FLEXPRICE PRIVACY POLICY
Privacy Policy
Squirrelly Technologies Private Limited ("Flexprice," "we," "our," or "us"), a company incorporated under the Companies Act, 2013, with its registered office at G 16/27, Ground Floor, Office Cabin, DLF Phase 1, Gurugram, 122002, India, owns and operates the Flexprice platform and related services (collectively, the "Services").
Data Controller and Representatives
The data controller responsible for the personal data described in this Privacy Policy is Squirrelly Technologies Private Limited, G 16/27, Ground Floor, Office Cabin, DLF Phase 1, Gurugram, Haryana 122002, India. Email: [email protected]
Our EU GDPR Representative is:
Rickert Rechtsanwaltsgesellschaft mbH – SQUIRRELLY TECHNOLOGIES PRIVATE LIMITED – Colmantstraße 15, 53115 Bonn, Germany Email: [email protected]
Our UK GDPR Representative is:
Rickert Services Ltd UK – SQUIRRELLY TECHNOLOGIES PRIVATE LIMITED – PO Box 1487, Peterborough, PE1 9XX, United Kingdom Email: [email protected]
Data subjects in the European Union and the United Kingdom may contact our representatives on any matter relating to the processing of their personal data and the exercise of their rights.
This Privacy Policy explains how we collect, use, store, and protect information in connection with:
Our website (flexprice.io and related domains)
Business contacts (prospects, customers, partners, vendors)
Users who interact with us for support, sales, or marketing purposes
This Privacy Policy is prepared in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable laws.
1. SCOPE AND RELATIONSHIP TO CUSTOMER AGREEMENTS
This Privacy Policy does NOT govern Customer Data processed within the Flexprice product environment pursuant to a Master Services Agreement (MSA) or similar agreement
Flexprice's Services are designed to operate without requiring customers to provide end-user personal data to us. However, customers may choose to submit personal data in event payloads or other free-form fields. In such cases, Flexprice processes that data solely as a processor on the customer's behalf, and customers remain responsible for ensuring that any data they submit complies with applicable data protection laws.
Customer Data (including any personal data customers choose to input into the Services) is processed on behalf of the customer in accordance with the applicable MSA, not under this Privacy Policy.
Customers are solely responsible for their own use and handling of any personal data they input into the Services.
Role of the Parties: When processing Customer Data on behalf of a customer within the Flexprice product environment, Flexprice acts as a data processor (or equivalent term under applicable data protection laws), and the customer acts as the data controller. Such processing is governed by the applicable Master Services Agreement between Flexprice and the customer and, where required by law, a separate Data Processing Addendum (DPA).
Subprocessors: Flexprice may use third-party subprocessors (e.g., cloud hosting providers, analytics services, email delivery services, and optional integrations such as Stripe or monitoring tools) to assist in providing the Services. A current list of subprocessors is available upon written request to Flexprice. Flexprice will not add or change subprocessors that have access to Customer Data without providing Customer with at least thirty (30) days' prior notice, except where required by law or in an emergency. Customer may object to any new or changed subprocessor for reasonable data protection concerns, in which case the Parties will work in good faith to find a commercially reasonable alternative.
This Privacy Policy applies to:
Information we collect when you visit our website or interact with our marketing materials
Business contact information of customer representatives, prospects, partners, and vendors
Support and account management communications
2. INFORMATION WE COLLECT
a) Business Contact Information: When you interact with Flexprice (e.g., request a demo, contact support, subscribe to updates), we may collect:
Name, work email address, job title, company name, work phone number
Account credentials (username, hashed passwords)
Communication preferences
b) Technical and Usage Information: We automatically collect technical information when you use our website or Services:
IP address, browser type, device identifiers, operating system
Pages visited, time spent, referral source
Cookies and similar tracking technologies
c) Information We Do NOT Collect: Flexprice does not intentionally collect:
Sensitive personal data or information (SPDI) such as financial account details, health information, biometric data, or government-issued ID numbers
Personal data of your end users or customers (unless you voluntarily input it as Customer Data under your MSA)
Do not submit sensitive personal information via our public website or support channels.
