Data Processing Addendum

Last updated: 17 July 2026

This Data Processing Addendum ("DPA") forms part of and is incorporated into the Terms of Service, Master Services Agreement, Subscription Agreement, Order Form, or other written agreement ("Agreement") between Cafiyn Innovations LLP ("Processor", "Service Provider", "we", "our", or "us") and the Customer ("Controller", "Business", "Customer", "you", or "your").

This DPA governs the processing of Personal Data by Cafiyn on behalf of Customer.

Purpose

The purpose of this DPA is to establish obligations regarding the processing, protection, confidentiality, and security of Personal Data processed by Cafiyn in connection with the Services.

Definitions

Applicable Data Protection Laws. All applicable privacy and data protection laws, including where applicable:

  • Digital Personal Data Protection Act, 2023 (India)
  • GDPR
  • UK GDPR
  • CCPA/CPRA
  • Other applicable privacy regulations

Personal Data. Any information relating to an identified or identifiable individual.

Processing. Any operation performed on Personal Data including collection, recording, organization, storage, use, disclosure, transfer, and deletion.

Data Subject. The individual to whom Personal Data relates.

Security Incident. Any confirmed unauthorized access, disclosure, destruction, alteration, or loss of Personal Data.

Subprocessor. A third party engaged by Cafiyn to process Personal Data on behalf of Customer.

Scope of processing

Customer appoints Cafiyn as a processor of Personal Data solely for purposes of providing the Services.

Cafiyn shall process Personal Data only:

  • As necessary to provide Services
  • According to Customer instructions
  • As required by applicable law

If Cafiyn is legally required to process Personal Data beyond Customer instructions, it shall inform Customer before such processing unless the law prohibits that disclosure.

Customer responsibilities

Customer represents and warrants that:

  • It has lawful authority to collect Personal Data.
  • Appropriate notices have been provided to Data Subjects.
  • Required consents have been obtained.
  • Processing instructions comply with applicable laws.
  • Personal Data submitted is relevant and necessary for intended purposes.

Customer remains responsible for determining the legal basis for processing.

Categories of personal data

Depending on Customer use of Services, Personal Data may include:

  • Identification data: first name, last name, full name
  • Contact information: email address, telephone number
  • Professional information: job title, employer, department
  • Demographic information: country, region, industry classification
  • Technical information: IP address, browser information, device information, usage information

Customer shall not submit sensitive personal data unless expressly authorized by written agreement.

Purposes of processing

Personal Data may be processed for:

  • Service delivery
  • Customer support
  • Account administration
  • Security monitoring
  • Service improvement
  • Analytics
  • Compliance obligations
  • Incident response

Processing shall be limited to purposes reasonably necessary to provide the Services.

Confidentiality

Cafiyn shall ensure that personnel with access to Personal Data:

  • Are subject to confidentiality obligations
  • Receive appropriate security awareness training
  • Access Personal Data only where necessary

Confidentiality obligations survive termination of employment or engagement.

Security measures

Cafiyn shall maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Data.

Security measures may include:

  • Access controls: role-based access, authentication controls, account management procedures
  • Encryption: encryption in transit using TLS, encryption at rest where applicable
  • Monitoring: security logging, audit trails, alerting mechanisms
  • Operational controls: change management, backup procedures, incident response procedures

Cafiyn reserves the right to improve or modify security measures provided overall security is not materially reduced.

Subprocessors

Customer authorizes Cafiyn to engage subprocessors as necessary to provide Services.

Potential subprocessors may include providers of:

  • Cloud hosting
  • Analytics
  • Customer support
  • Monitoring
  • Infrastructure services

Cafiyn shall:

  • Maintain appropriate agreements with subprocessors
  • Require confidentiality obligations
  • Require reasonable security measures
  • Provide notice of material changes to its subprocessors upon request or through reasonable means, and consider good-faith objections raised by Customer within a reasonable period

Cafiyn remains responsible for subprocessors to the extent required by applicable law.

Current subprocessors

As of the effective date above, Cafiyn engages the following subprocessors in the delivery of the Services. Additions or changes will be communicated through this page and the site changelog.

