Legal
Privacy Policy
How Qrynto protects your data
Last updated: 2026-04-24
PRIVACY POLICY
Last Updated: April 2026
This Privacy Policy (“Policy”) describes how Qrynto Innovations Private Limited (“Company”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal information through the Qrynto platform (“Platform”). This Policy applies to all users of the Platform, including Brand Clients, Supply Chain Partners, and Consumers.
We are committed to protecting your privacy and handling your personal information in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 (“DPDP Act”), and, where applicable, the General Data Protection Regulation (“GDPR”) of the European Union.
1. INFORMATION WE COLLECT
1.1 Brand Client Information
Business name, registration details, and tax identification numbers (GST/PAN)
Contact details of authorised personnel (name, email, phone number, designation)
Billing and payment information processed through authorised payment gateways
Product catalogue data, batch information, and manufacturing details
API access credentials and integration configuration data
Account activity logs and Platform usage patterns
1.2 Consumer Information (Collected During QR Code Scans)
Approximate geolocation at the time of scan (derived from IP address or device GPS, if permitted)
Device type, operating system, and browser information
Date, time, and frequency of scans
IP address
Optional information voluntarily provided by the Consumer, such as name or email, if the Consumer chooses to register a warranty or participate in a brand programme
1.3 Supply Chain Partner Information
Business name and registration details
Contact details of authorised personnel
Dispatch, logistics, and product movement data entered into the Platform
1.4 Automatically Collected Information
Server logs, including IP addresses, access times, pages viewed, and referring URLs
Cookies and similar tracking technologies (see Section 7)
Device identifiers and technical configuration data
2. PURPOSE OF DATA COLLECTION
We collect and process personal information for the following purposes:
Providing and maintaining the Platform Services, including QR code generation, activation, and verification.
Authenticating products and generating verification reports for Brand Clients.
Processing subscriptions, invoices, and payments.
Providing analytics, dashboards, and reports on scan activity and product verification trends.
Detecting and preventing fraud, abuse, and unauthorised use of the Platform.
Communicating with users regarding account matters, service updates, and technical support.
Improving and enhancing the Platform through aggregated and anonymised usage analysis.
Complying with legal obligations and responding to lawful requests from governmental authorities.
3. LEGAL BASIS FOR PROCESSING
We process personal data on the following legal bases:
Consent: Where you have provided explicit consent, such as opting into marketing communications or voluntarily providing information during a QR scan.
Contractual Necessity: Processing necessary to fulfil our contractual obligations to Brand Clients and Supply Chain Partners.
Legitimate Interest: Processing necessary for the legitimate interests of the Company, including fraud prevention, platform security, and service improvement, provided such interests are not overridden by your fundamental rights.
Legal Obligation: Processing required to comply with applicable laws and regulations.
4. DATA SHARING AND DISCLOSURE
4.1 Sharing with Brand Clients
Verification Data generated by Consumer scans of a Brand Client’s QR codes is shared with the relevant Brand Client in aggregated or individual form as part of the Platform Services. This data enables Brand Clients to monitor product authenticity and distribution.
4.2 Third-Party Service Providers
We may share personal information with trusted third-party service providers who assist in operating the Platform, including cloud hosting providers, payment processors, analytics services, and customer support tools. These providers are contractually obligated to process data only as instructed by us and to maintain appropriate security measures.
4.3 Legal Requirements
We may disclose personal information if required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, the safety of our users, or the public.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal information may be transferred to the successor entity, subject to the same privacy protections described in this Policy.
5. DATA RETENTION
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy or as required by law. Specific retention periods are as follows:
Brand Client account data: Retained for the duration of the subscription and for three (3) years thereafter for legal and compliance purposes.
Consumer scan data: Retained for up to two (2) years from the date of the scan, or longer depending on the Brand Client’s subscription plan or applicable legal requirements.
Billing and payment records: Retained for eight (8) years in accordance with Indian tax and accounting regulations.
Server logs: Retained for twelve (12) months.
Upon expiry of the retention period, personal data is securely deleted or anonymised.
6. DATA SECURITY
We implement industry-standard technical and organisational measures to protect personal information, including:
Encryption of data in transit using TLS 1.2 or higher.
Encryption of data at rest using AES-256 encryption.
Role-based access controls and multi-factor authentication for administrative access.
Regular security assessments and vulnerability testing.
Secure cloud infrastructure hosted on reputable providers with SOC 2 and ISO 27001 certifications.
Incident response procedures with notification protocols in the event of a data breach.
Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security and shall not be liable for breaches beyond our reasonable control.
7. COOKIES AND TRACKING TECHNOLOGIES
The Platform uses cookies and similar technologies for the following purposes:
Essential Cookies: Required for Platform functionality, authentication, and session management.
Analytics Cookies: Used to understand usage patterns and improve the Platform. These may include third-party analytics tools.
Preference Cookies: Used to remember user preferences and settings.
You may control cookie preferences through your browser settings. Disabling essential cookies may impair Platform functionality.
8. YOUR RIGHTS
8.1 Under Indian Law (DPDP Act, 2023)
As a Data Principal, you have the right to:
Access information about the personal data we hold about you.
Request correction of inaccurate or incomplete personal data.
Request erasure of your personal data, subject to legal retention requirements.
Withdraw consent where processing is based on consent.
Nominate a representative to exercise your rights in the event of your incapacity or death.
Lodge a grievance with our Grievance Officer or with the Data Protection Board of India.
8.2 Under GDPR (for EEA Residents)
If you are a resident of the European Economic Area, you additionally have the right to:
Data portability: Receive your personal data in a structured, commonly used format.
Restrict processing of your personal data in certain circumstances.
Object to processing based on legitimate interests.
Lodge a complaint with a supervisory authority in your jurisdiction.
To exercise any of these rights, contact us at [email protected]. We will respond within thirty (30) days of receiving a verifiable request.
9. INTERNATIONAL DATA TRANSFERS
The Platform is hosted on cloud infrastructure that may involve the storage or processing of data in jurisdictions outside India. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms recognised under applicable law.
10. CHILDREN’S PRIVACY
The Platform is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete such data promptly.
11. GRIEVANCE OFFICER
In accordance with the Information Technology Act, 2000, and the DPDP Act, 2023, we have appointed a Grievance Officer to address concerns regarding the processing of personal data:
Name: Sajan Saran, Founder
Email: [email protected]
Address: [Company Address]
The Grievance Officer will acknowledge your complaint within 48 hours and resolve it within thirty (30) days of receipt.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform at least thirty (30) days before they take effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
13. CONTACT US
For questions or concerns about this Privacy Policy, please contact:
Qrynto Innovations Private Limited
[Registered Address]
Privacy: [email protected]
General: [email protected]