Privacy Policy

Last updated on: 4 August 2026

1

General

1.1

The website https://www.boltic.io/ Website”) including the related mobile site (collectively called the “Platform”) are operated by Shopsense Retail Technologies Limited [CIN: U52100MH2012PLC236314] (“Fynd Boltic”, “we”, “us” or “our”), a company incorporated under the Companies Act, 1956, having its registered office at 1st Floor, Wework Vijay Diamond, Opp. SBI Branch, Cross Road B, Ajit Nagar, Kondivita, Andheri East, Mumbai 400093.

1.2

The Company owns and operates the Platform which offers a solution that enables a User to collaborate, collate, transform, centralize data and automate workflows. It provides a base that has integrations with third party service providers to help with a low code/no code home for modern data teams ("Service(s)").

1.3

The policy is applicable to users who browse the Platform, use the Services and/or create an account on the Platform ("you”, “your”,  “Users”).

1.4

This privacy policy (“Privacy Policy”), together with the Terms of Use governs your use of the Platform and describes our policies and procedures on the collection, use, disclosure, processing, protection, transfer, and storage of your  Information (defined hereinafter) provided to us by you. By using, browsing, accessing, or purchasing any Services from the Platform you agree to be bound by the terms of this Privacy Policy.

1.5

We operate the Platform from India and welcome users accessing it from around the world. Wherever you are, we aim to handle your Information to a consistent global baseline standard, as set out in this Privacy Policy. For legal certainty, this Privacy Policy and your use of the Platform are governed by the laws of India, including those applicable to data protection and privacy. By visiting the Platform, sharing your Information, or using our products or Services, you agree to be bound by this Privacy Policy, the Terms of Use, and the other policies published on the Platform. If you do not agree with them, we ask that you not use or access the Platform.

1.6

This document is an electronic record generated by a computer system and does not require any physical or digital signature. It is published in accordance with the provisions of the Information Technology Act, 2000 and the rules made thereunder relating to electronic records. In this Privacy Policy, "Data Protection Laws" means the data protection and privacy laws applicable to the processing of your Information, including the Digital Personal Data Protection Act, 2023 and the rules, regulations, and guidelines issued thereunder, and, as part of our global baseline standard, the EU General Data Protection Regulation, the UK GDPR, and applicable United States state privacy laws, in each case as amended from time to time and to the extent applicable to you.

1.7

As part of our global baseline standard, we have taken, and continue to take, steps designed to align our data handling practices with other applicable data protection frameworks for Users located outside India, including the EU GDPR, the UK GDPR (together with the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses), and applicable United States state privacy laws, each as further described in this Privacy Policy.

1.8

This Privacy Policy sets out the type of information collected from the Users, including the nature of the Sensitive Personal Data or Personal Information (defined hereinafter), the purpose, means and modes of usage of such information and how and to whom we shall disclose or transfer such information.

1.9

Where we process your Information on the basis of your consent, you may withdraw that consent at any time by writing to us at DPO@gofynd.com. If you withdraw consent for a particular service, we may no longer be able to provide that service to you. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, nor processing carried out on any other lawful basis as described in the "Legal Bases for Processing" section.

1.10

Your privacy is important to us. We are committed to being transparent about how we handle your Information and to protecting it using appropriate security measures, as described in this Privacy Policy.

1.11

Please take a moment to familiarize yourself with our Privacy Policy. If you do not agree with any provisions of the Terms or this Privacy Policy, we advise you to not use or access the Platform. This Privacy Policy applies to all current and former users accessing or using the Platform and/or Services or otherwise engaging with us through email or any other means of communication.

1.12

Where we process your Information on the basis of your consent, we will, at or before the time of seeking such consent, provide you with an itemised notice describing the Information sought to be collected and the specific purpose of its processing, the manner in which you may exercise your rights, and the manner in which you may make a complaint to the Data Protection Board of India, in accordance with the Digital Personal Data Protection Act, 2023. You may access the contents of such notice in English or in any language specified in the Eighth Schedule to the Constitution of India, as made available by us.

