Legal
Privacy Policy. Your data, your rights.
How QWR Interactive Solutions Pvt. Ltd. collects, uses, stores, and protects your personal data across our websites and services.
Version 1.1 · Last updated: 28 April 2026
1. Who we are
This privacy policy is issued by QWR Interactive Solutions Pvt. Ltd., a company incorporated under the laws of India (hereinafter "QWR", "we", "us", or "our"). We are the data controller (under GDPR) and data fiduciary (under India's Digital Personal Data Protection Act 2023, "DPDP Act") for the personal data described in this policy.
Registered office:
301, 303, 304 The Golden Bell, Koregaon Park Annexe, Industrial Area, Mundhwa, Pune, Maharashtra 411036, India
Corporate Identification Number (CIN): U72100MH2017PTC293580
2. Contact
For all privacy-related questions, requests, or complaints, please contact us at:
Privacy contact
[email protected]General enquiries
[email protected]If you are an investor using our investor portal at investor.questionwhatsreal.com, please refer to the Investor Portal Privacy Notice for additional terms specific to the portal.
3. What data we collect
3.1 When you visit our website
- IP address (anonymised where analytics consent is not given)
- User-agent string (browser type and version, operating system)
- Session identifier (randomly generated, not linked to your identity)
- Referrer URL (the page that linked you to us)
- Pages viewed, scroll depth, and time on page
- Country of origin (derived from IP via Cloudflare
CF-IPCountryheader; not stored beyond session)
3.2 When you contact us
- Name
- Email address
- Phone number (if provided)
- Message content
- Organisation name (if provided)
3.3 When you use the product configurator, RFP forms, or ROI calculator
- Your selections and answers within the tool
- Generated output (e.g. configuration summary, cost estimate)
- Form submissions linked to your contact details if you choose to submit
3.4 Bot detection
We use Cloudflare Bot Management and Turnstile CAPTCHA to detect automated traffic. Requests identified as bots are blocked without recording personal data. Cloudflare may process the IP address and user-agent for this purpose under its own privacy policy.
4. Lawful basis for processing
We process personal data under the following legal bases:
| Purpose | GDPR Art. 6 basis | DPDP Act equivalent |
|---|---|---|
| Website security, abuse prevention, IP logging | Legitimate interest (Art. 6(1)(f)) | Reasonable purpose (Sec. 7(f) — security) |
| Analytics cookies (GA4, Clarity) | Consent (Art. 6(1)(a)) | Consent (Sec. 6) |
| Advertising cookies (Google Ads) | Consent (Art. 6(1)(a)) | Consent (Sec. 6) |
| Handling contact form submissions and enquiries | Contract / pre-contractual measures (Art. 6(1)(b)) | Legitimate use (Sec. 7(a)) |
| Product configurator / RFP processing | Contract / pre-contractual measures (Art. 6(1)(b)) | Legitimate use (Sec. 7(a)) |
| Error monitoring and performance (Sentry) | Legitimate interest (Art. 6(1)(f)) | Reasonable purpose (Sec. 7(f)) |
Where we rely on legitimate interest, we have conducted a balancing test and concluded that our interest does not override your fundamental rights. You may object to legitimate-interest processing at any time (see Section 8).
5. Who processes your data (third-party processors)
We share personal data only with processors who act on our instructions and are contractually bound by data processing agreements (DPAs). We never sell personal data.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, storage | Seoul (AWS ap-northeast-2) |
| Sentry | Error and performance monitoring | Frankfurt, Germany (EU) |
| Google LLC (GA4, Ads) | Web analytics; advertising | Global |
| Microsoft (Clarity) | Session replay and heatmaps | Global |
| Cloudflare, Inc. | CDN, DNS, WAF, bot protection | Global edge network |
| DigitalOcean, LLC | Static site hosting | App-region specific |
| GitHub, Inc. | Source code hosting | United States |
6. Data retention
We retain personal data only as long as necessary for the purposes set out in this policy, or as required by law.
| Data category | Retention period |
|---|---|
| Analytics data (GA4) | 14 months |
| Advertising conversion data (Google Ads) | 13 months |
| Session replays (Clarity) | 30 days |
| Error telemetry (Sentry) | 90 days |
| Server and CDN logs (Cloudflare) | ~30 days |
| Contact form submissions | 2 years |
| Investor portal audit logs | 8 years (SEBI) |
After the retention period expires, data is deleted or anonymised.
7. International transfers
QWR is based in India. Your data may be processed in the following jurisdictions depending on the service involved:
- Seoul, South Korea — Supabase (database, authentication, storage)
- Frankfurt, Germany — Sentry (error monitoring)
- United States — GitHub (source hosting — no end-user PII)
- Global edge locations — Cloudflare, Google Analytics, Microsoft Clarity
India to outside India
Under the DPDP Act 2023, cross-border transfers of personal data are permitted except to countries specifically restricted by the Central Government. As of the date of this policy, no such restricted-country list has been notified.
8. Your rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
| Right | GDPR | DPDP Act |
|---|---|---|
| Access | Art. 15 | Sec. 11 |
| Rectification | Art. 16 | Sec. 12 |
| Erasure | Art. 17 | Sec. 12 |
| Restriction | Art. 18 | — |
| Portability | Art. 20 | — |
| Objection | Art. 21 | — |
| Withdraw consent | Art. 7(3) | Sec. 6(5) |
How to exercise your rights
Email [email protected] with your request.
10. Children's privacy
Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children.
11. Security
- Encryption in transit — HTTPS enforced with HSTS preload
- Encryption at rest — AES-256 via Supabase
- Row-Level Security (RLS) — enforced on all user-scoped tables
- Tamper-evident audit logs — SHA-256 integrity hashes
- Multi-factor authentication (MFA) — required for all admin accounts
12. Breach notification
In the event of a personal data breach, we notify the Data Protection Board of India within 72 hours, EU/UK supervisory authorities within 72 hours where required, and affected individuals without undue delay where the breach poses a high risk.
13. Changes to this policy
We may update this privacy policy from time to time. Material changes will be flagged at the top of this page for at least 30 days.
Last updated: 28 April 2026
Version: 1.1
14. Governing law
This privacy policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Mumbai, Maharashtra, India.