Important Notice
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Please read it carefully — it describes what personal data we collect when you interact with RESCUQR, why we collect it, how we use it, and your rights as a Data Principal.
1. Who We Are (Data Fiduciary)
RESCUQR is operated by RESCUQR Technologies LLP (“RESCUQR”, “we”, “us”, “our”), a private limited company incorporated under the Companies Act, 2013, with its registered office in Hyderabad, Telangana, India. For the purposes of the DPDP Act, RESCUQR acts as the “Data Fiduciary” in respect of personal data processed through its website, forms, services and the optional medical-ID wristband.
Data Fiduciary: RESCUQR Technologies LLP
Registered Address: Hyderabad, Telangana, India
Grievance Officer & Data Protection Officer: Purohit Sharma
Contact Email: support@rescuqr.in
2. What This Policy Covers
This policy applies to personal data you share with us through:
(a) the partner / onboarding form used by builders, RWAs, gated societies, corporates, schools, colleges and similar organisations to enquire about our community emergency-care service;
(b) the Rescuers waitlist form used by individuals (doctors, paramedics, drivers, organisers, students, volunteers and other supporters) who wish to join the RESCUQR community;
(c) the RESCUQR website at rescuqr.in and any subdomains;
(d) the optional medical-ID wristband and any associated emergency profile, if and when you choose to enrol; and
(e) any direct communication with us (email, phone, in-person calls).
3. Personal Data We Collect
We only collect what we genuinely need. The categories below are illustrative — we do not necessarily collect every item from every person.
3.1 Contact & Identity Data. Full name, organisation / role, designation, email address, phone number, city, and any details you voluntarily share in a form or message. Purpose: responding to your enquiry, scheduling calls, sending you proposals and service updates.
3.2 Community / Site Data (Partner enquiries). Type of organisation, approximate flat / employee / student count, location, current emergency arrangement (if any), preferred deployment model. Purpose: preparing a tailored quote and plan.
3.3 Rescuer Profile Data (Waitlist). Profession or background, areas of interest, city, optional links (e.g., LinkedIn), and free-text responses you choose to share. Purpose: evaluating fit and inviting you to early Rescuer programmes.
3.4 Optional Medical Profile (Wristband users). Blood group, allergies, current medications, relevant conditions, emergency contacts, preferred hospital, and any photograph you upload. This is “sensitive personal data” under Rule 3 of the IT (Sensitive Personal Data) Rules, 2011, and is processed only with your explicit consent, only for the purpose of being displayed during a medical emergency when your QR code is scanned.
3.5 Operational Data (Where service is live). Where you receive our stationed-care service through a partner community, we may also process incident-related operational data — call logs, dispatch records, on-scene notes, hospital handover details — to deliver, account for and audit the service.
3.6 Technical Data. IP address, browser type, device type, language, approximate geolocation derived from IP, and basic analytics events. Purpose: site security, fraud prevention, performance monitoring and service improvement.
3.7 Payment Data (When applicable). Transaction reference, amount, status. We do not store full card numbers, CVVs or UPI PINs. Payments, if any, are processed through RBI-authorised, PCI-DSS-compliant payment gateways.
4. Lawful Basis for Processing
We process personal data under the following lawful bases set out in the DPDP Act:
(a) Consent (Section 6): Where you fill in a form, sign up as a Rescuer or enrol an optional wristband profile, you provide free, specific, informed, unconditional and unambiguous consent through a clear affirmative action (submitting the form).
(b) Certain Legitimate Uses (Section 7): For performing obligations under contracts entered into with partner organisations, for responding to medical emergencies in order to protect the vital interests of a Data Principal, and for complying with applicable law.
5. How We Use Your Data
(a) To respond to enquiries, share proposals and operate the partner / waitlist programmes.
(b) To deliver and operate the community emergency-care service, where you are a resident, member, student or employee of a partner community.
(c) To display the optional medical profile of a wristband user to a bystander or first responder when the QR is scanned during an emergency.
(d) To send service-related communications (confirmations, reminders, updates).
(e) To improve our website and service through aggregated, non-identifying analytics.
(f) To comply with applicable law and respond to lawful requests from courts, regulators or law enforcement.
We do not sell, rent or trade your personal data.
6. Consent & Visibility Controls
(a) Consent is obtained through a clear, unbundled, specific mechanism at the point of collection.
(b) The purpose is communicated in plain language before consent is taken.
(c) You may withdraw consent at any time by emailing support@rescuqr.in. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
(d) For the optional medical wristband, you control which fields are visible on your public scan page through granular toggles (name, age, gender, blood group, conditions, allergies). Emergency contact call buttons remain available because they are essential to the safety function.
