Privacy Policy

Effective Date: 13 December 2016

Last Updated: 1 September 2026

This Privacy Policy has been reviewed and aligned with the data protection and privacy terms in Sections 7 and 8 of the Foxena Services Agreement (effective 1 July 2026). Where this Policy and the Services Agreement address the same subject, the Services Agreement governs for customers who have executed it; this Policy applies to all other users of Connex.

FOXENA TECHNOLOGIES (OPC) PRIVATE LIMITED (“Foxena”, “Service Provider”, “we”, “our”, or “us”) is a company incorporated under the laws of India (CIN: U72900KA2019OPC124733). We are committed to protecting the privacy of everyone who uses our services. This Privacy Policy explains how we collect, use, disclose, and protect information when you use Connex, our proprietary, web-based SaaS platform for IT & technology management systems (ITMS), customer relationship management (CRM), enterprise resource planning (ERP), and related business solutions, including our associated websites, mobile applications, APIs, and other related services (collectively, the “Service”).

This Policy applies to (a) individuals who register for or administer a Connex account (“Customer”), (b) individuals authorized by a Customer to use the Service on the Customer’s behalf (“Users”), and (c) visitors to our websites. It does not override any separate Data Processing Agreement (DPA) that Foxena has executed with an enterprise Customer, which will govern in the event of a conflict as to the processing of that Customer’s data.

1. Information We Collect

A. Account & Personal Information

When you register for or administer an Account, or are added as a User, we collect:

  • Full name
  • Email address
  • Phone number
  • Company name and business details
  • Billing and payment details
  • Role, job title, and permissions within the Account
  • IP address
  • Any other contact details you voluntarily provide

B. Usage Data

We collect analytics, interaction, and system logs, including:

  • Logins, session times, and navigation behavior
  • Device and browser information
  • Pages visited and actions taken within the Service
  • Crash reports and error logs
  • Authentication, security, and administrative-action logs, and other Service usage records, which we may retain and use for security, fraud prevention, troubleshooting, compliance, auditing, and Service-improvement purposes

C. Client/End-User Data

As part of using Connex, Customer and its Users may input data about their own customers, clients, or team members (“Client/End-User Data”). As between Foxena and the Customer, the Customer retains all right, title, and interest in this data — Foxena claims no ownership over it. We treat Client/End-User Data as confidential and process it strictly as the Customer’s instructions and applicable Data Processing Agreement (DPA) require. If you are an end-user or team member whose information has been entered into Connex by one of our Customers, please direct any privacy request to that Customer in the first instance; we assist our Customers in responding to such requests.

2. How We Use Your Information

We use the information described above solely to:

  • Provide, operate, maintain, and improve Connex and its features
  • Create and manage your Account and subscription
  • Process payments and manage billing
  • Provide customer support and technical assistance
  • Communicate with you regarding the Service, including transactional and administrative communications
  • Send product updates, marketing communications, or surveys (opt-in only — you may withdraw consent at any time)
  • Maintain security, detect and prevent fraud or abuse, and enforce our Terms of Service
  • Comply with applicable law

We do not use your personal information for any purpose other than as described in this Policy.

3. Legal Basis for Processing (GDPR)

If you are located in the European Union or United Kingdom, we process personal data under one or more of the following legal bases:

  • Performance of a contract — processing necessary to provide the Service and perform our agreement with you.
  • Consent — for optional processing such as marketing communications; you may withdraw consent at any time.
  • Legal obligation — processing necessary to comply with a legal requirement.
  • Legitimate interests — processing necessary for our legitimate interests in securing, maintaining, and improving the Service, provided those interests are not overridden by your rights.

4. Data Sharing and Disclosure

We do not use or sell your data, under any circumstances.

We may share data only in the following limited circumstances:

  • With third-party service providers who support our operation of the Service (e.g., hosting, payment processing), bound by confidentiality obligations
  • With legal authorities, where required by law or a valid court or governmental order
  • With affiliates or partners, only with your consent or in connection with a merger, acquisition, or sale of assets

If we were to use or sell your data, or share it with a third party, in breach of this commitment, we will promptly notify affected Customers in writing upon becoming aware of the breach, in addition to any remedies available under the applicable Services Agreement.

