1Who we are
Quinsta is a background verification service offered by Quinfy Technology Private Limited ("Quinfy", "we", "us", "our"), CIN U72500HR2019PTC082072, office at 541–542, Tower B3, Spaze I-Tech Park, Sector 49, Gurugram, Haryana 122018, India.
This policy explains how we collect, use, share, store and protect personal data when you use Quinsta through quinsta.ai, quinplus.com, quinfy.com, our mobile applications and related services (the "Service").
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), Quinfy is the Data Fiduciary for personal data processed through Quinsta. This policy should be read together with our Terms and Conditions.
2Laws and standards we follow
We process personal data in accordance with:
- the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025;
- the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
- the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, to the extent applicable;
- the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI regulations, wherever Aadhaar is used;
- CERT-In Directions of 28 April 2022 on cyber incident reporting and log retention;
- the EU General Data Protection Regulation (GDPR), where it applies to individuals in the European Economic Area.
Our information security and quality management systems are certified to ISO/IEC 27001 and ISO 9001. Our controls are independently audited under SOC 2 Type II.
3Key terms
- Personal data: any data about an individual who is identifiable by or in relation to that data.
- Data Principal: the individual to whom the personal data relates.
- You: the person using Quinsta, whether verifying yourself or requesting verification of another person.
- Subject: the person being verified.
- Processing: any operation on personal data, including collection, storage, use, sharing and erasure.
4Personal data we collect
We collect only the personal data needed for the verification you request.
| Category | Examples |
|---|---|
| From you as a Quinsta user | Name, email, mobile number, login details, billing information, record of verifications requested |
| About the Subject being verified | Full name, date of birth, gender, photograph, current and past addresses, identity documents (PAN, Aadhaar, passport, voter ID, driving licence), education, employment history, references |
| Facial verification and liveness | Live selfie or video and the facial match result, used only to confirm the Subject is real and matches their ID |
| From third-party and public sources | Results from government databases, court and police records, educational institutions, past employers, address and credit verification partners |
| Collected automatically | IP address, device type, operating system, browser, pages visited, time stamps, diagnostic logs; precise location only with permission (e.g. digital address verification) |
We do not collect data about caste, religion, political opinion, sexual orientation or health unless legally required for a specific check. If that applies, we will tell you before collecting it.
5Notice and consent
We process personal data on the basis of free, specific, informed, unconditional and unambiguous consent, given through a clear affirmative action. The exception is processing the DPDP Act permits for legitimate uses, such as complying with law or a court order.
Before collecting personal data, we give you a notice setting out what we collect, why, how to withdraw consent, and how to raise a grievance. The notice is available in English and, on request, in any language in the Eighth Schedule of the Constitution of India.
If you are verifying another person: Quinsta requires the Subject's own consent before any check begins. We send the Subject a consent link by SMS or email, and no verification runs until they consent. You must not submit a person's details without their knowledge, and you must use reports only for the lawful purpose you declared.
Withdrawing consent: you may withdraw consent at any time, as easily as you gave it, through your account settings or by contacting us (Section 17). Withdrawal does not affect processing already completed, but we may be unable to complete a pending verification. Where available, you may also manage consent through a Consent Manager registered with the Data Protection Board of India.
6How we use personal data
We use personal data to:
- carry out the identity, address, education, employment, criminal record and other checks you request, and deliver the report;
- authenticate users and Subjects, and prevent fraud and misuse of the Service;
- process payments and issue invoices;
- provide customer support and handle grievances;
- maintain security, resolve technical issues and keep audit logs;
- comply with legal obligations and respond to lawful requests from authorities;
- improve the Service, using aggregated or de-identified data wherever possible;
- send marketing communications, only if you have separately opted in.
We do not sell personal data, and we do not use verification data for advertising.
7Aadhaar and government identifiers
We use Aadhaar only through UIDAI-permitted methods, such as Aadhaar offline XML, DigiLocker or masked Aadhaar, and only with the Subject's explicit consent. We do not store full Aadhaar numbers; any stored copy shows only the last four digits. Aadhaar and other government ID data are used only to verify identity.
