Privacy Policy

Last updated: 29 August 2026

Introduction

Cafiyn Innovations LLP ("Cafiyn", "Company", "we", "our", or "us") is committed to protecting the privacy, confidentiality, integrity, and security of personal information entrusted to us by users, customers, prospects, partners, and visitors.

This Privacy Policy describes how we collect, use, disclose, store, transfer, and protect Personal Information obtained through:

  • Cafiyn websites
  • Web applications
  • Customer portals
  • Contact forms
  • Marketing forms
  • Product demonstrations
  • Support interactions
  • Events and webinars
  • Any related services operated by Cafiyn

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.

Definitions

Personal Information. Any information that identifies, relates to, describes, or can reasonably be associated with an identified or identifiable individual.

Processing. Any operation performed on Personal Information including collection, storage, use, transmission, disclosure, deletion, analysis, or modification.

Data Subject / Data Principal. The individual to whom Personal Information relates.

Services. All websites, software products, applications, platforms, and related services offered by Cafiyn.

Information we collect

Information you provide

When interacting with our Services, we may collect:

  • Identity information: first name, last name, full name
  • Contact information: email address, phone number, business contact details
  • Professional information: job title, organization, industry, department
  • Demographic information (where voluntarily provided): country, region, industry segment, company size
  • Communications: information submitted through contact forms, support tickets, survey responses, chat interactions, and email

Information automatically collected

We automatically collect certain information when you access our Services:

  • Device information: browser type, device type, operating system, language settings, screen resolution
  • Technical information: IP address, session identifiers, error logs, diagnostic information
  • Usage information: pages visited, clickstream data, session duration, feature usage, referral URLs, interaction patterns

Analytics information

We may utilize analytics platforms and similar technologies to understand:

  • User behavior
  • Website performance
  • Product adoption
  • Conversion metrics
  • Marketing effectiveness

Analytics data may be aggregated or anonymized whenever feasible. On our websites, analytics and advertising cookies are set only after you accept them through our cookie banner, and we use Google Consent Mode to signal your choice; see the Cookie Policy.

Business contact and prospect data

Some of our Services, including Cafiyn Lens and Cafiyn FlyWheel, involve processing professional contact information about individuals who may not have interacted with Cafiyn directly, on behalf of and at the direction of our customers.

  • What we process: business contact details such as name, job title, employer, business email address, business phone number, and professional profile links, together with firmographic information about the employer.
  • Where it comes from: our customers, licensed third-party business data providers, and publicly available professional sources.
  • Why we process it: to identify companies matching a customer's ideal customer profile and to conduct business-to-business outreach on that customer's behalf.
  • Legal basis: legitimate interests in business-to-business communication, and performance of our contract with the customer, who is responsible for the lawfulness of its instructions.

If you have received an outreach message through our Services, you can opt out using the unsubscribe or opt-out mechanism in the message itself, and we add you to a suppression list so you are not contacted again through our platform. You may also exercise any of the rights described in this Policy, including access, correction, deletion, and objection, by contacting infosec@cafiyn.com. Where a request concerns processing we perform on a customer's behalf, we may refer the request to that customer and assist them in responding.

Affiliate program information

If you join the Cafiyn Affiliate Program, we collect additional information specifically to run the program and pay you. This is separate from, and additional to, the information described above.

  • Application details: your name, email address, website or social profile, and a description of your audience.
  • Payout information: your chosen payout method and the corresponding payment details, such as a PayPal email address or bank account information. This is financial information and we treat it accordingly.
  • Referral activity: the performance of your referral links, including impressions, clicks, and conversions attributed to your affiliate code.

We use this information only to administer the program: to verify eligibility, attribute referrals, calculate and pay commissions, prevent fraud and abuse, and meet tax and accounting obligations. Affiliate payout details are retained for as long as needed to make payments and satisfy legal record-keeping requirements, then deleted or anonymized. You can ask us to close your affiliate account and remove your payout details at any time by contacting us.