5. Meta / Facebook Platform Data

Connex integrates with Meta Platforms, Inc. (“Meta”) APIs — including the Facebook Pages API, Lead Ads / Leads Retrieval API, Instagram Messaging API, and Business Management API — to let Customers connect their own Facebook Pages, Instagram business accounts, ad accounts, and other Meta Business assets to Connex for CRM purposes. This section describes how we access, store, use, and delete data obtained through these Meta integrations (“Meta Platform Data”).

What Meta Platform Data we access

Where a Customer connects a Meta account or Business asset and grants the relevant permissions, we may access:

  • Facebook Page information — Page profile details, posts, messages, and comments the Customer authorizes us to read or respond to
  • Leads — contact and form-response data submitted through Facebook or Instagram Lead Ads (e.g., name, email address, phone number, and other fields included in the Customer’s lead form)
  • Business assets — the list of Pages, ad accounts, Instagram accounts, and catalogs the Customer has granted us access to through Meta Business Login, together with the metadata needed to identify and manage those assets
  • Other Meta data the Customer explicitly authorizes through Meta’s permission dialog (for example, pages_show_list, pages_read_engagement, pages_messaging, leads_retrieval, or business_management), limited to what each permission covers

How we use it

We access and use Meta Platform Data solely to provide CRM functionality within Connex — for example, importing leads into the Customer’s CRM pipeline, associating leads with campaigns, and enabling the Customer to view and respond to Page or Instagram messages from within Connex. We do not use Meta Platform Data for advertising, do not sell it, and do not use it to build profiles for any purpose outside the CRM functionality the Customer has enabled, consistent with Section 4 (Data Sharing and Disclosure).

How it is stored

Meta Platform Data is treated as Client/End-User Data or Customer Data (as applicable) under this Policy and is stored and protected using the same safeguards described in Section 7 (Data Security), including AES-256 encryption at rest and TLS 1.2+ encryption in transit, with access restricted on a role-based, least-privilege basis.

Retention and deletion

We retain Meta Platform Data only for as long as the Customer’s Meta connection remains active or as needed to provide the CRM functionality it supports. Meta Platform Data is deleted:

  • Automatically, within a commercially reasonable period, when a Customer disconnects a Page, ad account, or other Meta asset from Connex, or revokes our access through their Meta Business Settings
  • Upon a verified deletion request submitted to [email protected], processed in accordance with Section 9 (Your Rights)
  • Upon termination of the Customer’s subscription, in accordance with Section 6 (Data Retention)

We comply with Meta’s Platform Terms and Developer Policies, including honoring user data deletion requests submitted directly through Meta and requesting only the permissions necessary for the CRM functionality described above.

6. Data Retention

We retain your data for as long as necessary to:

  • Provide the Service under your active subscription
  • Fulfill legal, tax, and regulatory obligations
  • Maintain security and service logs for legitimate business purposes

Upon termination or expiration of your subscription, you may request export of your data in a commonly used electronic format within thirty (30) days of termination. Following that period, we will delete your data from our active systems within sixty (60) days, except to the extent retention is required by applicable law or for legitimate backup purposes — any such retained data remains subject to the confidentiality and security obligations described in this Policy.

7. Data Security

We implement industry-standard technical and organizational measures to protect your data, including:

  • Encryption of data at rest using AES-256, and in transit using TLS 1.2 or higher
  • Role-based access controls restricted to personnel with a legitimate business need (least-privilege basis)
  • Security audits and vulnerability assessments conducted at least annually
  • Backups performed on a bi-weekly basis, retaining the two most recent copies, with at least one copy stored in encrypted form at a geographically separate location

No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we continuously work to protect your information using measures appropriate to the sensitivity of the data involved.

8. International Data Transfers

Your data may be processed in jurisdictions outside your location, where our servers, personnel, or service providers are located. Where a transfer involves personal data originating from the European Union, United Kingdom, or another jurisdiction that imposes cross-border transfer restrictions, we implement appropriate safeguards, including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, or an equivalent recognized transfer mechanism, together with the encryption measures described in Section 7 (Data Security).

