensuring they have appropriate authority before providing such information.

§6.10 AI Processing

Where AI-powered features are available, Sisotee may process Personal Data to:

49 of 124 --
Generate summaries;
Perform OCR;
Organize documents;
Provide recommendations;
Improve productivity;
Detect errors;
Support automation.

AI processing is carried out only where supported by an appropriate legal basis under applicable law.

Where required by law, additional disclosures or user choices may be provided before AI processing occurs.

§6.11 Security and Fraud Prevention

Processing necessary to:

Detect unauthorized access;
Prevent fraud;
Protect accounts;
Investigate abuse;
Monitor cybersecurity threats;
Secure infrastructure;
Maintain audit logs; and
Respond to security incidents

may be carried out where permitted by applicable law and reasonably necessary to protect users, Communities, Sisotee, and third parties.

§6.12 Business Transfers

Where reasonably necessary to complete:

A merger;
Acquisition;
Investment;
Financing;
Corporate restructuring;
Sale of assets; or
50 of 124 --
Other corporate transaction,

Personal Data may be processed pursuant to the lawful basis applicable under relevant law.

Appropriate confidentiality obligations will apply throughout such transactions.

§6.13 Compliance with the Digital Personal Data Protection

Act, 2023 Where the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") applies, Sisotee seeks to process Personal Data in accordance with its applicable requirements.

Depending on the circumstances, processing may be based on:

Your consent;
Certain legitimate uses recognized under the DPDP Act; or
Other lawful grounds permitted by the Act.

Where the DPDP Act grants individuals specific rights regarding their Personal Data, Sisotee will facilitate the exercise of those rights in accordance with the Act and applicable rules.

§6.14 International Privacy Laws

As Sisotee expands internationally, processing may also be subject to additional privacy and data protection laws in relevant jurisdictions.

Where applicable, Sisotee will comply with relevant legal requirements, which may include obligations relating to:

Transparency;
User rights;
International data transfers;
Security measures;
Breach notifications;
Cross-border processing;
Consent management; and
Accountability.

Additional region-specific privacy notices may supplement this Privacy Policy where required.

51 of 124 --

§6.15 Multiple Legal Bases

A single processing activity may rely upon more than one lawful basis.

For example, processing payment information may simultaneously be necessary for:

Performance of a contract;
Compliance with tax laws;
Fraud prevention;
Accounting obligations; and
Protection of Sisotee's legitimate interests.

The existence of one legal basis does not prevent another lawful basis from also applying.

§6.16 Withdrawal of Consent

Where processing is based on your consent, you may withdraw that consent at any time through available account settings or by contacting Sisotee, unless a different process is required by applicable law.

Withdrawal of consent:

Does not affect prior lawful processing;
May limit your ability to use certain optional features;
Does not affect processing carried out on another lawful basis.

§6.17 Data Minimization

Regardless of the legal basis relied upon, Sisotee aims to process only the Personal Data reasonably necessary for the relevant purpose.

We regularly review our processing activities to reduce unnecessary collection, storage, and use of Personal Data where practicable.

§6.18 Accountability

52 of 124 --

Sisotee maintains internal policies, technical safeguards, organizational measures, and governance processes designed to help ensure that Personal Data is processed responsibly and in accordance with applicable law.

We periodically review our privacy practices and may update them as technology, business operations, or legal requirements evolve.

CHAPTER 7 – HOW WE SHARE AND

DISCLOSE INFORMATION Sisotee shares Personal Data only where reasonably necessary to provide the Services, comply with legal obligations, protect legitimate interests, or as otherwise permitted by applicable law.

We do not sell Personal Data to third parties.

The categories of recipients described below depend on the Services used, Community configuration, your role, and applicable legal requirements.

§7.1 General Principles

When sharing Personal Data, Sisotee aims to ensure that:

Information is shared only where reasonably necessary;
Appropriate contractual, technical, or organizational safeguards are applied where

required;

Recipients receive only the information necessary for the relevant purpose;
Sharing complies with applicable law and this Privacy Policy.

§7.2 Sharing with Your Community

Because Sisotee is a community management platform, certain Personal Data is shared with the Community that you belong to or interact with.

Depending on your role and Community settings, this may include:

Name;
Contact information;
Unit details;
53 of 124 --
Resident status;
Vehicle information;
Visitor approvals;
Delivery records;
Domestic worker registrations;
Maintenance payment status;
Complaint records;
Facility bookings;
Community notices;
Other operational information necessary for Community administration.

Communities are independently responsible for how they manage and use information within the scope of applicable law.

§7.3 Sharing with Community Administrators

Authorized Community administrators may access information necessary to:

Manage resident records;
Process visitor approvals;
Maintain security operations;
Manage maintenance billing;
Resolve complaints;
Operate ERP modules;
Generate reports;
Perform administrative functions.

Access is generally governed by role-based permissions configured by the Community.

§7.4 Sharing with Security Personnel

Where necessary for gate access management, authorized security personnel may access information including:

Visitor details;
Delivery information;
Vehicle information;
Resident approvals;
Entry permissions;
Entry and exit logs;
54 of 124 --
QR codes;
OTP verification status; and
Other information necessary to perform access control duties.

Communities remain responsible for supervising their security personnel.

§7.5 Sharing with Residents

Depending on Community settings and the feature being used, residents may see information such as:

Community notices;
Discussion posts;
Polls;
Classified listings;
Resident directory information;
Facility bookings;
Complaint updates (where applicable); and
Other information intentionally shared within the Community.

Users should avoid sharing sensitive or confidential information through community features unless necessary.

§7.6 Sharing with Payment Service Providers

To process payments, Sisotee may share necessary information with authorized payment service providers.

This may include:

Customer identifiers;
Invoice information;
Transaction amounts;
Payment references;
Refund requests;
Billing identifiers; and
Other information required to process transactions.

Payment providers process such information in accordance with their own privacy policies and applicable law.

55 of 124 --

§7.7 Sharing with Banks and Financial Institutions

Where necessary to facilitate financial transactions, information may be shared with:

Banks;
Payment networks;
Financial institutions;
Settlement providers; and
Other authorized financial intermediaries.

Such sharing is limited to information reasonably necessary for payment processing, settlement, reconciliation, fraud prevention, or regulatory compliance.

§7.8 Sharing with Communication Providers

To deliver communications, Sisotee may share limited information with providers of:

SMS services;
Email services;
Push notifications;
WhatsApp messaging;
Voice communication services (where supported); and
Other messaging platforms.

Typically, only the information required to deliver the communication is shared.

§7.9 Sharing with Cloud Infrastructure Providers

Sisotee relies on cloud infrastructure providers to host and operate the Services.

Accordingly, Personal Data may be processed by infrastructure providers performing services such as:

Computing;
Storage;
Networking;
Backups;
Disaster recovery;
56 of 124 --
Content delivery; and
Security monitoring.

These providers process information under contractual obligations and are not authorized to use it for their own unrelated purposes.

§7.10 Sharing with Technology Service Providers

Sisotee may engage service providers to assist with:

Software development;
Technical support;
Security monitoring;
Error tracking;
Analytics;
Customer support;
Identity verification;
Fraud prevention;
AI services;
Infrastructure management; and
Other operational functions.

Such providers are granted access only to the extent reasonably necessary to perform the services they provide to Sisotee.

§7.11 Sharing Through APIs and Integrations

Where you or your Community enable integrations, Sisotee may exchange information with authorized third-party systems.

Examples include:

Accounting software;
ERP platforms;
Payment gateways;
Access control systems;
Smart building systems;
Identity verification providers;
Government-authorized systems;
Business automation platforms; and
57 of 124 --
Other supported integrations.

Information shared depends on the integration enabled and your or the Community's configuration.

§7.12 Sharing with Government Authorities

Sisotee may disclose Personal Data where required or permitted by applicable law, including in response to:

Court orders;
Search warrants;
Regulatory investigations;
Lawful requests from competent authorities;
Legal reporting obligations;
National security requirements;
Public safety requirements; or
Other legally binding requests.

Where legally permitted and appropriate, Sisotee may notify affected users before disclosing information.

§7.13 Sharing for Emergency Situations

Where reasonably necessary to protect life, health, safety, or property, Sisotee may disclose information to:

Emergency responders;
Law enforcement agencies;
Medical personnel;
Community administrators;
Other authorized persons.

Such disclosures will be limited to what is reasonably necessary under the circumstances.

§7.14 Sharing During Corporate Transactions

If Sisotee is involved in:

58 of 124 --
A merger;
Acquisition;
Investment;
Financing;
Corporate restructuring;
Insolvency proceeding; or
Sale of assets,

Personal Data may be disclosed to prospective or actual transaction participants, professional advisers, financiers, and regulators as reasonably necessary to evaluate or complete the transaction.

Reasonable confidentiality obligations will apply, and where required by applicable law, users will be notified.

§7.15 Sharing with Professional Advisers

Sisotee may share information with professional advisers, including:

Lawyers;
Auditors;
Accountants;
Tax advisers;
Compliance consultants; and
Insurance providers,

where reasonably necessary to obtain professional services, comply with legal obligations, protect legal rights, or manage business operations.

