Version 1.1 · In effect from 9 August 2026

Privacy notice — your HabileLabs digital business card

Who is responsible for your data

HabileLabs Private Limited, Jaipur, Rajasthan, India is the Data Fiduciary for the information described here, and is responsible for how it is handled, under India’s Digital Personal Data Protection Act, 2023. This notice covers one system only — the digital business card — and stands on its own: you do not need to read anything else to understand it.

In one paragraph

HabileLabs gives every eligible employee a QR code. If you choose to publish your card, scanning that code opens a public web page showing the work contact details you have agreed to publish. We count how many times your code is scanned, but we collect no personal information about the person scanning it. You choose whether to publish at all, and which individual fields appear. You can change your mind at any time, in under a minute, without asking anyone.

What we take from Microsoft Entra ID

Your name, job title, department, company, work email, work telephone and mobile number, and — only if you switch them on — your office location and photograph. We also read whether your account is enabled and which groups you belong to, in order to decide eligibility and to withdraw your card automatically when you leave. Those last items are never published.

We never collect your date of birth, home address, salary, grade or performance data. Those are not requested from the directory at all.

Our legal basis for reading and internally processing directory attributes is DPDP Section 7(i) — processing for the purposes of employment. Our legal basis for publishing them on a public web page is your consent, given separately and freely.

Publishing is your choice, and refusing costs you nothing

Your card starts as a draft and is not public. You consent per field, and your photograph has its own separate switch. Your mobile number is switched on when the card is prepared, because at HabileLabs it is generally the only number you have — you will see it listed before you publish anything, and you can switch it off there and at any time afterwards. Refusing to publish has no disciplinary, career, performance or pay consequence of any kind. If anyone suggests otherwise, that is a grievance and we want to hear about it.

What we record when someone scans your code

Which card was scanned, the date and hour (not the minute or second), the country and at most the region, whether the device was a phone, tablet or computer, broadly where the link was followed from, and whether the visitor saved your contact.

We do not record the scanner’s IP address, their full browser identification string, or anything that would let us recognise them again. We set no cookies and store nothing on their device. That is why this page has no cookie banner — there is nothing to consent to. If a visitor’s browser sends a Global Privacy Control or Do Not Track signal, we record nothing at all and the page still works.

Scan counts are never used to assess you

Scan data is not used, directly or indirectly, in performance evaluation, appraisal, promotion or any assessment of you. It exists to tell Marketing whether QR codes on a conference banner were worth printing. No view in this system shows a manager the scan counts of their reports. You can see your own numbers whenever you like.

If you scanned a card and shared your details back

This section is for visitors, not employees. The card page offers an optional form to send your own contact details to the person whose card you scanned. It is entirely optional, and skipping it changes nothing about the page you are reading.

If you use it, we store only what you type — your name, email, and anything else you choose to add — together with the fact that you ticked the box and the version of this notice you ticked it under. We do not record your IP address, your device, or anything else about your visit. Your details go to the relevant team at HabileLabs so they can respond to you. They are not sold, not passed to anyone outside HabileLabs, and not used to build a profile of you.

They are deleted automatically one year after you send them. You can ask us to delete them sooner, or tell you what we hold, by emailing support@habilelabs.io — you do not need an account, and you do not need to explain why.

When you leave

When your account is disabled in the directory, your card is withdrawn automatically within about 15 minutes. Nobody has to remember to do it. Thirty days later your personal data and photograph are permanently deleted. Your short address is retired forever and is never given to anyone else, so old printed cards fail safely rather than pointing at a stranger.

Your rights

You can see what we hold, correct it at source, withdraw your card or any single field yourself, ask for erasure, nominate someone to act for you, and complain. Withdrawing is exactly as easy as consenting and never needs an HR ticket.

Where your data lives

All data is stored in Amazon Web Services’ Mumbai region, in India, encrypted at rest and in transit. No third party receives your personal data other than AWS acting as our processor.

One rule worth memorising

No page reachable from a HabileLabs QR code will ever ask you for a password, a one-time code, or payment details. Not ever. If a page reached from one of our codes asks you to log in, it is fake — close it and report it.

Contact and complaints

For anything about this notice — a question, a correction, a request to see or erase what we hold, or a complaint — write to support@habilelabs.io. You do not need to explain why you are asking, and employees do not need to go through HR.

We answer grievances within 30 days, and within 90 days at the very latest. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.

Back

HabileLabs