Privacy notice.
This notice explains what personal data VeriTrace AI Technologies Private Limited collects, why we collect it, how long we keep it, and how you can exercise your rights under India's Digital Personal Data Protection Act, 2023.
Contents
1. Who we are and what this covers
VeriTrace AI Technologies Private Limited ("VeriTrace", "we", "us") is a company incorporated in India, with its registered office at Kandi, Sangareddy, Telangana 502284, India. We provide product authentication, serialization and supply-chain traceability software.
This notice covers personal data processed through our website at veritrace.in, our platform console, our consumer verification pages, and our mobile and web scanning applications.
Two distinct roles. This is important and often misunderstood:
- Where we are the Data Fiduciary. For our own marketing website, customer relationship management and business operations, we determine the purpose and means of processing and act as the Data Fiduciary.
- Where we are a Data Processor. When a manufacturer uses our platform to serialize products, the manufacturer is the Data Fiduciary for its customers' data, and we process that data on their documented instructions. If you are a consumer with a query about a product verification, the manufacturer is the appropriate first point of contact.
2. Personal data we collect
2.1 When you visit our website
- Technical data such as IP address, browser type and version, device type, operating system, referring URL and pages viewed.
- Approximate location derived from IP address, used for security and analytics.
- Cookie and similar-technology identifiers, subject to your cookie choices.
2.1.1 Website analytics
We use Google Analytics 4 (provided by Google) to understand how visitors reach and use this website — which pages are read, how long they are viewed, and roughly where visitors are located. This helps us improve the site and decide what content is worth writing. Google Analytics sets first-party cookies in your browser and collects your IP address, device and browser characteristics, and the pages you visit.
We have enabled IP anonymisation, so the full IP address is not stored in the analytics record. We do not use Google Analytics for advertising, we do not enable Google Signals or ad-personalisation features, and we do not attempt to identify individual visitors. Data is retained in Google Analytics for 14 months and then deleted automatically.
Google acts as our data processor for this purpose and may transfer data outside India. You can read Google's practices at policies.google.com/privacy. You can block analytics cookies at any time using your browser's cookie settings or an ad-blocking extension; the site works fully without them.
Note for the site owner: analytics cookies are non-essential processing under the DPDP Act and the EU GDPR. If you advertise to or receive visitors from the EU, add a cookie consent banner and enable Google Consent Mode (a commented block is ready in _partials/head.html).
2.2 When you submit an enquiry or subscribe
- Name, work email address, telephone number and company name.
- The content of your message and any information you choose to include.
- Preferred contact times and communication preferences.
2.3 When you create a platform account
- Name, work email address, telephone number and role within your organisation.
- Company details including GSTIN where you provide it for invoicing.
- Authentication credentials, stored only in hashed form. We never store passwords in plaintext.
- Audit records of account activity, including login times and administrative actions.
2.4 When a consumer verifies a product
This is the area where we have deliberately designed for minimum collection:
- Always collected: the serialized code scanned, the timestamp, and approximate location at city or pin-code level derived from IP address. This is necessary to detect cloned codes and impossible movement paths, which is the core security function of the service.
- Never collected without an active choice: your name, precise GPS location, device advertising identifiers, or any contact detail. A verification scan is fully functional without any of these.
- Collected only if you opt in: mobile number and, where required, name and delivery address, when you choose to claim a reward, register a warranty or submit feedback. In that case we also record the consent you gave and its timestamp.
2.5 When you apply for a role
- Your CV, contact details, employment history and any assessment submissions.
- Interview notes and references, where you provide them.
2.6 What we do not collect
We do not collect sensitive personal data such as health records, biometric identifiers, caste, religious belief or financial account credentials, except where a specific reward payout mechanism requires limited payment details — and then only with your explicit consent and only for the duration of the payout.
3. DPDP Act compliance and consent
We process personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and rules made under it. Our approach rests on the following commitments:
3.1 Lawful basis
We rely on your consent for marketing communications and for any optional data collection, and on legitimate uses permitted under the DPDP Act for the performance of a contract, for compliance with legal obligations, and for responding to medical emergencies or disasters.
3.2 Consent that is actually informed
- Consent requests are presented in clear, plain language, in English and in the relevant Indian language where the interface supports it.
- Every consent request states the specific purpose, the data involved, and how to withdraw.
- Consent is unbundled. You are never forced to accept marketing to use the core service.
- Pre-ticked boxes and consent by silence are not used.
- We maintain a verifiable record of each consent, including what was shown, what was accepted, and when.
3.3 Withdrawing consent
You may withdraw consent at any time with the same ease as you gave it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it does not prevent us from retaining data where a separate legal obligation requires us to. To withdraw, use the mechanism described in section 7 or write to our Data Protection Officer.
3.4 Notice and language
We provide this notice in English. Where a consumer-facing flow collects personal data, we present an itemised notice in the language of the interface, and we make a translation available on request.
