Privacy Policy
Introduction
By using CoFee, you agree to the terms outlined in this Privacy Policy. If you do not agree with these terms, we kindly recommend refraining from using our services.
Applicability
Depending on the service model, we may collect personal data:
- Directly from users (e.g., self-onboarding)
- As part of services provided to institutions or businesses using CoFee for onboarding
Information We Collect
Mandatory Data
- Full Name
- Contact Number (mobile)
- Bank Account Number & IFSC
- PAN (Permanent Account Number)
- GSTIN (if applicable)
- KYC Documents (Aadhaar, PAN, etc.)
Optional Data
- Date of Birth (DOB)
- Residential Address
How We Use Personal Information
We use personal data only for legitimate business purposes, including:
- Verifying identity and compliance (e.g., KYC, PAN validation)
- Setting up payment configuration
- Responding to support requests and service inquiries
- Delivering personalized experiences and communications
- Complying with financial and legal regulations
- Improving platform security and performance
Information Sharing
We do not sell your personal information. We may share it only in the following situations:
-
Service Providers
Third-party vendors that support our operations (e.g., hosting providers, payment gateways, etc) may access data under strict confidentiality agreements. -
Client Organizations
If your use of CoFee is managed by an institution, your data may be visible to them based on the agreed usage (e.g., student onboarding by a university). -
Legal Compliance
We may disclose information if required to comply with applicable laws, regulations, court orders, or government requests.
Data Security
We implement industry-standard technical and organizational measures to safeguard personal data, including:
- Encryption of data in transit (TLS) and at rest (AES)
- Role-based access controls (RBAC) and secure login mechanisms
- Multi-factor authentication for privileged users
- Application-layer firewalls and DDoS protection
- Periodic vulnerability scans and patch management
- Secure software development lifecycle (SSDLC) practices
- Data masking and tokenization for sensitive fields
- Regular security training for employees
- Incident response and escalation procedures
- Separation of production, development, and test environments
- Audit logging and security monitoring
Data Retention
- For the purposes for which it was collected
- To comply with legal, regulatory, or contractual obligations
Your Rights
- Right to Access: Obtain confirmation and a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion when data is necessary
- Right to Restrict Processing: Limit how your data is used
- Right to Object: Object to data use based on legitimate interest
If your data was submitted to CoFee by an organization, please reach out to that entity directly.
Cookies and Tracking Technologies
The CoFee website and app may use cookies or similar tools to:
- Recognize returning users
- Track usage trends for optimization
Changes to This Privacy Policy
We may update this policy periodically. Updates will be posted on this page with a revised "Last Updated" date.
International Data Transfers
We may transfer personal data across borders, including to countries where data protection laws may differ from those in your jurisdiction. To ensure an adequate level of protection, we implement appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) or similar legal mechanisms.
- Vendor contracts and periodic assessments to validate compliance with privacy standards.
Children’s Privacy
Contact Us
KeyValue Software Systems Pvt. Ltd.
C113, 1st Floor, Building SCK-01, SmartCity Rd, Kochi,
Kerala, India - 682042
Email: privacy@keyvalue.systems
If you wish to report a data breach or exercise your data protection rights, please contact our Data Protection Officer (DPO) using the same email address.