Loading Yolfin Group...
Loading Yolfin Group...
How Yolfin Group handles personal and business data. Effective and last updated: 1 September 2026.
Privacy in one sentence
We use personal and business data only for clear service, security, legal and operational purposes; we do not sell it; and we apply reasonable confidentiality and protection measures while recognising that no online system can be guaranteed completely secure.
Overview
This Privacy Policy is written for Yolfin Group's website, free-trial booking process and accounting and finance services in India and the UAE. It explains the information we collect, why we use it, when it may be shared, how it is protected and the choices available to individuals and clients.
This Privacy Policy explains how Yolfin Group collects, uses, stores, shares and protects personal data when a person visits our website, contacts us, books a free trial, uploads or sends business records, or receives our services. It applies to website visitors, prospective clients, clients, authorised client representatives, vendors and other business contacts.
This Policy is intended to operate consistently with applicable privacy and technology laws, including India's Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000 and applicable rules, and the UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data, in each case as brought into force, amended and applicable to the relevant processing.
A separate engagement letter, non-disclosure agreement or data processing agreement may provide additional or more specific privacy terms. If a specific written agreement applies, it will control for the client data and service covered by that agreement, to the extent permitted by law.
Yolfin Group provides business support services across India and the UAE. Accounting and finance is the currently active service on our website. Travel management and facility management are displayed as coming soon and are not offered through the website until Yolfin confirms their launch.
For this Policy, Yolfin Group is the organisation responsible for the personal data described here, except where we process personal data only on a client's documented instructions. Our principal contact address is Office No. 11/501, Areekode Road, Kondotty, Malappuram, Kerala 673638, India. Privacy questions and requests may be sent to yolfingroup@gmail.com, +91 95629 75022 in India, or +971 55 664 6580 in the UAE.
The data we collect depends on how a person interacts with us and on the scope of an agreed service. We seek to collect only information that is reasonably necessary for the stated purpose.
We may obtain data directly from a person through the website, free-trial form, email, telephone, WhatsApp, meetings or documents. We may also obtain data from a client's authorised representative, from records supplied by a client, from public business registers, from professional advisers, or from service providers used to operate the website and deliver agreed services.
If a client gives us personal data about another person, the client must have the legal right and authority to do so, must provide any required notice, and must ensure that the disclosure and our instructed processing are lawful. Clients should avoid sending data that is not relevant to the agreed work.
We use personal data for clear business and service purposes. Depending on the interaction, these purposes may include the following:
Where applicable law requires a legal basis, we rely on consent, steps requested before entering a contract, performance of a contract, compliance with a legal obligation, protection of legitimate business and security interests, or another basis recognised by applicable law.
When consent is the basis, the request will identify the purpose and will be separate from unnecessary processing. Consent may be withdrawn by contacting us. Withdrawal does not affect processing already lawfully completed and may prevent us from providing a service that cannot reasonably be delivered without the relevant data.
Providing data marked as mandatory may be necessary to respond to a booking or perform an agreed service. Optional data may be left blank. We will not make optional marketing consent a condition of receiving accounting services.
The free-trial form may request contact and business information needed to understand the requested service. Submitting the form does not require payment and does not automatically create a paid engagement. We may contact the person to verify details, assess scope and explain onboarding requirements.
Financial documents should be requested only after Yolfin confirms that the trial can begin and explains the secure method for sending them. If a trial is not started or the inquiry does not proceed, we will retain the inquiry only for as long as reasonably needed for follow-up, fraud prevention, record keeping and legal obligations, after which it will be deleted or anonymised in accordance with our retention process.
For personal data contained in a client's accounting, payroll, tax, customer, supplier or employee records, the client generally decides why the data is processed and is responsible for its lawful collection and use. Yolfin Group generally processes that data as a service provider on the client's documented instructions and only for the agreed scope.
We expect clients to apply data minimisation, provide required notices, respond to individuals' requests, maintain required consents or other legal grounds, and notify us promptly of any instruction that may be unlawful. We will maintain confidentiality, limit access to authorised personnel and assist with reasonable privacy or security requests as agreed and required by law.
Our website may use cookies, local storage, server logs or similar technologies. Essential technologies support page delivery, security, load balancing, form operation and user preferences. Analytics technologies may help us understand visits and improve performance. Marketing technologies, if introduced, may help measure campaigns.
Where required by law, non-essential cookies will not be activated until the visitor gives consent through a cookie banner or preference tool. Visitors may change browser settings or withdraw cookie consent, although disabling essential technologies may affect website functions. The website should identify material third-party analytics or advertising providers in its cookie notice before those tools are enabled.
We do not sell personal data. We may disclose limited data only when reasonably necessary for the purposes in this Policy, subject to confidentiality and security controls:
Yolfin supports clients in India and the UAE. Personal data may therefore be accessed, stored or processed in a country different from the person's location when necessary for the requested service or for a trusted service provider. Data-protection standards and government-access rules may differ between countries.