3. HOW WE USE YOUR INFORMATION
We use the information we collect for the following purposes:

Legal Bases for Processing (EU and UK GDPR)
Where the EU GDPR or UK GDPR applies to our processing, we rely on the following legal bases under Article 6(1):
Performance of a contract, Article 6(1)(b) — providing and administering the Services; managing your account; authenticating users; generating and delivering invoices, processing payments and reconciling accounts; responding to your enquiries and providing support.
Legal obligation, Article 6(1)(c) — maintaining statutory financial, tax and corporate records; recruitment and personnel administration, together with Article 6(1)(b).
Legitimate interests, Article 6(1)(f) — operating, debugging and securing the platform and investigating security incidents, in our interest and that of our customers in the security and continuity of the Services; understanding feature usage and product engagement in order to improve the Services; business development and managing prospect and customer relationships; establishing, exercising or defending legal claims.
Consent, Article 6(1)(a) — sending marketing communications where consent is required, and analytics and marketing cookies.
Where we rely on legitimate interests, we have carried out a Legitimate Interests Assessment balancing our interests against your rights and freedoms. You may request a summary using the contact details in Section 12.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
4. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar technologies to:
Remember your preferences and settings
Analyze website traffic and usage patterns
Deliver relevant marketing content
Types of cookies we use:
Essential cookies: Required for website functionality
Analytics cookies: Help us understand how visitors use our website (e.g., Google Analytics)
Marketing cookies: Used to deliver relevant ads and measure campaign effectiveness
Your choices:
Most browsers allow you to block or delete cookies via browser settings.
Blocking cookies may limit your ability to use certain features of our website.
Product Analytics
We use product analytics to understand how the Flexprice dashboard is used so that we can improve it. This processing relies on our legitimate interests. Analytics data is hosted in the European Union and is retained for 30 days.
You can disable product analytics at any time from within your account settings.
You may also object to this processing under Article 21(1) using the contact details in Section 12.
5. HOW WE SHARE YOUR INFORMATION
We do not sell your personal information. We may share your information in the following circumstances:
Service Providers: We engage third-party service providers (e.g., cloud hosting, email delivery, analytics, customer support tools) who process information on our behalf under strict confidentiality obligations.
Business Partners: With your consent, we may share your information with partners for joint marketing or integration purposes.
Legal Requirements: We may disclose your information to comply with applicable laws, regulations, legal process, or enforceable governmental requests, or to protect our rights, property, or safety.
Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity, subject to this Privacy Policy.
Customer Data Usage Restrictions: Flexprice does not use Customer Data processed within the Flexprice product environment for any purpose other than providing the Services to the applicable customer, as described in the Master Services Agreement. Specifically, Flexprice does not:
Use Customer Data to train machine learning or AI models
Analyze Customer billing data beyond what is required for service delivery and invoicing
Resell Customer Data to third parties
Customer Data is processed solely on behalf of the customer as a data processor and is not used for Flexprice's own commercial purposes.
6. DATA RETENTION
We retain your information for as long as necessary to:
Fulfill the purposes described in this Privacy Policy
Comply with legal, tax, and accounting obligations (typically 7 years for financial records)
Resolve disputes and enforce our agreements
When no longer needed, we securely delete or anonymize your information.
Retention Periods
We retain personal data for the following periods:
Account and user profile data — for the life of the account. On termination, data is made available for export on written request for 30 days, after which it may be deleted.
Usage event data processed on behalf of customers — up to 7 years from the date of the event, and deletable earlier on the customer's instruction.
Product analytics — 30 days.
Operational and security logs — between 15 and 90 days depending on the log type.
Webhook message payloads and delivery history — 90 days.
Financial and tax records — 8 financial years, as required by the Companies Act 2013 and Indian tax law.
Recruitment and personnel records — up to 8 years after the end of engagement, as required by Indian employment, tax and provident fund law.
Prospect and business contact records — while the business relationship or our legitimate interest subsists.
