Icon

Privacy Policy

Habsy Privacy Policy

Habsy Inc. (“Habsy,” “we,” “us,” “our”) provides habsy.ai, an AI-powered intelligent business card manager that helps professionals capture, organize, and enrich contacts using artificial intelligence, machine learning, and computer vision. We are committed to protecting the privacy and security of personal information processed through our services.
This Privacy Policy explains what personal information we collect, how we use it, how we share it, how we protect it, and what choices and rights you have when you:
● Visit our website (https://habsy.ai/)
● Use the Habsy Business Card Manager mobile or desktop app (“App”)
● Access related tools, APIs, or web interfaces
● Interact with our sales, support, or marketing teams
Together, these are referred to as the “Service.”
By installing the App, creating an account, or using the Service, you acknowledge that you have read and understood this Privacy Policy and, where required by law, consent to our processing of your personal information as described here. If you do not agree, please do not install the App, create an account, or use the Service.

Icon

Last Updated: August 8, 2026

1. Who We Are

Habsy Technologies Private Limited (“HTPL,” “we,” “us,” “our”) is a private limited company incorporated in India and headquartered in India. HTPL manages and performs the Service's operations and data processing, including hosting, engineering, customer support, and the processing of personal information described in this Policy.

Habsy Inc. is a registered entity incorporated in Canada.

The registered office addresses of both entities are provided in Section 18 (How to Contact Us).

In this Privacy Policy, “Habsy,” “we,” “us,” and “our” refer to HTPL, except where this Policy specifically distinguishes Habsy Inc.'s role, as it does in Section 1.1 below.

This Privacy Policy explains what personal information we collect, how we use it, how we share it, how we protect it, and what choices and rights you have when you visit our website (https://habsy.ai/), use the Habsy mobile or desktop application (the “App”) available on the Apple App Store and Google Play, access related tools, APIs, or web interfaces, or interact with our sales, support, or marketing teams. Together, these are referred to as the “Service.”

By installing the App, creating an account, or using the Service, you acknowledge that you have read and understood this Privacy Policy and, where required by law, consent to our processing of your personal information as described here.

1.1 Controller and Processor Roles
In this Section and throughout this Policy, the “Customer” means the individual user who creates an account and captures, uploads, or imports Contact Data through the Service or, where the Service is used on behalf of a company or other organization, that organization. Where this Policy says “you as the Customer,” it means that individual user or that organization, and not HTPL.

When the Customer uses the Service to capture, scan, import, or enrich Contact Data (including business card scans, event badge scans, QR/badge captures, manually entered contacts, notes, and voice memos), Habsy Technologies Private Limited (HTPL) acts solely as a Data Processor (or “service provider”). The Customer is the Data Controller of that Contact Data (the “business” under the CCPA/CPRA, and the “Data Fiduciary” under the DPDPA).

As the Data Controller of Contact Data, you as the Customer, or the organization on whose behalf you act, are responsible for and warrant that:

• You as the Customer have a lawful basis under every applicable law (GDPR Art. 6, PIPEDA meaningful consent, DPDPA S.6, CCPA notice at collection) for each contact record you capture, upload, import, or enrich through the Service, and where required, you have obtained appropriate consent from the individuals whose information you process.
• You as the Customer are responsible for any outreach you send or authorize through the Service, including courtesy notices, email, SMS, WhatsApp, and any other channel, and for complying with applicable electronic-communications and anti-spam laws (Canada CASL, US CAN-SPAM, EU ePrivacy, TCPA, DPDPA notice requirements, and equivalent).
• You as the Customer will respond to data-subject requests (access, correction, deletion, objection, portability, opt-out of sale or sharing) directed to you as Data Controller, and you will use the tools HTPL provides to give effect to those requests within the timelines the applicable law imposes on you.
• You as the Customer will maintain your own Record of Processing Activities to the extent applicable law requires it of Controllers.
• You as the Customer will not use the Service to process categories of data for which the Service is not designed or contracted (special-category data under GDPR Art. 9, health data, financial account data beyond payment for the Service, children's data, or any data whose processing would require a lawful basis or safeguard you have not established).
• You as the Customer will indemnify HTPL and Habsy Inc. for claims arising from your failure to meet these Controller obligations, on the terms set out in the Terms of Service and any applicable DPA.

These responsibilities rest with the Customer as Data Controller regardless of the technical means by which the Customer interacts with the Service.

