Q Logo

Privacy Policy

Last Updated: August 17, 2026

1. Introduction & Scope

QuantiFyd ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, use our services, or interact with us.

This Privacy Policy has been prepared to meet the requirements of:

  • The General Data Protection Regulation (GDPR) for individuals residing in the European Union (EU) and European Economic Area (EEA).
  • The Digital Personal Data Protection (DPDP) Act, 2023 of India for individuals residing in India.

2. Personal Data We Collect

We collect personal data that you voluntarily provide to us and data that is automatically recorded.

2.1 Data You Provide Directly

We collect and process different data points depending on whether you register as an individual user or a business/corporate entity:

(A) Individual Users (Candidates/Learners)

Data FieldPurpose & Processing Activities
Full NameTo address you professionally, authenticate your identity, and customize your experience.
Email AddressTo create your user account, deliver platform access details, send notifications, and provide support.
Phone NumberCollected when you contact us or submit support inquiries to resolve your requests.

(B) Business/Corporate Users (Firms & Organizations)

Data FieldPurpose & Processing Activities
First Name & Last NameTo manage organization admin/staff profile details.
Email AddressTo manage the primary admin account and authenticate access to organizational panels.
Company NameTo set up the workspace container for your organization.
AddressFor business validation, invoicing, and billing compliance.
Contact EmailFor corporate communications, invoicing, receipts, and billing updates.
Phone NumberTo communicate regarding business relations, support inquiries, and platform setup.
Company LogoFor white-label workspace branding and customized certificate/report generation.

2.2 Data Collected Automatically

When you navigate our website or dashboard, we automatically gather:

  • Internet Protocol (IP) address.
  • Browser type, language, and version.
  • Operating system and device metadata.
  • Usage statistics, clickstream data, pages viewed, time spent, and referral sources.

This data is collected using cookies and tracking technologies (see Section 5).

3. Consent & Processing of Email Address

We process your email address based on your explicit, affirmative consent (under both GDPR Article 6(1)(a) and DPDP Section 6) or to fulfill a contract/address pre-contractual requests.

Consent for Email Collection: When you provide your email address (e.g., through our "Contact Us" forms or account registration), you must actively check a consent box. This consent covers the use of your email to resolve your query and contact you with relevant information.

3.1 Right to Withdraw Consent

You have the right to withdraw your consent to email communications and processing at any time.

  • Marketing Emails: You can unsubscribe from marketing emails instantly by clicking the "Unsubscribe" link in any marketing email we send.
  • All Data Processing: You can withdraw consent for any processing of your email or other personal data by emailing us at info@quantifyd.com.

Note: Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal. If you withdraw consent, we may not be able to address your ongoing support requests or provide access to the platform.

4. GDPR Compliance (EU & EEA Residents)

If you are a resident of the European Union (EU) or the European Economic Area (EEA), you have specific rights under the General Data Protection Regulation (GDPR). For these processing activities, QuantiFyd acts as the Data Controller.

4.1 Legal Bases for Processing

We process your personal data under the following legal bases:

  • Consent (GDPR Art. 6(1)(a)): You have given clear consent for us to process your data for a specific purpose (e.g., email newsletter or query resolution).
  • Performance of a Contract (GDPR Art. 6(1)(b)): Processing is necessary for a contract we have with you, or to take steps before entering into one.
  • Legitimate Interests (GDPR Art. 6(1)(f)): Processing is necessary for our legitimate business operations, such as security, optimization, and website analytics, provided these do not override your fundamental rights.

4.2 Your Rights under GDPR

You have the following rights which you can exercise at any time:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data when it is no longer needed or if consent is withdrawn.
  • Right to Restriction of Processing: Request that we limit the processing of your data under specific circumstances.
  • Right to Data Portability: Request that we transfer your data to another controller in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw your consent at any time.

To exercise these rights, please email us at info@quantifyd.com. We will respond to your request within 30 days.

4.3 International Data Transfers

Your personal data may be transferred to and processed in countries outside the EU/EEA (such as India or the United States) where our servers are hosted. We ensure appropriate safeguards (such as Standard Contractual Clauses approved by the European Commission) are in place to secure your data.

