Products+
ODM / OEM+
Industries+
DefenceAbout Investor Portal Get in touch →

Legal

Privacy Policy. Your data, your rights.

How QWR Interactive Solutions Pvt. Ltd. collects, uses, stores, and protects your personal data across our websites and services.

Version 1.1 · Last updated: 28 April 2026

1. Who we are

This privacy policy is issued by QWR Interactive Solutions Pvt. Ltd., a company incorporated under the laws of India (hereinafter "QWR", "we", "us", or "our"). We are the data controller (under GDPR) and data fiduciary (under India's Digital Personal Data Protection Act 2023, "DPDP Act") for the personal data described in this policy.

Registered office:

301, 303, 304 The Golden Bell, Koregaon Park Annexe, Industrial Area, Mundhwa, Pune, Maharashtra 411036, India

Corporate Identification Number (CIN): U72100MH2017PTC293580

2. Contact

For all privacy-related questions, requests, or complaints, please contact us at:

Privacy contact

[email protected]

General enquiries

[email protected]

If you are an investor using our investor portal at investor.questionwhatsreal.com, please refer to the Investor Portal Privacy Notice for additional terms specific to the portal.

3. What data we collect

3.1 When you visit our website

  • IP address (anonymised where analytics consent is not given)
  • User-agent string (browser type and version, operating system)
  • Session identifier (randomly generated, not linked to your identity)
  • Referrer URL (the page that linked you to us)
  • Pages viewed, scroll depth, and time on page
  • Country of origin (derived from IP via Cloudflare CF-IPCountry header; not stored beyond session)

3.2 When you contact us

  • Name
  • Email address
  • Phone number (if provided)
  • Message content
  • Organisation name (if provided)

3.3 When you use the product configurator, RFP forms, or ROI calculator

  • Your selections and answers within the tool
  • Generated output (e.g. configuration summary, cost estimate)
  • Form submissions linked to your contact details if you choose to submit

3.4 Bot detection

We use Cloudflare Bot Management and Turnstile CAPTCHA to detect automated traffic. Requests identified as bots are blocked without recording personal data. Cloudflare may process the IP address and user-agent for this purpose under its own privacy policy.

4. Lawful basis for processing

We process personal data under the following legal bases:

PurposeGDPR Art. 6 basisDPDP Act equivalent
Website security, abuse prevention, IP loggingLegitimate interest (Art. 6(1)(f))Reasonable purpose (Sec. 7(f) — security)
Analytics cookies (GA4, Clarity)Consent (Art. 6(1)(a))Consent (Sec. 6)
Advertising cookies (Google Ads)Consent (Art. 6(1)(a))Consent (Sec. 6)
Handling contact form submissions and enquiriesContract / pre-contractual measures (Art. 6(1)(b))Legitimate use (Sec. 7(a))
Product configurator / RFP processingContract / pre-contractual measures (Art. 6(1)(b))Legitimate use (Sec. 7(a))
Error monitoring and performance (Sentry)Legitimate interest (Art. 6(1)(f))Reasonable purpose (Sec. 7(f))

Where we rely on legitimate interest, we have conducted a balancing test and concluded that our interest does not override your fundamental rights. You may object to legitimate-interest processing at any time (see Section 8).

5. Who processes your data (third-party processors)

We share personal data only with processors who act on our instructions and are contractually bound by data processing agreements (DPAs). We never sell personal data.

ProcessorPurposeLocation
SupabaseAuthentication, database, storageSeoul (AWS ap-northeast-2)
SentryError and performance monitoringFrankfurt, Germany (EU)
Google LLC (GA4, Ads)Web analytics; advertisingGlobal
Microsoft (Clarity)Session replay and heatmapsGlobal
Cloudflare, Inc.CDN, DNS, WAF, bot protectionGlobal edge network
DigitalOcean, LLCStatic site hostingApp-region specific
GitHub, Inc.Source code hostingUnited States

6. Data retention

We retain personal data only as long as necessary for the purposes set out in this policy, or as required by law.

Data categoryRetention period
Analytics data (GA4)14 months
Advertising conversion data (Google Ads)13 months
Session replays (Clarity)30 days
Error telemetry (Sentry)90 days
Server and CDN logs (Cloudflare)~30 days
Contact form submissions2 years
Investor portal audit logs8 years (SEBI)

After the retention period expires, data is deleted or anonymised.

7. International transfers

QWR is based in India. Your data may be processed in the following jurisdictions depending on the service involved:

  • Seoul, South Korea — Supabase (database, authentication, storage)
  • Frankfurt, Germany — Sentry (error monitoring)
  • United States — GitHub (source hosting — no end-user PII)
  • Global edge locations — Cloudflare, Google Analytics, Microsoft Clarity

India to outside India

Under the DPDP Act 2023, cross-border transfers of personal data are permitted except to countries specifically restricted by the Central Government. As of the date of this policy, no such restricted-country list has been notified.

8. Your rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

RightGDPRDPDP Act
AccessArt. 15Sec. 11
RectificationArt. 16Sec. 12
ErasureArt. 17Sec. 12
RestrictionArt. 18
PortabilityArt. 20
ObjectionArt. 21
Withdraw consentArt. 7(3)Sec. 6(5)

How to exercise your rights

Email [email protected] with your request.

9. Cookies & tracking technologies

We use a geo-gated consent model: EU/EEA/UK/Switzerland visitors see an opt-in prompt for analytics and advertising cookies; all other visitors get opt-out by default. We respect the DNT=1 header and Global Privacy Control signal.

To change your cookie preferences, click "Privacy settings" in the website footer.

10. Children's privacy

Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children.

11. Security

  • Encryption in transit — HTTPS enforced with HSTS preload
  • Encryption at rest — AES-256 via Supabase
  • Row-Level Security (RLS) — enforced on all user-scoped tables
  • Tamper-evident audit logs — SHA-256 integrity hashes
  • Multi-factor authentication (MFA) — required for all admin accounts

12. Breach notification

In the event of a personal data breach, we notify the Data Protection Board of India within 72 hours, EU/UK supervisory authorities within 72 hours where required, and affected individuals without undue delay where the breach poses a high risk.

13. Changes to this policy

We may update this privacy policy from time to time. Material changes will be flagged at the top of this page for at least 30 days.

Last updated: 28 April 2026
Version: 1.1

14. Governing law

This privacy policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Mumbai, Maharashtra, India.