HTPL stores and processes Contact Data solely on the Customer's documented instructions as Data Controller, for the purposes the Customer configures through the Service and as further set out in any applicable Data Processing Addendum. HTPL processes Contact Data to provide and improve the Service, including service operation, security, abuse prevention, performance measurement, and the notification and profile features described in this Policy, and otherwise on the Customer's documented instructions. HTPL provides tools to support the Customer's GDPR, PIPEDA, DPDPA, and CCPA/CPRA compliant handling of Contact Data, including the ability to discard captured Contact Data where consent has not been obtained or has been withdrawn.

For personal information HTPL collects directly about you as its own account holder or website visitor, for example Account and Profile Information (Section 4.1), Communication and Interaction Data (Section 4.7), Transaction and Subscription Data (Section 4.8), Diagnostic, Security, and Audit Data (Section 4.10), and Cookies and Tracking Technologies (Section 4.11), HTPL acts as the Data Controller (the “business” under the CCPA/CPRA, and the “Data Fiduciary” under the DPDPA) and determines the purposes and means of that processing.

Where HTPL acts as a Processor to the Customer, that processing is governed by the Terms of Service, this Policy, and any applicable Data Processing Addendum (DPA) executed between Habsy and the Customer.

habsy.ai is a cloud-based SaaS platform that securely processes and manages professional contact information for individual users and enterprise customers.

2.1 Business Card Capture, Event Lead Capture, and Digitization
• AI-powered mobile scanning for fast business card capture, including batch scanning of multiple cards at once (up to 150 cards in five minutes).
• Advanced OCR to extract key details (name, title, company, phone, email, address, social profiles, website) with real-time accuracy and an interface for manual verification.
• Event badge scanning (supports VCF and text-based badges), QR code scanning for instant digital business card sharing, and manual contact entry.
• Event lead capture with geo-tagging to associate contacts with specific events, venues, and locations (when location permission is enabled).
• Audio notes and voice capture to add context or reminders to contacts.
• Digital business card creation and sharing for contactless professional exchanges.

2.2 Person Enrichment Engine
Where the Service enriches contact records using publicly available professional information, HTPL performs enrichment as Processor on the Customer's instruction and on records the Customer has selected or authorized. The Customer is responsible for confirming that a lawful basis exists for enriching each individual's record, including where enrichment involves EU/UK/Swiss data subjects for whom the GDPR-permitted lawful bases for processing publicly available information may be narrower than in other jurisdictions. You may disable enrichment by contacting privacy@habsy.ai.

• Publicly available professional information (where permitted by law and source) may be collected to provide additional context about contacts, including public profile extraction, AI-generated professional bios, career history mapping, decision-maker identification, and professional insights.

2.3 Company Enrichment Intelligence
Where the Service enriches company profiles using publicly available company information, HTPL performs enrichment as Processor on the Customer's instruction and on company accounts the Customer has selected or authorized. You may disable company enrichment by contacting privacy@habsy.ai.

• Publicly available company information (including web presence, social channels, press mentions, and milestones) may be collected to enrich company profiles, including company overview, mission, organizational hierarchy, industry classification, office locations, and public contact details.

2.4 Contact Management and Organization
• Advanced tagging, segmentation, custom fields, multi-device synchronization (iOS, Android, web), offline access, contact notes, voice notes, reminders, follow-up scheduling, multi-language support, and user data export and deletion capabilities.

2.5 Relationship and Networking Features
• Follow-up reminders and scheduling, contact segmentation and filtering, smart outreach generation (WhatsApp, LinkedIn, email drafts), and contact export in standard formats (CSV, Excel, VCF).

2.6 Platform Integration and Portability
Integration-ready architecture for CRM and productivity tools (including Salesforce, HubSpot, and Zoho), data export in standard formats, and APIs and webhooks for enterprise workflows.

Habsy operates an Information Security Management System (ISMS) designed to align with leading security and privacy frameworks, including:

• SOC 2 Type II (AICPA Trust Services Criteria: Security, Availability, Confidentiality, Privacy)
• ISO/IEC 27001:2022 (International Standard for Information Security Management)
• PIPEDA (Canada's Personal Information Protection and Electronic Documents Act)
• GDPR and UK GDPR (EU/EEA and United Kingdom General Data Protection Regulation)
• CCPA/CPRA (California Consumer Privacy Act, as amended by the California Privacy Rights Act)
• DPDPA (India's Digital Personal Data Protection Act, 2023)

We use secure, industry-standard cloud infrastructure (see Section 8 for international data transfers) and follow best practices in access control and identity management, encryption of data in transit and at rest, network and application security, logging, monitoring, and incident response, vendor risk management, and regular security reviews with continuous compliance monitoring.