4.4 Right to Complain to a Supervisory Authority

If you believe our processing of your personal data violates the GDPR, you have the right to lodge a complaint with your local Supervisory Authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

5. DPDP Act Compliance (Indian Residents)

If you reside in India, your personal data is protected under the Digital Personal Data Protection (DPDP) Act, 2023. For the purposes of the DPDP Act, you are the Data Principal, and QuantiFyd is the Data Fiduciary.

5.1 Processing Notice

This Privacy Policy serves as the notice required under Section 5 of the DPDP Act. We process personal data only for lawful purposes based on your explicit consent or for specific legitimate uses allowed under Section 7 of the Act.

Notice Translation: In accordance with the DPDP Act, if you require this notice or consent request to be made available in any of the 22 regional languages specified in the Eighth Schedule to the Constitution of India, please contact us at info@quantifyd.com.

5.2 Rights of the Data Principal

Under the DPDP Act, you have the following rights:

  • Right to Access: Access a summary of the personal data being processed, identity of other Data Fiduciaries with whom it is shared, and details of processing.
  • Right to Correction, Completion, and Erasure: Request the correction of inaccurate data, completion of incomplete data, and deletion of data that is no longer necessary for the purpose for which it was collected.
  • Right to Grievance Redressal: The right to register grievances with our Grievance Officer regarding any act or omission by us regarding your personal data.
  • Right to Nominate: The right to nominate another individual to exercise your rights under the Act in the event of death or incapacity.

To exercise any of these rights, please email us at info@quantifyd.com with your request.

5.3 Consent Managers

Under Section 6(7) of the DPDP Act, you may give, manage, review, or withdraw your consent through a registered Consent Manager. When registered Consent Manager frameworks are fully operationalized by the Government of India, we will integrate support for you to manage your consent through them.

5.4 Grievance Redressal Officer

If you have any questions, concerns, or grievances regarding the processing of your personal data under the DPDP Act, please contact our designated Grievance Officer. You must exhaust our internal grievance redressal mechanism before filing a complaint with the Data Protection Board of India.

Designation: Data Protection Grievance Officer

Email: info@quantifyd.com

Address: Uttarakhand, India

Response Timeline: We will acknowledge your grievance within 48 hours and attempt to resolve it within 7 business days.

5.5 Right to Complain to the Data Protection Board of India (DPBI)

If your grievance is not resolved to your satisfaction through our internal grievance redressal mechanism, or if you believe there has been a breach of compliance by us, you have the right to file a complaint directly with the Data Protection Board of India (DPBI) in the manner prescribed by the Board.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to monitor usage and improve our services. The types of cookies we use include:

Necessary / Essential Cookies

Type: Session Cookies

Purpose: Essential for providing services and ensuring security and authentication.

Cookies Policy / Notice Acceptance Cookies

Type: Persistent Cookies

Purpose: Identifies users who have accepted or customized our cookie and tracking policy.

Functionality & Analytics Cookies

Type: Persistent Cookies

Purpose: Stores preferences (such as login details or language settings) and tracks anonymous traffic logs to improve our landing page speed and relevance.

You may adjust your browser settings to reject cookies, but this may limit some functionalities of our website.

7. Security Measures

We take precautions to protect your data by implementing industry-standard security protocols, including:

  • Encryption of data transferred via HTTPS using Secure Sockets Layer (SSL)/TLS protocols.
  • Regular security audits and restricted access to personal data to authorized personnel only.
  • Confidentiality and non-disclosure agreements with employees, contractors, and partners.

While we strive to protect your data, no method of transmission over the internet or storage is 100% secure. We work to ensure your information is protected but cannot guarantee absolute security.

8. Data Retention Period

We retain your personal data only as long as is necessary for the purposes outlined in this Privacy Policy, to comply with statutory audits, or as required by law.

  • Inquiry Data: Retained for a maximum of 12 months after the query is closed, unless a customer relationship is established.
  • Account Data: Retained for the duration of your active account subscription and deleted/anonymized within 180 days of account termination (unless required otherwise by legal or tax obligations).
  • Billing & Financial Records: Retained for 7 years in compliance with tax laws.

9. Policy Updates

We may update this Privacy Policy from time to time. When changes occur, we will:

  • Post the updated policy on this page with the modified date.
  • Notify you via email or through a prominent notice on our service before changes take effect.

We recommend reviewing this policy periodically. Your continued use of our services following updates constitutes acknowledgement of the updated terms.