PRIVACY POLICY





Last updated 12-Aug-2024



PREAMBLE



Welcome to Carufus's Privacy Policy (hereinafter referred to as "We," "Us," "Company," or “Platform”). We are dedicated to respecting and protecting your personal data. This policy outlines how we collect, process, and secure personal data, including data obtained from Google APIs, in accordance with the Google API Services User Data Policy, including the Limited Use requirements,


Your privacy is critically important to us. We have a few fundamental principles:

  1. We do not ask you for personal information unless we truly need it.
  2. We do not share your personal information with anyone except to comply with the law or protect our rights.
  3. We do not store personal information on our servers unless required for the ongoing operation of one of our services.

In this privacy policy, we would like to explain why you can trust us with your data and rest assured that your data is safe. It is important that you read this privacy policy together with any other privacy policy we may provide on specific occasions when we are collecting or processing your data about you so that you are fully aware of how and why we are using your data.


This policy becomes effective as of the moment you join our platform, which we'll refer to as the ("Effective Date") and accept the terms and conditions laid out on the site. We may alter this Privacy Policy as needed for certain products and services and abide by local laws or regulations around the world, such as by providing supplemental information in certain countries.



CONSEQUENCES OF NOT PROVIDING PERSONAL INFORMATION



If you choose not to provide the Personal Information required to process your request, we may not be able to fulfil the relevant purpose of processing, including providing any services to you, if applicable.



PERSONAL INFORMATION THAT WE PROCESS AND USE



Personal Information that we process



We may collect the following categories of Personal Information:

  1. Information collected as part of your visit and usage of our websites, such as Internet Protocol (IP) address, demographics, your computer’s operating system, device information, telemetry data and browser type and information collected via cookies or similar tracking technologies. As a website visitor who merely browses our websites (including the hosted content), without submitting any additional data, this is the most relevant paragraph for applicable data processing.
  2. Personal and Contact details, such as Name, title, e-mail address, phone number, address, designation, Company/Organization, Industry, Location (in terms of City/Country), LinkedIn profiles/URLs (or similar professional data set).
  3. Login credentials, such as Username and Passwords, when you register for any of our applicable services.
  4. Audio-visual information such as photographs or images captured, video recordings (if enabled), and other recordings made during our events, webinars, etc.
  5. Queries, comments, or feedback as submitted by you, including any correspondence you have made with us.
  6. Preferences relating to marketing communications, interest areas, subscription details, dietary preferences/allergies (in relation to events we may organize).
  7. Additionally, we may collect certain data points based on the categories of data subjects and their relationship with us, as detailed in additional Privacy Statements for relevant categories of data subjects at the end of this Statement.


Sources of Personal Information



We may collect the aforementioned Personal Information through various sources, such as mentioned below:

  1. Submitted by yourself, through our Website forms, applications on our portals, or by contacting/emailing our official contacts.
  2. Shared to Carufus employees, such as our sales or marketing representatives.
  3. Shared with or by Carufus’ affiliates.
  4. Shared by the employers of the visitors and contractors, where applicable.
  5. Sourced from public websites and social media, including your publicly accessible profiles.
  6. Shared by our suppliers, vendors and service providers.
  7. Sourced via Cookies and similar tracking technologies as deployed on our website (details are available in the Cookie Policy).


Use of your Personal Information



We may use your Personal Information for the following purposes:

  1. to provide better usability, troubleshooting and site maintenance
  2. to understand which parts of the website are visited and how frequently
  3. to create your login credentials, where applicable
  4. to identify you once you register on our website
  5. to facilitate communication with you, including contacting you and responding to your queries or requests
  6. to offer curated content tailored to your preferences
  7. To enable marketing and sales-related communications and related purposes
  8. to provide access to podcasts available on our website(s)
  9. to know your interest of participating in ideations or other competitions
  10. as a participant of any competitions and/or award ceremonies organized by us, to publish your name and corresponding details to make them available to larger audience on the Internet (including details of awards won); for the jury members and other associated delegates and speakers, to publish their name, title, photograph, and bio in a similar manner
  11. to invite you for events, seminars and equivalent ceremonies organized by us and related purposes such as running marketing or promotional campaigns, including such promotions or publications on social media
  12. to publish testimonials and case studies
  13. to generate and maintain leads as part of our Customer Relationship Management database
  14. to perform data analytics to provide a better user experience, enhance website performance and achieve business objectives
  15. to enhance and optimize our business operations, applications, systems, and processes, including operation and management of our communication assets and systems, ensuring and strengthening information security, maintenance of audit trail and associated records,
  16. to protect your data and Carufus assets from information security threats and to secure against any unauthorized access, disclosure, alteration, or destruction
  17. to comply with applicable laws and other legal requirements, such as regulatory filings, record-keeping and reporting obligations, cooperating with government-authorized inspections or requests, protecting our legal rights, and seeking remedies, including defending against any claims or engaging in legal proceedings, responding to subpoenas or court orders and managing documentation for related purposes
  18. to enhance your website experience and other associated purposes by deploying cookies or similar technologies. These may serve different purposes. For example, some of the cookies may be necessary for the operation of the website, while others are used to ensure its seamless performance. They may also enhance the functionalities provided on our website, help us understand how our online services are used, or determine the interests of our website visitors. Additionally, our advertising partners collaborate with us to provide and assist in the use of such technologies on Carufus and other sites.


