Legal · Regional compliance
Regional Compliance
YE-Tra is a platform operated by CalmCoral Private Limited. This page brings together the region-specific privacy notices required under two laws: India's Digital Personal Data Protection Act, 2023 (DPDP Act) and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Both supplement — and don't replace — our Privacy Policy, which covers our full data-handling practices across every region we operate in. Use the links above, or the table of contents below, to jump straight to either part.
Part 1 · India
Digital Personal Data Protection Act, 2023 (DPDP Act)
1. Overview
The DPDP Act governs how organisations processing the personal data of individuals in India ("Data Principals") must collect, use, and protect that data. YE-Tra is built around data minimisation as a first principle — we collect the least personal data necessary to run the platform, and shoppers who scan a YE-Tra QR code are never required to provide any personal information at all.
2. Our role: Data Fiduciary
YE-Tra acts as a Data Fiduciary for the account information brands provide us (name, contact email, product data), and as a processor on behalf of brand clients for the scan analytics we generate about their products. Brand clients remain responsible for any personal data they choose to include in their own product content.
3. Personal data we process
| Data | From whom | Purpose |
| Name, company name, contact email, phone | Brand clients, at signup | Account creation & operation |
| Hashed IP address, device/browser type, timestamp | Shoppers, on scan | Scan analytics, rate limiting & abuse prevention |
| Name, contact detail, message | Anyone using Contact Us | Responding to the inquiry |
Full detail on what's collected and why is in §2 of our Privacy Policy.
4. Legal basis & consent
- Contract performance — account data, product data, and billing information are processed to deliver the service a brand client signed up for.
- Legitimate interest — hashed IP addresses from scans are used only for rate limiting and abuse/fraud prevention.
- Consent — before AI-generated content is distributed via a QR code, the client explicitly acknowledges having reviewed it; that acknowledgement is logged with a timestamp and the policy version in effect.
5. Data minimisation — scan pages
Every YE-Tra scan page carries a plain-language notice, visible to the shopper at the point of scan:
🔒 Your scan is anonymous. No personal data is stored.
Shoppers are never asked to log in, provide contact details, or accept a tracking cookie to view a scanned product page or use its chatbot.
6. Your rights as a Data Principal
- Right to access — request a summary of the personal data we hold about you.
- Right to correction — update your name, email, and phone anytime from My Profile in the client portal, or contact us for anything not self-serviceable.
- Right to erasure — request deletion of your personal data, subject to our legal retention obligations (see §7).
- Right to grievance redressal — raise a complaint with our Grievance Officer (see §10); we acknowledge within 24 hours and aim to resolve within 15 days.
- Right to nominate — nominate another individual to exercise these rights on your behalf in the event of death or incapacity, by contacting us.
7. Data retention
- Deleted products are kept in a recovery cache for 10 days before permanent removal.
- Deleted QR Suite site summaries are kept in a trash folder for 30 days before permanent removal.
- Identity verification documents are retained only as long as your account remains active and verification is required.
- If you close your account, we delete or anonymize personal data within a reasonable period, except where we're required to retain records by law.
8. Security safeguards
- Brand client accounts sign in through AWS Cognito, with Google Sign-In as the supported method — we never receive, see, or store your password, and have no ability to reset or recover it; that's entirely between you and Google.
- IP addresses are hashed on arrival; we never persist a shopper's raw IP.
- QR/scan URLs are cryptographically signed to prevent tampering and forged scan inflation.
- Login attempts are rate-limited to reduce automated password-guessing.
- Access to identity verification documents and admin tools is restricted to authorized account administrators.
9. Breach notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, and take immediate steps to contain and remediate the breach.
10. Grievance Officer
As required under the DPDP Act and the IT Rules 2021, we have designated a Grievance Officer to address complaints about how your personal data is handled:
We acknowledge grievances within 24 hours and aim to resolve them within 15 days, in line with the IT Rules 2021.
11. Children's data
YE-Tra is a business-to-business platform intended for brands, retailers, and their adult staff. It is not directed at children, and we do not knowingly collect personal data from anyone under 18, consistent with the DPDP Act's provisions on children's data.
12. Changes to this notice
We may update this notice as the platform or applicable law evolves. The version number and effective date at the top of this page will change whenever we do.
This Part is provided for transparency about our DPDP Act compliance and does not constitute legal advice. If you need a jurisdiction-specific legal opinion, please consult a qualified lawyer.