We do not publish detailed internal infrastructure or vendor lists publicly for security reasons. Enterprise customers and prospects can request detailed security and compliance information under NDA by contacting privacy@habsy.ai.

Below are the categories of personal information we collect or that you capture and upload through the Service, along with the purposes and legal bases for each.

4.1 Account and Profile Information
Data Collected: Full name; email address; encrypted password (if not using SSO); organization name; profile photo (if uploaded); account preferences (language, time zone, feature settings).
Purpose: Account creation, login, identity verification, profile setup, service delivery, security notifications, and account recovery.
Legal Basis: Contract performance.

4.2 Business Card Content and Contact Information (HTPL is Processor; the Customer is Controller)
Data Collected: Contact names; job titles; company names; phone numbers; email addresses; physical addresses; websites and social media links; QR codes and event badges; scanned business card images; contact profile photos; manual contact entries; custom labels/tags; notes, reminders, and voice memos.
Purpose: Core business card digitization and OCR extraction, contact storage and syncing, relationship tracking, reminders, voice memos, offline access, and user-initiated sharing/export.
Legal Basis: Processed on the instructions of, and under the lawful basis established by, the Customer as Data Controller of this Contact Data. HTPL processes this data solely as Data Processor, on the Customer's instructions (consent for voice memos/audio capture where required).

HTPL does not use Contact Data to train third-party artificial intelligence or machine-learning models. HTPL processes Contact Data to deliver and improve the Service, to secure the Service, to comply with legal obligations, to enforce its terms, and for the notification, profile, and communication features described in this Policy.

The Customer is responsible for ensuring a lawful basis, such as consent or legitimate interest, for collecting and processing the personal data of each individual whose information the Customer captures, scans, imports, or enriches, before adding that individual as a contact through card scanning or any other means. Where the Customer's use includes outreach or marketing, the Customer is responsible for ensuring that the applicable lawful basis extends to that outreach, including any marketing communications, in each channel the Customer uses.

4.3 Enriched Person Data (AI-Generated)
Data Collected: Public professional profile data; AI-generated professional summaries and bios; career history (titles, companies, tenure); educational background (if publicly available); professional skills and role information; public social media presence.
Purpose: Contact enrichment, networking context, decision-maker identification, and business intelligence.
Legal Basis: Processed as Processor on the Customer's instruction, as part of enrichment the Customer initiates or authorizes under Section 2.2. The Customer, as Data Controller, is responsible for the lawful basis (such as legitimate interests) for enriching the individuals concerned.

4.4 Enriched Company Data (AI-Generated)
Data Collected: Company name and description; industry classification and estimated size; office locations and public contact details; mission, vision, products/services; organizational structure and leadership; notable public information (press, milestones).
Purpose: Company intelligence and organizational context to support networking and sales insights.
Legal Basis: Processed as Processor on the Customer's instruction under Section 2.3. Where enriched company profiles contain personal information about individuals, the Customer, as Data Controller, is responsible for the lawful basis (such as legitimate interests) for that enrichment.

4.5 Device and Technical Data
Data Collected: IP address; device identifiers; device type/model, OS version, browser type; app version, screen resolution, locale/language settings; pages or screens visited, features used, time spent, navigation patterns; button clicks, search queries, export/sharing activity; approximate geolocation (when enabled).
Purpose: App functionality and compatibility, security and fraud monitoring, abuse prevention, session management, analytics, performance/error detection, personalization, and optional location-based features.
Legal Basis: Contract performance; legitimate interests (security and service improvement); consent (for location data and analytics in specific jurisdictions).

4.6 Device Permissions (With Consent)
We request the following device permissions, each revocable via your device settings at any time:

• Notifications: reminders, follow-up prompts, and essential service or security notifications.
• Camera: card, badge, and QR code scanning.
• Photo/Media Library: importing card images.
• Contacts: importing or exporting contacts.
• Microphone: voice notes and audio capture.
• Location: optional contextual/location-based features.

Legal Basis: Explicit consent (granular, per permission; revocable via device settings).