Backups — personal data deleted from live systems persists in backups for up to 14 days before those backups expire.
Where we are required by law to retain data, for example financial records under tax law, that obligation overrides a request for erasure, as permitted by Article 17(3)(b) GDPR.
7. DATA SECURITY
We implement reasonable administrative, technical, and physical safeguards to protect your information, including:
Encryption of data in transit and at rest
Access controls and authentication mechanisms
Regular security assessments and monitoring
SOC 2 Type II certified infrastructure
However, no system is 100% secure. We cannot guarantee absolute security and are not liable for unauthorized access resulting from events beyond our reasonable control (e.g., hacking, force majeure events).
8. DATA LOCALIZATION AND INTERNATIONAL TRANSFERS
Personal data of individuals in the European Economic Area and the United Kingdom is stored and processed within the EEA. We do not transfer this data to third countries.
Other personal data covered by this Privacy Policy is stored and processed in India and the United States, using infrastructure providers including Amazon Web Services and Google Cloud Platform.
Customer Data processed within the Flexprice product environment is stored in the region selected by the customer. Customers may contact support to discuss regional requirements.
9. CHILDREN'S PRIVACY
Flexprice services are intended for business users and are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately.
10. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will post the updated Privacy Policy on our website with a revised "Last Updated" date. Your continued use of the Services after changes constitutes acceptance of the updated Privacy Policy.
11. YOUR RIGHTS AND CHOICES
Depending on your location, you may have the following rights:

We will respond within 30 days.
Your Rights Under the EU GDPR and UK GDPR
If you are in the European Union or the United Kingdom, you have the following rights:
Access — obtain confirmation of whether we process your personal data, and a copy of that data (Article 15).
Rectification — have inaccurate or incomplete personal data corrected (Article 16).
Erasure — have your personal data deleted, where no overriding legal obligation or legitimate ground applies (Article 17).
Restriction — request that we limit our processing of your personal data (Article 18).
Portability — receive personal data you provided to us in a structured, commonly used, machine-readable format (Article 20).
Object — object to processing based on our legitimate interests, and to direct marketing at any time (Article 21).
Withdraw consent — where processing is based on consent, withdraw it at any time (Article 7(3)).
Automated decision-making — not to be subject to decisions based solely on automated processing which produce legal or similarly significant effects (Article 22). We do not carry out such processing.
Response times. We will respond within one month of receiving your request, as required by Article 12(3). Where a request is complex or we receive a number of requests, we may extend this period by up to two further months and will inform you within the first month if we do so, with reasons. We do not charge a fee, except where a request is manifestly unfounded or excessive.
If your data was submitted to us by one of our customers. Where we process your personal data on behalf of a customer, that customer is the data controller and you should direct your request to them. If you contact us, we will refer you to the relevant customer and notify them of your request without undue delay.
Right to lodge a complaint. You have the right to lodge a complaint with a data protection supervisory authority. In the European Union this is the authority in the country of your habitual residence, place of work, or the place of the alleged infringement. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). We would appreciate the opportunity to address your concerns first.
12. CONTACT US / GRIEVANCE REDRESSAL
If you have questions, concerns, or wish to exercise your rights under this Privacy Policy, please contact the Grievance Officer:
Name: Koshima Satija
Email: [email protected]
- Phone: +91 9810488200
Address: G 16/27, Ground Floor, Office Cabin, DLF Phase 1, Gurugram 122002, India
Office Hours: 9:30 AM to 6:30 PM IST, Monday to Friday (excluding public holidays)
We will acknowledge your complaint within 24 hours and aim to resolve it within 30 days.
For questions about this Privacy Policy or to exercise your rights: [email protected]
Data subjects in the EU and UK may also contact our representatives, whose details appear at the top of this Privacy Policy.
13. GOVERNING LAW
This Privacy Policy is governed by the laws of India. Any disputes arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Bengaluru, Karnataka, India.
By using our website or Services, you acknowledge that you have read, understood, and agree to this Privacy Policy.
















