Privacy Policy

How Quinsta, a background verification service by Quinfy Technology Private Limited, collects, uses, shares and protects your personal data.

Effective: 01 September 2026Last updated: 01 September 2026

  • DPDP Act, 2023
  • IT Act, 2000
  • ISO/IEC 27001
  • ISO 9001
  • SOC 2 Type II

1Who we are

Quinsta is a background verification service offered by Quinfy Technology Private Limited ("Quinfy", "we", "us", "our"), CIN U72500HR2019PTC082072, office at 541–542, Tower B3, Spaze I-Tech Park, Sector 49, Gurugram, Haryana 122018, India.

This policy explains how we collect, use, share, store and protect personal data when you use Quinsta through quinsta.ai, quinplus.com, quinfy.com, our mobile applications and related services (the "Service").

Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), Quinfy is the Data Fiduciary for personal data processed through Quinsta. This policy should be read together with our Terms and Conditions.

2Laws and standards we follow

We process personal data in accordance with:

  • the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025;
  • the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
  • the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, to the extent applicable;
  • the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI regulations, wherever Aadhaar is used;
  • CERT-In Directions of 28 April 2022 on cyber incident reporting and log retention;
  • the EU General Data Protection Regulation (GDPR), where it applies to individuals in the European Economic Area.

Our information security and quality management systems are certified to ISO/IEC 27001 and ISO 9001. Our controls are independently audited under SOC 2 Type II.

3Key terms

  • Personal data: any data about an individual who is identifiable by or in relation to that data.
  • Data Principal: the individual to whom the personal data relates.
  • You: the person using Quinsta, whether verifying yourself or requesting verification of another person.
  • Subject: the person being verified.
  • Processing: any operation on personal data, including collection, storage, use, sharing and erasure.

4Personal data we collect

We collect only the personal data needed for the verification you request.

CategoryExamples
From you as a Quinsta userName, email, mobile number, login details, billing information, record of verifications requested
About the Subject being verifiedFull name, date of birth, gender, photograph, current and past addresses, identity documents (PAN, Aadhaar, passport, voter ID, driving licence), education, employment history, references
Facial verification and livenessLive selfie or video and the facial match result, used only to confirm the Subject is real and matches their ID
From third-party and public sourcesResults from government databases, court and police records, educational institutions, past employers, address and credit verification partners
Collected automaticallyIP address, device type, operating system, browser, pages visited, time stamps, diagnostic logs; precise location only with permission (e.g. digital address verification)

We do not collect data about caste, religion, political opinion, sexual orientation or health unless legally required for a specific check. If that applies, we will tell you before collecting it.

6How we use personal data

We use personal data to:

  1. carry out the identity, address, education, employment, criminal record and other checks you request, and deliver the report;
  2. authenticate users and Subjects, and prevent fraud and misuse of the Service;
  3. process payments and issue invoices;
  4. provide customer support and handle grievances;
  5. maintain security, resolve technical issues and keep audit logs;
  6. comply with legal obligations and respond to lawful requests from authorities;
  7. improve the Service, using aggregated or de-identified data wherever possible;
  8. send marketing communications, only if you have separately opted in.

We do not sell personal data, and we do not use verification data for advertising.

7Aadhaar and government identifiers

We use Aadhaar only through UIDAI-permitted methods, such as Aadhaar offline XML, DigiLocker or masked Aadhaar, and only with the Subject's explicit consent. We do not store full Aadhaar numbers; any stored copy shows only the last four digits. Aadhaar and other government ID data are used only to verify identity.

8Automated processing and QuinAI

Quinsta uses automated tools, including our QuinAI layer, to extract data from documents, match faces and flag discrepancies. No adverse finding is reported based solely on automated processing. A trained verification analyst reviews discrepancies before a final report is issued, and the Subject may request human review of any result.

9Cookies

We use strictly necessary cookies to operate the Service and keep it secure. We use analytics, preference and advertising cookies only with your consent, which you can give, refuse or change at any time through our cookie banner. Refusing non-essential cookies will not affect your use of Quinsta.