2

Type of Information Collected

2.1

You shall be asked to provide, input and/or upload data and/or information relating to you, your business, your product(s), service(s) or other individual(s), which when combined with other pieces of information available with us could reasonably allow you to be identified including:

2.1.1

name, mailing address, phone number, email address, contact details etc;

2.1.2

age, date of birth, gender;

2.1.3

financial identifiers viz financials, PAN, GSTIN certificate, VAT certificate, Bank account details etc;

2.1.4

any other usage and/or interaction details (collectively be referred to as “Personal Information”).

2.2

You shall also provide, input and/or upload and we may thereupon collect, receive, process or store certain sensitive personal data or information consisting of, but not limited to:

2.2.1

1.1.1 Passwords;

2.2.2

Any detail relating to the above Personal Information categories as provided to us for processing and/or providing Services, which shall be stored or processed under  lawful contract or otherwise (collectively be referred to as “Sensitive Personal Data”).

2.3

Information and/or data provided, shared, uploaded as enumerated under above clause 2.1 and clause 2.2 shall collectively be referred to as “Information” under this Privacy Policy. The table below sets out the categories of Information providing clarity on the purpose of collection of such data

Identifier Purpose Retention

Name

Billing

45 days after account deletion

Email

Billing/Communication/Authentication

45 days after account deletion

Password

Authentication

45 days after account deletion

Phone Number

Communication

45 days after account deletion

Billing Address

Billing

45 days after account deletion

Credit Card Details

Billing

Stored with third-party gateway

Uploaded files

Processing

45 days after account deletion

Technical data (e.g., IP address, browser type, device information).

Analytics

45 days after account deletion

2.4

You shall be asked to provide your Information, and we shall collect Information from you in the following instances :

2.4.1

anytime you visit, access, use or browse the Platform;

2.4.2

create an account on the Platform;

2.4.3

undertake any transaction on the Platform;

2.4.4

Submit feedback, queries, or support requests;

2.4.5

Interact with the Platform through cookies, log files, and similar tracking technologies;

2.4.6

We may also collect your Information from any third party service providers, affiliated entities in order to further facilitate any services, improve our quality, fulfil any transactions and support cross-platform functionality etc.

2.4.6

We shall share and use your account information and Technical Data consistently with this Privacy Policy and as required under Data Protection Laws, and may combine such information solely to provide, secure, and improve our Services. Further this clause does not extend to content, data, or files uploaded to or processed through the Services by a User (“User Content”), which we handle only as a processor on your instructions. We do not use User Content for advertising or to train or improve any AI or machine-learning models.  For clarity, the automated processing, transformation and delivery of data performed by the Platform is processing carried out on your instruction, in our capacity as a processor, and does not constitute automated decision-making producing legal or similarly significant effects in relation to you.

2.5

You agree to provide Information, which shall be true, correct, up to date and accurate. You may access, amend, alter or require deletion of your Information partially or fully by contacting us at customer care id: support@boltic.io

2.6

1.1 You understand and acknowledge that the Platform and Services is not intended for use by individuals who have not attained the age of majority and in India, this refers to individuals under the age of 18 years (“Minors”). In other jurisdictions, the definition of a Minor shall align with the age prescribed under the respective local laws. We do not knowingly collect any personal information from Minors, nor do we knowingly provide any services to Minors. If we become aware that we have inadvertently collected personal information from a Minor, we will take appropriate steps to delete such information within a reasonable timeframe, in accordance with applicable data protection laws. If a parent or legal guardian becomes aware that their child has provided personal information on the Platform without their consent, they may contact us at DPO@gofynd.com to request the deletion of such information. Please note that we are not responsible for any harm, loss, or damage suffered by a Minor arising from use of the Platform and/or Services in contravention of this Privacy Policy or the Terms of Use.

