Legal

    Privacy Policy

    Last updated: July 12, 2026

    Notice: This document is a working draft maintained by Tracetex 360 Innovations (OPC) Pvt Ltd. It is provided for transparency and is being refined in consultation with qualified legal counsel. It does not constitute legal advice, and specific commercial engagements are governed by separately signed agreements.

    1. Introduction

    Tracetex 360 Innovations (OPC) Pvt Ltd. ("Tracetex", "we", "us", or "our") operates digital traceability and sustainability infrastructure for the textile industry, including the Tracetex marketing site (tracetex.in), the Tracetex App (tracetexinfra.com), DigiWardrobe Hub, and the Tracetex Command Center (together, the "Services"). This Privacy Policy explains what personal data we process, why we process it, and the rights available to individuals in India, the European Union / European Economic Area, the United Kingdom, Australia, and other jurisdictions where our Services are used.

    This Policy is written to align with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, the Australian Privacy Act 1988, and India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") together with the DPDP Rules, 2025 notified on 13 November 2025. Where obligations differ across regimes, we apply the standard that is most protective of the individual.

    2. Data Controller / Data Fiduciary

    For personal data processed through the Services, the controller / Data Fiduciary is Tracetex 360 Innovations (OPC) Pvt Ltd., with offices in Kolkata and Durgapur, West Bengal, India. You may contact our privacy team at contact@tracetex.in. Where we process personal data on behalf of a customer brand, MSME, certification body, or government program (for example, worker or supplier records uploaded by that customer), we act as a processor / Data Processor and the customer remains the controller / Data Fiduciary for that data.

    3. Personal Data We Process

    3.1 Data you provide directly

    • Contact and account data: name, business name, role, email address, phone number, and password credentials when you register, request a demo, submit a partner form, or subscribe to updates.
    • Business and compliance data: company details, VAT / GST identifiers, certifications claimed, supplier declarations, and information needed to verify your identity as a Data Fiduciary or authorised representative.
    • Communications: messages you send to us by email, in-app messaging, or completed intake forms.
    • Payment data: billing details processed by our payment processor (Stripe); Tracetex does not store full card numbers on its own systems.

    3.2 Data you upload about others

    Customer brands and manufacturers may upload information about workers, farmers, weavers, suppliers, and supply chain partners in order to generate Digital Product Passports (DPPs), Unique IDs (UIDs), and audit-ready traceability records. Customers remain responsible for having a lawful basis and appropriate notices in place for this data.

    3.3 Data collected automatically

    • Device and usage data: IP address, browser type, operating system, referring URL, pages viewed, and interactions with the Services.
    • QR / UID scan events: timestamped scan records generated when a consumer scans a garment QR code, used to serve the correct DPP and to produce aggregate scan analytics for the associated brand.
    • Cookies and similar technologies: strictly necessary cookies for authentication and session security, and, where permitted, analytics cookies to help us improve the Services (see Section 8).

    We do not knowingly collect data revealing racial or ethnic origin, political opinions, religious beliefs, health, or sexual orientation, and we do not knowingly collect data from children under 18 (or the higher local age of majority). If you believe a child's data has been submitted to us, please contact us and we will delete it.

    4. Purposes and Legal Bases

    We process personal data only where we have a lawful basis to do so:

    • Performance of a contract — to create and manage your account, deliver the Services, generate DPPs / UIDs / QR codes, process payments, and provide customer support.
    • Legitimate interests — to secure the Services, prevent fraud and counterfeit activity, maintain audit logs, and improve product features, provided these interests are not overridden by your rights.
    • Consent — for optional communications (such as marketing emails or newsletters), non-essential cookies, and any processing where consent is the applicable basis under the DPDP Act. Consent can be withdrawn at any time.
    • Legal obligation — to comply with tax, corporate, sanctions, anti-money-laundering, and regulatory record-keeping obligations in India and other jurisdictions where we operate.