10Sharing of personal data

We share personal data only as needed for the purposes in Section 6, with:

  • Verification sources, such as government databases, courts, police authorities, educational institutions and former employers, to confirm information.
  • Data Processors acting on our instructions, including cloud hosting, SMS and email delivery, payment processing and field verification partners. Each is bound by a written contract requiring confidentiality, security and deletion.
  • The user who requested the verification, who receives the report the Subject consented to.
  • Authorities, where required by law, court order or a lawful request.
  • A successor entity in a merger, acquisition or restructuring, subject to this policy.

Payments are processed by PCI-DSS compliant providers. We do not store full card details.

11Storage and cross-border transfers

Quinsta data is stored on AWS servers. We transfer personal data outside India only when a verification requires it, such as confirming a foreign degree or overseas employment. Such transfers go only to countries not restricted by the Government of India under Section 16 of the DPDP Act, and under contractual safeguards.

12Data retention

We keep personal data only as long as its purpose requires, or as the law requires.

DataRetention period
Supporting documents and raw data for a checkDeleted within 90 days of the final report, unless law requires longer
Final verification reports12 months, unless you ask for earlier deletion
Facial images and liveness dataDeleted within 30 days of verification
Account dataWhile your account is active; deleted within 90 days of closure
Security and processing logsAt least one year, per the DPDP Rules and CERT-In Directions
Billing recordsAs required by tax and accounting laws

When the purpose is fulfilled or consent is withdrawn, we erase the data and ensure our Data Processors do the same, unless law requires retention.

13How we protect personal data

We apply reasonable security safeguards consistent with ISO/IEC 27001 and SOC 2 Type II, including:

  • encryption in transit (TLS 1.2 or higher) and at rest (AES-256);
  • role-based access controls with multi-factor authentication;
  • masking of identifiers, activity logging and monitoring;
  • regular vulnerability assessments and penetration tests;
  • employee confidentiality obligations and privacy training;
  • business continuity and disaster recovery plans.

No system is completely secure, but we continuously review and improve these measures.

14Personal data breaches

If a personal data breach occurs, we will inform affected Data Principals without undue delay. We will describe the breach, its likely consequences, the steps we are taking, and what they can do to protect themselves.

We will also notify the Data Protection Board of India without delay and submit a detailed report within 72 hours, and report cyber incidents to CERT-In within 6 hours, as required by law.

15Your rights

Under the DPDP Act, you have the right to:

  • access a summary of your personal data we process, our processing activities, and who we have shared it with;
  • correct, complete or update inaccurate or incomplete personal data;
  • erase personal data that is no longer needed, subject to legal retention requirements;
  • withdraw consent at any time;
  • grievance redressal through our Grievance Officer;
  • nominate another person to exercise your rights in the event of your death or incapacity.

If you are in the European Economic Area, you also have GDPR rights to restrict processing, object to processing, data portability, and not be subject to decisions based solely on automated processing.

To exercise any right, write to dpo@quinfy.com or use the privacy request option in your Quinsta account. We may need to verify your identity first. We will respond within 30 days, and in any case within the period prescribed under the DPDP Rules.

As a Data Principal, you are expected to provide accurate information, not impersonate another person, and not file false or frivolous complaints.

16Children

Quinsta is not intended for individuals under 18. We do not knowingly process a child's personal data without verifiable consent of a parent or lawful guardian, and we do not track, behaviourally monitor or target advertising at children.

If a verification involving a minor is legally required, we will obtain verifiable parental consent as prescribed under the DPDP Rules. If you believe we have collected a child's data without such consent, contact us and we will delete it.

17Grievance Officer and Data Protection Officer

Grievance Officer

Partha Barman
grievance@quinfy.com
080-46800968

Data Protection Officer

Aashish Singh
dpo@quinfy.com

Address: 541–542, Tower B3, Spaze I-Tech Park, Sector 49, Gurugram, Haryana 122018, India.

We will acknowledge grievances within 24 hours and resolve them within 15 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India after exhausting our grievance process.

18Links to other websites

The Service may link to third-party websites. We are not responsible for their privacy practices and encourage you to read their policies.

19Changes to this policy

We may update this policy to reflect changes in law or in our Service. We will post the updated version on this page with a new effective date. For material changes, we will notify you by email or in-app notice before they take effect, and ask for fresh consent where required.

20Contact us

Quinfy Technology Private Limited, 541–542, Tower B3, Spaze I-Tech Park, Sector 49, Gurugram, Haryana 122018, India