§7.16 Sharing to Protect Rights and Security

We may disclose information where reasonably necessary to:

Enforce our Terms of Service;
Investigate fraud;
Prevent abuse;
Protect intellectual property;
Defend legal claims;
Protect the rights, property, or safety of Sisotee, users, Communities, or third parties; or
Respond to cybersecurity incidents.
59 of 124 --

§7.17 Sharing of Aggregated and Anonymized Information

Sisotee may share aggregated or anonymized information that does not reasonably identify an individual.

Such information may be used for:

Research;
Product improvement;
Industry analysis;
Benchmarking;
Capacity planning;
Business reporting; and
Statistical purposes.

Where information has been irreversibly anonymized, it is no longer treated as Personal Data under this Privacy Policy.

§7.18 No Sale of Personal Data

Sisotee does not sell Personal Data to third parties.

We also do not permit third parties to purchase access to our user database for independent marketing purposes.

If our practices change in the future, we will update this Privacy Policy and comply with applicable legal requirements.

§7.19 Marketing Communications

Where permitted by applicable law, Sisotee may engage service providers to help deliver marketing communications.

Recipients of such communications may opt out using the unsubscribe mechanism provided in the communication or by adjusting their communication preferences where available.

This does not apply to essential service-related communications, which may continue to be sent where necessary.

60 of 124 --

§7.20 International Sharing

As Sisotee expands internationally, Personal Data may be transferred to recipients in other jurisdictions, subject to:

Applicable law;
Appropriate contractual safeguards;
Security measures;
Regulatory requirements; and
This Privacy Policy.

Additional information regarding international transfers is provided in Chapter 8.

§7.21 Data Minimization in Sharing

Before sharing Personal Data, Sisotee seeks to ensure that:

Only the minimum information reasonably necessary is disclosed;
Access is limited based on role or function where feasible;
Appropriate security measures are applied during transmission; and
Sharing remains proportionate to the purpose for which it occurs.

§7.22 Responsibility of Third Parties

Where Personal Data is lawfully shared with an independent third party, that third party may process the information under its own legal obligations and privacy practices.

Sisotee is not responsible for the privacy or security practices of independent third parties that are not acting on Sisotee's behalf, although we seek to work with reputable service providers and partners.

Users are encouraged to review the privacy policies of third-party services before using them.

61 of 124 --

CHAPTER 8 – INTERNATIONAL DATA

TRANSFERS, DATA STORAGE & DATA RETENTION Sisotee stores and retains Personal Data only for as long as reasonably necessary to provide the Services, comply with legal obligations, protect users and Communities, resolve disputes, and maintain the security and integrity of the Platform.

As Sisotee expands internationally, Personal Data may be processed or transferred across jurisdictions in accordance with applicable law and appropriate safeguards.

§8.1 General Principles

Sisotee seeks to ensure that Personal Data is:

Stored securely;
Protected against unauthorized access;
Retained only as long as reasonably necessary;
Deleted or anonymized when no longer required, subject to applicable law;
Processed in accordance with this Privacy Policy and applicable legal requirements.

§8.2 Data Storage

Personal Data may be stored using cloud infrastructure, data centers, and technology service providers selected by Sisotee.

Depending on operational requirements, data may be stored in:

Primary production systems;
Backup systems;
Disaster recovery environments;
Log management systems;
Security monitoring systems;
Archived storage; and
Other secure storage environments.

Storage locations may change over time as Sisotee expands or upgrades its infrastructure.

62 of 124 --

§8.3 Processing Locations

Personal Data may be processed:

In India;
In jurisdictions where Sisotee operates;
In jurisdictions where our authorized service providers maintain infrastructure; or
In other jurisdictions where processing is permitted under applicable law.

Processing locations may change without affecting the protections described in this Privacy Policy.

§8.4 International Data Transfers

As Sisotee grows internationally, Personal Data may be transferred between countries.

Where Personal Data is transferred internationally, Sisotee will take reasonable steps, where required by applicable law, to ensure that appropriate safeguards are implemented.

Such safeguards may include:

Contractual commitments;
Technical safeguards;
Organizational safeguards;
Encryption;
Access controls;
Other legally recognized transfer mechanisms.

§8.5 Service Providers

Authorized service providers assisting Sisotee may process Personal Data on our behalf.

Examples include providers offering:

Cloud hosting;
Content delivery;
Database services;
Backup services;
63 of 124 --
Disaster recovery;
Security monitoring;
Customer support tools;
Analytics;
AI services;
Communication services.

These providers are expected to process Personal Data only as necessary to provide services to Sisotee and in accordance with contractual obligations and applicable law.

§8.6 Data Residency

Where technically feasible and commercially reasonable, Sisotee may offer customers options regarding data residency.

Availability of such options depends upon:

Subscription plan;
Infrastructure capabilities;
Applicable law;
Operational requirements.

Unless otherwise agreed in writing, Sisotee determines the location of its processing infrastructure.

§8.7 Data Retention Principles

Sisotee retains Personal Data only for as long as reasonably necessary to:

Provide the Services;
Maintain account functionality;
Comply with legal obligations;
Maintain accounting records;
Prevent fraud;
Resolve disputes;
Enforce legal rights;
Protect security;
Support disaster recovery;
Conduct legitimate business operations.
64 of 124 --

Retention periods vary depending on the category of information.

§8.8 Account Information

Account information may be retained:

While your account remains active;
For a reasonable period after account closure;
As necessary to comply with legal obligations;
To resolve disputes;
To prevent fraud;
To enforce contractual rights.

After retention is no longer necessary, account information will be deleted, anonymized, or otherwise processed in accordance with applicable law.

§8.9 Visitor Records

Visitor records may be retained for periods determined by:

Community policies;
Applicable law;
Security requirements;
Regulatory obligations;
Community operational needs.

Communities may configure retention periods for certain visitor-related information where supported by the Platform.

§8.10 Financial Records

Financial information may be retained for periods required by:

Tax laws;
Accounting standards;
Regulatory requirements;
Audit obligations;
Legal proceedings;
65 of 124 --
Fraud investigations.

Such records may be retained even after account closure where legally required or permitted.

§8.11 Security Logs

Security logs may be retained for purposes including:

Detecting unauthorized access;
Investigating incidents;
Preventing fraud;
Supporting forensic investigations;
Protecting infrastructure;
Complying with legal obligations.

Retention periods depend on operational and legal requirements.

§8.12 Customer Support Records

Customer support records may be retained to:

Maintain service history;
Resolve recurring issues;
Improve customer support;
Train support personnel;
Defend legal claims;
Comply with legal obligations.

Support records may include emails, support tickets, attachments, and related communications.

§8.13 AI Processing Records

Where AI-powered features are used, related records may be retained for purposes such as:

Improving service quality;
Investigating misuse;
Maintaining security;
Debugging;
66 of 124 --
Improving system performance;
Complying with legal obligations.

Where feasible, Sisotee may use anonymized or aggregated information for AI improvement rather than directly identifiable Personal Data.

§8.14 Backup Copies

For resilience and disaster recovery, backup copies of information may continue to exist after data is deleted from active systems.

Backup data:

Is protected by security controls;
Is not ordinarily accessed except for recovery, legal, security, or operational purposes;
Will be overwritten or securely deleted in accordance with Sisotee's backup lifecycle and

applicable law.

§8.15 Archival Storage

Certain information may be moved from active systems to secure archival storage where continued retention is necessary for:

Legal compliance;
Financial recordkeeping;
Audit requirements;
Historical system integrity;
Disaster recovery;
Business continuity.

Archived information is subject to appropriate access controls.

§8.16 Secure Deletion

Where Personal Data is no longer required and no legal obligation or legitimate need exists to retain it, Sisotee will take reasonable steps to:

Delete it;
67 of 124 --
De-identify it;
Anonymize it; or
Otherwise render it no longer associated with an identifiable individual,

using methods appropriate to the nature of the data and the storage medium.

§8.17 Account Deletion Requests

Users may request deletion of their account in accordance with this Privacy Policy and applicable law.

Before processing such requests, Sisotee may require reasonable identity verification to protect against unauthorized deletion.

Deletion requests remain subject to:

Outstanding contractual obligations;
Financial recordkeeping;
Fraud prevention;
Security investigations;
Ongoing legal proceedings;
Regulatory requirements; and
Other lawful retention obligations.

§8.18 Legal Holds

Where Sisotee reasonably believes that information may be relevant to:

Litigation;
Government investigations;
Regulatory inquiries;
Court proceedings;
Legal claims;
Law enforcement requests,

the relevant information may be retained for as long as reasonably necessary, notwithstanding other retention periods.

68 of 124 --

§8.19 Business Continuity

Retention of certain operational information may be necessary to:

Restore services after outages;
Recover from disasters;
Protect platform integrity;
Maintain operational resilience;
Ensure continuity of critical business functions.