4.7 Communication and Interaction Data
Data Collected: Support emails and tickets; in-app support messages; feedback and feature requests; bug reports; email open/click rates; marketing email engagement; newsletter preferences and opt-in/opt-out history.
Purpose: Customer support and troubleshooting, service improvement, incident investigation, marketing communications (when opted-in or as otherwise permitted for existing users, with an opt-out in every message), and measuring communication effectiveness.
Legal Basis: Contract performance; legitimate interests (support and improvement); consent (for marketing where required).

4.8 Transaction and Subscription Data
Data Collected: Subscription plan details; billing address; invoices and transaction IDs; subscription status, renewal and cancellation dates.
Purpose: Billing and subscription management, payment processing, invoicing, renewal management, refunds, fraud prevention, and financial/tax compliance reporting.
Legal Basis: Contract performance; legal obligations (financial record-keeping); legitimate interests (fraud prevention).
We do not directly collect or store full payment card details. Payments are processed via PCI-DSS compliant third-party processors (e.g., Stripe). These providers handle card information on their systems and share only limited metadata with us for payment confirmation, invoicing, and subscription management.

4.9 Integration and API Data
Data Collected: Integration configuration details and authorization scopes; API tokens/keys (stored securely and encrypted); records of exported contacts to connected systems; webhook URLs and API usage logs.
Purpose: Enable CRM integrations, API-based workflows, webhooks, and data portability.
Legal Basis: Contract performance; consent (at the time of authorizing each integration).

4.10 Diagnostic, Security, and Audit Data
Data Collected: Error and crash logs; performance metrics; security event logs (logins, access changes, permission updates); API request logs and session IDs; MFA records and failed login attempts; suspicious activity alerts.
Purpose: Security and threat monitoring, incident response, fraud detection, vulnerability management, uptime monitoring, performance optimization, debugging, compliance auditing.
Legal Basis: Legitimate interests (security and reliability); legal obligations; contract performance.

4.11 Cookies and Tracking Technologies
HTPL acts as Controller for cookies and tracking technologies deployed on Habsy-operated properties (habsy.ai and the Habsy mobile applications). This Controller role is limited to Habsy properties and does not extend to Contact Data or customer-uploaded content, for which HTPL remains Processor as described in Section 1.1.

We use cookies and similar tracking technologies for session management and authentication, remembering preferences, analytics and product improvement, and measuring marketing performance. Where required by law (e.g., in the EU/UK), we present a cookie banner to obtain consent for non-essential cookies. You can manage preferences via our cookie controls or your browser settings.

Legal Basis: Contract performance (essential cookies); legitimate interests (improvement and security); consent (analytics/marketing cookies where required).

4.12 Data We Do Not Intentionally Collect
We do not intentionally collect or require: full credit card numbers or CVV codes, government-issued ID numbers (SIN, SSN, passport), medical or health information, biometric identifiers, data about children (individuals under 18), or precise background geolocation tracking without explicit opt-in. If you believe you have accidentally provided such information, please contact privacy@habsy.ai so we can delete or anonymize it.

4.13 Notification and Profile Data.
Where the Service notifies an individual that their information has been captured, HTPL processes that individual's contact details, notification and response status, privacy choices, and related interaction records to deliver the notification and honor the individual's choices. The notification informs the individual that a digital profile may be created and gives them the opportunity to opt out. If the individual does not opt out within the period stated in the notification, a digital profile may be published; the individual may still request removal, a change to stored information, or a change to storage location at any time through the notification or by contacting privacy@habsy.ai.

We process personal information to provide and operate the habsy.ai Service; enable AI-powered OCR and enrichment features; secure and protect user accounts and our platform; support and communicate with you; improve and innovate our product; and meet legal, regulatory, and contractual obligations. This includes operating notification and profile features that inform individuals when their information has been captured through the Service and provide them with privacy choices and controls, and sending service, marketing, and promotional communications to our users, from which they may opt out at any time, in each case consistent with Section 1.1 and applicable law.

We do not use your business card or contact data to build advertising profiles for third parties, and we do not sell personal information. We do not share personal information for cross-context behavioral advertising. We will not use your data for materially different purposes without explaining the new purpose and, where required, obtaining your consent.

We use artificial intelligence, machine learning, and computer vision technologies to recognize and extract text from business card images and event badges; normalize and structure contact and company information; enrich contacts with publicly available data; and generate summaries and contextual information to help you understand and prioritize relationships.

