Legal
Privacy Policy
Last updated: June 24, 2026
Effective Date: February 26, 2026
This Privacy Policy ("Policy") describes how Valloce Ventures Private Limited, a company incorporated under the Companies Act, 2013, having its registered office in Ahmedabad, Gujarat, India ("Company", "we", "us", or "our"), operating its product authentication platform under the brand name FirstScanIt, collects, uses, processes, stores, shares, and protects your Digital Personal Data and other information when you use our websites, mobile applications, APIs, and services (collectively, the "Services").
This Policy is published in compliance with the Digital Personal Data Protection Act, 2023("DPDP Act"), the Information Technology Act, 2000 (as amended), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and other applicable data protection laws of India and jurisdictions where our Services are available.
By accessing or using the Services, you consent to the collection and processing of your data as described in this Policy. This Policy should be read together with our Terms of Service. If you do not agree with this Policy, please do not use the Services.
1. Information We Collect
1.1 Information You Provide Directly
- Account Data: Email address, password (stored as a one-way cryptographic hash), name, phone number, organization name, and business contact details
- Medicine Management Data: Medicine names, dosage schedules, reminder preferences, adherence logs, family member profiles (names, relationship, medicine schedules), and health-context notes you voluntarily provide
- Medicine Photographs: Images of medicines uploaded for photo-based identification purposes
- Communications: Content of messages, support requests, and feedback you send to us
- Business Data (Enterprise Users): Product catalogs, batch information, serial codes, manufacturing details, and supply chain configurations
1.2 Information Collected Automatically
- Scan Telemetry: Timestamp, verification result, product identifier, scan duration, and interaction pattern for each product scan
- Device Information: Device type, model, operating system, browser type and version, screen resolution, language settings, and a non-reversible device fingerprint generated from device characteristics (used exclusively for fraud detection)
- Location Data: Approximate geographic location derived from IP address; precise GPS coordinates when you grant location permission (used for scan mapping, regional analytics, and counterfeit hotspot detection)
- Network Data: IP address, connection type, proxy/VPN detection signals, and request headers
- Usage Data: Pages viewed, features used, navigation paths, session duration, and interaction timestamps
- Consumption Events: Product scan history, ownership confirmations, consumption signals, and product lifecycle interactions
1.3 Derived and Inferred Information
Transparency Notice: We generate the following derived data through automated processing of collected information. This processing is essential to the operation of our fraud detection and analytics services.
- Fraud Detection Scores: Automated risk assessments computed from scan patterns, device behavior, location data, and historical activity
- Behavioral Classification: Device categorization (consumer / automated / suspicious) based on interaction pattern analysis
- Consumption Patterns: Aggregated consumption frequency, product preferences, regional demand signals, and seasonal trends extracted from scan and usage data
- Demand Forecasts: Statistical predictions of product demand by region, category, and time period, derived from aggregated consumption data
1.4 Cookies and Similar Technologies
- Essential Cookies: Session management and authentication tokens (httpOnly, secure) — strictly necessary for service operation
- Privacy-Preserving Analytics: Anonymous, aggregate usage analytics that do not track individuals across sessions or use persistent third-party cookies
- No Advertising Trackers: We do not use third-party advertising cookies, cross-site tracking pixels, or behavioral retargeting technologies
1.5 Payment and Billing Information
When you purchase a paid subscription or incur metered QR-generation ("/qr") usage, we collect billing contact details, billing address, GST registration number (GSTIN), and invoice and transaction history. Card and payment-instrument details are collected and processed directly by our PCI-DSS-compliant payment processor, Razorpay Software Private Limited; we do not store your full card number, CVV, or banking credentials on our systems. We receive only a payment reference, the card network and last four digits where provided, and the success or failure status of each transaction, which we use for billing, accounting, fraud prevention, and statutory record-keeping.
