Privacy Policy
Effective September 15, 2026 · Version 2.0
Kinetic Blume India Pvt Ltd (“Kinetic Blume”, “78Flex”, “we”, “us” or “our”) respects your privacy and is committed to handling personal data responsibly, transparently and securely.
This Policy explains what we collect, why, who receives it, how long we keep it, and what you can ask us to do about it. Where a statement below is specific — a retention period, a named processor, how a password is stored — it is specific on purpose, so that you can hold us to it.
1.About this Policy
1.1 This Policy applies to www.78flex.ai, our related websites, our web and mobile applications, and to workspace discovery, coworking, managed office, serviced office and virtual office services, enquiries, bookings, subscriptions, payments, communications, operator and partner onboarding, business and KYC verification, and marketing operated by the Company.
1.2 It should be read with our Terms and Conditions and our Cancellation & Refund Policy.
1.3 By using the Platform you acknowledge this Policy. Where the law requires your separate consent for a particular processing activity, we will ask for it separately; continued use of the Platform is not a substitute for that consent.
2.Applicable law
2.1 This Policy is designed to operate with Indian privacy and information-technology law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 where applicable, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
2.2 Where a foreign privacy law mandatorily applies to particular processing, we will comply with it to the extent required.
3.Who is responsible for personal data
3.1 Unless stated otherwise, Kinetic Blume determines the purposes and means of the processing it carries out, and acts as the Data Fiduciary (controller) for that processing.
3.2 Workspace operators are separate Data Fiduciaries. When we pass your booking to an operator, that operator decides for itself how it uses your details — for building access, its own records, its own communications. Its handling of your data is governed by its policies, not ours. This matters on a marketplace: we are not the only party processing your data, and we do not control the other one.
3.3 Where we process personal data solely on another organisation's instructions, we act as a Data Processor for that activity.
4.Personal data we collect
4.1 Information you give us
- Identity: name, date of birth where necessary, gender if you volunteer it, photographs you upload, and designation.
- Contact: email, phone number, billing address and — for virtual office subscriptions — registered office address.
- Account: username, password, and OTP verification records. Your password is stored as a salted hash, never as text we can read.
- Bookings: workspace, dates and times, party size, special requests, and notes you send the operator.
- Payments: transaction reference, amount, status, payment-method category, refunds and chargebacks. We do not store full card numbers or bank credentials — those are processed and held by Razorpay, our payment partner.
- Business and KYC (operator onboarding and virtual office subscribers): PAN, GSTIN, CIN, MCA filings, licences, proof of address, and authorised-signatory or beneficial-ownership details where required under the Goods and Services Tax laws and the Companies Act, 2013.
- Communications: enquiries, support requests, reviews, feedback and complaints, including chat with our assistant and with customer support.
4.2 Information collected automatically
- Device and connection: IP address, browser, operating system, device identifiers, and approximate location derived from IP.
- Precise location: only when you grant permission in your browser or device. We use it to sort workspaces by distance from you, and you can revoke it at any time in your settings.
- Usage: pages viewed, search queries, clicks, time on page, scroll depth and similar signals.
- Stored on your device, not sent to us: some conveniences live only in your browser's local storage — for example your recent searches, which are kept on your device so the search box can offer them back to you, and are never transmitted to our servers. Clearing them in the search box, or clearing your browser storage, removes them.
4.3 Information from third parties
- Operators and venue partners: information about your booking and on-site activity, for example badge swipes and check-in time.
- Razorpay: payment success or failure, settlement timing and chargeback notices.
- Identity verification services: document validation results for KYC.
- Google Places: venue details such as photos, opening hours and public reviews.
5.Sensitive personal data
5.1 We do not knowingly collect sensitive personal data or information (“SPDI”) within the meaning of the Information Technology Rules, 2011 — such as financial information beyond what is needed to process payments, biometric data, or information about health or sexual orientation — except where it is strictly required to provide the Platform (for example, for KYC verification) or where you volunteer it.
5.2 Where SPDI is collected, access is restricted to the people who need it for the purpose it was collected for, and administrative access to it is logged.