Part 2 · Canada
Personal Information Protection and Electronic Documents Act (PIPEDA)
14. Overview
PIPEDA governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activity in Canada. YE-Tra is built around data minimisation as a first principle — we collect the least personal information necessary to run the platform, and shoppers who scan a YE-Tra QR code are never required to provide any personal information at all.
15. Our role: Organization
Under PIPEDA, YE-Tra is the "organization" accountable for the personal information brands provide us (name, contact email, product data), and acts on behalf of brand clients for the scan analytics we generate about their products. Brand clients remain responsible for any personal information they choose to include in their own product content.
16. Personal information we process
| Data | From whom | Purpose |
| Name, company name, contact email, phone | Brand clients, at signup | Account creation & operation |
| Hashed IP address, device/browser type, timestamp | Shoppers, on scan | Scan analytics, rate limiting & abuse prevention |
| Name, contact detail, message | Anyone using Contact Us | Responding to the inquiry |
Full detail on what's collected and why is in §2 of our Privacy Policy.
17. The 10 fair information principles
PIPEDA is built around ten principles. Here's how each applies to YE-Tra:
- Accountability — our Privacy Officer (§23) is responsible for our compliance with this notice and our Privacy Policy.
- Identifying purposes — we state why we collect information at the point of collection (account signup, scan pages, Contact Us).
- Consent — account data is collected with your knowledge at signup; before AI-generated content is distributed via a QR code, the client explicitly acknowledges having reviewed it, logged with a timestamp and the policy version in effect.
- Limiting collection — we collect only what's needed to operate the service (see §16).
- Limiting use, disclosure & retention — information is used only for the purposes identified and retained only as long as necessary (see §20).
- Accuracy — account information can be corrected anytime from My Profile in the client portal.
- Safeguards — see our security measures in §21.
- Openness — this notice and our Privacy Policy are published and freely accessible.
- Individual access — you can request a summary of the personal information we hold about you (see §19).
- Challenging compliance — you can raise a complaint with our Privacy Officer (see §23).
18. Data minimization — scan pages
Every YE-Tra scan page carries a plain-language notice, visible to the shopper at the point of scan:
🔒 Your scan is anonymous. No personal data is stored.
Shoppers are never asked to log in, provide contact details, or accept a tracking cookie to view a scanned product page or use its chatbot.
19. Your rights
- Right to access — request a summary of the personal information we hold about you.
- Right to correction — update your name, email, and phone anytime from My Profile in the client portal, or contact us for anything not self-serviceable.
- Right to withdraw consent — request deletion of your personal information, subject to our legal retention obligations (see §20).
- Right to complain — raise a complaint with our Privacy Officer (see §23); if unresolved, you may escalate to the Office of the Privacy Commissioner of Canada.
20. Data retention
- Deleted products are kept in a recovery cache for 10 days before permanent removal.
- Deleted QR Suite site summaries are kept in a trash folder for 30 days before permanent removal.
- Identity verification documents are retained only as long as your account remains active and verification is required.
- If you close your account, we delete or anonymize personal information within a reasonable period, except where we're required to retain records by law.
21. Security safeguards
- Brand client accounts sign in through AWS Cognito, with Google Sign-In as the supported method — we never receive, see, or store your password, and have no ability to reset or recover it; that's entirely between you and Google.
- IP addresses are hashed on arrival; we never persist a shopper's raw IP.
- QR/scan URLs are cryptographically signed to prevent tampering and forged scan inflation.
- Login attempts are rate-limited to reduce automated password-guessing.
- Access to identity verification documents and admin tools is restricted to authorized account administrators.
22. Breach notification
In the event of a breach of security safeguards involving personal information that poses a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada and affected individuals as required under PIPEDA, and take immediate steps to contain and remediate the breach.
23. Privacy Officer
As required under PIPEDA's accountability principle, we have designated a Privacy Officer to address complaints about how your personal information is handled:
We acknowledge complaints promptly and aim to resolve them within 30 days.
24. Children's data
YE-Tra is a business-to-business platform intended for brands, retailers, and their adult staff. It is not directed at children, and we do not knowingly collect personal information from anyone under 18.
25. Changes to this notice
We may update this notice as the platform or applicable law evolves. The version number and effective date at the top of this page will change whenever we do.
This Part is provided for transparency about our PIPEDA compliance and does not constitute legal advice. If you need a jurisdiction-specific legal opinion, please consult a qualified lawyer.