Privacy Policy

Last updated: July 9, 2026 | complies with GDPR & EU AI Act

1. Data Collection & Processing Scope

At isAI Tech Ltd, we take B2B privacy extremely seriously. We collect and process two categories of data:

  • Operator Credentials: Contact details of the Participating Business administrators (Names, Emails, HQ addresses, LinkedIn Profiles) for identity verification and anti-spoofing compliance.
  • Dynamic Scan Session Logs: When an end-consumer scans a CnQRCB verification badge, we log their dynamic transaction timestamp, the system ID, and routing success status. We do NOT collect or store personally identifiable consumer data (PII) during scans. Session logs exist purely to verify authenticity and build immutable audit ledgers.

2. Purpose of Processing & Legal Basis

Our processing of operator contact credentials is based on contract performance and our legitimate interests in securing our platform from registration spoofing or fraudulent trademark representations.

The processing of anonymous scan metadata is conducted on the legal basis of compliance with legal obligations—specifically, facilitating compliance audits under Article 50(1) transparency clauses of the EU AI Act.

3. Data Retention & ledger Security

Operator accounts and registered systems details are retained for the duration of the subscription trial or active plan. Transaction logs for CnQRCB routing sessions are stored on an encrypted database, signed with cryptographic hashes, and retained for up to 5 years to defend operators in any regulatory or compliance investigations.

4. GDPR Rights

In accordance with the General Data Protection Regulation (GDPR), participating administrators have the right to access, rectify, or request erasure of their contact details, as well as the right to restrict or object to certain processing activities. To exercise these rights, please file a support ticket inside your dashboard.


Back to Home