Neurasense (Private) Limited ("Neurasense," "we," "us," or "our"), a company incorporated in the Democratic Socialist Republic of Sri Lanka, operates the software-as-a-service product NSQR, accessible at https://nsqr.neurasense.io ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with the Service.
Data controller: Neurasense (Private) Limited Company registration number: PV 00286247 Incorporated in the Democratic Socialist Republic of Sri Lanka under the Companies Act No. 7 of 2007 Email: payments.nsqr@neurasense.io
This Policy should be read together with our Terms of Service and Refund Policy.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Two Kinds of People This Policy Covers
NSQR generates dynamic QR codes on behalf of our customers, and records analytics when those codes are scanned. That means this Policy concerns two distinct groups:
- Account holders — the individuals and organisations who register for and use the Service. Where this Policy says "you," it means an account holder. For account holder information, Neurasense is the data controller.
- Scanners — members of the public who scan a QR code created by an account holder. Scanners have no account with us and no direct relationship with us. For scan data, the account holder is the data controller and Neurasense acts as their data processor, handling scan data only on that customer's documented instructions.
Section 3 deals specifically with scan data. If you scanned a QR code and want to know who is responsible for the resulting record, see Section 3(d).
2. Information We Collect From Account Holders
a) Information you provide directly
- Account information: name, email address, company name, and password when you register.
- Billing information: billing name, address, and country. Full card and payment credentials are collected and processed directly by our third-party payment processor — we do not store full payment card numbers on our own servers and never see them in complete form.
- Communications: information you provide when you contact us for support at payments.nsqr@neurasense.io.
- Customer Data: QR code configurations, destination URLs, uploaded design assets, campaign names, and any other content or files you upload or generate while using the Service.
b) Information collected automatically
- Usage data: pages visited, features used, timestamps, and interactions with the Service.
- Device and log data: IP address, browser type, operating system, device identifiers, and referring URLs.
- Cookies and similar technologies: used to operate, secure, and analyse the Service, and to remember your preferences (see Section 8).
c) Information from third parties
We may receive information about you from third-party services you connect to the Service, such as payment processors, in accordance with their own privacy policies.
3. Scan Data
This section describes information collected when a QR code created through the Service is scanned. It is the part of this Policy most likely to concern someone who is not one of our customers.
a) What is collected on scan
When a QR code generated by NSQR is scanned, we record:
- the date and time of the scan;
- the IP address of the scanning device;
- approximate location derived from that IP address — city and country level only;
- device and browser characteristics, such as operating system, device type, and browser user-agent string;
- the identifier of the QR code scanned and the destination it resolved to at that moment.
b) What is not collected
We do not collect precise or GPS-level location from scanning devices. NSQR does not request device location permissions, and location in our analytics is inferred from IP address alone, which gives an approximate city and country and is not a reliable indicator of a person's actual position. We do not collect names, email addresses, or contact details from scanners, and we do not attempt to identify individual scanners or build profiles that follow a scanner across different customers' QR codes.
c) Why it is collected
Scan data exists to provide our customers with the analytics feature they subscribe to — aggregate counts and breakdowns of scans by time, approximate location, and device type — and to detect fraud, abuse, and technical faults in the Service.
d) Who is responsible for it
The account holder who created the QR code determines why scan data is collected and is the data controller for it. Neurasense processes that data on their behalf and on their instructions, as their processor. If you scanned a QR code and wish to exercise rights over the resulting record, your request is properly directed to the organisation whose QR code you scanned. If you do not know who that is, contact us at payments.nsqr@neurasense.io and we will, where we reasonably can, identify the relevant customer or forward your request to them.
Our customers are required under our Terms of Service to have a lawful basis for collecting scan analytics and to disclose that collection in their own privacy notice. We do not independently verify that they have done so.
e) How long it is kept
Scan records are retained on a rolling 24-month basis and are automatically deleted after that period. Scan records are also deleted when the associated QR code is deleted, or when the account holder's account is deleted, in accordance with Section 7.
4. How We Use Information
We use the information described in Section 2 to:
- Provide, operate, and maintain the Service;
- Process subscriptions, payments, and refunds;
- Communicate with you, including service updates, invoices, and support responses;
- Monitor and analyse usage to maintain and improve the Service;
- Detect, prevent, and address fraud, abuse, security issues, and technical problems, including misuse of QR codes for phishing or malware distribution;
- Comply with legal obligations, including tax and financial regulations; and
- Enforce our Terms of Service.
We do not sell personal information. We do not use Customer Data or scan data to train machine learning models, and we do not use it to build datasets, benchmarks, or products offered to anyone other than the customer it belongs to. Our use of Customer Data is limited to delivering the Service to the customer who provided it.
5. Legal Basis for Processing
Where the EU or UK General Data Protection Regulation applies, we rely on the following bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service to account holders | Performance of a contract |
| Processing payments and issuing invoices | Performance of a contract; legal obligation |
| Retaining financial and tax records | Legal obligation |
| Security, fraud prevention, and abuse detection | Legitimate interests |
| Service analytics and product improvement | Consent (analytics cookies); otherwise legitimate interests |
| Non-essential cookies | Consent |
Where Sri Lanka's Personal Data Protection Act No. 9 of 2022 applies, we process personal data on the corresponding lawful bases available under that Act.