§8.20 Anonymization

Where appropriate, Sisotee may irreversibly anonymize Personal Data so that it no longer identifies an individual.

Anonymized information may be retained and used for:

Statistical analysis;
Product improvement;
Capacity planning;
Research;
Security analysis;
Business intelligence; and
Other lawful purposes.

Once information has been irreversibly anonymized, it is no longer treated as Personal Data under this Privacy Policy.

§8.21 Cross-Border Compliance

Where Personal Data is transferred across national borders, Sisotee will comply with applicable legal requirements relating to such transfers, including implementing additional safeguards where required.

Users acknowledge that the level of legal protection may differ between jurisdictions, and Sisotee will take reasonable measures to maintain appropriate protections consistent with applicable law.

69 of 124 --

§8.22 Continuous Review

Sisotee periodically reviews its storage, retention, archival, and deletion practices to:

Improve security;
Reduce unnecessary retention;
Support privacy by design;
Meet evolving legal obligations;
Improve operational efficiency; and
Maintain industry best practices.

Retention schedules may be updated from time to time as legal, regulatory, or operational requirements evolve.

CHAPTER 9 – YOUR PRIVACY RIGHTS

AND CHOICES Sisotee respects the privacy rights of its users and is committed to providing reasonable mechanisms for individuals to access, review, manage, and control their Personal Data, subject to applicable law, contractual obligations, Community administration requirements, and legitimate business interests.

The availability and scope of certain rights may vary depending on your jurisdiction, the Services you use, your role within a Community, and the applicable legal framework.

§9.1 General Principles

Sisotee aims to ensure that individuals are able to:

Understand how their Personal Data is processed;
Exercise applicable privacy rights;
Make informed choices regarding optional processing activities;
Raise questions or concerns regarding privacy practices;
Submit complaints where appropriate; and
Receive responses within a reasonable period, subject to applicable law.

§9.2 Right to Access Your Personal Data

70 of 124 --

Subject to applicable law, you may request confirmation regarding whether Sisotee processes your Personal Data.

Where applicable, you may also request access to information including:

Categories of Personal Data processed;
Sources from which the information was collected;
Purposes of processing;
Categories of recipients;
Retention practices;
Information relating to your account; and
Other information required by applicable law.

To protect privacy and security, Sisotee may require reasonable identity verification before responding to such requests.

§9.3 Right to Correct or Update Information

You may request correction of Personal Data that is:

Inaccurate;
Incomplete;
Outdated; or
Misleading.

Where possible, users may update certain information directly through their account settings.

Certain records maintained by a Community may require correction requests to be submitted through the relevant Community administrator.

§9.4 Right to Delete Personal Data

Subject to applicable law, you may request deletion of Personal Data held by Sisotee.

Deletion requests may be limited where retention is necessary to:

Comply with legal obligations;
Complete pending transactions;
Resolve disputes;
Prevent fraud;
Maintain security;
71 of 124 --
Protect legal rights;
Fulfill contractual obligations;
Maintain financial records;
Support disaster recovery;
Comply with lawful governmental requests.

Deletion of certain information may result in partial or complete loss of access to the Services.

§9.5 Right to Withdraw Consent

Where Personal Data is processed based on your consent, you may withdraw that consent at any time.

Examples include consent relating to:

Optional marketing communications;
Optional location services;
Camera permissions;
Microphone permissions;
Optional notifications;
Certain AI-powered features; and
Other optional processing activities.

Withdrawal of consent:

Does not affect processing previously carried out lawfully;
Does not affect processing based on another lawful basis;
May limit the availability of certain optional features.

§9.6 Right to Object

Where permitted by applicable law, you may object to certain processing activities based on grounds specific to your circumstances.

Sisotee will evaluate such requests in accordance with applicable law and may continue processing where a lawful basis exists.

§9.7 Right to Restrict Processing

72 of 124 --

Where recognized by applicable law, you may request that Sisotee temporarily restrict processing of certain Personal Data while:

Accuracy is being verified;
A legal claim is being assessed;
A dispute is pending;
Another lawful review is underway.

Restriction requests remain subject to applicable legal and contractual obligations.

§9.8 Right to Data Portability

Where applicable law provides such a right and where technically feasible, you may request a copy of certain Personal Data that you have provided to Sisotee in a structured, commonly used, and machine-readable format.

This right applies only where required by applicable law and may be subject to technical limitations, legal restrictions, and protection of the rights of other individuals.

§9.9 Right to Opt Out of Marketing Communications

Where marketing communications are sent, you may opt out by:

Using the unsubscribe link included in the communication;
Updating communication preferences within your account where available; or
Contacting Sisotee.

Opting out of marketing communications does not affect essential service communications, including:

Login alerts;
OTPs;
Visitor notifications;
Payment confirmations;
Security alerts;
Legal notices; and
Other operational communications necessary for the Services.
73 of 124 --

§9.10 Managing Device Permissions

You may manage certain permissions granted to the Sisotee mobile application through your device settings.

These permissions may include:

Camera;
Microphone;
Location;
Notifications;
Storage;
Photo library; and
Other operating system permissions.

Disabling certain permissions may affect the availability or functionality of specific features.

§9.11 Managing Cookies

For Sisotee's web-based Services, you may manage cookies and similar technologies through your browser settings.

Depending on your browser, you may:

Delete cookies;
Block cookies;
Restrict tracking technologies;
Receive notifications before cookies are stored.

Blocking cookies may affect certain website functionality.

Additional information is available in the Sisotee Cookie Policy.

§9.12 Rights Relating to AI Processing

Where AI-powered features are provided, users may:

Choose whether to use optional AI features;
Review AI-generated outputs before relying upon them;
Correct information submitted to AI features where applicable;
74 of 124 --
Report inaccurate AI outputs;
Provide feedback regarding AI-generated responses.

AI-generated outputs are intended to assist users and should not be considered professional, legal, financial, engineering, or medical advice.

§9.13 Account Deactivation

Users may deactivate or request closure of their account in accordance with Sisotee's Terms of Service.

Account closure may result in:

Loss of access to Services;
Removal from Communities;
Loss of certain user-generated content where permitted by law;
Termination of active subscriptions.

Certain records may continue to be retained in accordance with applicable legal obligations and this Privacy Policy.

§9.14 Community-Controlled Information

Certain Personal Data is managed by Communities using Sisotee.

Examples include:

Resident directories;
Visitor approvals;
Maintenance records;
Committee records;
Complaint management;
Community notices;
Financial records.

Requests relating to such information may need to be directed to the relevant Community administrator.

Sisotee may assist Communities in responding to such requests where appropriate.

75 of 124 --

§9.15 Identity Verification

Before fulfilling requests relating to Personal Data, Sisotee may require reasonable verification of your identity.

Verification measures help protect:

Your privacy;
Other users;
Community records;
Platform security.

Failure to provide sufficient verification may prevent Sisotee from processing certain requests.

§9.16 Response Time

Sisotee will respond to valid privacy requests within the time required by applicable law or, where no statutory period applies, within a reasonable timeframe.

Complex requests or requests involving multiple Communities, legal obligations, or technical limitations may require additional time.

Where appropriate, users will be informed of any delay.

§9.17 Refusal of Requests

Sisotee may decline or limit a request where permitted by applicable law, including where:

The request is manifestly unfounded or excessive;
Identity cannot be verified;
Compliance would adversely affect the rights of others;
Disclosure is prohibited by law;
Information is subject to legal privilege;
Retention is required by law;
Compliance would compromise security or fraud prevention;
The request relates to information that Sisotee is not legally authorized to modify.

Where reasonably possible, Sisotee will explain the basis for declining the request.

76 of 124 --

§9.18 Filing a Privacy Complaint

If you believe that Sisotee has processed your Personal Data in a manner inconsistent with this Privacy Policy or applicable law, you may submit a complaint to our Grievance Officer.

Please include, where possible:

Your full name;
Contact information;
Community name (if applicable);
Description of the issue;
Relevant dates;
Supporting documentation; and
The resolution you are seeking.

Sisotee will review complaints fairly, impartially, and in accordance with applicable law.

§9.19 Right to Approach Regulatory Authorities

Nothing in this Privacy Policy limits your right, where provided by applicable law, to contact or lodge a complaint with a competent data protection authority, regulatory body, or court.

Where appropriate, we encourage users to first contact Sisotee so that we have an opportunity to resolve concerns promptly and efficiently.

§9.20 Exercising Your Rights

Privacy requests may be submitted using the contact details provided in this Privacy Policy.

For privacy-related requests, please contact:

Grievance Officer Abha Bhushan Head – Support & Grievance Officer Email: support.sisotee@anabasis.in Registered Office:
Registered Office
Grievance Officer

ANABASIS INFRA PRIVATE LIMITED 13A, BG Tower

77 of 124 --

Chandni Chowk Kanke Road Ranchi – 834008 Jharkhand, India Phone: +91 95235 54222 Requests should include sufficient information to enable Sisotee to verify identity and process the request efficiently.