3

Use of Information Collected

3.1

We shall collect, use, manage or process your Information for the following purposes:

3.1.1

For creating and giving you access to your registered account on the Platform;

3.1.2

To manage user accounts, authenticate users;

3.1.3

For the purpose of enabling you the Services available on the Platform;

3.1.4

To develop, deliver, process and improve our products, Services, content and/or the Platform in order to personalize and improve your experience based on usage patterns;

3.1.5

To send marketing and promotional communications, subject to your explicit consent about our products, Services, offers, updates, upcoming events, including providing you information in relation to invoices, technical notices, security alerts or any other service related messages or other related information;

3.1.6

For internal analytical and research purposes such as auditing, data analysis and other internal functions;

3.1.7

To meet any legal or regulatory requirement or comply with a request from any governmental or judicial authority including but not limited to tax, audit and fraud prevention requirements;

3.1.8

To provide to our affiliates for operational, support and compliances purposes;

3.1.9

To resolve any request, dispute, grievance or complaint raised by you in relation to your use of the Platform;

3.1.10

To support cross-platform functionality (if any) and;

3.1.11

For any other purpose as may be required under applicable Data Protection Laws.

4

Legal Bases for Processing

4.1

As a matter of our global baseline standard, and irrespective of your location, we process your Information only where we have a lawful basis to do so. Depending on the Information concerned and the purpose for which we process it, we rely on one or more of the following legal bases:

4.1.1

1.1.1 Performance of a contract – where processing is necessary to provide the Services you have requested, to create and administer your account, to process payments, and to deliver support. This is our primary basis for processing account and transactional Information;

4.1.2

Legitimate interests – where processing is necessary for our legitimate business interests (such as securing the Platform, preventing fraud, conducting internal analytics, and improving our products and Services), provided such interests are not overridden by your rights and freedoms;

4.1.3

Consent – where you have given us consent to process your Information for a specific purpose, such as sending marketing communications or placing non-essential cookies. Where consent is the basis, you may withdraw it at any time in accordance with this Privacy Policy;

4.1.4

Compliance with a legal obligation – where processing is necessary to comply with applicable law, including tax, audit, regulatory, and fraud-prevention obligations.

4.2

Where we rely on consent for a particular processing activity and you withdraw that consent, we will cease the relevant processing; however, this will not affect processing carried out on any other lawful basis, nor our ability to continue providing the Services on the basis of contractual necessity.

5

Disclosure & Storage of Information Collected

5.1

We may from time to time be required to disclose the Information collected from you to relevant third party service providers who shall assist us in order to facilitate, and/or improve the provision of Services on the Platform viz our affiliates, partners including but not limited to sub-contractors, personnel, customer support platforms, analytics service providers etc. Such Information shall be shared on a need to know basis. For instance, we may share your Information with third party payment gateway provider to process transactions on the Platform. By using the Platform, you consent to any such disclosure of your Information with third party service providers. We ensure that such third party service providers are bound by reasonable confidentiality obligations and/ or use, maintain and follow generally accepted industry and security standards with respect to such Information.

5.2

We may also disclose your Information when such disclosure is requisitioned under any law or judicial decree or when we, in our sole discretion, deem it necessary in order to protect our rights or the rights of other Users, to prevent harm to persons or property, to fight fraud and credit risk.

5.3

We may also disclose or transfer your Information to any third party as a part of reorganization or a sale of the assets, division or transfer of a part or whole of us. We shall ensure that third party to which we transfer or sell our assets will have appropriate confidentiality and security measures, at least as protective as those described in this Privacy Policy, to handle your Information. You will have the opportunity to opt out of any such transfer if the new entity's planned processing of your Information differs materially from that set forth in this Privacy Policy.

5.4

A third party payment gateway provider may be required to collect certain financial information from you including but not limited to credit/debit card number, bank account details etc (collectively referred to as “Financial Information”). All Financial Information collected from you by such third party payment gateway providers will be used only for the purpose it has been collected viz billing and payment processes. The Financial Information collected from you is transacted through secure digital platforms of approved payment gateways which are under encryption, thereby complying with reasonably expected technology standards. The verification of the Financial Information is carried out solely by you through your own authentication process, in which we have no role to play. As such, we are not responsible for the actions or inactions of third party payment gateway providers, including any breach by them of their own representations or warranties. We shall also not be obligated to mediate or resolve any dispute or disagreement between you and such third party payment service providers.