For scan data, the lawful basis is determined by the account holder acting as controller, not by us.
6. How We Share Information
We share information with:
- Our third-party payment provider, solely to process payments, subscriptions, refunds, and applicable taxes. The provider we use is identified at checkout and on your invoice, and you may ask us who it is at any time at payments.nsqr@neurasense.io. Depending on the provider, it may act as merchant of record for your purchase, in which case it is the seller of record and handles your payment information as its own controller under its own privacy policy;
- Infrastructure and service providers who perform functions on our behalf, including hosting, database, email delivery, error monitoring, and analytics providers, each under written confidentiality and data protection obligations;
- Legal and regulatory authorities, where required to comply with applicable law, regulation, legal process, or a lawful governmental request;
- Successors, in connection with a merger, acquisition, or sale of assets, subject to protections equivalent to those in this Policy.
We do not share personal information with third parties for their own independent marketing purposes.
A current list of our sub-processors is available on request from payments.nsqr@neurasense.io.
7. Data Retention
| Category | Retention |
|---|---|
| Account information | For the life of the account, then deleted within 30 days of account closure |
| Customer Data (QR codes, assets, configurations) | For the life of the account, then deleted within 30 days of account closure |
| Scan analytics | Rolling 24 months, then automatically deleted |
| Billing and tax records | Retained as required by Sri Lankan tax and company law, regardless of account closure |
| Support correspondence | 24 months from the last message in the thread |
Deleted data is removed from active systems within the periods above and purged from encrypted backups within a further 90 days, after which backups holding it are cycled out. Billing records are retained where the law requires it even after a deletion request, as permitted under applicable data protection law.
8. Cookies
The Service uses cookies and similar technologies in two categories:
- Strictly necessary cookies — required for authentication, session management, and security. These cannot be disabled and are set without consent, as permitted by law.
- Analytics cookies — used to understand how the Service is used so we can maintain and improve it.
Where required by EU, UK, or other applicable law, analytics cookies are set only after you give consent through our cookie banner, and you may withdraw that consent at any time through the cookie settings link in the Service. You can also control cookies through your browser settings; disabling strictly necessary cookies will prevent parts of the Service from functioning.
9. Data Security
We implement technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure, or destruction. These include encryption of data in transit, access controls limiting staff access to what their role requires, and logging of administrative access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data Breach Notification
If we become aware of a personal data breach affecting your information, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Where we act as a processor for scan data, we will notify the affected account holder without undue delay so that they can meet their own notification obligations.
11. International Data Transfers
Neurasense is established in Sri Lanka, and our infrastructure and service providers may be located in other countries. Your information may therefore be transferred to, stored, and processed outside your country of residence, including outside the European Economic Area and the United Kingdom.
Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where required. A copy of the relevant safeguards is available on request from payments.nsqr@neurasense.io.
12. Your Rights
Depending on your location and applicable law, you may have the right to:
- Access the personal information we hold about you;
- Request correction of inaccurate or incomplete information;
- Request deletion of your personal information, subject to legal retention requirements;
- Object to or restrict certain processing;
- Receive a copy of your information in a portable, machine-readable format;
- Withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal;
- Lodge a complaint with a data protection supervisory authority. In the EU this is the authority in your country of residence, work, or where the alleged infringement occurred; in the UK it is the Information Commissioner's Office; in Sri Lanka it is the Data Protection Authority established under the Personal Data Protection Act No. 9 of 2022. You may complain to your authority without contacting us first, though we would welcome the chance to resolve it directly.
To exercise any of these rights, contact payments.nsqr@neurasense.io. We will respond within 30 days of receiving your request, and will tell you if we need to extend that period because the request is complex. We may need to verify your identity before acting, and we will not charge a fee unless a request is manifestly unfounded or excessive.
If your request concerns scan data rather than an account, see Section 3(d) — that request is properly directed to the organisation whose QR code you scanned.
13. Children's Privacy
The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have collected such information, we will delete it promptly. If you believe a child has provided us with personal information, contact payments.nsqr@neurasense.io.
14. Third-Party Links and Destinations
QR codes created through the Service resolve to destinations chosen by our customers, not by us. We do not control, endorse, or vet those destinations, and this Privacy Policy does not apply to any site or service a QR code leads to. The Service may also link to or integrate with third-party websites and services. We encourage you to review the privacy policies of any third party you interact with.
If you believe a QR code served through NSQR leads to a phishing, fraudulent, or malicious destination, report it to payments.nsqr@neurasense.io and we will investigate.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy with a revised "Last updated" date and, where the change materially affects your rights, by email to the address on your account. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
16. Contact Us
Questions about this Privacy Policy or how we handle information:
Neurasense (Private) Limited Company registration number: PV 00286247 Incorporated in the Democratic Socialist Republic of Sri Lanka under the Companies Act No. 7 of 2007 Email: payments.nsqr@neurasense.io Website: https://nsqr.neurasense.io