Privacy Policy

Privacy Policy for the Digi Parking Website

This Privacy Policy explains how Beyond Quantum Technologies Private Limited — the company that operates the Digi Parking brand — collects, uses, stores, shares, and protects personal data when you visit the Digi Parking website. It is published under the Information Technology Act, 2000, the SPDI Rules, the Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025.

Version 1.0 · Last Updated: August 2026  ·  Applies to digiparking.net

Effective Date: [INSERT DATE]  ·  Jurisdiction: Republic of India

1. Introduction

Beyond Quantum Technologies Private Limited is a company incorporated under the Companies Act, 2013, bearing Corporate Identity Number (CIN) [INSERT CIN], with its registered office at [INSERT REGISTERED OFFICE ADDRESS], India (the “Company,” “Beyond Quantum,” “we,” “us,” or “our”).

Digi Parking is a project of the Company. It is a technology platform for QR-code-based parking access management. Digi Parking is a brand and product name — it is not a separate legal entity, is not separately incorporated, and cannot sue or be sued in its own name. Every reference to “Digi Parking” in this document means Beyond Quantum Technologies Private Limited, and every right, limitation, exclusion, and indemnity expressed in favour of Digi Parking operates in favour of the Company.

The Company may operate projects, brands, and products in addition to Digi Parking. This document governs only what its scope section says it governs.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit our website at digiparking.net (the “Website”). It is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Digital Personal Data Protection Rules, 2025 made under it, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediary Guidelines”).

For the purposes of the DPDPA, the Company is the Data Fiduciary in respect of the personal data described in this Policy. You are the Data Principal.

What this Policy does not cover

This Policy covers only the Website. Our mobile applications collect different data for different purposes and are governed by their own separate privacy policies, provided at the point of installation and account creation. Cookies are dealt with in our separate Website Cookie Policy, which should be read alongside this Policy.

2. Definitions

3. Personal Data We Collect

3.1 Data you give us directly

We collect this data only when you choose to give it to us by filling in a form or writing to us.

ContextData collectedMandatory?
Business or partnership enquiryName, email address, phone number, company name, city, message contentName and email; rest optional
Operator partnership applicationName, email, phone, business name, number and location of parking facilities, message contentAll fields
Careers / job applicationName, email, phone, resume or CV, cover letter, links to professional profilesName, email, and resume
Newsletter or marketing subscriptionEmail address; optionally name and cityEmail address
Support or grievance submissionName, email, phone, description of the issue, any attachments you sendName and email
Demo or callback requestName, phone, email, preferred timeName and phone

3.2 Data collected automatically

When you visit the Website, certain technical data is collected automatically by our servers and our analytics providers, whether or not you submit any form.

3.3 Data we do not collect through the Website

Some of these categories are collected by our mobile applications under their own privacy policies.

4. Purposes and Lawful Basis

Under Section 4 of the DPDPA, personal data may be processed only for a lawful purpose for which you have given consent, or for a legitimate use specified in Section 7. The table below sets out each purpose and the basis on which we process.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal is as easy as giving consent: write to the Grievance Officer at the address in Section 11, or use the unsubscribe link in any marketing email. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not require us to erase data we are legally required to retain.

PurposeData usedLawful basis
Responding to your enquiry or callback requestContact details and message contentConsent (Section 6, DPDPA)
Assessing an operator partnership applicationContact and business detailsConsent; steps taken at your request prior to entering a contract
Assessing a job applicationApplication dataConsent; Section 7(i), DPDPA — purposes of employment
Sending marketing communicationsEmail address and nameConsent, withdrawable at any time
Operating and securing the WebsiteTechnical and automatically collected dataSection 7(a), DPDPA — data voluntarily provided for the specified purpose; necessary to deliver the service you requested
Measuring and improving Website performanceAnalytics dataConsent for non-essential analytics cookies
Detecting and preventing fraud, abuse, and attackTechnical data, submission patternsSection 17(1)(c), DPDPA — detection and investigation of an offence or contravention
Complying with statutory record-keepingAny data as requiredStatutory obligation under the Income-tax Act, 1961, the CGST Act, 2017, and the Companies Act, 2013
Establishing, exercising, or defending legal claimsAny relevant dataSection 17(1)(a), DPDPA — enforcing a legal right or claim

5. Notice Under Section 5 of the DPDPA

Section 5 of the DPDPA requires that, on or before seeking your consent, we give you an itemised notice describing the personal data sought, the purpose of processing, how you may exercise your rights under Sections 6(4) and 13, and how you may complain to the Data Protection Board of India.

