Cookie Policy

Effective date: January 1, 2026

This Cookie Policy explains how Hafinen Limited (“Hafinen”, “we”, “us”, or “our”) uses cookies and similar technologies when you access or use our websites, applications, and related services (collectively, the “Services”).

This Cookie Policy should be read together with our Privacy Policy.

By continuing to use our Services, you acknowledge the use of cookies and similar technologies as described in this Policy, subject to your preferences where required by law.

1. What Are Cookies?

Cookies are small text files stored on your device when you visit a website or use an online service.

Cookies help websites and applications function properly, remember preferences, improve performance, analyze usage, secure accounts, and personalize experiences.

Hafinen may also use similar technologies such as web beacons, local storage, session storage, pixels, device identifiers, and API session tokens.

For simplicity, all such technologies are referred to as “Cookies” in this Policy unless otherwise stated.

2. Why We Use Cookies

We use Cookies to authenticate users, maintain secure sessions, remember user preferences, improve platform performance, analyze product usage, detect fraud and abuse, measure feature adoption, monitor reliability, troubleshoot errors, improve security, support integrations, and manage API sessions.

3. Types of Cookies We Use

A. Strictly Necessary Cookies

These Cookies are essential for the Services to function.

They include login sessions, account authentication, CSRF protection, session continuity, load balancing, and security tokens.

These Cookies cannot be disabled through our Services.

B. Functional Cookies

These Cookies remember settings and preferences.

They include language preferences, timezone settings, theme preferences, interface customizations, and dashboard layout preferences.

C. Analytics Cookies

These Cookies help us understand how users interact with the Services.

This includes page visits, feature usage, user flow analysis, performance bottlenecks, crash tracking, and browser compatibility.

Analytics data may be aggregated or anonymized.

D. Performance Cookies

These Cookies improve speed and reliability.

They include caching behavior, asset optimization, CDN performance, and traffic balancing.

E. Security Cookies

These Cookies help detect suspicious activity, unauthorized access, brute-force attempts, abuse patterns, and API misuse.

F. Communication Cookies

These Cookies support notification delivery, email event tracking, SMS event confirmation, and system communication workflows.

4. Third-Party Cookies and Technologies

Hafinen may allow certain third-party providers to place Cookies or process technical metadata to support the Services.

These may include providers used for cloud hosting, CDN and DDoS protection, email delivery, SMS notifications, payment processing, analytics, and performance monitoring.

A current list of Hafinen’s service providers is available at:

https://www.hafinen.com/subprocessors

Third-party providers may have their own privacy and cookie practices.

5. Session Storage and Local Storage

Hafinen may use browser storage technologies to store authentication states, temporary workflow data, user interface preferences, offline session continuity, and draft records.

These may remain on your device until deleted or expired.

6. API Tokens and Authentication Identifiers

Where Customers use Hafinen APIs or webhooks, Hafinen may issue tokens, identifiers, and session artifacts for API authentication, webhook validation, integration security, rate limiting, and abuse prevention.

These are treated as security-related technologies under this Policy.

7. How to Manage Cookies

Users can manage Cookies through browser settings, device settings, and cookie consent banners where applicable.

Disabling some Cookies may impact functionality.

Examples of impacted features are login persistence, language settings, dashboard preferences, and secure session continuity.

8. Legal Basis for Cookies

Where required by applicable law strictly necessary Cookies are processed based on legitimate interest while optional Cookies may rely on consent.

Users may withdraw consent where applicable.

9. International Data Transfers

Technical metadata collected through Cookies may be processed internationally.

Where applicable, Hafinen implements reasonable safeguards for such transfers.

10. Changes to This Cookie Policy

Hafinen may update this Cookie Policy from time to time to reflect legal changes, technical changes, new integrations, new analytics tools, and new security measures.

Material changes may be communicated through the Services.

11. Contact

Hafinen Limited 107 Lower Kabete Road Westlands, Nairobi, Kenya Email: [email protected]

You can choose which optional cookies Hafinen may use to enhance your experience. Strictly necessary and security cookies are always enabled because they are essential for authentication, platform security, fraud prevention, and the reliable operation of the Services. You can update your preferences at any time.

Strictly Necessary Cookies

These cookies are essential for Hafinen to operate securely and reliably. They support account authentication, login sessions, CSRF protection, secure session continuity, load balancing, and other core platform functionality. Because these cookies are required for the Services to function, they cannot be disabled.

Security Cookies

These cookies help protect your account and the Services by detecting suspicious activity, preventing unauthorized access, mitigating abuse, validating API requests, supporting rate limiting, and maintaining platform integrity. These cookies are required for security and cannot be disabled.

Functional Cookies

Functional cookies remember your preferences and personalise your experience. They may store language, timezone, theme, accessibility settings, interface customisations, and dashboard preferences so you do not need to configure them each time you use the Services.

Analytics Cookies

Analytics cookies help us understand how the Services are used so we can improve usability, performance, and reliability. They collect information such as feature adoption, page interactions, navigation patterns, browser compatibility, crash reports, and performance metrics. Where possible, this information is aggregated or anonymised.

Performance Cookies

Performance cookies improve the speed, stability, and responsiveness of the Services. They support caching, content delivery optimisation, traffic balancing, asset loading, and other technologies that help deliver a consistent and reliable user experience.

Communication Cookies

Communication cookies support service-related interactions such as notification delivery, email event tracking, SMS confirmations, and other operational communication workflows that enhance how we keep you informed while using the Services.