9. Your Rights

Subject to applicable law (including GDPR, the UK GDPR, and other data protection laws described in Section 10), you have the right to:

  • Access the personal data we hold about you
  • Correct or update inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Withdraw consent at any time, where processing is based on consent
  • Request a portable export of your data

You can exercise these rights through the Service or by emailing [email protected]. We will respond to verified requests within thirty (30) days, or such shorter period as required by applicable law.

10. Region-Specific Disclosures

Depending on where you or your organization are located, the following additional terms apply:

European Union / United Kingdom

We comply with the GDPR and, for UK-based individuals, the UK GDPR and Data Protection Act 2018, as described in Sections 3, 8, and 9 above.

Singapore

For individuals located in Singapore, we collect, use, and disclose personal data in accordance with the Personal Data Protection Act 2012 (“PDPA”). We will not use or disclose personal data for any purpose other than one for which consent (including deemed consent) has been given or that is otherwise permitted under the PDPA, and we will notify affected Customers without undue delay of any data breach notifiable under the PDPA. Where we send marketing communications to Singapore telephone numbers, we do so in accordance with Singapore’s Do Not Call Registry requirements and the Spam Control Act 2007.

Australia

For individuals located in Australia, we handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), including by taking reasonable steps to protect personal information from misuse, interference, loss, and unauthorized access, and by providing access to and correction of personal information on request. Nothing in this Policy limits any right, guarantee, or remedy conferred by the Australian Consumer Law that cannot lawfully be excluded.

United States

For residents of U.S. states with applicable privacy laws (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act), we do not sell or share personal information as those terms are defined under such laws. We will honor verifiable requests to know, access, correct, or delete personal information, and will not discriminate against anyone for exercising these rights.

DIFC (Dubai)

Where applicable, we process personal data of individuals connected to the Dubai International Financial Centre in accordance with the DIFC Data Protection Law (DIFC Law No. 5 of 2020), including supporting rights of access, rectification, erasure, restriction, objection, and data portability, and notifying the DIFC Commissioner of Data Protection and affected individuals of any notifiable personal data breach.

11. Cookies and Tracking Technologies

We use cookies and similar technologies for session management, analytics, and personalization. You can manage your cookie preferences through your browser settings.

12. AI Features

Connex may incorporate artificial intelligence or machine-learning features (“AI Features”). Where you use an AI Feature, information you input may be processed by that feature to generate output. AI-generated output may be probabilistic, incomplete, or inaccurate, and does not constitute legal, financial, medical, or other professional advice. You are responsible for reviewing and validating any AI-generated content before relying on it. We do not use your data to train AI models for the benefit of other customers without your consent.

13. Children’s Privacy

Connex is not intended for individuals under the age of 16, and Customer Accounts may only be held by individuals of legal age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.

14. Data Processing Agreements for Enterprise Customers

Enterprise Customers may request a Data Processing Agreement (DPA), Security Annex, subprocessor list, or related documentation to address enterprise-specific data protection requirements. Please contact [email protected] to request these documents.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by email or through an in-app message, and will update the “Last Updated” date above.

16. Governing Law

This Policy is governed by the laws of India, without regard to its conflict of laws principles, and any dispute relating to this Policy is subject to the exclusive jurisdiction of the courts located in Bengaluru, Karnataka, India, without limiting any mandatory consumer or data protection rights available to you under the laws of your own country of residence.

17. Contact Us

FOXENA TECHNOLOGIES (OPC) PRIVATE LIMITED

CIN: U72900KA2019OPC124733

7th Floor, Fairway Business Park, Embassy Golf Links, behind Dell Road, Domlur, Bengaluru – 560071, Karnataka, India

Phone: +91 7028591666

Email: [email protected]

To exercise your data protection rights — including access, correction, deletion, or anonymization of your personal data, or deletion of data obtained through our Meta/Facebook integration (see Section 5) — you may submit a request through the platform or by contacting the email address above.