    5. How We Share Personal Data

    We share personal data only with the following categories of recipients:

    • Service providers (processors): cloud hosting, database (Supabase), email delivery, analytics, and payment processing (Stripe) — bound by written agreements requiring appropriate security and confidentiality.
    • Customer brands and certification bodies: where you interact with a specific brand's or certifier's Tracetex workspace, relevant records are visible to that customer as controller.
    • Public DPP lookup: information that a customer publishes on a garment's DPP (for example material composition or manufacturer name) is intentionally public via QR-scan and is not treated as confidential.
    • Regulators, auditors, and law enforcement: where required by law, court order, or valid regulatory request, or to protect our rights and the safety of users.
    • Corporate transactions: in the context of a merger, acquisition, financing, or reorganisation, with continued protection of your data.

    We do not sell personal data, and we do not use personal data for third-party advertising.

    6. International Transfers

    Tracetex is headquartered in India and serves customers globally. Personal data may therefore be transferred to, and processed in, countries outside your country of residence, including India and other jurisdictions where our service providers operate. Where personal data of individuals in the EU / EEA or UK is transferred, we rely on lawful transfer mechanisms such as the European Commission's Standard Contractual Clauses and, where relevant, supplementary safeguards. For transfers under the DPDP Act, we transfer personal data only to jurisdictions not restricted by the Central Government of India.

    7. Data Retention

    We retain personal data only for as long as necessary for the purposes described in this Policy, to satisfy contractual and legal obligations, to resolve disputes, and to enforce our agreements. Traceability, DPP, UID, and audit records are retained for the period required to support product-lifecycle transparency and applicable compliance obligations (typically the life of the product plus statutory retention periods). Account and billing data are retained for the duration of the account and for a reasonable period afterwards to meet statutory record-keeping requirements.

    8. Cookies and Analytics

    We use strictly necessary cookies to authenticate users and secure sessions. Where we use analytics or preference cookies, we request consent through a cookie banner and respect your choices. You can manage cookies through your browser at any time; disabling strictly necessary cookies may prevent parts of the Services from functioning correctly.

    9. Your Rights

    Subject to applicable law, you may exercise the following rights in relation to your personal data:

    • Access — obtain confirmation of processing and a copy of your personal data.
    • Correction — request that inaccurate or incomplete data be corrected.
    • Erasure / deletion — request deletion where the data is no longer needed or where you withdraw consent, subject to overriding legal obligations.
    • Restriction and objection — restrict or object to certain processing based on legitimate interests.
    • Data portability — receive certain data in a portable format (GDPR / UK GDPR).
    • Withdraw consent — where processing is based on consent, without affecting the lawfulness of prior processing.
    • Nominate — under the DPDP Act, nominate another person to exercise your rights in the event of death or incapacity.
    • Complain — lodge a complaint with a supervisory authority, including the Data Protection Board of India, your EU Data Protection Authority, the UK Information Commissioner's Office, or the Office of the Australian Information Commissioner.

    Requests can be submitted to contact@tracetex.in. We will respond within the timeframes required by applicable law.

    10. Security

    We maintain administrative, technical, and organisational safeguards designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include role-based access control, database row-level security, encryption of data in transit, secure credential storage, audit logging, and vendor security reviews. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to or stored on our Services.

    11. Breach Notification

    In the event of a personal data breach that is likely to result in risk to individuals' rights, we will notify the relevant supervisory authorities and affected individuals in accordance with applicable law, including the DPDP Act and GDPR notification timelines.

    12. Changes to this Policy

    We may update this Policy from time to time. Material changes will be highlighted on the Services and, where required, notified to you directly. The "Last updated" date at the top of this page reflects the most recent revision.

    Contact

    Tracetex 360 Innovations (OPC) Pvt Ltd.
    Kolkata & Durgapur, West Bengal, India
    Email: contact@tracetex.in
    Phone: +91 7890110465