This is version 1.1, which is no longer in force. It is kept because consent given before it was superseded was given against this text. The notice in force is version 1.2.

Privacy notice — your HabileLabs digital business card

Version 1.1 — in effect from 9 August 2026

This notice is standalone: you should be able to understand it without reading any other document. It tells you exactly what happens if you publish a digital business card, and exactly how to stop.


1. In one paragraph

HabileLabs gives every eligible employee a QR code. If you choose to publish your card, scanning that code opens a public web page showing the work contact details you have agreed to publish. We count how many times your code is scanned, but we do not collect any personal information about the person scanning it. You choose whether to publish at all, and which individual fields appear. You can change your mind at any time, in under a minute, without asking anyone.

2. Who is responsible

HabileLabs Private Limited, Jaipur, Rajasthan, India, is the Data Fiduciary for this processing under India's Digital Personal Data Protection Act, 2023.

3. What we take from Microsoft Entra ID, and why

We read the following from the company directory. We read it; we never write to it.

FieldWhy
Display name, first name, surnameIdentifies you on the card and in the saved contact
Job titleTells the person who scanned what you do
DepartmentSame
Company nameBrand
Work email addressSo they can email you
Work / desk telephoneSo they can call you
Mobile telephoneOn by default. You will see it listed before you publish anything, and you can switch it off there or at any time afterwards
Office location, cityOnly if you switch it on
Profile photographOnly if you give separate permission for the photograph
Account enabled, user type, group membershipTo decide who is eligible, and to withdraw your card automatically when you leave. Never published
Entra object ID, employee ID, user principal nameInternal linkage only. Never published

We never collect your date of birth, home address, salary, grade or performance data. Those are not requested from the directory at all.

Our legal basis for reading and internally processing these directory attributes is DPDP Section 7(i) — processing for the purposes of employment. Our legal basis for publishing them on a public web page is your consent, given separately and freely.

4. Publishing is your choice, and refusing costs you nothing

5. What the public page shows

Only the fields you switched on. Nothing else. The page carries no advertising, no third-party content and no tracking scripts.

6. What we record when someone scans your code

We record, for each scan:

We do not record the scanner's IP address, their full browser identification string, their name, or anything that would let us recognise them again. We set no cookies and store nothing on their device. This is why the page has no cookie banner — there is nothing to consent to. If a visitor's browser sends a Global Privacy Control or Do Not Track signal, we record nothing at all and the page still works normally.

7. Scan counts are never used to assess you

Scan data is not used, directly or indirectly, in performance evaluation, appraisal, promotion or any assessment of you. It exists to tell Marketing whether QR codes on a conference banner were worth printing. Using it to evaluate an individual is prohibited by design, and no view in the system shows a manager the scan counts of their reports.

You can see your own scan numbers whenever you like.

8. Your details are always current, and you cannot be left stale

Directory changes appear on your card within about 15 minutes. Your QR code and web address never change when your details do — the code you printed keeps working.

If a field is wrong, you cannot edit it here, because the company directory is the single source of truth and letting the two disagree would defeat the point. Use Request correction on your card page; it raises a ticket, HR or IT fixes the directory, and your card follows automatically.

9. When you leave

When your account is disabled in the directory, your card is withdrawn automatically, within about 15 minutes. Nobody has to remember to do it. From then on the address returns "410 Gone" with a generic message that does not name you and does not say you have left.

Thirty days later your personal data and your photograph are permanently deleted. Your short address is retired forever and is never given to anyone else, so old printed cards fail safely rather than pointing at a stranger.

10. How long we keep things

WhatHow long
Your profile while you work hereDuration of employment, then 30 days
Your photographSame, then permanently deleted including backups of the object
Individual scan records90 days, then automatically expired
Scan totals24 months; your linkage to them is severed when your profile is deleted
Record of your consent choices7 years after consent ends — this is the evidence that we asked you
Administrative action logAt least 12 months, held in India

These are enforced automatically by scheduled deletion, not by anyone remembering.

10a. If you scanned a card and shared your details back

This section is for visitors, not employees.

The card page offers an optional form to send your own contact details to the person whose card you scanned. It is optional in the ordinary sense of the word: skipping it changes nothing.

If you use it we store what you type — your name, email address, and whatever else you choose to add — along with the fact that you ticked the consent box and which version of this notice you ticked it under. We do not record your IP address, your device, or anything else about your visit.

What you send goes to the relevant team at HabileLabs so they can respond to you. It is not sold, not passed to anyone outside HabileLabs, and not used to build a profile of you.

It is deleted automatically one year after you send it. You can ask us to delete it sooner, or to tell you what we hold, by emailing support@habilelabs.io. You do not need an account and you do not need to give a reason.

11. Your rights

You can, at any time:

12. Where your data lives, and who else touches it

All data is stored in Amazon Web Services' Mumbai region (ap-south-1), in India. It is encrypted at rest and in transit. AWS acts as our processor under a data processing agreement. No other third party receives your personal data. If you have your card printed, the printer receives only your QR image and the details you chose to publish, under equivalent contractual terms.

13. Security, and one rule worth memorising

We keep access logs, restrict access to administrators, and encrypt everything.

No page reachable from a HabileLabs QR code will ever ask you for a password, a one-time code, or payment details. Not ever, under any circumstance. If a page reached from one of our codes asks you to log in, it is fake — close it and report it. Please pass that rule on to anyone you give a card to.

14. Changes to this notice

If we change this notice materially we will ask for your consent again against the new version. Every consent record stores the version of the notice you agreed to, so it is always possible to establish what you were told.


Version 1.1, in effect from 9 August 2026. Version 1.0 differed in one respect: the mobile number was not published by default.

The DPDP position on publishing employee details publicly is not settled law. This notice is deliberately written to the stricter reading throughout — consent is treated as the basis for publication, refusal is consequence-free, and every field is individually withdrawable — so that a narrower interpretation later would restrict scope rather than invalidate what people were told.

The current notice