Privacy Policy
Introduction
By using CoFee, you agree to the terms outlined in this Privacy Policy. If you do not agree with these terms, we kindly recommend refraining from using our services.
Applicability
Depending on the service model, we may collect personal data:
- As part of onboarding KYC process
- As part of services provided to Customers using CoFee for fee collection
Information We Collect
Mandatory Data
- Full Name
- Contact Number (mobile)
- Address
- EmailID
- Bank Account Number & IFSC
- PAN (Permanent Account Number)
- GSTIN (if applicable)
- KYC and KYB Documents (including but not limited to documents such as AADHAAR, PAN, Business Licence, GST certificate required for KYC (Know Your Customer) and KYB (Know Your Business))
Optional Data
- Institution Website, if any
- Additional self declarations as applicable for KYB
How We Use Personal Information
We use personal data only for legitimate business purposes, including:
- Verifying identity and compliance (e.g., KYC, KYB, PAN and Bank Account validation)
- Setting up payment configuration
- Responding to support requests and service inquiries
- Delivering personalized experiences, analytics and communications
- Complying with financial and legal regulations
- Improving platform security and performance
Information Sharing
We do not sell your personal information. We may share your personal data only to the extent necessary to provide you the service and in accordance with applicable law in the following circumstances:
-
Service Providers
We may share personal data with third-party service providers who support our operations (such as hosting providers, cloud service providers, and payment gateways), strictly on a need-to-know basis and subject to contractual confidentiality and data protection obligations. -
Business Entity
Where your use of CoFee is facilitated, sponsored, or managed by a business entity (such as an educational institution or enterprise), your personal data may be shared with or made accessible to such entity in accordance with the applicable contractual arrangements, user permissions, and the agreed scope of us -
Legal Compliance
We may disclose personal data where required to comply with applicable laws, regulations, court orders, governmental or regulatory requests, or where such disclosure is necessary to enforce our rights, investigate or prevent fraud or security issues, or protect the rights, property, or safety of CoFee, our users, or others.
Data Security
We implement industry-standard technical and organizational measures to safeguard personal data, including:
- Encryption of data in transit (TLS) and at rest (AES)
- Role-based access controls (RBAC) and secure login mechanisms
- Multi-factor authentication for privileged users
- Application-layer firewalls and DDoS protection
- Periodic vulnerability scans and patch management
- Secure software development lifecycle (SSDLC) practices
- Data masking and tokenization for sensitive fields
- Regular security training for employees
- Incident response and escalation procedures
- Separation of production, development, and test environments
- Audit logging and security monitoring
Data Retention
- For the purposes for which it was collected
- To comply with legal, regulatory, or contractual obligations
Your Rights
- Right to Access: Obtain confirmation and a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data, subject to applicable laws, statutory or regulatory retention requirements, court orders, and lawful directions of competent authorities, and to the extent such data is required for compliance, dispute resolution, or enforcement of legal rights.
- Right to Restrict Processing: Limit how your data is used
- Right to Object: Object to data use based on legitimate interest
If your data was submitted to CoFee by any Business entity, please reach out to that entity directly.
Cookies and Tracking Technologies
The CoFee website and app may use cookies or similar tools to:
- Recognize returning users
- Track usage trends for optimization
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, regulatory requirements, or business operations. Any updates will be posted on this page with a revised “Last Updated” date and shall become effective upon publication, unless otherwise required by applicable law. Continued use of the Services after such updates constitutes acceptance of the revised Privacy Policy.
International Data Transfers
We may transfer personal data across borders, including to countries where data protection laws may differ from those in your jurisdiction. To ensure an adequate level of protection, we implement appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) or similar legal mechanisms.
- Vendor contracts and periodic assessments to validate compliance with privacy standards.
Children’s Privacy
Where personal data of a child has been provided by misrepresenting that such individual is above the age of 16, and CoFee has implemented reasonable measures to prevent such access and is unable to identify such misrepresentation at the time of collection, CoFee shall not be responsible or liable for such collection, processing, or use of the data prior to such discovery.
Contact Us
CoFee Fintech Pvt. Ltd.
Door No. XXIV/527, Meda Commercial Hub, Near T.V Station, Seaport-Airport Road, CSEZ P.O, Kakkanad, Ernakulam, Kerala, India, 682037
Email: privacy@cofee.life
If you wish to report a data breach or exercise your data protection rights, please contact our Data Protection Officer (DPO) using the same email address.