6.Why we use personal data
- To create and manage your account, including login, authentication and OTP verification.
- To deliver what you asked for: discovery, bookings, virtual office subscriptions and support.
- To let you and the operator communicate about your booking.
- To process payments and issue tax invoices, including GST invoices where applicable.
- To carry out KYC and business verification, and to meet legal and tax obligations.
- To detect, prevent and respond to fraud, security incidents and abuse.
- To handle support requests, complaints and disputes.
- To improve the Platform: analytics, debugging, testing and product development.
- To send transactional messages — booking confirmations, invoices, status updates — by email and WhatsApp.
- To send marketing communications where you have opted in.
- To establish, exercise or defend legal claims, and to protect the rights and safety of users, the Company and others.
7.Lawful basis and consent
7.1 We process personal data on one or more of these bases:
- Consent — marketing, precise location, and optional cookies.
- Performance of a contract — fulfilling bookings and the services you requested.
- Legal obligation — tax, anti-money-laundering and other statutory requirements.
- Legitimate and lawful purposes recognised by applicable law — analytics, fraud prevention, security and service improvement, where not overridden by your rights.
7.2 Where consent is required we will ask for it through an appropriate mechanism, and it will be as easy to withdraw as it was to give. Withdrawal does not make earlier lawful processing unlawful, and it may mean we can no longer provide a service that depends on that processing.
9.AI and automated processing
9.1 78Flex uses artificial intelligence and automated tools for workspace search and recommendations, our conversational assistant (RAMA), classification, fraud and security checks, customer support and product improvement.
9.2 When you use RAMA, the words you type or speak are sent to Google to be processed by its Gemini model so that a reply can be generated. Your conversation is also stored by us so the assistant can keep context within a session and so we can improve it.
9.3 Please do not put confidential or highly sensitive information into AI-powered features that is not needed for what you are asking.
9.4 We do not make decisions producing legal or similarly significant effects about you by automated means alone. Where transparency or review rights apply to automated processing under applicable law, we will honour them.
11.Our service providers
11.1 These are the processors we use and what each one does. Each is bound by confidentiality and data-protection obligations. We will update this list as the Platform changes.
- Razorpay — payments, refunds and settlement.
- Railway and Vercel — application hosting.
- Resend — transactional email delivery.
- Meta (WhatsApp Business Platform) — WhatsApp messaging.
- Google Firebase — phone authentication, including delivery of the one-time password by SMS.
- Google Gemini — the language model behind RAMA; see clause 9.2.
- Google Places — venue information, photos and public reviews.
12.No sale of personal data
12.1 We do not sell your personal data. This does not prevent the lawful processing described in clauses 10 and 11, disclosures required or permitted by law, fraud prevention, or a corporate transaction under clause 10.
13.Directors, employees and associates
13.1 We process information about our directors, employees, consultants, contractors and associates for recruitment, onboarding, identity verification, payroll, taxation, benefits, access control, compliance, security and business administration.
13.2 Anyone authorised to access Company or customer data must keep it confidential and follow our privacy and information-security requirements. Unauthorised access, disclosure, copying, transfer or misuse may lead to disciplinary, contractual, civil or criminal consequences.
13.3 Nothing in this Policy transfers, excludes or limits any responsibility or liability that cannot lawfully be transferred, excluded or limited.
14.Security
14.1 We use technical and organisational measures appropriate to the nature and risk of the processing, including encryption in transit (TLS) across the Platform, encryption at rest as provided by our hosting and database providers, role-based access controls, audit logging of administrative actions, monitoring, backups, vulnerability management, incident response and vendor controls. We require our processors to maintain comparable safeguards.
14.2 No method of transmission or storage is completely secure, and we do not claim absolute security.
15.Personal data breaches
15.1 If we become aware of a personal data breach we will assess, contain, investigate, mitigate and remediate it.
15.2 Where the DPDP Act requires it, we will notify affected individuals and the Data Protection Board of India within the timelines the law prescribes.
16.International processing
16.1 Some of our providers process or store information outside India. Where that happens we put an appropriate safeguard in place — such as a data processing addendum with the recipient — and transfer only to jurisdictions permitted under the DPDP Act and applicable rules.
