This Data Processing Addendum ("DPA") forms part of and is incorporated into the Terms of Service, Master Services Agreement, Subscription Agreement, Order Form, or other written agreement ("Agreement") between Cafiyn Innovations LLP ("Processor", "Service Provider", "we", "our", or "us") and the Customer ("Controller", "Business", "Customer", "you", or "your").
This DPA governs the processing of Personal Data by Cafiyn on behalf of Customer.
The purpose of this DPA is to establish obligations regarding the processing, protection, confidentiality, and security of Personal Data processed by Cafiyn in connection with the Services.
Applicable Data Protection Laws. All applicable privacy and data protection laws, including where applicable:
Personal Data. Any information relating to an identified or identifiable individual.
Processing. Any operation performed on Personal Data including collection, recording, organization, storage, use, disclosure, transfer, and deletion.
Data Subject. The individual to whom Personal Data relates.
Security Incident. Any confirmed unauthorized access, disclosure, destruction, alteration, or loss of Personal Data.
Subprocessor. A third party engaged by Cafiyn to process Personal Data on behalf of Customer.
Customer appoints Cafiyn as a processor of Personal Data solely for purposes of providing the Services.
Cafiyn shall process Personal Data only:
If Cafiyn is legally required to process Personal Data beyond Customer instructions, it shall inform Customer before such processing unless the law prohibits that disclosure.
Customer represents and warrants that:
Customer remains responsible for determining the legal basis for processing.
Depending on Customer use of Services, Personal Data may include:
Customer shall not submit sensitive personal data unless expressly authorized by written agreement.
Personal Data may be processed for:
Processing shall be limited to purposes reasonably necessary to provide the Services.
Cafiyn shall ensure that personnel with access to Personal Data:
Confidentiality obligations survive termination of employment or engagement.
Cafiyn shall maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Data.
Security measures may include:
Cafiyn reserves the right to improve or modify security measures provided overall security is not materially reduced.
Customer authorizes Cafiyn to engage subprocessors as necessary to provide Services.
Potential subprocessors may include providers of:
Cafiyn shall:
Cafiyn remains responsible for subprocessors to the extent required by applicable law.
As of the effective date above, Cafiyn engages the following subprocessors in the delivery of the Services. Additions or changes will be communicated through this page and the site changelog.
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Hostinger International Ltd. | Web hosting for cafiyn.com static site + CDN | EU (Lithuania) / global CDN edge | DPA in place; TLS in transit; access-controlled admin |
| Supabase, Inc. | Managed Postgres for waitlist and Blueprint data | United States, EU regions available | SOC 2 Type II; encryption at rest and in transit; SCCs |
| Web3Forms (Web3Forms LLC) | Form submission relay for waitlist, contact, and affiliate forms | United States | TLS in transit; no persistent form-content storage beyond delivery; SCCs where applicable |
| Plausible Analytics OÜ | Cookieless privacy-first web analytics | European Union (Germany) | No cookies; no personal data collected; EU-hosted; DPA in place |
| Google LLC (Google Analytics 4, Google Ads) | Analytics and advertising measurement, gated by user consent | United States, EU regions available | Consent Mode v2; IP anonymization; SCCs; Data Processing Terms accepted |
| Cloudflare, Inc. | DNS resolution and edge network (transit-only) | Global edge network | SOC 2 Type II; encryption in transit; SCCs; transit-only, no persistent storage |
Customers who require additional subprocessor detail (contract terms, security certifications, or data-flow diagrams) may request them at infosec@cafiyn.com.
Personal Data may be processed in countries outside the country of origin.
Where required by applicable law, Cafiyn shall implement reasonable safeguards for such transfers, such as recognized transfer mechanisms or contractual protections.
Customer acknowledges and authorizes such transfers where necessary to provide Services.
To the extent legally required, Cafiyn shall provide reasonable assistance to Customer in responding to requests relating to:
Customer remains responsible for responding to Data Subject requests. If a Data Subject contacts Cafiyn directly, Cafiyn will refer the request to Customer where appropriate.
Cafiyn shall maintain procedures designed to identify and manage Security Incidents.
Upon becoming aware of a confirmed Security Incident involving Customer Personal Data, Cafiyn shall:
Notification does not constitute admission of fault or liability.
Upon reasonable written request, and subject to confidentiality obligations, Cafiyn may provide information regarding its security practices sufficient to demonstrate compliance with this DPA.
Any audit rights shall:
Cafiyn may satisfy audit requests through security documentation, questionnaires, certifications, or independent assessments.
Personal Data shall be retained only for:
Retention periods may vary depending upon legal and operational requirements.
Upon termination of Services and written request from Customer, Cafiyn shall return Customer Personal Data where feasible, or delete Customer Personal Data, except where retention is required:
Residual copies contained in backups may be retained until overwritten through normal retention cycles.
Each party shall comply with applicable privacy and data protection laws relevant to its role and responsibilities.
Nothing in this DPA shall require either party to violate applicable law.
Liability arising under this DPA shall be subject to the limitations and exclusions contained in the governing Agreement unless prohibited by applicable law.
This DPA becomes effective upon processing of Personal Data by Cafiyn and remains effective for the duration of such processing.
Termination of the Agreement automatically terminates this DPA except for obligations that survive by their nature.
Cafiyn may update this DPA from time to time to:
Material changes shall be communicated through appropriate channels.
Privacy, security, and data protection requests: infosec@cafiyn.com
Requests relating to Personal Data, privacy rights, security incidents, or data protection matters should be directed to the above address.
Questions about this policy? Email infosec@cafiyn.com.
← All policies