8Automated processing and QuinAI
Quinsta uses automated tools, including our QuinAI layer, to extract data from documents, match faces and flag discrepancies. No adverse finding is reported based solely on automated processing. A trained verification analyst reviews discrepancies before a final report is issued, and the Subject may request human review of any result.
11Storage and cross-border transfers
Quinsta data is stored on AWS servers. We transfer personal data outside India only when a verification requires it, such as confirming a foreign degree or overseas employment. Such transfers go only to countries not restricted by the Government of India under Section 16 of the DPDP Act, and under contractual safeguards.
12Data retention
We keep personal data only as long as its purpose requires, or as the law requires.
| Data | Retention period |
|---|---|
| Supporting documents and raw data for a check | Deleted within 90 days of the final report, unless law requires longer |
| Final verification reports | 12 months, unless you ask for earlier deletion |
| Facial images and liveness data | Deleted within 30 days of verification |
| Account data | While your account is active; deleted within 90 days of closure |
| Security and processing logs | At least one year, per the DPDP Rules and CERT-In Directions |
| Billing records | As required by tax and accounting laws |
When the purpose is fulfilled or consent is withdrawn, we erase the data and ensure our Data Processors do the same, unless law requires retention.
13How we protect personal data
We apply reasonable security safeguards consistent with ISO/IEC 27001 and SOC 2 Type II, including:
- encryption in transit (TLS 1.2 or higher) and at rest (AES-256);
- role-based access controls with multi-factor authentication;
- masking of identifiers, activity logging and monitoring;
- regular vulnerability assessments and penetration tests;
- employee confidentiality obligations and privacy training;
- business continuity and disaster recovery plans.
No system is completely secure, but we continuously review and improve these measures.
14Personal data breaches
If a personal data breach occurs, we will inform affected Data Principals without undue delay. We will describe the breach, its likely consequences, the steps we are taking, and what they can do to protect themselves.
We will also notify the Data Protection Board of India without delay and submit a detailed report within 72 hours, and report cyber incidents to CERT-In within 6 hours, as required by law.
15Your rights
Under the DPDP Act, you have the right to:
- access a summary of your personal data we process, our processing activities, and who we have shared it with;
- correct, complete or update inaccurate or incomplete personal data;
- erase personal data that is no longer needed, subject to legal retention requirements;
- withdraw consent at any time;
- grievance redressal through our Grievance Officer;
- nominate another person to exercise your rights in the event of your death or incapacity.
If you are in the European Economic Area, you also have GDPR rights to restrict processing, object to processing, data portability, and not be subject to decisions based solely on automated processing.
To exercise any right, write to dpo@quinfy.com or use the privacy request option in your Quinsta account. We may need to verify your identity first. We will respond within 30 days, and in any case within the period prescribed under the DPDP Rules.
As a Data Principal, you are expected to provide accurate information, not impersonate another person, and not file false or frivolous complaints.
16Children
Quinsta is not intended for individuals under 18. We do not knowingly process a child's personal data without verifiable consent of a parent or lawful guardian, and we do not track, behaviourally monitor or target advertising at children.
If a verification involving a minor is legally required, we will obtain verifiable parental consent as prescribed under the DPDP Rules. If you believe we have collected a child's data without such consent, contact us and we will delete it.
17Grievance Officer and Data Protection Officer
Grievance Officer
Partha Barman
grievance@quinfy.com
080-46800968
Data Protection Officer
Aashish Singh
dpo@quinfy.com
Address: 541–542, Tower B3, Spaze I-Tech Park, Sector 49, Gurugram, Haryana 122018, India.
We will acknowledge grievances within 24 hours and resolve them within 15 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India after exhausting our grievance process.
18Links to other websites
The Service may link to third-party websites. We are not responsible for their privacy practices and encourage you to read their policies.
19Changes to this policy
We may update this policy to reflect changes in law or in our Service. We will post the updated version on this page with a new effective date. For material changes, we will notify you by email or in-app notice before they take effect, and ask for fresh consent where required.
20Contact us
Quinfy Technology Private Limited, 541–542, Tower B3, Spaze I-Tech Park, Sector 49, Gurugram, Haryana 122018, India
- General: hello@quinfy.com
- Privacy: dpo@quinfy.com
- Phone: 080-46800968
- Website: www.quinfy.com