5.5

While we take best efforts to ensure that your Information is duly protected by undertaking security measures prescribed under applicable laws, you are strongly advised to exercise reasonable discretion while providing your Information including Financial Information while using services of any third party service providers given that the internet is susceptible to security breaches.

5.6

We reserve the right to conduct a security review at any time to validate your identity, age, the state from where you are accessing the Platform and other registration data provided by you and to verify your use of the Services and your financial transactions for potential breach of our Terms of Use and of the applicable law.

6

Security

6.1

The security of your Information is important to us. We have implemented security policies, rules and technical  and organizational measures, as required under applicable Data Protection Law including firewalls, TLS encryption, regular audits, transport layer security and other physical and electronic security measures to ensure protection of your Information from unauthorized access, improper use or disclosure, unauthorized modification and unlawful destruction or accidental loss. Please note that we use such standards and security measures in safeguarding your Information as required under applicable Data Protection Laws.  As a matter of good practice, such measures are designed to be capable of supporting compliance with the requirements of multiple data protection frameworks, including the DPDP Act, 2023, the EU GDPR, and the UK data protection regime (including, where applicable, the UK Standard Contractual Clauses/International Data Transfer Agreement).

6.2

However, it is clarified that although we make best possible efforts to collect, store, process, and transmit your Information in a secure operating environment that is not open to public, no method of transmission or storage over the internet can be guaranteed to be completely secure, and unintended disclosures or security breaches may still occur despite these measures.

6.3

Please note that you have the right to a) access your Information; b) request rectification or deletion of your Information; c) restrict or object to processing of your Information. We have a strong notice and takedown mechanism in place, in case it has come to your knowledge that the Information is being misused or used in for any illegal or fraudulent activity, you are required to inform us on immediate basis. To exercise your rights, you are requested to email us at support@boltic.io or contact us at DPO@gofynd.com.

6.4

Data Breach Notification. Where we become aware of a personal data breach affecting your Information that is likely to cause harm to you, we will notify the Data Protection Board of India and any other competent regulatory or supervisory authority as required under applicable Data Protection Laws, within the timeframe prescribed under such laws, including, where applicable, within 72 (seventy-two) hours of becoming aware of the breach under the EU GDPR or the UK GDPR. Where such a breach is likely to result in a high risk to your rights and freedoms, or is otherwise required to be intimated to you under applicable Data Protection Laws, we will also notify you without undue delay, describing in clear and plain language the nature of the breach, the Information likely affected, the likely consequences, and the measures taken or proposed to be taken to address the breach and mitigate its possible adverse effects, through email, in-app notification, or such other reasonable means as we may adopt. Our obligations under this clause are subject to any exemptions, extensions, or staged-disclosure permissions available under applicable Data Protection Laws, including where immediate notification could impede a law enforcement, security, or regulatory investigation.

7

Your Rights in Relation to Your Information

7.1

As part of our global baseline standard, we extend the following rights to all Users worldwide, regardless of the jurisdiction in which you are located, subject to applicable law and to verification of your identity:

7.1.1

Right of access – to obtain confirmation of whether we process your Information and to obtain a copy of it;

7.1.2

Right to rectification – to have inaccurate or incomplete Information corrected or updated;

7.1.3

Right to erasure – to request deletion of your Information in the circumstances permitted under applicable law;

7.1.4

Right to restriction – to request that we restrict the processing of your Information in certain circumstances;

7.1.5

Right to object – to object to processing carried out on the basis of our legitimate interests, and to object to processing for direct-marketing purposes at any time;

7.1.6

Right to data portability – to receive Information you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible;

7.1.7

Right in relation to automated decision-making – not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, save as permitted under applicable law;

7.1.8

Right to withdraw consent – where processing is based on consent, to withdraw that consent at any time;

7.1.9

Right to nominate- to nominate, in the manner prescribed under the Digital Personal Data Protection Act, 2023, another individual who may, in the event of your death or incapacity, exercise your rights under that Act on your behalf.

