PRIVACY POLICY

Last Updated: July 31, 2026

Flutterby Labs Private Limited ("Flutterby", "Company", "we", "us", or "our") respects privacy and is committed to processing personal information in a lawful, fair, transparent, and secure manner. This privacy policy ("Privacy Policy") explains how we collect, use, disclose, store, transfer, and protect personal information when you interact with us in connection with our Site, products, platforms, services, and business operations.

This Privacy Policy applies to:

  • Visitors to our website at www.flutterby.co ("Site");
  • Users of our products, applications, portals, or services (including "Elnior", available through Elnior application on the Google Play Store and Apple App Store);
  • Individuals and organizations that contact us through forms, events, support, or business communications;
  • Candidates, vendors, customers, partners, and other persons whose personal information we process in the course of business.

If local law provides greater protection or imposes additional requirements, those laws will apply in addition to this Privacy Policy. By accessing or using our Site or services, you acknowledge that you have read this Privacy Policy.

1. Information We Collect

We may collect personal information directly from you, automatically through your use of our Site or services, and from third parties.

a. Information you provide to us

  • Name, email address, phone number, and zipcode / pincode;
  • Country, region, or location;
  • Billing, invoicing, and payment/subscription-related information;
  • Communications, inquiries, feedback, or support requests;
  • Information submitted through forms, registrations, demos, webinars, surveys, events, or downloads;
  • Account credentials or profile information;
  • Learning and behavioural data (including existing knowledge, onboarding preferences, professional aspirations, skill levels, interest profiles, and module completion velocities), precise service data, device/log data, app usage insights, and engagement data;
  • Any other information solely in connection with the above.

You should not provide sensitive personal information unless it is necessary for the stated purpose and lawfully requested or otherwise permitted.

b. Information collected automatically

  • IP address;
  • Browser type and version;
  • Device type and identifiers;
  • Operating system;
  • Approximate geographic location;
  • Pages viewed and time spent;
  • Clickstream, navigation and session data;
  • Referring and exit URLs;
  • Access timestamps;
  • Cookies and similar tracking technologies.

c. Information from third parties

  • Ad click identifiers (Meta: fbclid/fbp/fbc cookies; Google: gclid) stored when users arrive via ads;
  • Conversion/event data — actions on the site (purchase, add to cart, form submission) shared with Meta and Google for measurement;
  • Hashed customer data (email, phone, name) shared with ad platforms via Conversions API / enhanced conversions;
  • Customer lists uploaded to Meta/Google for custom and lookalike audiences;
  • Campaign attribution data (UTM parameters — ad, campaign, source);
  • Cross-device and cross-platform tracking by Meta/Google;
  • Lead form data collected within Facebook/Instagram (if lead ads are run);
  • Session recording/heatmap tools.

2. How We Use Information

We process personal information for the following purposes, in compliance with the relevant local law, as may be applicable:

a. Service delivery and business operations

  • To provide, operate, maintain, and improve our Site, products, and services;
  • To manage accounts, subscriptions, and business relationships;
  • To process transactions, requests, and customer support matters;
  • To fulfill contractual obligations.

b. Communications

  • To respond to inquiries and support requests;
  • To send service-related, administrative, and transactional communications;
  • To send marketing communications, newsletters, and event invitations where permitted by law;
  • To personalize communications and content.

c. Analytics and product improvement

  • To analyze usage patterns and improve functionality;
  • To conduct research, development, testing, and analytics;
  • To measure website performance, engagement, and campaign effectiveness;
  • To develop new products, services, and features.

d. Security, compliance, and legal purposes

  • To detect, prevent, and investigate fraud, misuse, abuse, security incidents, and unauthorized access;
  • To enforce our terms, policies, and legal rights;
  • To comply with applicable legal, regulatory, tax, accounting, audit, and reporting obligations;
  • To protect the rights, property, safety, and security of the Company, our users, customers, partners, and others.

Please note that Elnior uses artificial intelligence to curate, summarise, structure and recommend learning content based on your goals, preferences, activity and progress. We do not use Elnior to make decisions that produce legal or similarly significant effects about you. We will state separately if user data is used to train or improve artificial intelligence models.

3. Compliance with Applicable Laws

Where required by law, we will obtain consent or provide notice at the time of collection, and we will process personal information only for specified, lawful, and disclosed purposes. We may also rely on other legal bases or permissions available under applicable law, including contractual necessity, legitimate interests, compliance obligations, and protection of legal rights, as recognized in the relevant jurisdiction.

