Privacy Policy
Last Updated: July 16, 2026 | QRitagya LLP, 713, Devika Tower, Nehru Place, New Delhi – 110 019 | info@qritagya.com
QRitagya LLP ("QRitagya", "we") handles personal data in compliance with India's Digital Personal Data Protection Act, 2023 ("DPDPA") and, where applicable, the EU GDPR. By using our website, QR tags, or Services you consent to this Policy. If you disagree, do not proceed.
-
1. Our Role and Scope
QRitagya links a unique QR tag to a registered owner and, on scan, delivers the scan event — tag identifier, precise location, and date-time stamp — to the owner so they can recover their item. Thereafter, owner and finder communicate directly; QRitagya is not a party to that conversation. We are Data Fiduciary (DPDPA) / Controller (GDPR) only for registration data, scan-event data, and consent records.
-
2. Precise Location Is the Purpose of the Service
QRitagya's essential function is to tell an item's owner where their item was scanned. Precise location is intrinsic to the Service. We deliberately do not use approximate or network/ISP-based location.
- Before you scan, the tag and/or landing screen states that scanning shares the item's location with its owner.
- Scanning is voluntary; there is no obligation to scan or to contact an owner.
- By choosing to scan after this notice, you knowingly consent to sharing the scan location with the owner for item recovery.
- Location is captured only at the instant of a scan — never continuously or in the background.
- If your device or browser blocks location, the scan cannot fulfil its purpose and no location is shared.
-
3. Data We Collect
- Owner registration data: phone number (WhatsApp Business), optionally name/email.
- Scan-event data: precise location, tag ID, date-time stamp — on a voluntary scan.
- Finder data: scan location/time; contact details ONLY if the finder chooses.
- Technical data: IP and basic device info for security.
- Website: strictly-necessary cookies only. No advertising or tracking cookies.
-
4. Legal Basis
Data Purpose Legal Basis Owner contact Link tag; send alerts Consent Scan location Tell owner where item was found Informed consent via voluntary, pre-notified scan Scan-event (tag ID, time) Enable recovery Consent + legitimate use Finder contact Let owner reach finder Explicit finder consent Technical/IP Security, abuse prevention Legitimate use -
5. How We Use Your Data
- Link your tag to you and alert you on scan.
- Deliver scan-event data (precise location, tag ID, timestamp) to the owner.
- Facilitate the initial owner-finder connection.
- Secure the platform and prevent abuse.
-
6. Sharing Your Data
- With the tag owner: scan-event data, including the scan location.
- Contact details: shared only to the extent each party chooses.
- Sponsors: identity shown to users; they receive only aggregated, non-identifiable insights.
- Processors: Meta (WhatsApp Business API) and AWS (hosting).
- Law enforcement/government: under due legal process. We do not sell personal data.
-
7. International Data Transfers
Meta (WhatsApp Business API) and AWS may process/store data outside India and the EU. We rely on contractual data-protection commitments and applicable safeguards (including GDPR Standard Contractual Clauses where relevant). (AWS Region: ap-south-1, Mumbai).
-
8. Finder Data
Finders are data principals. When a finder voluntarily scans a tag — having been told scanning shares the item's location — we process the scan location and timestamp for recovery. Finder contact details are shared with the owner only if the finder chooses. Finders may request deletion via info@qritagya.com.
-
9. Data Retention
- Owner registration data: while tag is active + 12 months after deactivation.
- Scan-event & location data: 90 days, then deleted or anonymised.
- Finder contact data: 30 days after interaction, then deleted.
- Consent records: as long as legally required to demonstrate compliance.
-
10. Your Rights
Under DPDPA (and GDPR where applicable): access, correct, update, erase; withdraw consent; nominate a representative; file a grievance. GDPR-covered individuals also have portability and objection rights. Contact info@qritagya.com; we respond within statutory timeframes.
-
11. Security & Breach Notification
We apply reasonable technical and organisational measures (encryption in transit, access controls) on AWS. On any personal-data breach we notify the Data Protection Board of India and affected principals as required by DPDPA, and (where GDPR applies) the supervisory authority within 72 hours of awareness.
-
12. Children
Services are strictly for individuals aged 18+. We do not knowingly onboard minors or collect their data; any such data found will be deleted.
-
13. Grievance Officer / DPO
Grievance Officer / DPO: QRitagya Legal Team, QRitagya LLP, 713, Devika Tower, Nehru Place, New Delhi – 110 019. Email: dpo@qritagya.com. If unresolved, you may approach the Data Protection Board of India.
-
14. Changes & Governing Law
We may update this Policy and notify you via website/WhatsApp; continued use implies acceptance. Governed by Indian law; exclusive jurisdiction: courts of New Delhi.