7.1.10

Right to grievance redressal – to have available a readily accessible means of registering a grievance with us in respect of any act or omission regarding the processing of your Information or the exercise of your rights, and to receive a response within the period prescribed under applicable Data Protection Laws, including the Digital Personal Data Protection Act, 2023;

7.1.11

Right to give and withdraw consent through a Consent Manager – where and to the extent a Consent Manager registered with the Data Protection Board of India is made available, you may give, manage, review and withdraw your consent to the processing of your Information through such Consent Manager, in the manner prescribed under the Digital Personal Data Protection Act, 2023.

7.2

To exercise any of these rights, you may write to us at DPO@gofynd.com. We will respond to your request within 30 (thirty) days of receipt and verification. This period may be extended where permitted by applicable law for complex or numerous requests, in which case we will inform you of the extension and the reasons for it. We will not discriminate against you for exercising any of these rights.

7.3

The rights described above apply to all Users as our baseline standard. Certain jurisdictions confer additional or modified rights; these are set out in the region-specific supplements at the end of this Privacy Policy, which prevail over this section to the extent of any inconsistency for Users in the relevant region.

8

Duty of the Data Principal

7.3

Where you are a Data Principal under the Digital Personal Data Protection Act, 2023, you agree that you shall: (a) comply with the provisions of all applicable laws while exercising your rights under this Privacy Policy; (b) not impersonate another person while providing your Information; (c) not suppress any material information while providing your Information for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities; (d) not register a false or frivolous grievance or complaint with us or the Data Protection Board of India; and (e) furnish only such Information as is verifiably authentic while exercising your right to correction or erasure.

9

International Transfers of Information

9.1

Your Information may be stored, processed, and transferred to, and accessed from, India and other countries in which we or our sub-processors operate.

9.2

As part of our global baseline standard, where we transfer Information originating from the European Economic Area, the United Kingdom, or any other jurisdiction that restricts cross-border transfers, we implement appropriate safeguards recognised under applicable law.

9.3

For transfers of Information governed by the Digital Personal Data Protection Act, 2023, we transfer such Information only to countries that have not been restricted for such transfers by notification of the Central Government of India, in accordance with that Act.

9.4

You may obtain a copy of the relevant transfer safeguards, or further information about the countries to which your Information is transferred, by writing to us at DPO@gofynd.com.

10

Cookies Policy

10.1

Due to the communication standards on the internet, when you visit, access, or browse the Platform, we automatically receive various electronic identification data, such as the uniform resource locator of the site from which you visit the Platform, details of the   website you   visit   on   leaving   the   Platform,   the   internet   protocol   (“IP”)   address,   device information   (including   device   name,  device type,   operating   system,   time   zones,   and   data   identifiers), browser data (type of web browser used, the name of the User’s internet service provider), location data, access logs and usage behaviour (collectively “Technical Data”). The Technical Data to maintain login sessions, analyse overall User trends, and secure and improve our Services. We do not use Technical Data to serve personalised or targeted advertising. The link between the User’s IP address and the User’s personally identifiable information is not shared with third parties without the User’s permission except when required by law or to provide or facilitate the Service(s). We may share Technical Data in aggregated and de-identified form, from which you cannot reasonably be identified, with partners, sponsors, and investors on a need-to-know basis for business purposes; we do not share your specific, identifiable data in this manner. The amount of Technical Data we receive depends on the settings of the web browser used to access the Platform.

10.2

Cookies are small files to enhance user experience and analyse traffic. The following table outlines the types of cookies utilized, along with the purpose of their collection:

Type Name Purpose

Essential

bltc_anonymous_id

Authentication

Essential

bg.session

Authentication

Essential

csrf_token

Protects against hacking and malicious actors.

Essential

__stripe_mid

Fraud prevention and detection

Essential

__stripe_sid

Fraud prevention and detection

Essential

m

Tracks the user’s session for payment gateway

Essential

__cf_bm

Bot management

Analytics

s7

Gather data regarding site usage and user behaviour on the website.