We design these systems with privacy and security controls. As disclosed on our AI Transparency page (habsy.ai/ai-transparency), we use third-party AI services, including OpenAI, for assistance features such as drafting, summarization, content improvement, and email template generation. AI-generated outputs are presented as suggestions for you to review, modify, or discard before use. We do not use your Contact Data to train third-party artificial intelligence or machine-learning models. Customer input data, and its association with specific enrichment results, are treated as confidential.

AI-generated and enriched information may occasionally be incomplete, outdated, or inaccurate. These features are intended to assist you and should be used in combination with your own judgment.

We do not sell your personal information. We share personal data only in the following limited circumstances.

Service Providers
Where HTPL engages third parties as Subprocessors for Contact Data, HTPL flows down the Processor obligations under this Policy and the applicable DPA, including confidentiality, security, purpose limitation, deletion or return, and audit rights, consistent with GDPR Art. 28(4), DPDPA S.9, and CCPA §1798.140(ag) service-provider requirements. We engage carefully vetted third-party service providers to help operate the Service (cloud hosting, analytics, payment processing, email delivery, customer support, and compliance services). All providers are bound by confidentiality and data protection obligations and may only process personal information on our instructions. HTPL's processing of Contact Data as the Customer's Processor, described in Section 1.1, is the core Service relationship and is not a third-party disclosure. Enterprise customers may request a detailed subprocessor list under NDA by contacting privacy@habsy.ai.

AI and LLM Providers
Portions of the data we process may be sent to third-party AI and LLM providers for OCR, classification, extraction, and enrichment purposes. We select providers that offer appropriate data protection commitments and, where available, use configurations that prevent our data from being used to train their general-purpose models.

Legal, Security, and Protection of Rights
We may disclose personal information to comply with applicable laws, regulations, or legal processes; respond to lawful requests from public authorities; enforce our agreements and terms; protect the rights, property, or safety of HTPL, Habsy Inc., our users, or others; and detect, investigate, or prevent fraud, security incidents, or abuse.

Business Transfers
In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets involving HTPL or Habsy Inc., personal information may be transferred as part of the transaction, subject to customary confidentiality commitments and continued protection consistent with this Privacy Policy.

We do not sell your personal information. We share personal data only in the following limited circumstances.

Service Providers
Where HTPL engages third parties as Subprocessors for Contact Data, HTPL flows down the Processor obligations under this Policy and the applicable DPA, including confidentiality, security, purpose limitation, deletion or return, and audit rights, consistent with GDPR Art. 28(4), DPDPA S.9, and CCPA §1798.140(ag) service-provider requirements. We engage carefully vetted third-party service providers to help operate the Service (cloud hosting, analytics, payment processing, email delivery, customer support, and compliance services). All providers are bound by confidentiality and data protection obligations and may only process personal information on our instructions. HTPL's processing of Contact Data as the Customer's Processor, described in Section 1.1, is the core Service relationship and is not a third-party disclosure. Enterprise customers may request a detailed subprocessor list under NDA by contacting privacy@habsy.ai.

AI and LLM Providers
Portions of the data we process may be sent to third-party AI and LLM providers for OCR, classification, extraction, and enrichment purposes. We select providers that offer appropriate data protection commitments and, where available, use configurations that prevent our data from being used to train their general-purpose models.

Legal, Security, and Protection of Rights
We may disclose personal information to comply with applicable laws, regulations, or legal processes; respond to lawful requests from public authorities; enforce our agreements and terms; protect the rights, property, or safety of HTPL, Habsy Inc., our users, or others; and detect, investigate, or prevent fraud, security incidents, or abuse.

Business Transfers
In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets involving HTPL or Habsy Inc., personal information may be transferred as part of the transaction, subject to customary confidentiality commitments and continued protection consistent with this Privacy Policy.

9. Security Measures

The Service is operated on secure cloud infrastructure. We apply industry-standard controls including encryption in transit and at rest, multi-factor authentication, least-privilege role-based access, logging and monitoring, vulnerability management, and secure change management.