SubprocessorPurposeLocationSafeguards
Hostinger International Ltd.Web hosting for cafiyn.com static site + CDNEU (Lithuania) / global CDN edgeDPA in place; TLS in transit; access-controlled admin
Supabase, Inc.Managed Postgres for waitlist and Blueprint dataUnited States, EU regions availableSOC 2 Type II; encryption at rest and in transit; SCCs
Web3Forms (Web3Forms LLC)Form submission relay for waitlist, contact, and affiliate formsUnited StatesTLS in transit; no persistent form-content storage beyond delivery; SCCs where applicable
Plausible Analytics OÜCookieless privacy-first web analyticsEuropean Union (Germany)No cookies; no personal data collected; EU-hosted; DPA in place
Google LLC (Google Analytics 4, Google Ads)Analytics and advertising measurement, gated by user consentUnited States, EU regions availableConsent Mode v2; IP anonymization; SCCs; Data Processing Terms accepted
Cloudflare, Inc.DNS resolution and edge network (transit-only)Global edge networkSOC 2 Type II; encryption in transit; SCCs; transit-only, no persistent storage

Customers who require additional subprocessor detail (contract terms, security certifications, or data-flow diagrams) may request them at infosec@cafiyn.com.

International data transfers

Personal Data may be processed in countries outside the country of origin.

Where required by applicable law, Cafiyn shall implement reasonable safeguards for such transfers, such as recognized transfer mechanisms or contractual protections.

Customer acknowledges and authorizes such transfers where necessary to provide Services.

Data subject rights

To the extent legally required, Cafiyn shall provide reasonable assistance to Customer in responding to requests relating to:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Objection
  • Portability
  • Withdrawal of consent

Customer remains responsible for responding to Data Subject requests. If a Data Subject contacts Cafiyn directly, Cafiyn will refer the request to Customer where appropriate.

Security incidents

Cafiyn shall maintain procedures designed to identify and manage Security Incidents.

Upon becoming aware of a confirmed Security Incident involving Customer Personal Data, Cafiyn shall:

  • Investigate the incident
  • Take reasonable containment measures
  • Notify Customer without undue delay
  • Provide available information reasonably necessary for Customer response

Notification does not constitute admission of fault or liability.

Audits and information requests

Upon reasonable written request, and subject to confidentiality obligations, Cafiyn may provide information regarding its security practices sufficient to demonstrate compliance with this DPA.

Any audit rights shall:

  • Be reasonable in scope
  • Avoid disruption of operations
  • Protect confidential information
  • Be subject to mutually agreed procedures

Cafiyn may satisfy audit requests through security documentation, questionnaires, certifications, or independent assessments.

Data retention

Personal Data shall be retained only for:

  • Duration of Services
  • Legitimate business purposes
  • Compliance obligations
  • Security requirements

Retention periods may vary depending upon legal and operational requirements.

Return or deletion of data

Upon termination of Services and written request from Customer, Cafiyn shall return Customer Personal Data where feasible, or delete Customer Personal Data, except where retention is required:

  • By law
  • For security purposes
  • For legitimate business records
  • For dispute resolution

Residual copies contained in backups may be retained until overwritten through normal retention cycles.

Compliance with law

Each party shall comply with applicable privacy and data protection laws relevant to its role and responsibilities.

Nothing in this DPA shall require either party to violate applicable law.

Liability

Liability arising under this DPA shall be subject to the limitations and exclusions contained in the governing Agreement unless prohibited by applicable law.

Term and termination

This DPA becomes effective upon processing of Personal Data by Cafiyn and remains effective for the duration of such processing.

Termination of the Agreement automatically terminates this DPA except for obligations that survive by their nature.

Changes to this DPA

Cafiyn may update this DPA from time to time to:

  • Reflect legal developments
  • Improve security practices
  • Address operational requirements

Material changes shall be communicated through appropriate channels.

Contact information

Privacy, security, and data protection requests: infosec@cafiyn.com

Requests relating to Personal Data, privacy rights, security incidents, or data protection matters should be directed to the above address.

Questions about this policy? Email infosec@cafiyn.com.

← All policies