10.3

You understand that you may set or amend your web browsers to delete or disable cookies. If you choose to disable cookies on your computer or mobile telecommunication device, it may impair, degrade or restrict access to certain areas of the Platform. In case you wish to delete any Technical Data, you can write to us at DPO@gofynd.com for such request.

10.4

We may allow other third party service provider or entities to serve advertisements and/or offer their products or services on the Platform to you. In case you opt to avail services from any such third-party service providers, you shall be governed by the terms and privacy policies of such third party service providers. We may target some advertisements to you on the Platform that fit a certain general profile. We do not use or share your Information to target advertisements specifically to you. In the course of serving advertisements or optimizing the Services on the Platform for Users, we may allow authorised third parties to place or recognize a unique cookie on the User’s browser.

10.5

You agree and understand that we do not exercise control over third party websites displayed as search results or links on the Platform. These other sites may place their own cookies or other files on the Users’ computer, collect data or solicit personal information from the Users, on which we have no control and shall not be held responsible or liable. We do not make any representations concerning the privacy practices or policies of such third parties or terms of use of such websites, and we do not verify or endorse the accuracy, integrity, or quality of the information, data, text, software, sound, photographs, graphics, videos, messages or other materials available on such websites. The inclusion or exclusion does not imply any endorsement by us of such websites, the websites’ provider, or the information on such websites.

10.6

We may keep records of telephone calls received from and made to Users for the purpose of administration of services, research and development, training, business intelligence, business development, or for User administration. We may share such telephone records with third parties when required by law or when required to provide or facilitate the User with the services.

10.7

You consent to our reproduction/publishing of all testimonials and reviews given by you on the Platform in relation to the Services or the Platform. You agree that we may edit the testimonials and reviews provided by you and reproduce/publish such edited or paraphrased versions of the testimonials and reviews on the Platform. If the User has any concerns with the reproduction/publication of any testimonial or review provided by you, the User may contact us at customer care id: support@boltic.io.

11

Opt-Out Policy

11.1

If you choose to opt for or engage with any service offered by a third-party service provider through the Platform, we may share your Information with such third parties to facilitate the provision of their services to you. In such instances, these third-party service providers may  market   their  own  services,   send   promotional  emails,   or  engage   in  other  promotional communication with you. We do not oversee, and are not responsible for, such communications or interactions between you and the third-party service providers.

11.2

We may send you promotional offers, product updates, or service announcements based on your preferences and consent provided. If you wish to remove your contact information from all our mailing lists and newsletters, you can click on the "unsubscribe" link or follow the instructions in each e-mail message. Alternatively,  you can update your communication preferences in your account settings or you can contact us at customer care id: support@boltic.io. We reserve the right to limit membership based on availability of contact information. All Users will be notified by email prior to any actions taken.

12

Retention & Deletion of Information

12.1

We will retain your Information for as long as necessary for the purpose for which it was collected, including to provide the Services to you, and thereafter to comply with our legal, regulatory, tax, accounting and reporting obligations, to resolve disputes, and to enforce our agreements. Where your Information is no longer required for these purposes, we will erase it or irreversibly anonymise it. Following deletion of your account, we will erase your Information in accordance with Section 2 of this Policy, save where a longer period is required or permitted under applicable Data Protection Laws.

12.2

You can exercise your right at any time to delete any Information that you have provided to us by writing to us at support@boltic.io or DPO@gofynd.com Upon receipt of such request, your Information will be securely erased within a period of 45 (forty-five) days from the date of intimation, provided no legal or contractual obligations prevent such deletion.

10.2

Deletion requests under the following circumstances may be denied:

10.2

  • Where required by applicable government or regulatory mandates;
  • In the event of incomplete financial transactions;
  • If the request is found to be fraudulent or invalid;

13

Modification

13.1

We reserve the right to modify and/or amend this Privacy Policy at any time.

13.2

The Privacy Policy, as and when modified, shall be updated on the Platform. We encourage you to review this Privacy Policy whenever you visit our Platform to understand how your Information is used.

14

Governing Law

14.1

The terms of this Privacy Policy shall be governed and construed in accordance with the laws of India. Any dispute regarding or arising out of this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Mumbai, Maharashtra.