§9.21 Continuous Improvement

Sisotee periodically reviews its privacy practices, user controls, and rights management procedures to ensure continued compliance with evolving legal requirements, technological developments, and industry best practices.

As new privacy rights become available under applicable law, Sisotee may update this Privacy Policy to reflect those rights and provide users with additional controls over their Personal Data.

CHAPTER 10 – COOKIES, ANALYTICS &

SIMILAR TECHNOLOGIES Sisotee uses cookies, software development kits ("SDKs"), local storage, pixels, device identifiers, log files, and similar technologies to provide, secure, improve, and maintain the Services.

These technologies help authenticate users, remember preferences, enhance security, measure performance, diagnose technical issues, and improve the overall user experience.

This Chapter explains how these technologies work and the choices available to users.

§10.1 Overview

Depending on the platform you use (website, mobile application, or integrated services), Sisotee may use:

HTTP cookies;
Session cookies;
78 of 124 --
Persistent cookies;
Browser storage;
Local storage;
Session storage;
Mobile SDKs;
Device identifiers;
Pixels;
Beacons;
Log files;
API telemetry;
Crash reporting tools;
Performance monitoring tools; and
Similar technologies.

Not every technology is used on every platform.

§10.2 What Are Cookies?

Cookies are small text files placed on your device by a website or web application.

Cookies may help:

Recognize your device;
Remember login sessions;
Save user preferences;
Improve navigation;
Enhance security;
Analyze usage patterns; and
Improve website performance.

Cookies generally cannot execute software or access unrelated information stored on your device.

§10.3 Types of Cookies We Use

Sisotee may use several categories of cookies.

(a) Essential Cookies Essential cookies are necessary for the operation of the Services.

79 of 124 --

Examples include:

User authentication;
Session management;
Security protections;
Fraud prevention;
Load balancing;
Account functionality.

Without these cookies, certain Services may not function properly.

(b) Functional Cookies Functional cookies help remember user preferences such as:

Preferred language;
Interface settings;
Notification preferences;
Accessibility settings;
User interface customization.

(c) Performance Cookies Performance cookies help us understand how users interact with the Services by collecting information such as:

Pages visited;
Feature usage;
Session duration;
Navigation patterns;
Performance statistics.

Whenever practical, this information is aggregated or de-identified.

(d) Analytics Cookies Analytics technologies help Sisotee:

Measure platform usage;
Improve product performance;
80 of 124 --
Identify usability issues;
Understand feature adoption;
Plan future improvements.

Analytics data may include technical and usage information but is not intended to directly identify individuals unless necessary for security or troubleshooting.

§10.4 Mobile SDKs

The Sisotee mobile application may use SDKs provided by Sisotee or trusted service providers.

SDKs may assist with:

Push notifications;
Authentication;
Security;
Crash reporting;
Performance monitoring;
Payment processing;
Analytics;
AI functionality;
Communication services.

SDKs operate differently from browser cookies but may perform similar functions.

§10.5 Local Storage and Session Storage

Sisotee's web applications may use browser storage technologies including:

Local Storage;
Session Storage;
IndexedDB;
Other browser-supported storage mechanisms.

These technologies may temporarily store information necessary for:

Faster page loading;
User preferences;
Offline functionality (where supported);
Session continuity;
Security.
81 of 124 --

§10.6 Device Identifiers

Depending on your device and operating system, Sisotee may process device identifiers such as:

Device ID;
Installation ID;
Push notification token;
Operating system identifiers;
Application instance identifiers;
Security identifiers.

These identifiers help:

Maintain account security;
Deliver notifications;
Diagnose technical issues;
Prevent fraud;
Improve platform reliability.

§10.7 Log Files

Sisotee automatically generates operational logs during normal use of the Services.

These logs may include:

IP address;
Browser information;
Device type;
Login timestamps;
Error events;
API requests;
Session identifiers;
Security events;
System performance information.

Log files are primarily used for security, troubleshooting, auditing, and service reliability.

82 of 124 --

§10.8 Analytics

Sisotee may use analytics technologies to understand how the Services are used.

Analytics may help us:

Improve product design;
Identify software defects;
Measure feature adoption;
Improve navigation;
Evaluate system performance;
Plan infrastructure capacity;
Improve accessibility.

Where feasible, analytics data is aggregated or anonymized.

§10.9 Crash Reporting

To improve stability, Sisotee may collect technical information relating to software failures.

Crash reports may include:

Application version;
Device model;
Operating system version;
Error messages;
Diagnostic information;
Performance metrics;
Technical logs.

Crash reports are used solely to identify, investigate, and resolve technical issues.

§10.10 Performance Monitoring

Sisotee may monitor system performance to:

Improve response times;
Detect infrastructure issues;
Identify bottlenecks;
Optimize resource utilization;
83 of 124 --
Improve service availability;
Maintain reliability.

Performance monitoring generally focuses on technical metrics rather than user content.

§10.11 Security Technologies

Sisotee uses technical mechanisms designed to improve platform security, including technologies that help:

Detect suspicious activity;
Identify fraudulent behavior;
Prevent unauthorized access;
Protect user sessions;
Monitor authentication events;
Maintain audit trails.

These technologies are essential to maintaining the security and integrity of the Services.

§10.12 API Telemetry

Where APIs are used, Sisotee may collect operational telemetry including:

API endpoints accessed;
Response times;
Error rates;
Authentication events;
Rate-limiting information;
System diagnostics.

API telemetry helps maintain reliable integrations and improve platform stability.

§10.13 Communication Technologies

To deliver communications, Sisotee may use technologies supporting:

SMS delivery;
Email delivery;
84 of 124 --
Push notifications;
In-app notifications;
WhatsApp messaging (where supported);
Transactional messaging.

These technologies may generate delivery confirmations, timestamps, message identifiers, and diagnostic information.

§10.14 Advertising Technologies

At the time of publication of this Privacy Policy, Sisotee is not designed to serve third-party behavioral advertising based on Personal Data collected through the Services.

If Sisotee introduces advertising or advertising-related technologies in the future, this Privacy Policy will be updated and any legally required notices or consent mechanisms will be implemented before such technologies are used.

§10.15 Do Not Track Signals

Some web browsers provide a "Do Not Track" ("DNT") setting.

Because there is no universally accepted standard governing how DNT signals should be interpreted, Sisotee does not currently respond differently to DNT signals unless required by applicable law.

Should a legally recognized standard emerge, Sisotee may update its practices accordingly.

§10.16 Managing Cookies

Users may manage cookies through their browser settings.

Depending on the browser, users may:

Delete cookies;
Block cookies;
Restrict cookies;
Receive notifications before cookies are stored;
Limit tracking technologies.
85 of 124 --

Blocking essential cookies may affect the availability or functionality of certain Services.

§10.17 Managing Mobile Permissions

Users may manage application permissions through their mobile operating system.

Permissions may include:

Camera;
Microphone;
Location;
Notifications;
Photo library;
Storage.

Disabling permissions may limit certain application features.

§10.18 Consent for Non-Essential Technologies

Where required by applicable law, Sisotee will obtain user consent before using non-essential cookies or similar technologies.

Users may withdraw such consent at any time through available settings or other mechanisms provided by Sisotee.

Withdrawal of consent does not affect technologies that are strictly necessary for the operation, security, or legal compliance of the Services.

§10.19 Third-Party Technologies

Some third-party services integrated with Sisotee may independently use cookies, SDKs, or similar technologies.

Such technologies are governed by the respective third party's privacy policy and terms of service.

Sisotee encourages users to review the privacy practices of integrated third-party services before enabling or using them.

86 of 124 --

§10.20 Updates to Cookie Practices

As technology evolves, Sisotee may introduce new cookies or similar technologies to improve the Services, strengthen security, or comply with legal obligations.

Where required by applicable law, users will be notified of material changes, and consent will be obtained before introducing new categories of non-essential technologies.

§10.21 Cookie Policy

Sisotee may publish a separate Cookie Policy that supplements this Privacy Policy.

Where a separate Cookie Policy exists, it should be read together with this Privacy Policy. In the event of any inconsistency, this Privacy Policy will prevail unless expressly stated otherwise.

CHAPTER 11 – SECURITY MEASURES

Sisotee is committed to protecting Personal Data through a combination of technical, administrative, organizational, and physical security measures designed to reduce the risk of unauthorized access, disclosure, alteration, destruction, or loss of information.

While no method of transmission or storage can guarantee absolute security, Sisotee continually evaluates and improves its security practices to address evolving threats, technological developments, and applicable legal requirements.

§11.1 Security by Design

Sisotee strives to incorporate security considerations throughout the design, development, deployment, and maintenance of the Services.

Our security objectives include:

Protecting confidentiality;
Maintaining integrity;
Ensuring availability;
Reducing operational risk;
87 of 124 --
Preventing unauthorized access; and
Supporting regulatory compliance.

Security considerations are integrated into our product lifecycle wherever reasonably practicable.

§11.2 Organizational Security Measures

Sisotee maintains internal policies and procedures relating to information security, including measures designed to:

Protect Personal Data;
Define employee responsibilities;
Restrict unauthorized access;
Respond to security incidents;
Promote secure operational practices; and
Support ongoing compliance.