Before making a cross-border transfer, we will consider applicable transfer restrictions and use appropriate contractual, organisational and technical safeguards where required. We may restrict a transfer or choose a different service-delivery method if a lawful and secure transfer cannot reasonably be arranged.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, the duration of a client relationship, completion of professional work, statutory accounting or tax record periods, dispute and limitation periods, regulatory requirements, security, backup cycles and proof of instructions or consent.
Retention periods differ by record type and country. Client engagement records and accounting or tax working files may need to be kept for longer than an inquiry or unsuccessful trial request. When data is no longer required, we take reasonable steps to delete, destroy or irreversibly anonymise it. Backup copies are removed or overwritten according to secure backup cycles and are not restored for ordinary business use after deletion.
We use reasonable and proportionate technical and organisational measures based on the sensitivity, volume and risk of the data. Measures may include role-based access, confidentiality obligations, authentication controls, encryption in transit where supported, protected storage, device and account security, backups, logging, staff awareness, vendor review and secure disposal.
No website, transmission method or storage system can be guaranteed completely secure. For that reason, Yolfin does not promise absolute or 100 percent security. Clients and users must also protect their devices, email and WhatsApp accounts, use secure networks, check recipient details and promptly report suspected compromise.
We maintain procedures to assess and respond to suspected loss, unauthorised access, disclosure, alteration or misuse of personal data. If an incident creates a notification duty, we will notify the relevant authority, affected client or affected individuals in the manner and time required by applicable law.
A person who believes data shared with Yolfin has been compromised should contact us immediately at the email or phone number in Section 2 and provide enough information for us to investigate. Do not include passwords, OTPs or unnecessary financial information in the incident report.
Depending on location and applicable law, a person may have rights to receive information about processing, obtain access, correct or update inaccurate data, complete incomplete data, request deletion, withdraw consent, object or restrict certain processing, request transfer of data where recognised, nominate another person where recognised, and use a grievance or complaint process.
Requests may be sent to yolfingroup@gmail.com with the subject 'Privacy Request'. We may ask for reasonable information to verify identity and authority. We will respond within the time required by applicable law and explain any lawful restriction, extension or refusal. A request may not require deletion of records that must be retained for tax, legal, fraud-prevention, professional or dispute purposes.
When Yolfin holds personal data only for a client, we may refer the request to that client or assist the client in responding. A person may also complain to the competent data-protection or regulatory authority where the law provides that right, after using our grievance process where required.
We may send relevant service news or offers to business contacts where permitted by law. Marketing messages will identify Yolfin Group and provide a reasonable way to opt out. A person may opt out at any time by using the unsubscribe method in the message or contacting us.
Opting out of marketing does not stop service, security, billing, legal or operational communications that are necessary for an inquiry or client engagement. We may keep a limited suppression record to respect an opt-out request.
The website and services are intended for businesses and authorised adults and are not directed to children. We do not knowingly invite a child to submit personal data or enter a client engagement. If a client record legitimately contains a child's data, such as a lawful payroll dependent record, the client must ensure the processing is necessary and lawful and that any required parent or guardian authorisation has been obtained.
If we learn that a child submitted data directly without valid authorisation, we will take reasonable steps to delete it, subject to any legal retention duty.
The website may link to third-party websites or communication platforms such as WhatsApp, email, maps or service-provider pages. Those providers control their own processing, terms and security. This Policy does not govern a third party's independent practices.
Clients should consider the sensitivity of a document before sending it through an ordinary messaging service. Yolfin may require a more secure channel for financial, payroll, identity or tax records. A third-party link is not an endorsement of every service or statement on that site.
We do not use website data to make a solely automated decision that produces a legal or similarly significant effect on a person unless we first provide a specific notice and any choice or review required by law.
If technology or artificial intelligence is used to assist document classification, reconciliation, drafting or quality checks, authorised personnel remain responsible for appropriate review. Client-confidential data will not be used to train a public or unrelated model without lawful authority, appropriate contractual safeguards and any required client approval.
We may update this Policy to reflect changes in services, technology, legal requirements or business practices. The current version will be posted on the website with its effective date. If a change materially affects how we use previously collected personal data, we will provide additional notice or obtain consent where required by law.
Visitors should review the current Policy before submitting new information. Earlier versions may be requested using the contact details below where records are available.
Privacy Contact / Grievance Contact: Yolfin Group, Office No. 11/501, Areekode Road, Kondotty, Malappuram, Kerala 673638, India. Email: yolfingroup@gmail.com. India phone and WhatsApp: +91 95629 75022. UAE direct phone: +971 55 664 6580.
Please state the nature of the request, the relevant relationship with Yolfin, the approximate dates and a safe contact method. We aim to acknowledge a privacy grievance promptly, investigate it fairly and provide a response within the period required by applicable law. Urgent suspected security incidents should be clearly marked 'Urgent - Data Security'.
Email Inquiries
yolfingroup@gmail.com
Telephone & WhatsApp
+91 95629 75022 (India)
+971 55 664 6580 (UAE)
Registered Office
Office No. 11/501, Areekode Road, Kondotty, Malappuram, Kerala 673638, India