We apply organizational, technical, and physical safeguards to protect personal information, including:

Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256).
Access Controls: Role-based access control (RBAC) with least privilege; multi-factor authentication (MFA) for all internal systems handling personal information; regular access reviews and rapid revocation on role change or departure.
Monitoring: Security event logging, continuous monitoring with alerting for suspicious activities, and comprehensive audit trails.
Incident Response: Documented incident response plan covering detection, containment, investigation, notification (including GDPR's 72-hour breach notification and PIPEDA's “as soon as feasible” requirement), and post-incident review.
Privacy by Design: Data Protection Impact Assessments (DPIAs) conducted when required; data minimization practices throughout the development lifecycle.
Training: Regular privacy and security training for all staff, with enhanced training for engineering and operations teams.

We align our security program with SOC 2 Type II and ISO/IEC 27001:2022 standards. While no system can be guaranteed 100% secure, we continuously monitor and strengthen our security posture.

Account and profile data: Retained while your account is active and for a reasonable period after closure, unless a longer period is required by law.
Business card images and contact data: Retention decisions for Contact Data sit with the Customer as Data Controller. HTPL retains Contact Data per the Customer's configuration and instructions, until the Customer deletes it or closes the account, or as legally required. Where an individual whose information is stored requests deletion, HTPL will delete or de-identify that individual's Contact Data, or route the request to the relevant Customer, in accordance with applicable law. After deletion or account closure,
Security and diagnostic logs: Retained for approximately ninety (90) days, or as required by law, then deleted or aggregated.
Backups: Retained per our backup and disaster recovery policies and not used for day-to-day processing except for recovery purposes.

We may retain aggregated or de-identified information (which cannot reasonably be linked back to an individual) indefinitely for analytics, research, or product improvement purposes.

11. Your Rights and Choices

Your privacy rights depend on your jurisdiction, but we aim to respect core privacy rights for all users. If HTPL processes your personal information as the Customer's Processor, we may redirect your request to the relevant Customer as Data Controller and will assist that Customer in responding, consistent with applicable law.

11.1 Access, Correction, Deletion, Restriction
You may have the right to access the personal information we hold about you; correct inaccurate or incomplete information; delete personal information (subject to legal or contractual obligations); and restrict or object to certain processing activities (for example, opting out of enrichment processing).

11.2 Data Portability
You may request a copy of your data in a machine-readable format (CSV, VCF, JSON) and, where technically feasible, have us transfer it to another service.

11.3 Marketing Communications
You can opt out of marketing emails at any time by clicking the “unsubscribe” link or by contacting us. We will still send essential transactional and security communications.

11.4 Canadian Residents (PIPEDA)
If you are located in Canada, you have rights under PIPEDA, including the right to access the personal information we hold about you, the right to challenge the accuracy and completeness of your information and have it amended as appropriate, the right to withdraw consent to our collection, use, or disclosure of your personal information (subject to legal or contractual restrictions), and the right to file a complaint with the Office of the Privacy Commissioner of Canada.

11.5 EU/UK Residents (GDPR/UK GDPR)
If you are located in the EEA, UK, or Switzerland, you have rights to access, rectification, erasure, restriction, objection, and data portability. You also have the right to lodge a complaint with your local Data Protection Authority. Where our processing is based on legitimate interests, you have the right to object, and we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defense of legal claims.

11.6 California Residents (CCPA/CPRA)
If you are a California resident, you have rights to know what personal information we collect, use, disclose, and share; the right to delete your personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information (Habsy does not sell personal information, and does not share it for cross-context behavioral advertising); the right to limit the use of sensitive personal information; and the right to non-discrimination for exercising your privacy rights. You may designate an authorized agent to make a request on your behalf, subject to verification.

11.7 India Residents (DPDPA)
If you are located in India, you have rights under the Digital Personal Data Protection Act, 2023, including the right to access, correction, and erasure of your personal data, the right to grievance redressal, and the right to nominate another person to exercise your rights in the event of your death or incapacity. You may also file a complaint with the Data Protection Board of India.

11.8 How to Exercise Your Rights
To exercise any of your rights, contact us at privacy@habsy.ai with the subject line “Privacy Request: [Access/Deletion/Correction/Portability/Objection].” We may need to verify your identity for security purposes and will respond within the timeframes required by applicable law, generally within thirty (30) days.

The Service is intended for business and professional use and is not directed to individuals under 18. We do not knowingly collect personal information from children. If you become aware that a child has provided personal information to us, please contact privacy@habsy.ai and we will take steps to delete such information.