Employees, contractors, and authorized personnel who require access to Personal Data are expected to comply with confidentiality obligations and internal security requirements.

§11.3 Access Controls

Access to Personal Data is restricted based on business necessity and job responsibilities.

Security controls may include:

Role-based access controls (RBAC);
Least-privilege access principles;
Administrative approval processes;
Segregation of duties;
Access logging;
Periodic access reviews; and
Timely removal of unnecessary access privileges.

§11.4 Authentication Security

Sisotee implements authentication mechanisms intended to help protect user accounts.

88 of 124 --

Depending on the Services used, authentication measures may include:

Password authentication;
Multi-factor authentication (MFA);
One-Time Passwords (OTPs);
Passkeys and supported passwordless authentication methods;
Trusted device management;
Session validation; and
Account recovery procedures.

Users are responsible for maintaining the confidentiality of their authentication credentials.

§11.5 Password Protection

Where passwords are used, Sisotee does not intentionally store passwords in plaintext.

Instead, passwords are protected using appropriate cryptographic hashing techniques and related security controls designed to reduce the risk of unauthorized disclosure.

Users should:

Choose strong and unique passwords;
Avoid sharing passwords;
Enable multi-factor authentication where available; and
Promptly update credentials if compromise is suspected.

§11.6 Encryption

Sisotee seeks to protect Personal Data through encryption where appropriate.

Security measures may include:

Encryption of data in transit using industry-standard transport security protocols;
Encryption of sensitive data at rest where appropriate;
Secure key management practices;
Encrypted backups where feasible; and
Secure communication channels between integrated services.

The specific encryption technologies used may change over time as industry standards evolve.

89 of 124 --

§11.7 Network Security

Sisotee employs measures intended to protect its network infrastructure, which may include:

Firewalls;
Network segmentation;
Traffic filtering;
Intrusion detection and monitoring;
Rate limiting;
Distributed denial-of-service (DDoS) mitigation;
Secure remote access controls; and
Network activity monitoring.

§11.8 Application Security

Sisotee incorporates security practices into software development and maintenance, including, where appropriate:

Secure coding practices;
Security reviews;
Dependency management;
Vulnerability remediation;
Configuration management;
Security testing;
Change management procedures; and
Controlled deployment processes.

§11.9 Infrastructure Security

Infrastructure supporting Sisotee may include safeguards such as:

Secure cloud environments;
Environment isolation;
Infrastructure monitoring;
Backup systems;
Disaster recovery capabilities;
Redundancy;
Capacity monitoring; and
Operational health checks.
90 of 124 --

§11.10 Logging and Monitoring

Sisotee maintains operational and security logs to support:

Security monitoring;
Incident detection;
Fraud prevention;
System diagnostics;
Audit trails;
Performance monitoring;
Operational troubleshooting; and
Compliance activities.

Access to logs is restricted to authorized personnel with a legitimate business need.

§11.11 Vulnerability Management

Sisotee periodically reviews its systems to identify and address potential security vulnerabilities.

Security activities may include:

Vulnerability assessments;
Patch management;
Security updates;
Configuration reviews;
Dependency updates;
Internal testing; and
Continuous improvement of security controls.

The timing and frequency of such activities may vary based on operational priorities and identified risks.

§11.12 Security Incident Response

Sisotee maintains processes designed to detect, investigate, respond to, and recover from security incidents.

Incident response activities may include:

91 of 124 --
Identification of suspicious activity;
Investigation of reported incidents;
Containment measures;
System recovery;
Internal review;
Documentation;
Remediation; and
Lessons learned to improve future resilience.

Where required by applicable law, Sisotee will provide notifications regarding certain security incidents or Personal Data breaches.

§11.13 Business Continuity and Disaster Recovery

Sisotee maintains measures intended to support operational resilience, including:

Data backups;
Disaster recovery procedures;
Service restoration planning;
Infrastructure redundancy where appropriate;
Operational continuity planning; and
Recovery testing where reasonably practicable.

These measures aim to minimize service disruption but do not guarantee uninterrupted availability.

§11.14 Employee Confidentiality

Employees, contractors, consultants, and other authorized personnel with access to Personal Data are expected to:

Maintain confidentiality;
Access information only where authorized;
Follow internal security policies;
Report suspected security incidents promptly; and
Complete applicable security or privacy training where required.

Access privileges are reviewed and adjusted as roles change or relationships end.

92 of 124 --

§11.15 Physical Security

Where Sisotee or its service providers maintain physical facilities containing information systems, reasonable physical safeguards may include:

Controlled facility access;
Visitor management procedures;
Environmental protections;
Equipment security;
Physical monitoring; and
Other appropriate physical security controls.

Many infrastructure services may be operated through third-party cloud providers with their own physical security programs.

§11.16 Third-Party Security

Sisotee works with service providers and partners that are expected to implement appropriate security measures for the services they provide.

Where appropriate, Sisotee may evaluate service providers based on factors including:

Security capabilities;
Reliability;
Compliance commitments;
Operational resilience; and
Contractual safeguards.

However, Sisotee cannot guarantee the security practices of independent third parties.

§11.17 User Responsibilities

Users also play an important role in protecting Personal Data.

Users should:

Protect account credentials;
Keep devices updated;
Install security updates;
Avoid sharing login information;
93 of 124 --
Verify suspicious communications before responding;
Report suspected unauthorized access promptly;
Log out from shared devices; and
Use the Services responsibly.

Failure to follow basic security practices may increase the risk of unauthorized account access.

§11.18 Responsible Disclosure

Sisotee encourages responsible reporting of suspected security vulnerabilities.

Individuals who believe they have identified a security issue are encouraged to contact Sisotee using the designated security or support contact information.

Users should not:

Attempt unauthorized access;
Exploit vulnerabilities;
Interfere with the availability of the Services;
Access data belonging to others; or
Conduct testing that may negatively affect users or infrastructure without prior written

authorization.

Sisotee reserves the right to investigate and respond to unauthorized security testing or malicious activity.

§11.19 Limitations of Security

Although Sisotee implements reasonable security measures, no technology can eliminate all security risks.

Accordingly:

No transmission over the Internet is completely secure;
No storage system is immune from compromise;
No security measure can guarantee absolute protection.

Users acknowledge these inherent limitations and agree to use the Services with an understanding of such risks.

94 of 124 --

§11.20 Continuous Improvement

Sisotee periodically reviews and enhances its security practices to address:

Emerging cybersecurity threats;
Technological advancements;
Changes in legal requirements;
Operational experience;
User feedback; and
Industry best practices.

Security measures may be modified, strengthened, or replaced without prior notice where necessary to maintain the security and integrity of the Services.

§11.21 Security Contact

If you believe your account has been compromised, identify a security vulnerability, or become aware of unauthorized access involving Sisotee, you should notify us promptly using the contact information provided in this Privacy Policy.

Prompt reporting enables Sisotee to investigate the issue, take appropriate remedial action, and help reduce potential harm to users and Communities.

CHAPTER 12 – CHILDREN'S PRIVACY

Sisotee recognizes the importance of protecting the privacy of children and is committed to processing information relating to minors responsibly and in accordance with applicable laws.

Sisotee is primarily designed for use by residential communities, property owners, residents, tenants, administrators, security personnel, vendors, and other authorized users. While information relating to children may be processed as part of legitimate community management activities, Sisotee is not intended to be independently used by young children without the involvement or authorization of a parent, legal guardian, or other legally authorized adult, where required by applicable law.

§12.1 General Principles

Sisotee seeks to ensure that Personal Data relating to children is:

95 of 124 --
Processed lawfully;
Collected only where reasonably necessary;
Protected through appropriate security measures;
Used only for legitimate purposes;
Subject to appropriate access controls; and
Handled in accordance with applicable child privacy laws.

§12.2 Information Relating to Children

Depending on the Community's requirements and the Services used, information relating to a child may include:

Name;
Relationship to a resident;
Residential unit details;
Emergency contact information;
Profile photograph, where voluntarily provided;
Access permissions;
Visitor authorization information;
Facility booking participation;
Community event registrations; and
Other information reasonably necessary to provide the Services.

Sisotee does not intentionally request more information relating to children than is reasonably necessary for the relevant purpose.

§12.3 Sources of Children's Information

Information relating to children is generally provided by:

Parents;
Legal guardians;
Residents;
Authorized family members;
Community administrators; or
Other persons legally authorized to provide such information.

Sisotee ordinarily does not collect Personal Data directly from children without appropriate authorization where required by applicable law.

96 of 124 --

§12.4 Purpose of Processing

Where information relating to children is processed, it may be used for purposes including:

Maintaining resident records;
Emergency contact management;
Community access management;
Visitor approvals;
Family member identification;
Community administration;
Safety and security;
Facility access; and
Other legitimate community management purposes.

Processing is limited to purposes consistent with this Privacy Policy and applicable law.