4. Legal Bases for Processing

Where applicable law requires a legal basis for processing, we may rely on one or more of the following:

  • Your consent;
  • Performance of a contract;
  • Compliance with legal obligations;
  • Legitimate interests, provided those interests are not overridden by your rights and interests;
  • Protection of vital interests;
  • Establishment, exercise, or defense of legal claims.

Where processing is based on consent, you may withdraw consent at any time, subject to legal or contractual restrictions and the lawfulness of processing before withdrawal.

5. Disclosure of Information

We do not sell personal information, nor do we share your personal information for cross-context behavioural advertising purposes. We may disclose personal information in the following circumstances:

a. Service providers and vendors

We may share personal information with third-party service providers that help us with cloud hosting, analytics, CRM, marketing, payment processing, IT/cybersecurity, and technical support. These parties may use personal information only as necessary to perform services on our behalf and are expected to maintain confidentiality and appropriate safeguards.

b. Business transfers

We may disclose personal information in connection with mergers, acquisitions, financing, restructuring, or sale of assets or business units.

c. Legal and regulatory disclosures

We may disclose personal information where we believe disclosure is necessary to comply with applicable law, respond to court orders or governmental authorities, enforce agreements, investigate fraud, or protect rights, safety, and security.

d. Affiliates and advisors

We may share personal information with our affiliates, auditors, insurers, legal counsel, consultants, and other professional advisors, subject to confidentiality obligations.

6. Cookies and Tracking

We use cookies, pixels, SDKs, analytics tools, and similar technologies to enable core functionality, remember preferences, analyze traffic, measure campaign performance, improve user experience, and personalize content. Some cookies may be placed by third parties. Where required by law, we will obtain consent for non-essential cookies and provide a mechanism to manage preferences.

7. International Transfers

Because we operate internationally, personal information may be transferred to, stored in, and processed in countries other than the country in which it was collected. Our primary servers are located in Singapore. Where required, we use lawful transfer safeguards such as contractual protections, standard contractual clauses, or other legally recognised mechanisms.

8. Retention

We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, provide services, comply with legal obligations, resolve disputes, enforce agreements, and maintain security. When information is no longer required, we may delete, anonymize, or de-identify it, subject to applicable law.

9. Security

We maintain reasonable administrative, technical, organizational, and physical safeguards to protect personal information against unauthorized access, disclosure, alteration, loss, misuse, or destruction. Personal information stored in our production environment is hosted primarily in Singapore and encrypted at rest. We use HS256 for JWT encryption and SHA256 for password hashing, along with access controls, encryption in transit, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your Rights

Subject to applicable law and your jurisdiction, you may have the right to:

  • Access personal information we hold about you;
  • Correct inaccurate or incomplete information;
  • Request deletion or erasure;
  • Withdraw consent where processing is based on consent;
  • Object to or restrict certain processing;
  • Request information about how your personal information is processed;
  • Opt out of marketing communications;
  • Data portability;
  • Designate a nominee to exercise your data rights in the event of incapacity or death;
  • Lodge a complaint with us or a competent authority, where applicable.

Rights may differ depending on your jurisdiction. We may require verification of identity before acting on a request.

11. Marketing Communications

Where permitted by law, we may send promotional communications about our products, services, events, and updates. You may opt out by clicking the unsubscribe link in any email or by contacting us. Even if you opt out of marketing, we may still send non-promotional service, administrative, or security notices.

12. Children and Minors

Our Site and services are not directed to children under 16 years of age or the minimum age required under applicable local law. We do not knowingly collect personal information from children without appropriate authorization or consent. If we learn that we have collected information from a child in violation of applicable law, we will take appropriate steps to delete it.

13. Third-Party Links

Our Site may contain links to third-party websites, applications, or services that are not operated by us. We are not responsible for the privacy, security, or content practices of those third parties. We encourage you to review their privacy policies before providing personal information.

14. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised "Last Updated" date. We will also notify you of any significant changes through your registered email address or an in-app notification. Your continued use of our Site or services after the effective date of any update constitutes acceptance of the revised policy, to the extent permitted by law.

15. Contact Us

For inquiries or to exercise your rights, contact our Privacy Lead / Grievance Officer at support@flutterby.co. We will acknowledge receipt of your request within 48 hours and resolve it within statutory timelines.