Legal basis of the processing



The applicable privacy and data protection laws provide for certain justifiable grounds for the collection and processing of personal data, commonly referred to as the legal basis of processing. We primarily rely on the following legal bases:

  1. We process your Personal Information when it is necessary for the performance of a contract to which you are a party or to take steps at your request prior to entering into a contract, e.g., when you engage with us to receive our services and offerings or when managing the data of our employees to ensure the performance of their employment contract.
  2. We process your Personal Information when it is necessary for the purposes of a legitimate interest pursued by us or a third party (when these interests are not overridden by your data protection rights), e.g., when we need to understand your usage of our website and interaction with the same, for generating your secure login credentials, or to optimize our processes.
  3. We process your Personal Information with your consent. Where we process Personal Data based on consent, your consent is revocable at any time, e.g., when registering and inviting you to events organized by us or for sharing our marketing-related communications with you.
  4. We may process your personal Information to comply with our Legal obligations, including applicable laws, protect our legal rights, seek remedies, and defend against claims.


DATA RECIPIENTS, TRANSFER, AND DISCLOSURE OF PERSONAL INFORMATION



  1. We do not share your Personal Information with third parties for their direct marketing purposes.
    We share your Personal Information within
    1. Carufus or with any of its subsidiaries;
    2. Business partners;
    3. Service providers;
    4. Authorized third-party agents or
    5. Auditors and/or government authorities, where applicable.
  2. Facilitating International Data Transfers:


YOUR RIGHTS:



Your rights may differ depending on applicable data protection local laws. We respect your right to be informed, access, correct, request deletion or request restriction, portability, objection, and rights in relation to automated decision-making and profiling in our usage of your personal information as may be required under applicable law. We also take steps to ensure that the personal information we collect is accurate and up to date. Subject to such laws, you may have the following rights:

  1. You have the right to know what personal information we maintain about you
  2. We will provide you with a copy of your personal information in a structured, commonly used and machine-readable format on request
  3. If your personal information is incorrect or incomplete, you have the right to ask us to update it
  4. You have the right to object to our processing of your personal information
  5. You can also ask us to delete or restrict how we use your personal information, but this right is determined by applicable law and may impact your access to some of our services
  6. You can have the right to access your personal information
  7. You have a right to object to the processing of your personal information where it is so conducted by automated means and involves any kind of decision-making
  8. Further, you have the option to file a complaint for suspected or actual violations of your data protection rights with the relevant supervisory authority if you are from EEA.
  9. Please note: You will also not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.


PROCESSING OF PERSONAL INFORMATION IN EU/EEA REGIONS



For the purposes of processing your Personal Information within the EU/ EEA Regions, we will follow the Data Privacy Principles and regulations of the General Data Protection Regulation (commonly known as 'GDPR’). Please note that the following provisions will apply to you if you are a Data Subject (resident or citizen) within the EU/EEA region, in addition to Carufus Global Privacy Statement.


Cross-Border Transfer of Data

  1. In general, Carufus Limited, domiciled in Bangalore, is the data controller processing your personal information. We may transfer your personal data outside the EU/EEA region to third parties, including countries where the data protection legislation may differ from that of the EU/ EEA region.
  2. As per the obligation called out under the GDPR, when we process your Personal Information in countries deemed adequate by the European Commission, we will rely on the European Commission's decision to protect your Personal Information
  3. For transfers to Carufus group companies and service providers outside the EEA, where Adequacy decision is not available, we use standard contractual clauses or rely on a service provider's (EU data protection authority approved) corporate rules that are in place to protect your Personal Information. Additionally, we shall take all the necessary steps to ensure confidentiality and security of the transferred data

Your Data Subject Rights in EU/EEA

  1. As a Data Subject located in EU/EEA, you are entitled to the following rights:
  2. Right to be informed when personal data has been obtained from the data subject, where applicable.
  3. Right to access the personal information that we collect about you.
  4. Right to rectify the inaccurate personal data that we hold about you.
  5. Right to request erasure of your personal data, where applicable.
  6. Right to object to the processing of your personal data, where applicable.
  7. Right to data portability, i.e. to request your personal data to be transferred to a third party, where applicable.
  8. Right to be informed before being made a part of automated decision making, where applicable.
  9. Right to obtain restriction of processing from the controller, where applicable.
  10. If you are an EU/EEA resident and you wish to exercise your data subject rights as called out above, please refer to section on exercising ‘Your Rights’ in the Carufus Global Privacy Statement.