That notice is presented separately at the point where consent is sought — at each form on the Website — and is offered in English and in the languages specified in the Eighth Schedule to the Constitution of India that we support. This Policy supplements that notice; it does not replace it.

If the Central Government notifies the Company as a Significant Data Fiduciary under Section 10 of the DPDPA, we will appoint a Data Protection Officer based in India who will be the point of contact for the grievance redressal mechanism, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits, as that Section requires. We will publish the Data Protection Officer’s contact details in this Policy at that point.

6. How We Share Personal Data

We do not sell personal data. We do not rent, trade, or otherwise make personal data available to third parties for their own independent marketing purposes.

6.1 Service providers acting as Data Processors

We engage third parties to perform functions on our behalf. They may process personal data only on our documented instructions, only for the purposes we specify, and are bound by written contracts imposing confidentiality and security obligations at least as protective as those in this Policy. Categories include cloud hosting and infrastructure, web analytics, email delivery and marketing automation, customer relationship management, recruitment and applicant tracking, and security, fraud prevention, and bot mitigation.

Under Section 8(1) of the DPDPA we remain responsible to you for compliance in respect of processing carried out by a Data Processor on our behalf, regardless of any agreement to the contrary between us and that Processor.

6.2 Group companies and successors

We may share personal data with any holding company, subsidiary, or affiliate of the Company, and with any acquirer or successor in a merger, acquisition, restructuring, sale of assets, or insolvency, provided the recipient honours the commitments in this Policy or gives you notice of any material change.

6.3 Legal and regulatory disclosure

We may disclose personal data where required or permitted by law, including in response to a summons, warrant, court order, or lawful direction from a court, tribunal, or statutory authority; to a law enforcement agency acting under a valid legal instrument; to a regulator exercising statutory powers; where necessary to establish, exercise, or defend legal claims; and where necessary to prevent or investigate fraud, a security incident, or a threat to life or safety.

Section 17(1)(c) of the DPDPA disapplies Chapter II (other than Sections 8(1) and 8(5)), Chapter III, and Section 16 where processing is in the interest of prevention, detection, investigation, or prosecution of any offence or contravention of any law in force in India. Section 17(1)(a) applies where processing is necessary for enforcing a legal right or claim. Where we rely on either provision, we record the basis for doing so, disclose only what the instrument requires, and will notify you unless notification is prohibited by law or would prejudice an investigation.

6.4 Professional advisers

We may share personal data with our lawyers, auditors, accountants, insurers, and other professional advisers where necessary for them to advise us, and where they are bound by professional duties of confidentiality.

7. Data Retention

We retain personal data only for as long as necessary for the purpose it was collected, or for such longer period as required by law. Section 8(7) of the DPDPA requires erasure once the purpose is no longer served and retention is no longer necessary for legal compliance.

At the end of a retention period, personal data is deleted or irreversibly anonymised. Anonymised data, which cannot be linked back to any individual, falls outside the scope of the DPDPA and may be retained indefinitely for statistical purposes.

Backup copies are overwritten on a rolling cycle. Where personal data has been deleted from live systems but persists in a backup, that data is isolated from active processing and is deleted when the backup cycle completes.

