Privacy Policy
We believe your data belongs to you. This policy explains exactly what we collect, why we collect it, and the controls you have over it.
We never store your enterprise search content or use it to train AI models. Your data stays yours.
Independently audited security controls covering confidentiality, availability, and processing integrity.
All data in transit and at rest is encrypted using AES-256 and TLS 1.3.
Full compliance with European and California privacy regulations, with data subject rights honoured.
Overview
Fyndo ("we", "our", or "us") operates an AI-powered enterprise search platform. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit fyndo.ai, use our platform, or interact with us.
We distinguish between Website Visitors who browse fyndo.ai, and Platform Users who access Fyndo through an enterprise account. Different data practices apply to each.
The short version: We do not store your enterprise search queries or results, we do not sell your data, we do not use your content to train AI models, and you can request deletion of your personal data at any time.
Data We Collect
2.1 Information you provide directly
- Account registration: Name, work email, company name, job title, and password.
- Contact and inquiry forms: Name, email, phone, company, and message when you submit a demo request, support ticket, or enquiry.
- Billing information: Payment details are processed by Stripe (PCI-DSS compliant). We do not store full card numbers.
- Communications: Content of emails, support chats, or other messages you send us.
2.2 Information collected automatically
- Usage data: Pages visited, features used, search query metadata (not content), session duration, and click interactions.
- Device & technical data: IP address, browser type, operating system, and referrer URL.
- Cookies: Session, preference, and analytics cookies. See Section 9 for details.
- Log data: Server logs capturing API requests, timestamps, and error information.
2.3 Enterprise platform data
When you connect Fyndo to your enterprise tools, Fyndo indexes content from those systems to power search. This content is processed in real time and is never stored on Fyndo servers.
Zero Data Retention: Fyndo does not retain, cache, or log the content of documents, messages, or records retrieved from your integrated tools. We also do not use this content to train or fine-tune any AI model.
2.4 Information from third parties
- OAuth profile data (name, email, profile picture) when you sign in via Google or Microsoft SSO.
- Business contact data from CRM or LinkedIn integrations if enabled by your administrator.
Google API Services
Fyndo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data accessed and purpose
We read email content solely to answer your questions via AI. Emails are processed in real time within your session only.
✓ Never stored beyond sessionWe read file content solely to answer your questions via AI. File content is processed in real time and immediately discarded after each query.
✓ Never stored beyond sessionWe read calendar events solely to answer scheduling-related questions via AI. Event data is not stored beyond your current session.
✓ Never stored beyond sessionWe read contact names and email addresses solely to assist the AI in responding to your queries. Contact data is not stored beyond your session.
✓ Never stored beyond sessionWe read your task lists solely to assist the AI agent in responding to your queries. Task data is not stored beyond your current session.
✓ Never stored beyond sessionOur commitments: Fyndo does not sell, share, or transfer Google user data to any third party. We do not use Google user data for advertising, and we never use Google data to train AI models. Google data is accessed solely to fulfil the specific in-session request you initiate.
OAuth tokens and access revocation
OAuth access and refresh tokens are stored encrypted using AES-256. Tokens are permanently deleted within 24 hours of disconnecting a service. You may revoke access at any time via Google Account Permissions.
Fyndo's use of Google APIs is limited to the purposes described above and is consistent with Google's Limited Use Policy.
How We Use Data
3.1 Providing and operating the platform
- Authenticating your identity and managing your account.
- Processing search queries across your connected integrations.
- Enforcing permission boundaries — ensuring users only retrieve content they are authorised to access.
- Delivering AI-generated summaries and cited answers from your enterprise data.
3.2 Improving Fyndo
- Analysing aggregated, anonymised usage patterns to improve search relevance and performance.
- Monitoring error rates and system health to maintain uptime.
We do not use your enterprise content to train AI models. Only anonymised interaction metadata may inform platform improvements.