2. Purposes of Processing
We process your data for the following lawful purposes under the DPDP Act, 2023:
2.1 Service Delivery
- Operating and maintaining product authentication and verification services
- Providing medicine reminders, dosage alerts, and adherence tracking for you and your family members
- Processing medicine photographs for identification and purpose determination
- Delivering counterfeit product alerts and safety notifications
- Enabling supply chain tracking and product traceability features
2.2 Security and Fraud Prevention
- Detecting, investigating, and preventing counterfeit products, fraudulent scans, and unauthorized access
- Computing fraud risk scores through automated analysis of scan telemetry
- Generating non-reversible device fingerprints for bot detection and abuse prevention
- Maintaining audit trails for compliance and forensic investigation purposes
2.3 Analytics, Machine Learning, and Service Improvement
ML Training Notice: We use anonymized and aggregated data to train and improve our machine-learning systems. No personally identifiable data is used in model training. You may opt out of contributing to aggregate analytics by contacting us.
- Training and improving our proprietary fraud-detection and risk-scoring models
- Enhancing visual authentication systems using product image data (with all personally identifiable information removed)
- Developing and refining demand forecasting algorithms from aggregated consumption patterns
- Improving medicine identification accuracy from anonymized photograph datasets
- Analyzing regional scan patterns to identify counterfeit distribution networks
- Generating statistical insights for product quality and supply chain optimization
2.4 Commercial Intelligence
- Creating anonymized, aggregated demand intelligence reports for manufacturers and authorized commercial partners
- Generating regional consumption trend analyses, seasonal demand predictions, and category-level forecasts
- Providing supply chain optimization insights based on aggregated logistics and delivery data
2.5 Legal Compliance
- Complying with applicable laws, regulations, court orders, and governmental requests
- Enforcing our Terms of Service and protecting the rights and safety of the Company and its users
- Meeting regulatory reporting obligations under pharmaceutical, food safety, and consumer protection laws
3. Consent
By using the Services, you provide free, specific, informed, unconditional, and unambiguous consent to the processing of your Digital Personal Data as described in this Policy. For processing of Sensitive Personal Data (including health-related information such as medicine schedules and adherence data), we obtain verifiable consent through clear, affirmative action at the point of collection.
Withdrawal of Consent: You may withdraw your consent at any time by contacting our Data Protection Officer at dpo@firstscanit.com. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Please note that withdrawal may result in the limitation or termination of certain features of the Services that depend on the processing of your data.
4. Data Sharing and Disclosure
We do not sell your Personal Data. We may share your information in the following limited circumstances:
- Infrastructure Providers: With trusted cloud infrastructure and service providers who process data on our behalf under contractual obligations of confidentiality and data protection no less restrictive than this Policy
- Manufacturers and Brands: With manufacturers and brands who use our platform, limited to verification-related data pertaining to their own products (scan outcomes, counterfeit alerts, regional statistics) — never your personal identity or health data
- Aggregated Intelligence: With authorized commercial partners, we share anonymized, aggregated demand intelligence, consumption trend reports, and supply chain analytics. This data cannot be used to identify any individual user
- Legal Requirements: When required by applicable law, regulation, court order, subpoena, or governmental authority of competent jurisdiction
- Safety and Rights: To protect the rights, property, or safety of the Company, our users, or the public, including detecting and preventing fraud and counterfeit activities
- Business Transfers: In connection with any merger, acquisition, reorganization, asset sale, or bankruptcy proceeding, subject to the acquirer agreeing to honor this Policy
5. Data Security
We implement reasonable and appropriate technical and organizational security measures to protect your data, including:
- Encryption at Rest: Personal data is encrypted using industry-standard authenticated encryption; passwords are hashed using adaptive one-way functions with appropriate work factors
- Encryption in Transit: All data transmissions are protected by TLS 1.2+ with HSTS enforcement
- Access Controls: Role-based access control (RBAC) with principle of least privilege; multi-factor authentication for administrative access
- Audit Logging: Comprehensive structured logging of data access and modification events
- Infrastructure: Services hosted on globally distributed, enterprise-grade cloud infrastructure with DDoS protection, WAF, and automated threat mitigation
- Organizational Measures: Confidentiality agreements with all personnel and contractors; regular security assessments and vulnerability scanning
Despite our efforts, no method of transmission or storage is completely secure. We cannot guarantee absolute security but commit to promptly addressing any breach in accordance with applicable law and our incident response procedures.
