Legal
Acceptable Use Policy
Rules for using Qrynto
Last updated: 2026-04-24
ACCEPTABLE USE POLICY
Last Updated: April 2026
This Acceptable Use Policy (“AUP”) governs the use of the Qrynto platform (“Platform”) provided by Qrynto Innovations Private Limited (“Company”). This AUP forms part of the Terms of Service and applies to all users, including Brand Clients, Supply Chain Partners, and Consumers. Violation of this AUP may result in suspension or termination of your access to the Platform.
1. PERMITTED USE
The Platform is intended solely for lawful product authentication, anti-counterfeiting, supply chain tracking, and related business purposes. Users may:
Generate, activate, and manage QR codes for legitimate product authentication.
Use the verification interface to check the authenticity of products.
Access analytics, dashboards, and reports for business intelligence and product monitoring.
Integrate with the Platform APIs in accordance with the API documentation and usage limits.
Manage supply chain data for products registered on the Platform.
2. PROHIBITED ACTIVITIES
You shall not, directly or indirectly, engage in any of the following activities:
2.1 Unlawful and Fraudulent Use
Using QR codes generated through the Platform on counterfeit, pirated, illegal, or prohibited products.
Misrepresenting the authentication status, origin, or quality of any product.
Creating fraudulent verification results or manipulating scan data.
Using the Platform to facilitate any form of fraud, deception, or misrepresentation to consumers or regulatory authorities.
2.2 Technical Abuse
Attempting to reverse-engineer, decompile, disassemble, or derive the source code of any part of the Platform.
Circumventing or disabling any security, authentication, or access control mechanisms.
Deploying automated bots, scrapers, crawlers, or similar technologies to access the Platform or its APIs without express written permission.
Deliberately overloading the Platform infrastructure, including denial-of-service attacks or excessive API calls beyond permitted rate limits.
Uploading or transmitting malicious code, viruses, worms, Trojans, ransomware, or other harmful software.
2.3 Data Misuse
Collecting, harvesting, or aggregating personal data of Consumers or other users beyond what is necessary for the stated purpose and permitted under the Platform’s Privacy Policy.
Selling, sharing, or disclosing Verification Data or Consumer information to third parties not authorised under the Terms of Service.
Using Consumer scan data for purposes unrelated to product authentication, such as unsolicited marketing, profiling, or surveillance, without appropriate consent.
Failing to comply with applicable data protection laws when processing personal data obtained through the Platform.
2.4 Intellectual Property Violations
Using the Platform to infringe the intellectual property rights of any third party, including trademarks, patents, or copyrights.
Reproducing, distributing, or creating derivative works from the Platform or its components without written authorisation.
Removing or altering any proprietary notices, labels, or branding on the Platform.
2.5 Interference and Disruption
Interfering with the Platform’s operation, performance, or availability for other users.
Attempting to access accounts, data, or systems belonging to other users without authorisation.
Transmitting spam, unsolicited communications, or excessive requests through the Platform.
3. API USAGE AND RATE LIMITING
Brand Clients and their authorised integrators using the Platform APIs shall additionally comply with the following:
Respect all published rate limits and usage quotas. The Company enforces rate limiting on all API endpoints. Exceeding rate limits may result in temporary throttling, and persistent abuse may lead to permanent suspension of API access.
Authenticate all API requests using valid API keys issued by the Company. API keys are confidential and must not be shared, published, or embedded in client-side code.
Do not use the API to build a competing product or service, or to replicate core Platform functionality.
Ensure that all API integrations handle errors gracefully and do not generate excessive retry loops that could be interpreted as a denial-of-service attack.
The Company reserves the right to modify rate limits, introduce new usage tiers, or revoke API access at any time with reasonable notice. Current rate limits are published in the API documentation.
4. MONITORING AND ENFORCEMENT
4.1 Monitoring
The Company monitors Platform usage to ensure compliance with this AUP. Monitoring may include automated analysis of API call patterns, scan volumes, account activity, and system logs. The Company will not access the content of Brand Client data except as necessary to investigate a suspected violation or as required by law.
4.2 Enforcement Actions
Upon identifying a violation of this AUP, the Company may, at its sole discretion, take one or more of the following actions:
Issue a written warning specifying the nature of the violation and corrective measures required.
Temporarily suspend access to the Platform or specific features pending investigation.
Permanently terminate the user’s account.
Remove or disable QR codes associated with prohibited use.
Report violations to law enforcement or regulatory authorities where required or appropriate.
Pursue legal remedies, including claims for damages.
4.3 Notice and Opportunity to Cure
Except in cases of severe or urgent violations that pose an immediate risk to the Platform, its users, or the public, the Company will provide written notice of the alleged violation and a reasonable opportunity (not exceeding fifteen (15) days) to cure the violation before taking enforcement action.
5. SECURITY VULNERABILITY REPORTING
The Company is committed to maintaining the security of the Platform and values the contributions of security researchers and the broader community in identifying potential vulnerabilities.
If you discover a security vulnerability in the Platform, please report it responsibly to [email protected]. When reporting, please include a detailed description of the vulnerability, steps to reproduce, and any relevant evidence. The Company encourages responsible disclosure and will work promptly to investigate and resolve reported issues.
The Company will not pursue legal action against individuals who report vulnerabilities in good faith, provided that: (a) the reporter does not exploit the vulnerability beyond what is necessary to demonstrate it; (b) the reporter does not access, modify, or delete data belonging to other users; and (c) the reporter does not publicly disclose the vulnerability before the Company has had a reasonable opportunity to address it.
6. REPORTING VIOLATIONS
If you become aware of any activity that violates this Acceptable Use Policy, please report it to [email protected]. All reports will be treated confidentially and investigated promptly. The Company encourages responsible reporting and will not take adverse action against users who report violations in good faith.
7. CHANGES TO THIS POLICY
The Company reserves the right to modify this Acceptable Use Policy at any time. Changes will be communicated through the Platform or via email. Continued use of the Platform after the effective date of changes constitutes acceptance of the revised AUP.
8. CONTACT INFORMATION
For questions about this Acceptable Use Policy:
Qrynto Innovations Private Limited
[Registered Address]
Security: [email protected]
General: [email protected]