§12.5 Parental and Guardian Responsibility

Parents, legal guardians, and other authorized adults are responsible for:

Providing accurate information;
Ensuring they are legally authorized to provide the information;
Reviewing information submitted through the Platform;
Requesting corrections where necessary; and
Supervising a child's use of the Services where applicable.

Where consent is required by law, the responsible adult must provide such consent before the relevant processing occurs.

§12.6 Community Responsibilities

Communities using Sisotee are responsible for ensuring that information relating to children is collected and processed in compliance with applicable law.

Communities should:

Obtain any legally required consent or authorization;
Limit access to children's information to authorized personnel;
97 of 124 --
Establish appropriate internal policies;
Protect confidentiality; and
Use such information only for legitimate community purposes.

Sisotee provides the technology platform but does not supervise the Community's independent privacy practices.

§12.7 Age Requirements

The minimum age for independently creating or managing a Sisotee account may vary depending on:

Applicable law;
Community policies;
The specific Services being used.

Where applicable law requires parental or guardian involvement, users should not create or use an account independently unless such requirements have been satisfied.

§12.8 Consent Where Required

Where applicable law requires verifiable consent before processing Personal Data relating to a child, Sisotee or the relevant Community will seek to ensure that such consent is obtained through an appropriate lawful mechanism.

The method of obtaining consent may vary depending on:

Applicable law;
The age of the child;
The nature of the processing;
The Community's administrative processes.

§12.9 Educational and Community Activities

Where Communities use Sisotee to organize events, activities, educational programs, sports, or recreational facilities, information relating to children may be processed solely to:

Register participation;
98 of 124 --
Manage attendance;
Facilitate communication;
Coordinate logistics;
Maintain safety;
Support emergency response.

Such processing should be limited to what is reasonably necessary.

§12.10 Children's Photographs

Where Communities or authorized users upload photographs relating to children, they should ensure that:

They are legally authorized to do so;
Applicable consent requirements have been satisfied;
The photographs are used only for legitimate purposes.

Sisotee does not independently verify the authority of users uploading such photographs.

§12.11 AI Features

Where AI-powered features process documents or information that may relate to children, Sisotee seeks to apply the same privacy, confidentiality, and security standards applicable to other Personal Data.

Users should avoid submitting unnecessary Personal Data relating to children into AI-powered features.

AI-generated outputs should always be reviewed by a responsible adult before being relied upon for decisions affecting a child.

§12.12 Marketing

Sisotee does not knowingly direct marketing communications specifically at children through the Services.

Where marketing communications are sent, they are generally directed toward:

99 of 124 --
Residents;
Community administrators;
Property managers;
Authorized adult users; and
Business customers.

§12.13 Discovery of Unauthorized Collection

If Sisotee becomes aware that Personal Data relating to a child has been collected or processed in a manner inconsistent with applicable law, we may take appropriate action, including:

Investigating the matter;
Restricting access to the information;
Requesting additional authorization or documentation;
Correcting records where appropriate;
Deleting information where legally required; or
Taking other reasonable remedial measures.

§12.14 Requests from Parents and Guardians

Subject to applicable law and appropriate identity verification, parents or legal guardians may request:

Access to information relating to their child;
Correction of inaccurate information;
Deletion of information where applicable;
Withdrawal of consent where consent is the legal basis for processing; or
Other rights available under applicable law.

Certain requests may need to be coordinated with the relevant Community where it determines the purposes and means of processing.

§12.15 International Compliance

As Sisotee expands internationally, the processing of children's Personal Data may become subject to additional child privacy requirements in different jurisdictions.

100 of 124 --

Where applicable, Sisotee will take reasonable steps to comply with relevant legal requirements concerning:

Age verification;
Parental consent;
Data minimization;
Security safeguards;
Children's rights; and
Cross-border data transfers.

Additional region-specific notices may supplement this Privacy Policy where required.

§12.16 Data Retention

Information relating to children is retained only for as long as reasonably necessary to:

Provide the Services;
Support Community operations;
Comply with legal obligations;
Resolve disputes;
Protect safety;
Maintain security; and
Fulfill other lawful purposes described in this Privacy Policy.

Once retention is no longer required, such information will be deleted, anonymized, or otherwise handled in accordance with Sisotee's data retention practices.

§12.17 Security of Children's Information

Sisotee applies the security measures described in Chapter 11 to information relating to children.

Access to such information is intended to be limited to authorized persons with a legitimate need to access it, and appropriate technical and organizational safeguards are maintained to reduce the risk of unauthorized access, disclosure, alteration, or loss.

§12.18 Changes to Children's Privacy Practices

101 of 124 --

Sisotee may update its practices relating to children's privacy as legal requirements, technology, or the Services evolve.

Where required by applicable law, users or Communities will be provided with appropriate notice of material changes before such changes take effect.

§12.19 Contact Regarding Children's Privacy

Questions, concerns, or requests relating to the processing of Personal Data concerning children may be directed to Sisotee's Grievance Officer using the contact details provided in this Privacy Policy.

We will review such requests in accordance with applicable law, this Privacy Policy, and our obligations to protect the rights and interests of children.

CHAPTER 13 – AI, AUTOMATED

DECISION-MAKING & EMERGING TECHNOLOGIES Sisotee may use Artificial Intelligence ("AI"), Machine Learning ("ML"), Optical Character Recognition ("OCR"), automation technologies, and other emerging technologies to improve the functionality, efficiency, security, and user experience of the Services.

These technologies are designed to assist users and Communities. Unless expressly stated otherwise, AI-generated outputs are intended to support human decision-making and are not intended to replace professional judgment or independent verification.

§13.1 Purpose of AI Technologies

Sisotee may use AI and related technologies for purposes including:

Improving user productivity;
Automating repetitive tasks;
Enhancing document processing;
Organizing information;
Assisting with searches;
102 of 124 --
Generating summaries;
Detecting anomalies;
Improving customer support;
Strengthening platform security;
Enhancing accessibility; and
Supporting future product innovation.

AI features are intended to augment, rather than replace, human decision-making.

§13.2 AI Features Available on the Platform

Depending on the Services enabled, Sisotee may provide AI-assisted features such as:

OCR for uploaded documents;
Document summarization;
Visitor data extraction;
Invoice and receipt data extraction;
Search assistance;
Smart recommendations;
Automated categorization;
Intelligent notifications;
Workflow automation;
Predictive suggestions; and
Other AI-powered productivity tools.

The availability of AI features may vary based on subscription plans, technical capabilities, and regional availability.

§13.3 Optical Character Recognition (OCR)

Where OCR functionality is used, Sisotee may process uploaded images or documents to extract text or structured information.

Examples include:

Identity documents;
Invoices;
Receipts;
Community records;
Maintenance documents;
103 of 124 --
Vendor documents;
Visitor records; and
Other supported file types.

OCR technology may not always extract information accurately. Users remain responsible for reviewing extracted information before relying upon it.

§13.4 AI-Generated Content

AI may generate:

Summaries;
Suggested responses;
Recommendations;
Organizational labels;
Search results;
Workflow suggestions;
Automated descriptions; and
Other generated outputs.

AI-generated content is based on available information and computational models and may contain errors, omissions, or inaccuracies.

Users should independently verify important information before making decisions based on AI-generated outputs.

§13.5 Automation Features

Sisotee may automate certain operational processes, including:

Visitor approval workflows;
Notification delivery;
Document organization;
Data synchronization;
Reminder generation;
Access control workflows;
Report generation;
Administrative tasks; and
Other routine platform functions.
104 of 124 --

Automation improves efficiency but may still require human review depending on the circumstances.

§13.6 AI Training and Improvement

To improve AI-enabled Services, Sisotee may analyze information relating to AI interactions, including:

User prompts;
User feedback;
Error reports;
Performance metrics;
Feature usage statistics;
System diagnostics; and
Operational metadata.

Where reasonably practicable, Sisotee seeks to use aggregated, anonymized, or de-identified information for AI improvement.

§13.7 Human Oversight

Sisotee believes that important decisions affecting individuals should generally involve appropriate human judgment.

Accordingly:

AI outputs should be reviewed by users;
Community administrators remain responsible for administrative decisions;
Financial decisions should be independently verified;
Security personnel remain responsible for access decisions;
Legal compliance decisions should involve qualified professionals where appropriate.

Sisotee's AI features are assistive tools and are not substitutes for professional advice or independent decision-making.

§13.8 Automated Decision-Making

105 of 124 --

At the time of publication of this Privacy Policy, Sisotee is not designed to make solely automated decisions that produce legal effects or similarly significant effects on individuals without appropriate human involvement, except where such processing is expressly authorized by applicable law or requested by the user.

If Sisotee introduces such capabilities in the future, we will provide appropriate disclosures and implement additional safeguards where required by applicable law.

§13.9 Accuracy and Limitations

AI systems may:

Misinterpret information;
Produce incomplete outputs;
Generate inaccurate recommendations;
Fail to recognize context;
Produce inconsistent responses; or
Reflect limitations inherent in machine learning technologies.