RIGHT TO OPT-OUT



  1. Carafus respects your privacy considerations and hence provides an option to you, to not provide the data or information sought to be collected.
  2. Further, you can also withdraw your consent, which was earlier given to Carafus (which shall not affect the lawfulness of processing based on consent before its withdrawal), and the same must be communicated to Carufus in writing. Please note you can always unsubscribe to the marketing communication by clicking unsubscribe available in the marketing communication(s) you receive.


BREACH OF PERSONAL INFORMATION



As a software company, we implement appropriate measures to uphold the security of Personal Information collected from our clients. In the event of a security breach, we are committed to promptly addressing the situation. If such a breach results in an unauthorized intrusion into our system, significantly impacting a client, we will make efforts to notify the affected client at the earliest possible instance. Additionally, we will report the actions taken in response to the breach as necessary or required by Applicable Laws, Rules, and Regulations.



POLICY FOR CHILDREN



We do not knowingly solicit information from or market to children under the age of 18. If we learn that we have collected personal information from a child under 18 without parental consent, we will delete that information as quickly as possible



DATA RETENTION AND ERASURE



  1. We are dedicated to retaining your personal data only for the necessary duration to fulfil the specified purposes outlined in this notice and as required or permitted by applicable law.
  2. We will cease to retain personal data or anonymize it when it is reasonable to believe that the purpose for which it was collected is no longer served, and retention is no longer necessary for legal or business requirements.
  3. For legal and business purposes, we maintain copies of customer contracts, information for identification verification checks, and records related to financial crime and anti-money laundering checks, as mandated by law, for up to 3 years after the termination or expiration of our contract with you. Additionally, we retain records such as electronic communications, face-to-face meeting minutes, suitability and appropriateness assessments, periodic statements, and details of orders and transactions in financial instruments on your behalf for a period of 3 years from the date of receipt.
  4. Data received from Google APIs is retained only temporarily to provide the service requested and is then deleted within 180 days unless a longer retention period is required or permitted by law.


COMPLAINTS



If you have a complaint regarding how we manage your personal data, please reach out to our data protection officer using the provided contact information. We encourage you to submit your complaint in writing, offering specific details about your concern. This information will enable our data protection officer to conduct a thorough investigation. Appropriate actions will be taken in response to your complaint, which may involve internal discussions with relevant business representatives. We may get in touch with you for further details or clarification. Rest assured, we will communicate our response to your complaint.



CHANGES TO THIS PRIVACY POLICY



  1. We reserve the right to update this Privacy Policy periodically. The latest version will be posted on our website, and any significant changes will be communicated to you.
  2. By using our website, you acknowledge and agree to the terms of this Privacy Policy. Thank you for trusting us with your personal information as we work towards democratizing finance and unlocking every individual's potential.
  3. Significant changes will also be communicated to users via their registered email address and will require re-consent where applicable, especially concerning the use of Google user data.


OUR CONTACT DETAILS



  1. We understand that privacy and data protection are important to you, and we are here to answer any questions or address any concerns you may have about this Privacy Policy or how we handle your personal data. Here are the ways you can reach us:
    Email: For direct communication, please email us at info@carufus.com. We aim to respond to all email inquiries within 72 hours
  2. By using Carufus, you acknowledge and consent to our collection, storage, use, and disclosure of your information as described in this Privacy Policy. We are committed to protecting your privacy and ensuring that your personal data is handled in accordance with the best practices and applicable laws.
  3. By proceeding with the use of our services and agreeing to our policies, you acknowledge and confirm that you are 18 years of age or older. This requirement is in place to ensure compliance with applicable laws and regulations regarding the use of our services by minors. By agreeing to our policies, you represent and warrant that you meet the minimum age requirement.
  4. Your trust is important to us, and we encourage you to contact us if you need any clarification regarding your data or wish to discuss your privacy rights. Our team is dedicated to providing you with the support and information you need to feel secure and informed about your data privacy when using Carufus.