Category of dataRetention periodReason
Enquiry and contact form submissions24 months from last contactHandling follow-up queries; maintaining a record of dealings
Operator partnership applications (unsuccessful)12 months from decisionReconsideration if circumstances change; evidence of a fair process
Job applications (unsuccessful)12 months from decisionConsideration for future roles; defence of any claim
Marketing subscription recordsUntil withdrawal, plus 24 monthsEvidencing the consent on which marketing was sent
Grievance and complaint records36 months from closureRegulatory record-keeping and defence of claims
Website server and security logs180 daysSecurity monitoring and incident investigation
Security incident records36 months from closureDemonstrating compliance with Section 8(5), DPDPA
Analytics data (pseudonymised)26 monthsYear-on-year trend analysis
Cookie consent recordsUp to 36 months from the consent eventDemonstrating the lawful basis on which cookies were set
Records required under tax or company law8 yearsSection 128, Companies Act, 2013; Section 149, Income-tax Act, 1961; Section 36, CGST Act, 2017

8. Security Safeguards

Section 8(5) of the DPDPA requires a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breach. The measures we implement in relation to the Website include:

How to read this section

This section describes our security posture at the date of this document. Security is not static: we review and update these measures as threats and technology change, and we may replace a named technology or protocol with one offering equivalent or better protection.

The description of a specific technology here is a statement of current practice, provided so that you can understand how we protect your data. It is not a warranty, a service level, or a contractual guarantee that any named technology will be in use at any given moment. Our obligation is the obligation the law imposes: to take reasonable security safeguards under Section 8(5) of the DPDPA.

An honest statement about security

No system connected to a network is perfectly secure, and no organisation can promise that it will never suffer a breach. A determined attacker with sufficient resources — including one exploiting a previously unknown vulnerability in software we did not write, or compromising a supplier we depend on — may defeat safeguards that are objectively reasonable.

What we commit to is what the law requires and what is within our control: taking reasonable security safeguards under Section 8(5) of the DPDPA, maintaining them, testing them, and responding properly when something goes wrong. We do not promise that a breach will never occur, and any statement in this document should be read in that light.

9. Personal Data Breach

Notification

In the event of a personal data breach we will, in accordance with Rule 7 of the Digital Personal Data Protection Rules, 2025:

We will not condition notification on completing our investigation. Where facts are still emerging, we will notify on the basis of what is known and supplement as more becomes clear.

What we are responsible for, and what we are not

Where a breach occurs despite reasonable safeguards, our liability is limited to the extent permitted by applicable law and by the limitation of liability provisions in the Terms of Use applicable to your use of the service. Nothing in this document excludes or limits any liability that cannot lawfully be excluded, including under the DPDPA and the Consumer Protection Act, 2019.

Your part in keeping your data secure

Security is shared. You must:

Where a compromise of your data results from your failure to meet these obligations — for example where you have shared your credentials, or where your device was compromised by software you installed — that is not a breach of our systems, and our responsibility is correspondingly limited. We will still help you secure your account.

Breaches at a third party

Where a personal data breach occurs at a processor we have engaged, we remain accountable to you under Section 8(1) of the DPDPA and will handle notification as though the breach had occurred in our own systems. Where a breach occurs at a party that is an independent Data Fiduciary in its own right — for example a payment aggregator that collected payment credentials directly from you, or a parking operator in respect of its own records — that party is accountable for it, and we will assist you in identifying and contacting them.

Reporting a vulnerability

If you discover a security vulnerability, report it to security@digiparking.net rather than disclosing it publicly or exploiting it. We will acknowledge a good-faith report within 72 hours and will not pursue legal action against a researcher who reports a vulnerability in good faith, does not access or exfiltrate personal data beyond the minimum needed to demonstrate the issue, does not degrade our service, and gives us a reasonable opportunity to remediate before disclosing.

10. Your Rights as a Data Principal

Chapter III of the DPDPA confers the following rights on you in relation to your personal data:

To exercise any of these rights, send a request to the Grievance Officer using the contact details in Section 11. To protect your data we will verify your identity before acting on a request — we may ask you to confirm details you have previously given us, or to respond from the email address associated with the data. We will acknowledge your request within 24 hours and respond substantively within the period prescribed by the Digital Personal Data Protection Rules, 2025, and in any event within 15 days.