Users should not rely exclusively on AI-generated outputs for decisions involving:

Legal rights;
Financial obligations;
Health or medical matters;
Emergency situations;
Security incidents;
Engineering decisions; or
Other matters requiring professional judgment.

§13.10 User Responsibilities

When using AI-powered features, users should:

Review generated outputs;
Verify important information;
Avoid submitting unlawful content;
Avoid uploading unnecessary Personal Data;
Respect the rights of others;
Report significant inaccuracies where appropriate.
106 of 124 --

Users remain responsible for the content they submit and for decisions made based on AI-generated outputs.

§13.11 Confidential Information

Users should exercise caution before submitting confidential, proprietary, or sensitive information into AI-powered features.

Where AI functionality is used, users should:

Submit only information reasonably necessary for the requested task;
Ensure they are authorized to provide the information;
Avoid sharing third-party confidential information without appropriate authority.

§13.12 AI Security

Sisotee seeks to apply appropriate technical and organizational safeguards to AI-enabled Services, including measures designed to:

Protect Personal Data;
Restrict unauthorized access;
Maintain confidentiality;
Improve system reliability;
Detect misuse;
Monitor operational performance; and
Reduce security risks.

Security practices may evolve as AI technologies develop.

§13.13 Bias and Fairness

AI systems may have limitations and may not always produce identical outcomes across different situations.

Sisotee seeks to:

Continuously evaluate AI performance;
Improve model quality;
107 of 124 --
Reduce unintended bias where reasonably practicable;
Encourage user feedback regarding inaccurate or inappropriate outputs.

Despite these efforts, AI-generated outputs may not always be complete, accurate, or free from unintended bias.

§13.14 Third-Party AI Services

Some AI-powered features may rely upon technology provided by authorized third-party service providers.

Where third-party AI services are used:

Sisotee seeks to engage reputable providers;
Appropriate contractual or technical safeguards may be implemented where applicable;
Processing remains subject to this Privacy Policy and applicable law.

Independent third-party AI providers may also be subject to their own terms and privacy policies.

§13.15 AI and Children

Users should avoid unnecessarily submitting Personal Data relating to children into AI-powered features.

Where information relating to children is processed through AI features, the protections described in Chapter 12 continue to apply.

Parents, guardians, Communities, and authorized users remain responsible for ensuring that any submission of children's information complies with applicable law.

§13.16 Future AI Technologies

As AI technologies evolve, Sisotee may introduce additional AI-enabled capabilities designed to:

Improve productivity;
Enhance security;
Simplify administration;
108 of 124 --
Improve accessibility;
Increase operational efficiency; and
Expand platform functionality.

Where new AI features involve materially different processing of Personal Data, Sisotee will update this Privacy Policy and provide any additional notices or obtain any consents required by applicable law before implementing such features.

§13.17 User Feedback

Users are encouraged to report:

Incorrect AI outputs;
Security concerns;
Unexpected behavior;
Potential bias;
Technical issues; and
Suggestions for improvement.

User feedback assists Sisotee in improving the quality, safety, and reliability of AI-powered Services.

§13.18 Compliance with Applicable Law

Sisotee intends to operate its AI-powered Services in accordance with applicable laws governing privacy, data protection, cybersecurity, consumer protection, intellectual property, and the responsible use of AI.

As legal and regulatory frameworks evolve, Sisotee may update its AI governance practices, internal policies, and this Privacy Policy to reflect new legal obligations and industry best practices.

§13.19 No Guarantee of AI Output

While Sisotee strives to provide reliable AI-assisted functionality, AI-generated outputs are provided on an "as is" and "as available" basis.

109 of 124 --

Except to the extent prohibited by applicable law, Sisotee does not warrant that AI-generated outputs will be:

Accurate;
Complete;
Current;
Error-free;
Suitable for a particular purpose; or
Free from interruptions.

Users remain responsible for evaluating and verifying AI-generated outputs before acting upon them.

§13.20 Continuous Improvement

Sisotee periodically reviews its AI technologies, governance framework, security controls, and operational practices to improve:

Accuracy;
Reliability;
Transparency;
Privacy protection;
Security;
User experience; and
Regulatory compliance.

AI capabilities, safeguards, and user controls may evolve over time as technology and applicable legal requirements develop.

CHAPTER 14 – CHANGES TO THIS

PRIVACY POLICY Sisotee may update this Privacy Policy from time to time to reflect changes in applicable laws, regulations, technology, security practices, business operations, Services, or other legitimate operational requirements.

We encourage users to review this Privacy Policy periodically to remain informed about how Personal Data is collected, used, shared, protected, and otherwise processed.

110 of 124 --

§14.1 Right to Update this Privacy Policy

Sisotee reserves the right to modify, amend, supplement, replace, or update this Privacy Policy at any time.

Updates may be made for reasons including:

Compliance with new laws or regulations;
Court decisions;
Government guidance;
Technological developments;
Introduction of new products or services;
Changes to existing functionality;
Security improvements;
Business restructuring;
Operational improvements;
Clarification of existing provisions; or
Other legitimate business or legal reasons.

§14.2 Periodic Review

Sisotee periodically reviews this Privacy Policy to ensure that it remains:

Accurate;
Current;
Transparent;
Consistent with our Services;
Compliant with applicable law; and
Reflective of evolving privacy and security practices.

§14.3 Effective Date

Each version of this Privacy Policy will identify its effective date.

Unless otherwise stated, the revised version becomes effective on the date specified at the beginning of the Privacy Policy.

Where applicable law requires advance notice or delayed implementation of certain changes, Sisotee will comply with those requirements.

111 of 124 --

§14.4 Types of Changes

Changes to this Privacy Policy may include:

Updates to legal references;
Modifications to data processing practices;
Changes in technology;
Introduction of new Services;
Addition of new AI features;
Expansion into new jurisdictions;
Changes in contact information;
Clarifications of existing language;
Editorial improvements;
Corrections of typographical errors; and
Other updates necessary to accurately describe Sisotee's practices.

§14.5 Material Changes

Where Sisotee makes changes that materially affect the processing of Personal Data or users' privacy rights, we will provide appropriate notice where required by applicable law.

Depending on the nature of the change, such notice may be provided through one or more of the following methods:

In-app notifications;
Website announcements;
Email communications;
Push notifications;
Login notices;
Community administrator communications; or
Other reasonable communication methods.

The method of notification may vary depending on the nature and significance of the change.

§14.6 Non-Material Changes

112 of 124 --

Minor or administrative changes that do not materially affect users' rights or Sisotee's privacy practices may become effective upon publication without individual notice, unless otherwise required by applicable law.

Examples include:

Formatting improvements;
Editorial corrections;
Clarification of existing provisions;
Updated contact details;
Updated cross-references;
Improved readability.

§14.7 User Responsibility

Users are encouraged to review this Privacy Policy periodically, particularly before:

Providing new Personal Data;
Using newly introduced features;
Enabling optional integrations;
Uploading sensitive documents; or
Continuing to use the Services after a revised Privacy Policy becomes effective.

Remaining informed about our privacy practices helps users make informed decisions regarding their use of the Services.

§14.8 Continued Use of the Services

Subject to applicable law, your continued access to or use of the Services after a revised Privacy Policy becomes effective constitutes your acknowledgment of the updated Privacy Policy.

Where applicable law requires explicit consent for particular changes, Sisotee will obtain such consent before processing Personal Data under the revised provisions.

Nothing in this section limits any statutory rights available to users under applicable law.

§14.9 New Features and Services

113 of 124 --

As Sisotee introduces new products, features, integrations, or technologies, this Privacy Policy may be updated to describe:

Additional categories of Personal Data;
New processing activities;
New recipients of information;
Additional user choices;
Updated retention practices;
New security measures; or
Other relevant privacy information.

Where required by applicable law, additional notices or consent mechanisms will be implemented before materially different processing begins.

§14.10 Changes in Applicable Law

Privacy and data protection laws continue to evolve in many jurisdictions.

Sisotee may revise this Privacy Policy to comply with:

New legislation;
Amendments to existing laws;
Judicial decisions;
Regulatory guidance;
Industry standards; or
Government directives.

Such updates may occur without materially changing the overall functionality of the Services.

§14.11 Regional Supplements

As Sisotee expands internationally, we may publish region-specific privacy notices or supplements addressing legal requirements applicable in particular jurisdictions.

Where a regional supplement applies to you:

It should be read together with this Privacy Policy;
It supplements this Privacy Policy to the extent necessary to comply with local law; and
In the event of a conflict, the applicable regional supplement will prevail only to the

extent required by the relevant law.

114 of 124 --

§14.12 Version History

Sisotee may maintain a version history indicating significant revisions made to this Privacy Policy.

Version history may include:

Version number;
Effective date;
Summary of significant changes; and
Other relevant publication information.

Version history is intended to improve transparency regarding updates to this Privacy Policy.

§14.13 Archived Versions

Previous versions of this Privacy Policy may be retained for:

Legal compliance;
Audit purposes;
Historical reference;
Regulatory inquiries;
Internal governance; and
Other legitimate business purposes.