4. How and why we use personal data
- To provide the service. Issuing identifiers, recording scans, detecting cloning and diversion, operating consumer verification pages, and processing rewards.
- To respond to you. Answering enquiries, scheduling pilots, and providing support.
- To operate and secure the platform. Authentication, fraud prevention, anomaly detection, capacity planning and incident response.
- To meet legal obligations. Tax and accounting records, GST compliance, responding to lawful requests from authorities, and maintaining audit trails.
- To improve our products. Aggregated, de-identified analysis of how the platform is used. We do not use customer operational data to train shared models.
- To send marketing, only with consent. Product updates and invitations. Every message includes a working unsubscribe link.
We do not sell personal data. We do not rent, trade or share it with advertisers. We do not use consumer verification data for any purpose other than traceability, security and the reward mechanic the consumer opted into.
5. How long we keep data
- Marketing enquiries: 24 months from last contact, then deleted.
- Customer account data: for the duration of the contract, then 12 months, then deleted or returned to the customer.
- Serialization and scan records: retained for the period agreed with the customer manufacturer, typically 7 years, in line with regulatory record-keeping and product liability expectations.
- Consumer reward claims: 24 months, plus the period required by applicable financial and tax law.
- Job applications: 12 months, unless you ask us to keep them longer.
- Audit and security logs: 12 months, or as required for an ongoing investigation.
Where a customer manufacturer specifies a shorter retention period in its contract, that shorter period prevails. Retention is enforced by automated expiry, not by manual review.
6. Sharing and disclosure
We share personal data only in these circumstances:
- With the manufacturer whose product you verified. Where you claim a reward, register a warranty or submit feedback, the relevant manufacturer receives the information you provided, because they are fulfilling the reward or warranty.
- With service providers acting on our instructions. Cloud hosting, payment processing, email delivery and support tooling. All are bound by contract to process data only on our instructions, to maintain confidentiality, and to apply appropriate security measures. We maintain a register of sub-processors and review it annually.
- With authorities where legally required. Where we receive a lawful order or request we are legally obliged to comply with. Where permitted, we will notify the affected customer unless prohibited from doing so.
- In a corporate transaction. In the event of a merger, acquisition or sale of assets, with obligations of confidentiality continued and notice given to affected individuals.
We do not transfer personal data outside India except where a customer explicitly requests it for a specific integration, or where a sub-processor operates outside India and the transfer is permitted by law. Where such a transfer occurs, we apply contractual safeguards and record the basis for the transfer.
7. Your rights
Under the DPDP Act you have the right to:
- Access. Obtain a summary of the personal data we process about you, the purposes, and the categories of parties with whom it has been shared.
- Correction. Request correction of inaccurate or incomplete data, and completion of data that is incomplete.
- Erasure. Request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations.
- Grievance redressal. Raise a complaint with us, and escalate to the Data Protection Board of India if you are not satisfied with our response.
- Nomination. Nominate another individual to exercise your rights in the event of your death or incapacity.
- Withdraw consent. As described in section 3.3.
How to exercise a right. Email our Data Protection Officer at veritrace.ai@gmail.com with the right you wish to exercise and enough information for us to verify your identity. Consumer reward claims can also be managed directly on the verification page where you claimed the reward.
Response time. We acknowledge within 3 working days and respond fully within 30 days. Where a request is complex or involves data we process on behalf of a manufacturer, we will coordinate with them and keep you informed of the delay and the reason.
8. Security and data residency
Personal data is encrypted in transit using TLS 1.3 and at rest using AES-256. Access is governed by role-based permissions with least-privilege defaults, and privileged actions are logged immutably. Staff access to production data requires multi-factor authentication and is recorded.
Serialization records, consumer verification data and backups are stored in data centres located in India by default. On-premises and private-cloud deployments are available for customers with specific residency requirements.
Full detail is available in our security overview. In the event of a personal data breach, we notify affected customers and, where required, the Data Protection Board of India, in accordance with applicable timelines.
9. Children's data
Our services are not directed at children under 18. We do not knowingly process the personal data of children, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If a reward mechanism is accessible to a minor, consent will be sought from a parent or lawful guardian as required by the DPDP Act. If you believe we hold a child's data, write to veritrace.ai@gmail.com and we will delete it.
10. Changes and contact
We may update this notice. When we make a material change, we will revise the version number and effective date at the top of this page, notify account holders by email, and where the change affects a processing purpose that relied on consent, seek fresh consent before applying it.
Data Protection Officer
VeriTrace AI Technologies Private Limited
Kandi, Sangareddy, Telangana 502284, India
Email: veritrace.ai@gmail.com
Grievance officer: [name], veritrace.ai@gmail.com
Grievance escalation. If you are not satisfied with our response, you may escalate to the Data Protection Board of India. If you are a consumer in the European Union and we process your data under the GDPR, you may lodge a complaint with your local supervisory authority.