15

Severability

15.1

Whenever possible, each section of this Privacy Policy shall be interpreted in a manner so as to be valid under applicable law. However, in the event any provision is held to be prohibited or invalid, such provision shall be ineffective only to the extent of such prohibition or invalidity, without invalidating the remainder of such provision or other remaining provisions of this Privacy Policy.

16

Redressal Mechanism

16.1

In case, you have any questions, grievance or complaints about this Privacy Policy, or the Platform, you may contact our grievance officer on the below mentioned details:

0

Name: Ms Shivani Kawale
Designation: Grievance Officer
Email Address: shivanikawale@gofynd.com
Registered Office: Shopsense Retail Technologies Limited
1st Floor, Wework Vijay Diamond, Opp. SBI Branch, Cross Road B,
Ajit Nagar, Kondivita, Andheri East, Mumbai 400093

16.2

15.1 Further, in case of any privacy related issue you can write to us at DPO@gofynd.com

16.3

Further, if you wish to raise a formal complaint, you may contact India’s Data Protection Board/Data Privacy Board of India, as per applicable law.

16.4

We will acknowledge and respond to any grievance received under this Section within the period prescribed under applicable Data Protection Laws, and in any event without undue delay. You may approach the Data Protection Board of India only after you have exhausted the opportunity of redressal through the Grievance Officer named above.

Supplement A – United States (California and other State Privacy Laws)

1.

This Supplement applies to Users who are residents of the State of California and, to the extent applicable, other United States with comprehensive consumer privacy laws. It supplements, and prevails over, the main body of this Privacy Policy to the extent of any inconsistency for such Users.

2.

No Sale or Sharing. No sale or sharing of personal information: We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising, in each case as those terms are defined under the California Consumer Privacy Act, 2018 as amended by the California Privacy Rights Act (collectively, “CCPA”).

3.

Your California Rights. Subject to the CCPA, you have the right to: (i) know and access the categories and specific pieces of personal information we have collected about you; (ii) request deletion of your personal information; (iii) request correction of inaccurate personal information; (iv) opt out of any sale or sharing of personal information; (v) limit the use and disclosure of sensitive personal information; and (vi) not be subject to discrimination for exercising these rights.

4.

Categories and Disclosures. The categories of personal information we collect, the purposes of collection, and the categories of recipients are set out in the tables in the main body of this Privacy Policy. We disclose personal information to service providers (such as payment gateways, hosting, and analytics providers) solely for the business purposes described therein.

5.

Exercising Your Rights. To exercise your rights, you or your authorised agent may contact us at DPO@gofynd.com. We will verify your request and respond within 45 (forty-five) days, extendable by a further 45 (forty-five) days were reasonably necessary, with notice to you.

Supplement B – European Economic Area and United Kingdom

1.

This Supplement applies to Users located in the European Economic Area (“EEA”) and the United Kingdom (“UK”) and supplements the main body of this Privacy Policy. For the purposes of the EU General Data Protection Regulation (“EU GDPR”) and the UK GDPR, we act as a controller in respect of the account and transactional Information we collect about you, and as a processor in respect of the media content and files you upload for processing through the Services, which we process on your instructions.

2.

The lawful bases on which we process your Information are set out in the “Legal Bases for Processing” section above. The rights set out in the “Your Rights in Relation to Your Information” section above are available to you in accordance with the EU GDPR and the UK GDPR.

3.

Supervisory Authority. You have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO). In the EEA, you may complain to the supervisory authority of the Member State of your habitual residence, place of work, or place of the alleged infringement.

4.

If you have any questions or concerns about this Privacy Policy or our data practices, you can contact us at DPO@gofynd.com. We will respond to your query in accordance with applicable data protection laws.

5.

Cookies. Where we rely on your consent for non-essential cookies and similar technologies, we obtain such consent through a consent-management mechanism presented to you before those technologies are deployed. You may withdraw or change your cookie preferences at any time through that mechanism.

Create the automation that drives valuable insights

Create the automation that drives valuable insights