Privacy Policy

QRisTix Business Technologies OPC (P) Ltd
Effective Date: 20th May 2026 | Last Updated: 20th May 2026

QRisTix Business Technologies OPC (P) Ltd ("QRisTix", "we", "us", or "our") is the developer and operator of the QRisTix-FSM, ServiceTix, and TASQED software-as-a-service platforms (collectively, the "Services").

This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our websites, sign up for a trial or subscription, or use any of our Services.

We are a company incorporated in India with our registered office in Bangalore, Karnataka. This policy is designed to comply with the Digital Personal Data Protection Act, 2023 (India) and to align with the data protection expectations of our customers across India, the United Arab Emirates, the Kingdom of Saudi Arabia, and Qatar.

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use the Services.

1. Scope and Roles

This policy applies to two distinct categories of data and two distinct roles that QRisTix plays:

This Privacy Policy primarily addresses our role as Data Fiduciary. Our processing of Customer Data is governed by the agreement we have with the relevant customer.

2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information From Third Parties

We may receive information from resellers, referral partners, payment processors, authentication providers, and publicly available business directories.

3. How We Use Information

4. Legal Bases for Processing

5. How We Share Information

Our current core hosting provider is Amazon Web Services (AWS), with all production data stored in the AWS Asia Pacific (Mumbai) region.

6. Data Hosting and International Transfers

All Customer Data and primary production data are hosted in India on AWS infrastructure in the Mumbai (ap-south-1) region.

Certain operational or support-related data may be processed outside India by service providers subject to contractual safeguards.

7. Data Retention

8. Your Rights

9. Security

We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction.

These measures include encryption in transit, role-based access controls, audit logging, network segregation, and regular backups.

10. Children

The Services are intended for business use and are not directed at children under 18 years of age.

11. Third-Party Links and Integrations

The Services may contain links to third-party websites or integrations. We are not responsible for their privacy practices.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through email or in-product notices where appropriate.

13. Contact

If you have questions about this Privacy Policy or wish to exercise any of your rights, please contact:

Email: info@qristix.com

```