Archived versions may be made available upon request where appropriate and where required by applicable law.

§14.14 Questions Regarding Changes

If you have questions regarding revisions to this Privacy Policy, you may contact Sisotee using the contact details provided in Chapter 15.

We will make reasonable efforts to explain material changes affecting the processing of Personal Data or users' rights.

115 of 124 --

§14.15 Commitment to Transparency

Sisotee is committed to maintaining transparency regarding its privacy practices.

Whenever reasonably practicable, updates to this Privacy Policy will be written in clear, understandable language while preserving the legal precision necessary to accurately describe our data processing practices and legal obligations.

§14.16 No Waiver of Rights

A delay in updating this Privacy Policy following changes in law, technology, or business operations does not constitute a waiver of any legal rights or obligations available to Sisotee or to users under applicable law.

Similarly, publication of an updated Privacy Policy does not reduce or limit any mandatory rights that users may have under applicable privacy or data protection legislation.

§14.17 Severability of Updates

If any provision introduced through a future update to this Privacy Policy is determined by a court or competent authority to be invalid, unlawful, or unenforceable, the remaining provisions shall continue in full force and effect to the maximum extent permitted by applicable law.

§14.18 Contact Before Significant Implementation

Where practical and legally appropriate, Sisotee aims to provide users with a reasonable opportunity to review material changes before they take effect.

Nothing in this section obligates Sisotee to delay the implementation of changes that are necessary to:

Comply with applicable law;
Address security vulnerabilities;
Respond to emergency circumstances;
Prevent fraud or abuse; or
Protect the rights, safety, or security of users, Communities, Sisotee, or third parties.
116 of 124 --

CHAPTER 15 – CONTACT INFORMATION,

GRIEVANCE OFFICER & REGULATORY COMPLIANCE Sisotee values transparency, accountability, and responsible handling of Personal Data. If you have any questions regarding this Privacy Policy, wish to exercise your privacy rights, or would like to report a privacy or security concern, you may contact us using the details provided in this Chapter.

We will make reasonable efforts to respond to legitimate privacy-related requests and inquiries in accordance with applicable law.

§15.1 Data Protection Commitment

ANABASIS INFRA PRIVATE LIMITED is committed to:

Protecting Personal Data;
Respecting user privacy;
Implementing appropriate technical and organizational safeguards;
Maintaining transparency regarding data processing activities;
Continuously improving privacy practices; and
Complying with applicable privacy and data protection laws.

Privacy protection forms an integral part of Sisotee's product development, operational governance, and customer support processes.

§15.2 Company Information

Company Name ANABASIS INFRA PRIVATE LIMITED Registered Office 13A, BG Tower Chandni Chowk Kanke Road

117 of 124 --

Ranchi – 834008 Jharkhand, India Website https://www.sisotee.com

§15.3 Grievance Officer

In accordance with applicable law, Sisotee has designated the following Grievance Officer for privacy-related matters.

Name Abha Bhushan Designation Head – Support & Grievance Officer Email support.sisotee@anabasis.in Telephone +91 95235 54222 The Grievance Officer is responsible for receiving, reviewing, coordinating, and responding to privacy-related complaints, requests, and inquiries in accordance with applicable law.

§15.4 Privacy Requests

Users may contact Sisotee regarding matters including:

Access to Personal Data;
Correction of inaccurate information;
Deletion requests;
Withdrawal of consent where applicable;
Restriction or objection requests;
Data portability requests where applicable;
118 of 124 --
Questions regarding AI processing;
Security concerns;
General privacy inquiries; and
Other rights available under applicable law.

To help us process your request efficiently, please provide sufficient information to verify your identity and understand the nature of your request.

§15.5 Security Reporting

If you believe that:

Your Sisotee account has been compromised;
Personal Data has been accessed without authorization;
You have identified a security vulnerability;
You have received suspicious communications claiming to be from Sisotee; or
You suspect fraudulent activity involving the Services,

please notify Sisotee promptly using the contact details provided in this Chapter.

Prompt reporting helps us investigate potential security incidents and take appropriate remedial action.

§15.6 Grievance Redressal Process

Upon receiving a privacy-related complaint or request, Sisotee may:

1. Acknowledge receipt of the complaint where appropriate;

2. Verify the identity of the requester, if necessary;

3. Review the relevant facts and supporting information;

4. Coordinate internally or with the relevant Community where appropriate;

5. Respond within the timeframe required by applicable law or within a reasonable period

where no statutory timeframe applies; and

6. Take appropriate corrective or remedial action where warranted.

Additional information may be requested where necessary to process a request accurately and securely.

119 of 124 --

§15.7 Community-Related Requests

Certain Personal Data processed through Sisotee is managed by Communities using the Platform.

Where a request relates to information that is controlled or administered by a Community, Sisotee may:

Assist the Community in processing the request;
Redirect the requester to the appropriate Community representative;
Coordinate with the Community where appropriate; or
Process the request directly where Sisotee has the legal authority or obligation to do so.

§15.8 Identity Verification

Before disclosing, correcting, deleting, or otherwise modifying Personal Data, Sisotee may require reasonable verification of the requester's identity.

Identity verification helps protect:

Users;
Residents;
Visitors;
Communities;
Sisotee; and
Other affected individuals.

Requests that cannot be reasonably verified may be declined or delayed until sufficient verification is provided.

§15.9 Regulatory Compliance

Sisotee seeks to comply with applicable privacy and data protection laws governing the jurisdictions in which it operates.

This includes, where applicable:

The Digital Personal Data Protection Act, 2023 (India);
Rules, regulations, and notifications issued under applicable legislation;
Lawful directions of competent governmental authorities; and
120 of 124 --
Other applicable privacy, cybersecurity, and consumer protection laws.

As legal frameworks evolve, Sisotee may revise its privacy practices and this Privacy Policy to maintain compliance.

§15.10 International Operations

As Sisotee expands globally, additional legal obligations may apply in different jurisdictions.

Where required, Sisotee may:

Publish region-specific privacy notices;
Designate local representatives;
Implement jurisdiction-specific user rights;
Adopt additional contractual safeguards;
Modify operational procedures to comply with local law.

Such regional requirements supplement, but do not replace, this Privacy Policy unless expressly stated.

§15.11 Legal Interpretation

This Privacy Policy should be interpreted:

In accordance with applicable law;
Together with the Sisotee Terms of Service;
Together with any applicable regional privacy notices;
Together with any product-specific privacy disclosures.

Headings are provided for convenience only and do not affect the interpretation of this Privacy Policy.

§15.12 Governing Law

Unless otherwise required by mandatory applicable law, this Privacy Policy shall be governed by and interpreted in accordance with the laws of the Republic of India.

121 of 124 --

Nothing in this Privacy Policy limits any mandatory rights available to individuals under applicable privacy or data protection legislation.

§15.13 Jurisdiction

Subject to any mandatory rights provided by applicable law, disputes arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts located in Ranchi, Jharkhand, India.

Where applicable law requires a different forum or grants users additional rights, those rights shall prevail to the extent required by law.

§15.14 Severability

If any provision of this Privacy Policy is determined by a court or competent authority to be invalid, unlawful, or unenforceable, the remaining provisions shall continue in full force and effect to the maximum extent permitted by applicable law.

§15.15 No Waiver

Failure by Sisotee to enforce any provision of this Privacy Policy shall not constitute a waiver of that provision or of any other rights available under applicable law.

Any waiver shall be effective only if made expressly and in writing by an authorized representative of Sisotee.

§15.16 Entire Privacy Policy

This Privacy Policy, together with the Sisotee Terms of Service and any applicable supplemental policies expressly incorporated by reference, constitutes the complete privacy notice governing the processing of Personal Data through the Services.

Where a separate product-specific privacy notice applies, that notice shall supplement this Privacy Policy for the relevant product or feature.

122 of 124 --

§15.17 Language

This Privacy Policy has been prepared in the English language.

If Sisotee provides translations for convenience, the English version shall prevail to the extent permitted by applicable law in the event of any inconsistency or conflict.

§15.18 Effective Date

This Privacy Policy becomes effective on the Effective Date specified at the beginning of this document and remains in effect until replaced by a revised version published by Sisotee.

Users are encouraged to review the latest version periodically.

§15.19 Contact Summary

For all privacy-related matters, please contact:

ANABASIS INFRA PRIVATE LIMITED
Registered Office
13A, BG Tower
Chandni Chowk
Kanke Road
Ranchi – 834008
Jharkhand, India
Website
https://www.sisotee.com
Email
support.sisotee@anabasis.in
Phone
+91 95235 54222
Grievance Officer
Abha Bhushan
Head – Support & Grievance Officer

§15.20 Final Statement

Sisotee recognizes that privacy is fundamental to the trust placed in us by Communities, residents, businesses, visitors, and all other users of the Platform.

We are committed to continuously strengthening our privacy, security, and governance practices while delivering reliable, secure, and innovative community management solutions.

As our Services evolve, we will continue to review and enhance our privacy framework to reflect technological advancements, legal developments, and industry best practices.