3.3 Communications
- Responding to enquiries, support tickets, and demo requests.
- Sending transactional emails (account confirmations, billing receipts).
- Sending product update and marketing emails where you have opted in. You can unsubscribe at any time.
3.4 Security and compliance
- Detecting and preventing fraudulent or unauthorised activity.
- Complying with legal obligations, including responding to lawful government requests.
- Maintaining audit trails required for SOC 2 and HIPAA compliance.
Data Sharing
We do not sell your personal data. We share data only in the following limited circumstances:
4.1 Service providers (sub-processors)
- Cloud infrastructure: AWS (data hosted in your selected region)
- Payment processing: Stripe
- Email delivery: Amazon SES
- Error monitoring: Sentry
- Customer support: Intercom
- Analytics: Mixpanel (anonymised, aggregated data only)
4.2 Your organisation
If you access Fyndo through an enterprise account, your administrator can view account-level usage data, audit logs, and connected integration status.
4.3 Legal requirements
We may disclose personal data if required by law, court order, or to protect the rights, property, or safety of Fyndo, our customers, or the public.
4.4 Business transfers
If Fyndo is involved in a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity under the same privacy protections.
Security
- Encryption in transit: TLS 1.3 for all communications.
- Encryption at rest: AES-256 for all stored data.
- Access controls: Role-based access control with source-level permission enforcement on every query.
- Real-time permission sync: Access changes in connected systems propagate instantly to Fyndo.
- SOC 2 Type II: Independently audited annually across Security, Availability, and Confidentiality criteria.
- Audit logging: Comprehensive, immutable logs of all access events.
- Penetration testing: Annual third-party penetration tests and continuous vulnerability scanning.
- Incident response: Documented incident response plan with SLAs for notification and remediation.
To report a security vulnerability, email security@fyndo.ai. We investigate all reports and respond within 48 hours.
Retention & Deletion
6.1 Enterprise search content
Zero data retention applies. Content retrieved from your connected tools is never written to persistent storage and is discarded immediately after the query resolves.
6.2 OAuth tokens
OAuth tokens are stored encrypted (AES-256) for the duration of the connection and permanently deleted within 24 hours of disconnecting a service.
6.3 Account data
We retain account information for the duration of your subscription and up to 90 days following account termination, after which it is securely deleted or anonymised.
6.4 Audit logs
SOC 2 and HIPAA-required audit logs are retained for a minimum of 12 months and a maximum of 7 years.
6.5 Requesting deletion
Email privacy@fyndo.ai. We will process verified requests within 30 days.
Your Rights
7.1 Rights available to all users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Opt-out of marketing: Unsubscribe at any time via any email link.
7.2 EEA / UK users (GDPR)
- Right to object to processing based on legitimate interests.
- Right to restrict processing in certain circumstances.
- Right to lodge a complaint with your local supervisory authority.
7.3 California residents (CCPA / CPRA)
- Right to know what personal information is collected, used, shared, or sold.
- Right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising.
- Right to non-discrimination for exercising your privacy rights.
To exercise any rights, contact privacy@fyndo.ai. We respond within 30 days.
International Transfers
Fyndo is headquartered in Hyderabad, India. Data is processed and stored in AWS regions chosen by your organisation (available: ap-south-1 Mumbai, us-east-1 Virginia, eu-west-1 Ireland, and others on request).
For EEA/UK customers, transfers outside adequate countries are governed by Standard Contractual Clauses (SCCs). A Data Processing Agreement (DPA) is available on request.
For Indian residents, we comply with applicable provisions of the Digital Personal Data Protection Act, 2023 (DPDPA).
Policy Changes
When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Send an in-app notification and/or email to account holders at least 14 days before changes take effect.
- Obtain fresh consent where required by applicable law.
Contact Us
For questions, concerns, or requests relating to this Privacy Policy:
Registered address: Fyndo Technologies Pvt. Ltd., Hyderabad, Telangana, India.