6. Data Retention
We retain Personal Data only as long as necessary to fulfill the purposes described in this Policy, or as required by applicable law. Our retention periods are:
| Data Category | Retention Period |
|---|---|
| Account Data | Duration of account + 90 days after deletion |
| Scan Records | 3 years from scan date |
| Medicine/Reminder Data | Duration of account + 30 days after deletion |
| Medicine Photographs | Processed and deleted within 30 days; derived features retained in anonymized form |
| Device Fingerprints | 1 year from last associated activity |
| Consumption Events | 3 years; anonymized form retained indefinitely |
| Anonymized/Aggregated Data | Retained indefinitely (non-identifiable) |
| ML Training Data | Retained indefinitely in anonymized form only |
| Legal Hold / Compliance Data | As required by applicable law or regulatory order |
7. Your Rights as a Data Principal
Under the DPDP Act, 2023 and other applicable laws, you have the following rights:
- Right to Access: Request confirmation of whether we process your Personal Data and obtain a summary of such data
- Right to Correction: Request correction of inaccurate or incomplete Personal Data
- Right to Erasure: Request deletion of your Personal Data, subject to legal retention requirements and the preservation of anonymized/aggregated data
- Right to Grievance Redressal: Lodge complaints regarding our data processing practices with our Grievance Officer or the Data Protection Board of India
- Right to Withdraw Consent: Withdraw previously given consent, subject to the consequences outlined in Section 3
- Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the DPDP Act
To exercise any of these rights, contact our Data Protection Officer at dpo@firstscanit.com. We will respond within the timelines prescribed by the DPDP Act and its Rules.
8. Cross-Border Data Transfers
Your data may be transferred to and processed in countries outside India where our infrastructure providers maintain data centers. Such transfers are made only to countries or entities that ensure an adequate level of data protection as prescribed by the Central Government under the DPDP Act, 2023, or under appropriate contractual safeguards that provide protections no less stringent than those afforded under Indian law.
Our primary infrastructure is hosted on globally distributed cloud infrastructure, which processes data at the location nearest to the user to minimize latency. Data at rest is stored within facilities that comply with applicable data localization requirements.
9. Children's Privacy
DPDP Act Compliance:Under Section 9 of the Digital Personal Data Protection Act, 2023, processing of children's data requires verifiable parental or guardian consent.
- Our Services are not directed to individuals under the age of 18
- Account creation requires the user to be at least 18 years of age
- Consumer scanning (without account) does not collect personally identifiable information from children
- Family medicine management features allow parents/guardians to manage data on behalf of minor family members — this data is processed under the parent/guardian's consent
- We do not knowingly collect personal data from children without verifiable parental consent
- If we discover that we have inadvertently collected data from a child without proper consent, we will delete such data promptly
If you believe we have collected data from a child without proper consent, contact us immediately at dpo@firstscanit.com.
10. Automated Decision-Making
We employ automated processing systems for the following purposes:
- Fraud Detection: Automated scoring of scan events to assess counterfeit probability. These scores inform verification results displayed to users but do not produce legal effects or automated decisions that significantly affect individuals.
- Device Classification: Behavioral analysis to categorize devices as consumer, automated, or suspicious. This classification is used for platform security and does not restrict access to verification results.
- Medicine Identification: AI-powered image analysis of uploaded photographs. Results are informational and are not automated decisions affecting legal rights.
- Demand Forecasting: Statistical models processing aggregated consumption data. These operate exclusively on anonymized, non-personal data.
Where any automated processing could significantly affect you, you have the right to request human review by contacting our Data Protection Officer.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. Material changes will be communicated by posting the revised Policy on this page, updating the "Last updated" date, and where required by law, providing direct notification via email or in-app notice. Your continued use of the Services after any modification constitutes acceptance of the updated Policy.
12. Grievance Redressal
In accordance with the DPDP Act, 2023 and the Information Technology Act, 2000, we have appointed a Grievance Officer to address your concerns regarding data processing:
Valloce Ventures Private Limited
A-603, Aatishya-100, Tulsi Status, Tragad, Ahmedabad, Gujarat 382470, India
Data Protection Officer: dpo@firstscanit.com
Grievance Officer: privacy@firstscanit.com
Security Issues: security@firstscanit.com
Legal Inquiries: legal@firstscanit.com
We will acknowledge your complaint within 48 hours and endeavor to resolve it within the timelines prescribed under the DPDP Act. If you are unsatisfied with our response, you may file a complaint with the Data Protection Board of India.