Privacy notice — your HabileLabs digital business card
Version 1.2 — in effect from 6 September 2026
What changed since version 1.1. Two things, both of which need your agreement before they affect you:
- You can now have more than one card. Each has its own web address and its own QR code, and each counts its own scans.
- HabileLabs can offer you ready-made content to put on a card — a tagline, a list of what you do, partner or accreditation logos. Version 1.1 promised the page carried "no advertising and no third-party content", and partner logos are arguably both, so we cannot rely on your agreement to 1.1 for them.
Nothing on any card you have already published changes because of this notice. If you do nothing, your card stays exactly as it is.
This notice is standalone: you should be able to understand it without reading any other document. It tells you exactly what happens if you publish a digital business card, and exactly how to stop.
1. In one paragraph
HabileLabs gives every eligible employee a QR code. If you choose to publish your card, scanning that code opens a public web page showing the work contact details you have agreed to publish. We count how many times your code is scanned, but we do not collect any personal information about the person scanning it. You choose whether to publish at all, and which individual fields appear. You can change your mind at any time, in under a minute, without asking anyone.
2. Who is responsible
HabileLabs Private Limited, Jaipur, Rajasthan, India, is the Data Fiduciary for this processing under India's Digital Personal Data Protection Act, 2023.
- Grievance contact: support@habilelabs.io — monitored, and open to employees and members of the public alike.
- We answer grievances within 30 days (90 days maximum).
- You may complain to the Data Protection Board of India at any time.
3. What we take from Microsoft Entra ID, and why
We read the following from the company directory. We read it; we never write to it.
| Field | Why |
|---|---|
| Display name, first name, surname | Identifies you on the card and in the saved contact |
| Job title | Tells the person who scanned what you do |
| Department | Same |
| Company name | Brand |
| Work email address | So they can email you |
| Work / desk telephone | So they can call you |
| Mobile telephone | On by default. You will see it listed before you publish anything, and you can switch it off there or at any time afterwards |
| Office location, city | Only if you switch it on |
| Profile photograph | Only if you give separate permission for the photograph |
| Account enabled, user type, group membership | To decide who is eligible, and to withdraw your card automatically when you leave. Never published |
| Entra object ID, employee ID, user principal name | Internal linkage only. Never published |
We never collect your date of birth, home address, salary, grade or performance data. Those are not requested from the directory at all.
Our legal basis for reading and internally processing these directory attributes is DPDP Section 7(i) — processing for the purposes of employment. Our legal basis for publishing them on a public web page is your consent, given separately and freely.
4. Publishing is your choice, and refusing costs you nothing
- Your card starts as a draft. It is not public. Until you actively publish it, the address returns "not found".
- You give consent per field. You can publish your desk phone and not your mobile.
- Your photograph has its own separate switch, distinct from everything else.
- Refusing to publish has no disciplinary, career, performance or pay consequence of any kind. This is a commitment, not a courtesy. If anyone suggests otherwise, that is a grievance and we want to hear about it.
5. What the public page shows
Only the fields you switched on, plus any HabileLabs content you chose to add (§5a). Nothing else. The page carries no tracking scripts, no analytics service, no cookies and no advertising network.
5a. HabileLabs content you can choose to add
HabileLabs writes and approves blocks of content you may put on a card: a tagline, the services or products you work on, partner logos, accreditation badges.
Four things about them, and each is a rule we hold ourselves to rather than a description of current behaviour:
- Every one is off until you switch it on. Nothing is pre-selected, and there is no administrator action anywhere in the system that can add one to your card. An administrator can remove content from a card; nobody but you can put it there.
- You choose per card. A conference card can carry a product list your company card does not.
- What you picked is what stays. Each card records the exact version of each block you chose. If HabileLabs later edits the wording, your card keeps the wording you agreed to until you choose the new one.
- If HabileLabs withdraws a block, it disappears from your card. That is the one change to a published card you have not personally made, and it can only ever remove content, never add or alter it.
Partner and accreditation logos belong to the organisations they name. We show them only where HabileLabs holds the right to, and an administrator has to confirm that right by name before such a logo can be offered to anybody.
5b. Having more than one card
You can create up to five cards. Each has its own address, its own QR code and its own scan count, and you publish and unpublish each one separately.
Being honest about what that means:
- The cards are visibly the same person. They carry your name and your directory details. Somebody holding two of your cards can tell they are yours. They are not aliases and are not intended as a way to be anonymous with anyone.
- A card's address is permanent, and archiving one does not free it. A code is never reissued to anybody else, ever — so a card printed years ago can never resolve to a stranger. An archived card's address says the card is no longer available, for good.
- You are limited to ten addresses in total over your time here, for the same reason: every address we issue is one we must keep answering for permanently.
- HabileLabs staff can take any of your cards down. They cannot publish one, edit what it says, or create one for you.
6. What we record when someone scans your code
We record, for each scan:
- which card was scanned;
- the date and hour (not the minute or second);
- the country, and at most the region, the scan came from;
- whether the device was a phone, tablet or computer;
- broadly where the link was followed from (direct, email, social, other);
- whether the visitor saved your contact.