16.2 Where the GDPR, UK GDPR or another foreign privacy law applies, we will use a recognised transfer mechanism where one is required.
17.Retention
17.1 We keep personal data only as long as necessary for the purposes in this Policy, including legal, tax, accounting and reporting requirements. Indicative periods:
- Account data — while your account is active, plus one year after closure.
- Booking and payment records — at least 8 years, in line with tax record-keeping requirements.
- KYC records (operators and virtual office subscribers) — at least 5 years after the relationship ends.
- Marketing preferences — until you unsubscribe or withdraw consent, plus any legally required period.
- Server logs and analytics — typically 12 to 18 months.
- Complaints and disputes — until resolved, plus the applicable limitation period.
17.2 Retention may be extended where required for legal proceedings, investigations or regulatory requirements. Once a period expires we delete, anonymise or de-identify the data, subject to legal holds.
18.Your rights as a data principal
18.1 Subject to applicable law, you have the right:
- To information — a summary of the personal data we process about you.
- To access and correction — to see your data and have inaccuracies corrected.
- To erasure — to ask us to delete your data, subject to clause 17.
- To withdraw consent — at any time, without affecting processing before withdrawal.
- To grievance redressal — see clause 26.
- To nominate — to name someone to exercise your rights in the event of death or incapacity, under the DPDP Act.
18.2 We may need to verify your identity before acting on a request, to avoid disclosing your data to someone else. We respond within the timelines applicable law prescribes.
19.Marketing communications
19.1 Where you have opted in, we may send product updates, offers and recommendations by email or WhatsApp.
19.2 Every marketing message carries an unsubscribe link or instructions, and you can change your preferences in your account profile at any time. Transactional messages about a booking you have made are not marketing and will continue.
20.Third-party websites
20.1 The Platform links to third-party websites and services, which operate under their own policies. We are not responsible for the privacy practices of third parties we do not control.
21.Children
21.1 The Platform is not intended for children under 18 and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
22.Your responsibilities
22.1 Please give us accurate information, and do not submit another person's personal or confidential information unless you are authorised to.
22.2 You are responsible for keeping your account credentials safe and for activity carried out through your account, subject to applicable law.
23.Legal disclosures
23.1 Nothing in this Policy prevents us from complying with applicable law, court orders, governmental or law-enforcement requests and regulatory requirements, from protecting our systems and intellectual property, from preventing fraud, or from establishing, exercising or defending legal claims.
24.Changes to this Policy
24.1 We may update this Policy to reflect changes in law, technology, Platform functionality or our operations. The current version is always on the Platform with its effective date at the top.
24.2 We will tell registered users about material changes by email or in-app notice at least 7 days before they take effect. Continued use of the Platform is not a substitute for separate consent where separate consent is legally required.
25.Governing law
25.1 This Policy is governed by the laws of India, subject to any mandatory rights available to you under an applicable foreign law. Dispute and jurisdiction provisions should be read together with our Terms and Conditions.
26.Grievance and privacy contact
26.1 In accordance with the Information Technology Act, 2000 and the rules made thereunder, and with the DPDP Act, the contact details of the Grievance Officer are:
Grievance Officer
Kinetic Blume India Pvt Ltd
1105, 11th Floor, Ansal Bhawan, 16 Kasturba Gandhi Marg
New Delhi 110001, India
Email: support@78flex.ai
Telephone: +91 98187 99144
26.2 The Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt.
26.3 A complaint about a booking, cancellation or refund follows a different route and a different statutory timetable — see clause 10 of our Cancellation & Refund Policy, which provides for acknowledgement within 48 hours and redressal within one month under the Consumer Protection (E-Commerce) Rules, 2020. The two timetables are deliberate, not inconsistent: they arise under different rules.
26.4 When you write to us, please include enough detail to identify you and to locate the relevant account, booking or transaction.
26.5 General privacy questions can be sent to the same address: Kinetic Blume India Pvt Ltd, 1105, 11th Floor, Ansal Bhawan, 16 Kasturba Gandhi Marg, New Delhi 110001, India.