By installing the Habsy App, creating an account, or continuing to use the Service, you acknowledge and (where applicable) consent to the collection and use of your personal information as described in this Privacy Policy; the use of AI, OCR, and enrichment technologies to digitize business cards and enrich profiles using publicly available data; the use of device permissions as requested by your operating system; the use of secure cloud infrastructure and international data transfers with appropriate safeguards; the use of cookies and analytics as described herein; the receipt of essential communications and optional marketing communications (with the ability to opt out); and the processing of third-party personal information that you provide to us, on the understanding that you as the Customer have the necessary authorization or lawful basis to do so.

Withdrawing Consent
Where we rely on your consent, you may withdraw it at any time by updating your preferences in the App, using the “unsubscribe” link in any marketing email, changing your device settings to revoke permissions, or contacting privacy@habsy.ai. Withdrawal of consent for essential processing may limit our ability to provide certain features of the Service.

Our website and App may contain links or integrations to third-party websites, applications, and services (e.g., CRM systems, event platforms, public professional profile sites). This Privacy Policy does not apply to information collected by those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you connect with through Habsy.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technologies, legal obligations, or business practices. When we make material changes, we will update the “Last Updated” date at the top of this policy and, where appropriate, provide additional notice (via email, in-app alert, or website notice), and obtain consent if required by law.

16. Governance, Risk, and Compliance Program

HTPL and Habsy Inc. have implemented a formal Governance, Risk, and Compliance (GRC) program designed to align internal security and privacy controls with globally recognized standards. We work with a leading GRC and compliance automation provider to support continuous compliance, evidence collection, and audit readiness.

Core Privacy and Security Principles
Customer Ownership:
You remain the owner of the data you upload to habsy.ai. We process your data only to provide the Service and do not claim ownership of your contacts or content.
Transparency: We explain what we collect, why, and how we use and protect it.
Security First: Personal information is protected using industry-standard encryption, access controls, and monitoring.
Minimal Collection: We collect only data necessary to operate and improve the Service and meet legal obligations.
User Control: You have meaningful control over your data, including the ability to access, correct, delete, export, or opt out of certain processing.

Our compliance program and certification efforts do not limit your rights under this Privacy Policy or applicable law. For questions about our compliance program, contact privacy@habsy.ai.

Current Status (July 2026)
SOC 2 Type II:
Controls internally implemented; evidence collection and observation period underway. Independent audit targeted for Q4 2026.
ISO/IEC 27001:2022: ISMS fully implemented and operating; pre-audit preparation in progress. Certification targeted for Q4 2026.
GDPR: Compliance framework implemented (lawful bases, data subject rights processes, DPIAs, security measures). External verification in progress.
PIPEDA: Aligned with all ten PIPEDA Fair Information Principles. Third-party personal information access control procedures documented and operational. Breach notification framework documented.
CCPA/CPRA: Consumer rights (access, deletion, correction, opt-out, portability) implemented. Opt-out mechanisms and preference settings operational.
DPDPA: Implementation in progress. Compliance monitoring and grievance redressal framework under development.

Evidence and Validation
To support customer due diligence, we can provide compliance documentation including engagement letters from our GRC automation partner, policy and control summaries, and templates for key compliance documents (DPA, SCCs). Some materials may be provided under NDA. To request documentation, contact privacy@habsy.ai with the subject line “Request: Compliance Documentation.”

Trust and Security Page
We are developing a dedicated Trust and Security page at habsy.ai/trust. Until that page is live, this Privacy Policy and documentation provided directly serve as the primary sources of information about our security and compliance program.

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Email (global privacy contact for both entities): privacy@habsy.ai

General Inquiries: contact@habsy.ai

Our India privacy team (Habsy Technologies Private Limited, registered in India) may be reached by contacting privacy-in@habsy.ai or via mail at:

Habsy Technologies Private Limited, Privacy Team
#62/6, Ground Floor, Anekal BG Road, Near Tent Jigani, Anekal Taluk
Bangalore, Karnataka 560105, India

or

11/4 Pooja Garden, Kalapatti Main Road, SITRA
Coimbatore, Tamil Nadu 641014, India

Our Canada privacy team (Habsy Inc., registered in Canada, Ontario) may be reached by contacting privacy@habsy.ai or via mail at:

Habsy Inc., Privacy Team
300-181 University Ave
Toronto, ON M5H 3M7, Canada
© 2026 Habsy Technologies Private Limited and Habsy Inc. All rights reserved.