Privacy Policy

Qualityfy Technologies Private Limited · Last updated: 24 August 2026

This Privacy Policy explains how Qualityfy Technologies Private Limited ("Qualityfy", "we", "us", "our") collects, uses, discloses, and safeguards personal data across our website qualityfy.com and our platforms Qualityfy (qualityfy.in) and QCnomics (qcnomics.com) (together, the "Services"). We handle digital personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian law. On request, you may access this notice in English or in any language specified in the Eighth Schedule to the Constitution of India by writing to support@qualityfy.com.

1. Our role

For our website, marketing, billing and the user accounts we administer, Qualityfy is the Data Fiduciary. Where a customer organisation (a hospital or laboratory, the "Customer") uses our platforms to record personal data — including patient or staff data entered in quality, audit, incident or feedback modules — the Customer is the Data Fiduciary and Qualityfy acts as its Data Processor under a written agreement, processing such data only on the Customer's documented instructions.

2. Personal data we collect and why

Data you provide: name, work email, phone number, organisation, role/designation and your message — when you book a demo, contact us, subscribe or register. Purpose: responding to your enquiry, providing and billing the Services.

Account & login data: credentials (stored hashed), access rights, and login/logout events. Purpose: authentication, security and audit trails.

Customer-entered operational data: quality, accreditation, audit, incident and related records entered by Customers, which may include personal data of patients and staff. Purpose: providing the platform to the Customer, on its instructions, as its Data Processor.

Usage & device data: IP address, browser/device information, pages viewed and timestamps. Purpose: operating and securing the Services.

We collect only the personal data necessary for these purposes.

3. Grounds for processing

We process personal data on the grounds recognised by the DPDP Act: (a) your consent, obtained through a clear affirmative action after notice; (b) certain legitimate uses under Section 7 of the DPDP Act — including data you voluntarily provide to us for a specified purpose (such as a demo request), processing for employment purposes, compliance with law or court orders, and responding to medical emergencies; and (c) where we act as a Data Processor, the instructions of the Customer that is the Data Fiduciary.

4. Consent and its withdrawal

Where processing is based on consent, you may withdraw it at any time, and doing so is as easy as giving it — write to support@qualityfy.com or use the unsubscribe/opt-out controls in our communications. Withdrawal does not affect the lawfulness of processing already carried out. On withdrawal we will stop, and cause our processors to stop, the relevant processing within a reasonable time unless continued processing is required by law.

5. Cookies & analytics

The Services use essential cookies for functionality, authentication and session management, and Google Analytics to understand aggregate usage. You can manage cookies in your browser and opt out of Google Analytics with Google's opt-out browser add-on.

6. Sharing of personal data

Service providers (processors): hosting, communications, payment and analytics providers who process data on our behalf under written contracts with confidentiality and security obligations. Customers: data entered within a Customer's account is accessible to that Customer's authorised users per their configured access rights. Legal: where required by law or legal process. We do not sell personal data, and we never use patient or clinical data for advertising.

7. Security safeguards

We implement reasonable security safeguards to prevent personal data breach, including encryption in transit, role-based access control, tenant isolation, hashed credentials, session controls and audit logging of user actions including logins. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Personal data breach

In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act, and — where we act as a Data Processor — notify the affected Customer without undue delay so it can meet its own obligations.

9. Storage, retention and erasure

Data is hosted on servers located in India. We retain personal data only as long as needed for the specified purpose or as required by law, accreditation or record-keeping obligations, and we erase it when you withdraw consent or when it is reasonable to assume the specified purpose is no longer being served, whichever is earlier. On termination of a Customer subscription, Customer data is returned or erased in accordance with the applicable agreement, and we cause our sub-processors to do the same.

10. Your rights as a Data Principal

Where Qualityfy is the Data Fiduciary, you have the right to: access a summary of your personal data and our processing activities; correction, completion, updating and erasure of your personal data; grievance redressal through the contact below; and to nominate another individual to exercise your rights in the event of your death or incapacity. To exercise any right, email support@qualityfy.com from your registered address. Where Qualityfy acts as a Data Processor, please direct requests concerning Customer-controlled data (for example, patient records) to the relevant hospital or laboratory; we assist our Customers in responding.

11. Grievance redressal and the Data Protection Board

We will acknowledge grievances within 7 days and aim to resolve them within 30 days (or any shorter period prescribed by law). If you are not satisfied after exhausting this process, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act and its rules.

12. Children's data

Our website and platforms are intended for authorised professional users aged 18 or over. Any patient data concerning minors is entered and controlled by the Customer as Data Fiduciary, which is responsible for obtaining verifiable consent of the parent or lawful guardian as required by Section 9 of the DPDP Act; our platforms are not used for tracking, behavioural monitoring of, or targeted advertising directed at children.

13. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above reflects the latest revision, and material changes will be communicated through the Services or by other appropriate means.

14. Contact — Grievance Officer

Grievance Officer, Qualityfy Technologies Private Limited
102, Gopala Tower, Kakadeo, Kanpur (UP), India — 208025
CIN: U62013UP2026PTC248938
Email: support@qualityfy.com · support@qualityfy.com