We do not record the scanner's IP address, their full browser identification string, their name, or anything that would let us recognise them again. We set no cookies and store nothing on their device. This is why the page has no cookie banner — there is nothing to consent to. If a visitor's browser sends a Global Privacy Control or Do Not Track signal, we record nothing at all and the page still works normally.
7. Scan counts are never used to assess you
Scan data is not used, directly or indirectly, in performance evaluation, appraisal, promotion or any assessment of you. It exists to tell Marketing whether QR codes on a conference banner were worth printing. Using it to evaluate an individual is prohibited by design, and no view in the system shows a manager the scan counts of their reports.
You can see your own scan numbers whenever you like.
8. Your details are always current, and you cannot be left stale
Directory changes appear on your card within about 15 minutes. Your QR code and web address never change when your details do — the code you printed keeps working.
If a field is wrong, you cannot edit it here, because the company directory is the single source of truth and letting the two disagree would defeat the point. Use Request correction on your card page; it raises a ticket, HR or IT fixes the directory, and your card follows automatically.
9. When you leave
When your account is disabled in the directory, your card is withdrawn automatically, within about 15 minutes. Nobody has to remember to do it. From then on the address returns "410 Gone" with a generic message that does not name you and does not say you have left.
Thirty days later your personal data and your photograph are permanently deleted. Your short address is retired forever and is never given to anyone else, so old printed cards fail safely rather than pointing at a stranger.
10. How long we keep things
| What | How long |
|---|---|
| Your profile while you work here | Duration of employment, then 30 days |
| Your photograph | Same, then permanently deleted including backups of the object |
| Individual scan records | 90 days, then automatically expired |
| Scan totals | 24 months; your linkage to them is severed when your profile is deleted |
| Record of your consent choices | 7 years after consent ends — this is the evidence that we asked you |
| Administrative action log | At least 12 months, held in India |
These are enforced automatically by scheduled deletion, not by anyone remembering.
10a. If you scanned a card and shared your details back
This section is for visitors, not employees.
The card page offers an optional form to send your own contact details to the person whose card you scanned. It is optional in the ordinary sense of the word: skipping it changes nothing.
If you use it we store what you type — your name, email address, and whatever else you choose to add — along with the fact that you ticked the consent box and which version of this notice you ticked it under. We do not record your IP address, your device, or anything else about your visit.
What you send goes to the relevant team at HabileLabs so they can respond to you. It is not sold, not passed to anyone outside HabileLabs, and not used to build a profile of you.
It is deleted automatically one year after you send it. You can ask us to delete it sooner, or to tell you what we hold, by emailing support@habilelabs.io. You do not need an account and you do not need to give a reason.
11. Your rights
You can, at any time:
- See what we hold about you — it is all on your own card page;
- Correct it — via Request correction, which fixes it at source;
- Withdraw — unpublish your card, or any single field, yourself. It takes effect within 5 minutes and is reversible. Withdrawing is exactly as easy as consenting, and never needs an HR ticket;
- Erase — ask for your data to be deleted, subject to any documented legal hold;
- Nominate someone to exercise these rights on your behalf if you are unable to;
- Complain — to the grievance contact above, or to the Data Protection Board of India.
12. Where your data lives, and who else touches it
All data is stored in Amazon Web Services' Mumbai region (ap-south-1), in India. It is encrypted at rest and in transit. AWS acts as our processor under a data processing agreement. No other third party receives your personal data. If you have your card printed, the printer receives only your QR image and the details you chose to publish, under equivalent contractual terms.
13. Security, and one rule worth memorising
We keep access logs, restrict access to administrators, and encrypt everything.
No page reachable from a HabileLabs QR code will ever ask you for a password, a one-time code, or payment details. Not ever, under any circumstance. If a page reached from one of our codes asks you to log in, it is fake — close it and report it. Please pass that rule on to anyone you give a card to.
14. Changes to this notice
If we change this notice materially we will ask for your consent again against the new version. Every consent record stores the version of the notice you agreed to, so it is always possible to establish what you were told.
Older versions stay published for as long as any consent record cites them. Version 1.1 is at /privacy/1.1.
Version 1.2 is the first change since this system launched, and it is additive: it describes two things you may now choose to do. It removes nothing and it changes nothing about a card you have already published. Until you accept 1.2 you keep everything 1.1 promised you, and the two new capabilities are simply unavailable — the software checks the version you accepted before offering either of them, so this is enforced and not merely stated.
Version 1.2, in effect from 6 September 2026. It adds §5a (HabileLabs content you can choose to add) and §5b (having more than one card), and amends §5 so the "no third-party content" promise reads correctly alongside them. Version 1.1 — archived at /privacy/1.1 — differed in those respects and no other. Version 1.0 differed from 1.1 in one respect: the mobile number was not published by default.
The DPDP position on publishing employee details publicly is not settled law. This notice is deliberately written to the stricter reading throughout — consent is treated as the basis for publication, refusal is consequence-free, and every field is individually withdrawable — so that a narrower interpretation later would restrict scope rather than invalidate what people were told.
Earlier versions: version 1.1