Important Notice
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It explains what personal data we collect when you interact with RESCUQR, why, how we use and protect it, and your rights as a Data Principal. Your emergency medical information is “sensitive personal data” and is handled with heightened care.
1. Who We Are (Data Fiduciary)
RESCUQR is operated by RESCUQR Technologies Private Limited (“RESCUQR”, “we”, “us”, “our”), a company incorporated under the Companies Act, 2013, with its registered office in Hyderabad, Telangana, India. For the purposes of the DPDP Act, RESCUQR is the “Data Fiduciary” for personal data processed through its Site, products, emergency profiles, call line and Quick Response Team operations.
Data Fiduciary: RESCUQR Technologies Private Limited
Registered Address: Opposite IKEA, Plot No. 18/2, Sector-III, HUDA Techno Enclave, HITEC City, Hyderabad, Telangana 500081
Grievance Officer & Data Protection Officer: Purohit Sharma
Contact: support@rescuqr.in | +91 77310 88893
2. Personal Data We Collect
We collect only what we genuinely need. The categories below are illustrative — we do not necessarily collect every item from every person.
2.1 Identity & Contact Data. Name, phone number, email, city, and account credentials. Purpose: creating and operating your account, orders and communications.
2.2 Emergency Profile (sensitive personal data). Blood group, allergies, medical conditions, medications, treating doctor, preferred hospital, emergency-contact names and numbers, and any photo you add. This is “sensitive personal data” under Rule 3 of the IT (Sensitive Personal Data) Rules, 2011, and is processed only with your explicit consent and only to be shown to a verified bystander / first responder and our Quick Response Team during a medical emergency.
2.3 Scanner Data. When someone scans your code, we collect the Scanner’s name, phone number, OTP-verification status, time, and any location they choose to share via “alert family”. Purpose: authenticating access, enabling coordination, and maintaining a security / audit log.
2.4 Incident & Coordination Data. Quick Response Team call logs, actions taken, and hospital / ambulance coordination notes. Purpose: delivering, auditing and improving the response.
2.5 Order & Payment Data. Products purchased, delivery address, and transaction reference / amount / status. We do not store full card numbers, CVVs or UPI PINs; payments are processed through an RBI-authorised, PCI-DSS-compliant payment gateway.
2.6 Technical Data. IP address, device / browser type, and basic analytics events. Purpose: site security, fraud prevention and performance.
3. Lawful Basis for Processing
(a) Consent (Section 6, DPDP Act): your free, specific, informed and unambiguous consent given through a clear affirmative action (creating a profile, placing an order, submitting a form).
(b) Certain Legitimate Uses (Section 7, DPDP Act): to protect the vital interests of a Data Principal in a medical emergency, to perform obligations under a contract, and to comply with applicable law.
4. How We Use Your Data
(a) To display your approved emergency information to a verified Scanner and our Quick Response Team during an emergency;
(b) to enable calling of, and alerts to, your emergency contacts, and to share location;
(c) to coordinate hospitals and ambulances through partners;
(d) to fulfil orders and provide support;
(e) to secure, operate and improve the Services through aggregated, non-identifying analytics; and
(f) to comply with applicable law and respond to lawful requests from courts, regulators or law enforcement.
We do not sell, rent or trade your personal data.
5. Consent & Visibility Controls
(a) Consent is obtained through a clear, unbundled, specific mechanism at the point of collection, after the purpose is stated in plain language.
(b) You may withdraw consent at any time by emailing support@rescuqr.in. Withdrawal is prospective and does not affect processing carried out before the withdrawal.
(c) You control which fields are visible on your public scan page; emergency-contact calling remains available because it is essential to the safety function.
