Quesscorp

Privacy Notice

Key definitions

S. No. Term Definition
1
Data
Includes a representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by humans or by automated means, whether in physical or digital form
2
Personal Data
Data about or relating to a natural person who is directly or indirectly identifiable, having regard to any characteristic, trait, attribute, or any other feature of the identity of such natural person, whether online or offline, or any combination of such features with any other information, and shall include any inference drawn from such data for the purpose of profiling. For e.g., name, health data, identification data (Aadhar, PAN, Passport), sexual orientation, financial data (bank account, cheque book etc.), biometric data, genetic data and any other information capable of identifying an individual directly or indirectly
3
Data Fiduciary/ Data Controller
Any person, including the State, a company, any juristic entity, or any individual who alone or in conjunction with others determines the purpose and means of processing of personal data and is responsible for ensuring compliance with applicable data protection laws.
4
Data Principal
Means the individual to whom the personal data relates. This includes any natural person whose personal data is collected, processed, stored, or otherwise handled and where such individual is-
i. a minor, includes the parents or lawful guardian of such a child.
ii. a person with disability, includes their lawful guardian, acting on her behalf
5
Data Processor
Any person, including the State, a company, any juristic entity or any individual, who processes personal data on behalf of a data controller/ fiduciary under valid contractual arrangements and subject to the instructions of the Data Fiduciary.
6
Processing
Any activity in relation to personal data, means an operation or set of operations performed on personal data, and may include operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, use, alignment, or combination, indexing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction whether carried out by automated means or otherwise.
7
Consent Manager
A person registered with the Data Protection Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.
8
Personal Data Breach
Any unauthorized processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the confidentiality, integrity, or availability of personal data and triggers obligations of notification and remediation under applicable law.
9
Cookie
A cookie is a text file stored on a user’s device that allows websites to remember information about the user’s interactions and preferences. These are used to coordinate the information on websites as closely as possible to the preferences of a visitor (such as country and language choices). Further, cookies are used to personalize content and advertisements, to provide social media features and to analyze website traffic and may be managed by the user through browser settings or consent management tools, where applicable
10
Consent
Consent of the data principal means any freely given, specific, informed, and unambiguous indication of the data principal’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Applicable Data Protection Laws

For the purpose of this Policy, “Applicable Data Protection Laws” shall mean all applicable privacy and data protection laws and regulations governing the collection, use, processing, storage, and transfer of personal data, as may be in force in the jurisdictions where Quess operates. This includes, without limitation, the laws listed below, as well as any amendments, re-enactments, or other applicable laws in additional regions where Quess conducts business.

Region Applicable Data Protection Law
India
Digital Personal Data Protection Act, 2023 (DPDP Act)
Malaysia
Personal Data Protection Act 2010 (PDPA)
Singapore
Personal Data Protection Act 2012 (PDPA)
Philippines
Data Privacy Act of 2012
Vietnam
Personal Data Protection Decree (Decree No. 13/2023/ND-CP)
Sri Lanka
Personal Data Protection Act, No. 9 of 2022
Middle East
Applicable national data protection laws, including but not limited to UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, Saudi Personal Data Protection Law (PDPL), and other jurisdiction-specific regulations

Thank you for visiting www.quesscorp.com (the “Website”). This Privacy Notice (“Policy”) aims to inform you about how Quess Corp. Limited (“we,” “us,” or “our”) collects, processes, stores, shares, uses, protects your personal data and outlines and respect your privacy rights. We are committed to ensuring that your personal data is handled in a lawful, fair, and transparent manner.

This Policy applies to, www.quesscorp.com, and any third parties that may store and access your personal data, cookies, IP addresses, and other tracking technologies on a need to know basis. These technologies are used to enable platform functionality, collect aggregated data about website usage, enhance your online experience, maintain security, comply with legal obligations and manage and tailor our advertising and service communications with you.

At Quess Corp Limited, its business units, and subsidiaries (collectively referred to as ‘the Company,’ ‘we,’ ‘our,’ or ‘us’), we collect and process personal data to enhance your experience on our website and services. We use your data to operate, maintain, and improve the functionality, performance, and security of our website and services, ensure smooth operation, improve user experience, and provide relevant communications, including service-related updates and, where permitted, promotional content based on your preferences. Additionally, we comply with legal requirements and prioritize security to protect your information from unauthorized access and breaches.

By understanding these purposes, you can make informed decisions about your interactions with us. We are committed to maintaining your trust and respecting your privacy at all times.

We collect information about visitors to our website. We collect information directly from you, about you from other entities, and automatically as you use our website and our services using cookies and similar technologies. In this privacy notice, unless we distinguish among types of visitors to our website, the scope of information that we collect applies to all visitors to our website.