7. Sharing With Third Parties (Data Processors)
We work with carefully selected service providers strictly for the purposes stated below. They are contractually bound to process your data only on our instructions and to maintain appropriate security:
(a) Hosting & Infrastructure: Vercel Inc. (website hosting and edge delivery).
(b) Forms & Workflow: Google Forms / Google Workspace, for collecting partner enquiries and Rescuer waitlist submissions and for related email communications.
(c) Payment Gateways (Where applicable): RBI-authorised, PCI-DSS-compliant payment processors. We do not retain card data.
(d) Partner Medical Providers: licensed ambulance operators, hospitals, paramedics, pharmacies and diagnostic partners who form part of the emergency-care network. Sharing is limited to what is necessary to provide care.
(e) Professional Advisors: auditors, lawyers and accountants, where engagement requires.
(f) Law Enforcement / Regulators: where disclosure is required by law, court order, or government directive, including under Section 69 of the IT Act, 2000.
8. Storage & Security
We implement reasonable security practices and procedures as required by the IT (Reasonable Security Practices) Rules, 2011, including:
(a) encryption of sensitive data at rest and TLS encryption in transit;
(b) role-based access control and least-privilege access for our team;
(c) regular access reviews, log monitoring and security patching;
(d) secrets, keys and credentials stored as environment variables and never exposed to client-side code;
(e) rate limits and abuse controls on sensitive operations such as masked calling and emergency-contact dispatch;
(f) periodic backups and tested restore procedures.
No method of electronic storage or transmission is perfectly secure. While we strive to protect your data using industry-standard safeguards, we cannot guarantee absolute security.
9. Data Retention
(a) Enquiry and waitlist data is retained for as long as the relationship is reasonably active, and in any event for not more than 24 months after the last meaningful interaction, unless a longer period is required by law or for a live contract.
(b) Optional medical-profile data is retained for the duration of your active enrolment. On de-registration, it is deleted within 30 days, subject to lawful retention obligations.
(c) Operational records relating to incidents and dispatches are retained as long as required for service audit, regulatory compliance and lawful claims, typically not exceeding 7 years.
(d) Aggregated, anonymised analytics (with no personally identifiable information) may be retained indefinitely.
(e) Financial records (invoices, payment confirmations, GST records) may be retained for up to 8 years as required under the Income Tax Act, 1961 and the Central Goods and Services Tax Act, 2017.
10. Your Rights as a Data Principal
Subject to the DPDP Act, you have the right to:
(a) Access (Section 11): obtain a summary of personal data being processed and the processing activities relating to you.
(b) Correction & Erasure (Section 12): have inaccurate data corrected, completed or updated, and request erasure of data that is no longer necessary for the purpose for which it was collected.
(c) Grievance Redressal (Section 13): raise a grievance with us through the channels set out below.
(d) Nomination (Section 14): nominate another individual to exercise your rights in the event of your death or incapacity.
(e) Withdraw Consent: at any time, with effect from the date of withdrawal.
To exercise any of these rights, email support@rescuqr.in from your registered email address.
11. Children’s Data
In accordance with Section 9 of the DPDP Act, we do not knowingly process personal data of a child (a person below 18 years of age) or of a person with disability without verifiable consent of the parent or lawful guardian. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
12. Personal Data Breach
In the event of a personal data breach we will (a) report the breach to the Data Protection Board of India in accordance with the DPDP Act, (b) notify affected Data Principals without unreasonable delay where required, and (c) take prompt remedial measures to contain and mitigate the breach.
13. Grievance Officer / DPO
If you have a complaint or concern about how your personal data is being processed, please contact us at:
Name: Purohit Sharma
Designation: Founder & Director, Grievance Officer & Data Protection Officer
Organisation: RESCUQR Technologies LLP
Email: support@rescuqr.in
Address: Hyderabad, Telangana, India
Grievances will be acknowledged within 48 hours and addressed within 30 days. If you are not satisfied with the resolution, you may escalate the matter to the Data Protection Board of India as constituted under the DPDP Act.
14. Cross-Border Transfers
Some of our processors (such as hosting providers and form / email services) operate infrastructure outside India. Any such transfers are conducted in compliance with Section 16 of the DPDP Act and only to countries or territories not restricted by the Central Government. We require those processors to maintain adequate data-protection standards through their service agreements and applicable certifications.
15. Cookies & Analytics
The RESCUQR website uses essential cookies needed for security and basic functionality, and may use limited analytics to understand aggregate usage. We do not use cookies to build advertising profiles. You can control cookies through your browser settings.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email (where we have your address) and/or a prominent notice on the website at least 15 days before they take effect. The “Last updated” date at the top reflects the most recent revision.
17. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of India. Any dispute, controversy or claim arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts in Hyderabad, Telangana, India.
For any questions about this Policy, email support@rescuqr.in. You may also review our Terms & Conditions and Refund Policy.