6. Sharing With Third Parties (Data Processors)
We share data only as necessary, with service providers who are contractually bound to process it only on our instructions and to maintain appropriate security:
(a) Hosting, infrastructure & database providers (website delivery and secure data storage);
(b) SMS / OTP and voice-calling providers (verification and emergency communications);
(c) Payment gateways — RBI-authorised, PCI-DSS-compliant processors; we do not retain card data;
(d) Hospital, ambulance and first-responder partners, limited to what is necessary to provide help;
(e) Professional advisors (auditors, lawyers, accountants) where engagement requires; and
(f) Courts, regulators or law enforcement, where disclosure is required by law, court order or government directive, including under Section 69 of the IT Act, 2000.
7. Storage & Security
We implement reasonable security practices and procedures as required by the IT (Reasonable Security Practices) Rules, 2011 and the DPDP Act, including: (a) TLS encryption in transit and encryption of sensitive data at rest; (b) role-based, least-privilege access control; (c) access reviews, log monitoring and security patching; (d) secrets and credentials stored as environment variables and never exposed to client-side code; (e) rate limits and abuse controls on sensitive operations such as scanning, OTP and emergency-contact calling; and (f) periodic, tested backups. No method of electronic storage or transmission is perfectly secure, and we cannot guarantee absolute security.
8. Data Retention
(a) Emergency-profile data is retained for the duration of your active enrolment and deleted within 30 days of de-registration, subject to lawful retention obligations.
(b) Scanner and incident logs are retained as long as required for security, audit and lawful claims, typically not exceeding 7 years.
(c) Enquiry and waitlist data is retained for as long as the relationship is reasonably active, and not more than 24 months after the last meaningful interaction, unless a longer period is required by law.
(d) Financial records may be retained for up to 8 years as required under the Income Tax Act, 1961 and the Central Goods and Services Tax Act, 2017.
(e) Aggregated, anonymised analytics (with no personally identifiable information) may be retained indefinitely.
9. Your Rights as a Data Principal
Subject to the DPDP Act, you have the right to: (a) Access (Section 11) a summary of your personal data and related processing; (b) Correction & Erasure (Section 12) of inaccurate data and of data no longer necessary; (c) Grievance Redressal (Section 13); (d) Nomination (Section 14) of another individual to exercise your rights on your death or incapacity; and (e) Withdraw Consent at any time. To exercise these rights, email support@rescuqr.in from your registered email address.
10. Children & Persons With Disability
In accordance with Section 9 of the DPDP Act, we do not knowingly process the personal data of a child (a person below 18 years) or of a person with a disability without the verifiable consent of the parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
11. Personal Data Breach
In the event of a personal data breach we will (a) report the breach to the Data Protection Board of India, and notify affected Data Principals, in accordance with the DPDP Act, and (b) take prompt containment and remedial measures under our breach-response plan.
12. Cross-Border Transfers
Some of our processors may operate infrastructure outside India. Any such transfer is conducted in compliance with Section 16 of the DPDP Act, only to countries or territories not restricted by the Central Government, and under contractual data-protection safeguards.
13. Grievance Officer / DPO
If you have a complaint or concern about how your personal data is being processed, please contact us at:
Name: Purohit Sharma
Designation: Grievance Officer & Data Protection Officer
Organisation: RESCUQR Technologies Private Limited
Email: support@rescuqr.in | Phone: +91 77310 88893
Address: Opposite IKEA, Plot No. 18/2, Sector-III, HUDA Techno Enclave, HITEC City, Hyderabad, Telangana 500081
Grievances will be acknowledged within 48 hours and addressed within 30 days. If you are not satisfied with the resolution, you may escalate to the Data Protection Board of India constituted under the DPDP Act, 2023.
14. Cookies & Changes to This Policy
The RESCUQR website uses essential cookies needed for security and basic functionality, and limited, non-advertising analytics to understand aggregate usage. You can control cookies through your browser settings. We may update this Policy from time to time; material changes will be communicated via a prominent notice on the Site and, where we have your email address, by email at least 15 days before they take effect. The “Last updated” date above reflects the most recent revision.
15. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with it shall be subject to the exclusive jurisdiction of the competent courts at Hyderabad, Telangana, India.
For any questions about this Policy, email support@rescuqr.in. See also our Terms & Conditions and Refund, Returns & Cancellation Policy.