Information We Collect:

    • Personal Identification Information: Name, email address, phone number, etc and any other identifiers voluntarily provided by you through forms or communications.
    • Technical Data: IP address, browser type, operating system, etc. including device identifiers, location data (where enabled), and log information collected for security and analytics purposes.
    • Usage Data: Information about how you use our website/application which may include pages visited, time spent, navigation patterns, and interaction data, which help us improve functionality and user experience.
    • Cookies and Tracking Technologies: Information collected through cookies and other tracking technologies.

We process your personal data based on the following legal grounds:

Consent:

Affirmative Consent: We process your data when you have explicitly given us permission to do so through clear and affirmative action. This includes situations where you have opted in to receive marketing communications, agreed to participate in surveys, or allowed us to share your data with third parties for specific purposes. You have the right to withdraw your consent at any time, subject to applicable legal or contractual restrictions.

Legitimate Interests

Compliance with Laws and Regulations: We process your data when we are required to do so to comply with applicable laws and regulations. This includes responding to legal requests, such as subpoenas, court orders, or government demands, and maintaining records for tax purposes or regulatory compliance obligations.

Performance of a Contract: We process your data when it is necessary to fulfil our contractual obligations to you. This includes processing your orders, managing your account, providing customer support, and delivering products and services you have requested.

Business Interests: We process your data when it is necessary for our legitimate business interests including purposes recognized as legitimate uses under applicable law, provided these interests do not override your rights and freedoms. This includes improving our services, conducting research and analysis, ensuring the security of our website, and enhancing user experience.

We use your information that we collect for lawful purposes associated with the growth, maintenance and management of our business while also respecting your privacyThese uses include our internal operations and administration, communicating with you and fulfilling your service requests and to improve, develop, enhance, and otherwise provide our services.

More specifically, we use your data to:

  • Facilitate Transactions: To help you buy/sell our products and services and enable secure and efficient processing of such transactions
  • Registration: To process and create your account and manage your access to our services
  • Customer Service: To provide services, respond to inquiries, and offer customer support including resolving complaints and providing assistance.
  • Marketing: To send you information about products and services that may interest you, including those from our affiliates and other entities using permitted tracking technologies and analytics tools.
  • Advertising: To assist in advertising on third-party websites, apps, and online services, and to evaluate our advertising campaigns including enforcement of terms and prevention of misuse.
  • Protect Rights and Interests: To protect our rights and interests, as well as those of other users, and for general business operations.
  • Research and Analytics: To conduct research and analyze data to improve our services, offerings, and user experience.
  • Surveys and Questionnaires: To administer surveys and questionnaires for market research or user satisfaction.
  • Legal Purposes: To respond to requests from law enforcement and for other legal purposes.
  • Fraud Prevention: To prevent fraud, including using automated decision-making. Where applicable, such processing is carried out with appropriate safeguards to protect your rights.
  • Website Improvement: To evaluate and improve our website, including reviewing popular features and user feedback and ensuring optimal functionality, performance, and security
  • For other purposes: We may use Your information for other purposes, such as identifying usage trends, and to evaluate and improve our Service, products, and your experience.

We share your personal data with:

  • Affiliates and Group Companies: Our affiliates may contact you for marketing purposes and help us deliver services, manage your account, and ensure compliance with policies.
  • Service Providers: We share data with couriers, payment providers, IT platforms, fraud detection services, survey providers, product catalogue providers, and customer service suppliers who process such data strictly on our behalf under contractual obligations, ensuring data protection and confidentiality requirements
  • Social media: If you use social media features on our site, your data may be processed by those platforms according to their privacy policies.
  • For Business transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.

We use cookies to enhance your browsing experience, personalize content and ads, provide social media features, and analyse our traffic. Cookies help us understand how you interact with our website, allowing us to improve our services and provide you with a more tailored experience. Such use of cookies and similar tracking technologies is carried out in accordance with applicable law, and where required, based on your consent obtained through cookie banners or preference management tools. For more detailed information on how we use cookies and how you can manage your cookie preferences, Refer to our Cookie Policy for more details.

Quess Corp respects your rights regarding how your personal data is being processed. You have the following rights as a Data Principal regarding the processing of your Personal Information:

  • Right to Access: You have the right to request and obtain a summary of your personal data that we process. This includes information about the purposes of processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data has been or will be disclosed.
  • Right to Correction: You can request the correction of any inaccurate or incomplete personal data. We will take reasonable steps to ensure that any data inaccuracies are rectified promptly based on information provided by you and subject to verification, where required
  • Right to Erasure: You have the right to request the deletion of your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected, or if you withdraw your consent and there is no other legal ground for processing subject to our obligation to retain certain data for legal or regulatory purposes.
  • Right to Withdraw Consent: You have the right to withdraw your consent to the processing of your personal data at any time. Upon such withdrawal, we will cease processing your personal data unless such processing is required or permitted under applicable law. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to Grievance Redressal: If you have any concerns or complaints regarding the processing of your personal data, you have the right to lodge a complaint with our designated grievance officer (DPO). We are committed to addressing your concerns promptly and transparently.
  • Right to Nominate: You can nominate another individual to exercise your data privacy rights on your behalf in case of incapacity or posthumously.
By exercising these rights, you can ensure greater control and transparency over your personal data and may do so by contacting us through the details provided in this Privacy Notice.
Quess is committed to safeguarding your personal data and has a comprehensive data security framework and implements reasonable and appropriate administrative, technical and organizational safeguards designed to protect personal data throughout its lifecycle. We adopt a risk-based approach to data protection, ensuring that security measures are proportionate to the sensitivity and volume of personal data processed. Our measures include:

