Skip to content
Legal

Privacy Policy

This policy explains what personal data Caddy Limited (“Caddy”, “we”, “us”) collects when you use our website and services, why we collect it, and the rights you have over it.

Last updated · 1 July 2026

This page is provided for general information and is a starting template. It is not legal advice. Caddy Limited will tailor and finalise these terms with qualified counsel before relying on them; please confirm the current version with us at hello@caddy.finance.

01Who we are

Caddy Limited operates the Caddy servicing layer for onchain yield — the agentic layer between yield protocols and institutional systems. We are the data controller for personal data processed through this website and our business operations. We operate from UAE and EU and USA. You can reach us at hello@caddy.finance for any privacy matter, including to reach our data protection contact.

Important: Caddy is read-only by design and never holds client funds or signs a transaction. Where we provide infrastructure to a regulated institution, that institution is typically the controller for end-user and position data, and we act as a processor on their instructions.

02Data we collect

Information you give us

  • Contact & access requests: name, work email, company, role and any message you send when you request access, contact us, or subscribe to updates.
  • Business & onboarding details: information exchanged with prospective and active institutional partners during evaluation, contracting and integration.

Information we collect automatically

  • Usage & device data: IP address, browser and device type, pages viewed, referring URLs and similar diagnostics, collected via cookies and analytics.
  • Operational logs: security, performance and audit logs generated when our services run, which may include identifiers and metadata but are designed to avoid unnecessary personal data.

We do not seek to collect special-category personal data through this website, and we ask that you not send it to us unsolicited.

03How we use your data

  • To respond to enquiries and process access requests.
  • To provide, operate, secure and improve our website and services.
  • To send product and company updates you have asked to receive (you can unsubscribe at any time).
  • To meet legal, regulatory, audit and reporting obligations that apply to us and to the institutions we serve.
  • To detect, investigate and prevent fraud, abuse and security incidents.

04Legal bases for processing

Where the EU/UK GDPR applies, we rely on one or more of the following bases: your consent (e.g. marketing emails); the performance of a contract or steps taken at your request; our legitimate interests in running, securing and growing our business (balanced against your rights); and legal obligation where the law requires us to process data.

05Cookies & analytics

We use a small number of cookies and similar technologies to make the site work and to understand aggregate usage. Analytics may be provided by third parties such as Google Analytics. You can control cookies through your browser settings; disabling some cookies may affect site functionality.

06Sharing your data

We share personal data only as needed, and never sell it. Recipients may include:

  • Service providers: hosting, analytics, email, security and infrastructure vendors acting under contract on our behalf.
  • Partners & institutions: where you engage with us through a regulated counterparty, and as needed to deliver agreed services.
  • Authorities & advisers: regulators, auditors and professional advisers where required by law or to establish, exercise or defend legal claims.
  • Corporate transactions: an acquirer or successor in a merger, financing or sale of assets, subject to this policy.

07International transfers

We operate across multiple jurisdictions, including the EU and India, so your data may be transferred and processed outside your country. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses or an equivalent legal mechanism.

08Data retention

We keep personal data only for as long as necessary for the purposes described above, including to satisfy legal, accounting, audit and regulatory requirements. When data is no longer needed, we delete or anonymise it.

09Your rights

Subject to your jurisdiction, you may have rights to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent. To exercise any right, contact hello@caddy.finance. You also have the right to complain to your local data protection authority.

10Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls and audit logging. No system is perfectly secure, but protecting data is core to how Caddy is built.

11Changes to this policy

We may update this policy from time to time. We will post the revised version here and update the “last updated” date above. Material changes will be highlighted where appropriate.

Questions about this policy? Contact us at hello@caddy.finance.