Purposes of processing

We process information for legitimate business purposes including:

  • Service delivery: providing Services, managing accounts, authenticating users, responding to inquiries
  • Customer support: resolving technical issues, providing assistance, troubleshooting
  • Security: threat detection, fraud prevention, abuse monitoring, access control
  • Product improvement: feature development, performance optimization, service enhancement
  • Marketing (subject to applicable law): product announcements, service updates, educational content, event invitations

Legal basis for processing

Where applicable under relevant privacy laws, including the Digital Personal Data Protection Act, 2023 (India) and, for individuals in the European Economic Area or United Kingdom, the GDPR and UK GDPR, processing may be based on:

  • Consent: when you voluntarily provide consent.
  • Contractual necessity: to provide requested Services.
  • Legal obligation: to comply with regulatory requirements.
  • Legitimate interests: including security monitoring, fraud prevention, service improvement, and business operations.

Cookies and tracking technologies

We utilize session cookies, persistent cookies, analytics cookies, and preference cookies.

Cookie usage, including our consent banner and how to manage your choice, is described in our Cookie Policy.

Users may modify browser settings to refuse cookies, though certain functionality may become unavailable.

Disclosure of information

We do not sell Personal Information.

We may disclose information to:

  • Service providers, including providers of cloud infrastructure, hosting services, analytics platforms, advertising and campaign measurement platforms, CRM platforms, and customer support tools
  • Professional advisors, including legal counsel, auditors, and compliance consultants
  • Regulatory authorities, when required by law, court order, government request, or legal process

International data transfers

Information may be transferred to and processed in countries outside the country in which it was originally collected.

Where required by law, appropriate safeguards shall be implemented to protect transferred information.

Data retention

We retain Personal Information only for as long as necessary to:

  • Fulfill contractual obligations
  • Deliver Services
  • Meet legal requirements
  • Resolve disputes
  • Enforce agreements

Retention periods may vary depending upon the nature of the information and applicable legal obligations.

Information security

Cafiyn maintains administrative, technical, and organizational safeguards designed to protect information from unauthorized access, unauthorized disclosure, loss, destruction, and alteration.

Security controls may include:

  • Encryption in transit
  • Access controls
  • Logging and monitoring
  • Vulnerability management
  • Secure development practices
  • Periodic security reviews

No system can be guaranteed to be completely secure. Our Information Security Policy describes the security program in more detail.

Data subject rights

Subject to applicable law, individuals may have rights to:

  • Access: request access to Personal Information.
  • Correction: request correction of inaccurate information.
  • Deletion: request deletion of information.
  • Restriction: request restriction of processing.
  • Portability: request transfer of information where applicable.
  • Objection: object to processing activities.
  • Withdrawal of consent: withdraw previously provided consent.

Requests may be submitted to infosec@cafiyn.com. We will respond within the timelines required by applicable law.

Grievance redressal

In accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023, individuals may raise privacy grievances with our grievance contact:

Grievance contact: infosec@cafiyn.com, Cafiyn Innovations LLP, No. 235, 13th Cross, Indiranagar 2 Stage, Bengaluru, Karnataka, India, 560038.

We aim to acknowledge grievances promptly and resolve them within the timelines prescribed by applicable law. If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant supervisory authority, including the Data Protection Board of India, once operational, or your local data protection authority.

Children's privacy

Our Services are not directed toward children under thirteen (13) years of age or any higher minimum age required by applicable law, including eighteen (18) years under Indian law where consent of a parent or lawful guardian is otherwise required.

We do not knowingly collect Personal Information from children. If we become aware that such information has been collected, reasonable steps will be taken to remove it.

Third-party links

Our Services may contain links to third-party websites.

Cafiyn is not responsible for the privacy practices, security controls, or content of third-party websites. Users should review the privacy policies of those websites independently.

Privacy incidents

In the event of a confirmed privacy incident affecting Personal Information, Cafiyn will take appropriate steps to:

  • Investigate the incident
  • Mitigate impact
  • Restore service integrity
  • Notify affected parties and authorities when legally required

Changes to this policy

We may modify this Privacy Policy periodically.

Material changes will be communicated through reasonable means, including website publication or direct communication where appropriate.

Continued use of Services following updates constitutes acceptance of the revised Privacy Policy.

Contact information

Privacy and data protection contact: infosec@cafiyn.com

All privacy requests, concerns, complaints, and inquiries should be directed to the above address.

Questions about this policy? Email infosec@cafiyn.com.

← All policies