Technical Measures:

  • Encryption: We use advanced encryption protocols to protect your data during transmission and storage including industry-standard encryption mechanisms and secure communication channels.
  • Access Controls: We employ strict access controls to ensure that only authorized personnel can access your data based on role-based access and the principle of least privilege.
  • Regular Security Audits: We conduct regular security audits and vulnerability assessments to identify and mitigate potential risks and ensure ongoing effectiveness of our security controls.

Organizational Measures:

  • Data Protection Policies: We have established robust data protection policies and procedures to guide our data handling practices.
  • Employee Training: Our employees undergo regular training on data protection and privacy to ensure they understand and comply with our security protocols and confidentiality obligations.
  • Incident Response Plan: We have a detailed incident response plan in place to promptly address any data breaches or security incidents including containment, mitigation, investigation, and remediation procedures.

Monitoring and Reporting:

  • Continuous Monitoring: We continuously monitor our systems for any signs of unauthorized access or data breaches using appropriate detection and alert mechanisms.

Breach Notification:

In the event of a data breach, we will notify the relevant authorities and affected individuals as required by the by applicable privacy laws and regulations, within the timelines and manner prescribed under such laws. By implementing these measures, we aim to protect your personal data from unauthorized access, alteration, disclosure, or destruction, ensuring its confidentiality, integrity, availability, and maintaining a high standard of data security and accountability.
Quess Corp is committed to retaining your personal data only for as long as necessary to fulfil the purposes outlined in this Privacy Statement, or as required by applicable laws and regulations. Our data retention practices include:

Retention Periods:

We retain personal data for the duration necessary to achieve the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements and for the establishment, exercise, or defense of legal claims, where applicable.

In certain circumstances, we may anonymize your personal data so that it can no longer be associated with you and would no longer constitute personal data, in which case we may use this information indefinitely without further notice to you.

Secure Disposal:

When personal data is no longer required, we ensure its secure disposal through appropriate methods such as shredding, degaussing, or secure digital deletion in a manner that prevents unauthorized access, reconstruction, or recovery of such data.

We regularly review our data retention policies to ensure compliance with the latest legal and business requirements and to ensure that personal data is not retained longer than necessary.

Legal and Business Requirements:

We may retain personal data for longer periods if required by law or for legitimate business purposes, such as resolving disputes, enforcing our agreements, or complying with legal obligations or regulatory directives issued by competent authorities.
Quess Corp may transfer your personal data to countries outside India. In these cases, we implement appropriate safeguards, such as Data transfer agreements and standard contractual clauses, to ensure that your personal data is adequately protected and processed in accordance with applicable legal and regulatory requirements, including restrictions notified under the applicable laws.

We are committed to ensuring that your privacy rights are maintained during these transfers, and you may request further information about these safeguards by contacting us directly through the contact details provided in this Privacy Notice.
We do not knowingly collect personal information from minors without proper consent from a parent or legal guardian. If you believe that we may have collected personal information from a minor without the requisite consent, please let us know using the methods described in the “Contact Us” section below and we will investigate and promptly address the issue and take appropriate remedial action. For these purposes, we define a “minor” to mean an individual who is under the age of majority in the territory in which they are resident.

Minors, or their legal guardians, may change or revoke the consent choices previously made or request access to or removal of any personal data that they have provided or posted to Quess sites. Within thirty days of such a request (unless another period is provided by law) We will anonymize or remove from public view such content or take other appropriate action in accordance with applicable law unless legally required to retain such content or information. Such requests may be subject to verification of identity and authority of the requesting individual.
The policy is subject to modification periodically. If we decide to change our policy, we will post those changes along with the effective date. We may notify you of the modifications via email or through portals or other appropriate communication channels, where required under applicable law.

As per applicable data protection laws, you are entitled at any time to access, rectify or delete your personal data, as well as to object for legitimate purpose. In addition, you have the right to receive personal data relating to you which you have provided to us directly. These rights may be exercised, by you by sending an email to privacy@quesscorp.com.

Data Protection Officer/Grievance Officer:

In case you have any complaints and/or grievances in relation to the processing of your personal information please send your complaints via e-mail to our Data Protection Officer:
Data Protection Officer
Quess Corp Limited
Bangalore
Email: privacy@quesscorp.com
Scroll to Top