We do not charge a fee for exercising your rights. Where a request repeats an earlier one without any change in circumstances, we may refer you to our earlier response rather than repeating the exercise.

Your duties as a Data Principal

Section 15 of the DPDPA places duties on you. You must not impersonate another person when providing personal data, must not suppress material information when providing data for a legal purpose, must not register a false or frivolous grievance, and must furnish only authentic information when exercising your right to correction or erasure. Section 33 read with the Schedule to the DPDPA provides for financial penalties for breach of these duties.

11. Grievance Officer

In accordance with Rule 3(2) of the Intermediary Guidelines and Section 13 of the DPDPA, we have appointed a Grievance Officer to receive and address complaints relating to this Policy and to our processing of personal data.

Name: [INSERT NAME OF GRIEVANCE OFFICER]

Designation: Grievance Officer, Beyond Quantum Technologies Private Limited

[INSERT REGISTERED OFFICE ADDRESS]
[INSERT PHONE NUMBER]

Hours: Monday to Friday, 10:00 to 18:00 IST, excluding public holidays

In accordance with Rule 3(2)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Grievance Officer will acknowledge every complaint within 24 hours of receipt and will dispose of it within 15 days. Complaints concerning your rights as a Data Principal under the DPDPA will be resolved within the period prescribed by the Digital Personal Data Protection Rules, 2025.

If you are not satisfied with the outcome, or if we fail to respond within the prescribed period, you may complain to the Data Protection Board of India in the manner prescribed under the DPDPA.

12. Children’s Personal Data

The Website is not directed at children. Section 9 of the DPDPA prohibits processing of a child’s personal data that is likely to cause any detrimental effect on the wellbeing of the child, and prohibits tracking, behavioural monitoring, and targeted advertising directed at children. We do not engage in any of those activities.

We do not knowingly collect personal data from any person under the age of 18 through the Website. If we become aware that we have collected a child’s personal data without verifiable parental consent, we will delete it promptly. If you are a parent or guardian and believe your child has provided personal data to us, contact the Grievance Officer and we will act on it.

13. Automated Decision-Making

We do not use personal data collected through the Website to make any decision producing a legal effect concerning you, or significantly affecting you, solely on the basis of automated processing, including profiling. Automated tooling is used only to filter spam and abusive submissions and to mitigate automated attack traffic; where such tooling blocks a legitimate submission, you may contact the Grievance Officer and a person will review it.

14. Third-Party Websites

The Website may contain links to websites operated by third parties, including social media platforms, app stores, and partner websites. This Policy does not apply to them. We do not control them, are not responsible for their content or privacy practices, and a link is not an endorsement. Read the privacy policy of any third-party website before providing personal data to it.

15. Cross-Border Transfer of Personal Data

Personal data is stored and processed primarily on servers located in India.

Some processors may process personal data outside India. Section 16 of the DPDPA permits transfer of personal data outside India except to a territory notified as restricted by the Central Government. Where we transfer personal data outside India, we do so only to territories not so notified, and only under contractual arrangements requiring the recipient to apply protections equivalent to those in this document. We do not transfer personal data to any territory notified as restricted.

16. Changes to This Policy

We may amend this Policy to reflect changes in law, in our practices, or in the service. The current version is always available on the Website and shows the date it was last updated.

Where a change is material — for example where we begin processing personal data for a substantially new purpose — we will give prior notice, and where the DPDPA requires fresh consent for the new purpose we will obtain that consent before the change takes effect in relation to you. Your continued use after a non-material change takes effect constitutes acceptance of the amended Policy.

17. Governing Law

This Policy is governed by and construed in accordance with the laws of the Republic of India. Subject to the dispute resolution provisions of the Website Terms of Use, the courts at [INSERT CITY], India, have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.

End of document

END OF WEBSITE PRIVACY POLICY
Beyond Quantum Technologies Private Limited
Digi Parking | CIN [INSERT CIN]