Privacy Policy
Effective —
This Privacy Policy describes the information we collect in connection with our website, our early-access waitlist and the DistriQT services; the purposes for which we use that information; the circumstances in which it may be disclosed; and the choices available to you. Please read it carefully. By accessing or using the Services you acknowledge the practices described in this Policy.
P.01Scope and definitions
This Policy applies to distriqt.app (the "Site"), including its early-access waitlist, and to the DistriQT application made available to customer firms at core.distriqt.app (together, the "Services"). "Customer Data" means the records, entries, documents, media and other materials submitted to the Services by or on behalf of a customer firm, together with the information the Services derive from them.
Where a customer firm has entered into a separate written agreement with us, that agreement governs to the extent of any conflict with this Policy.
P.02Information we collect
We collect information in the following categories:
- Information you provide directly. When you join the waitlist, we collect the information you submit — an email address and, where provided, a company name and a telephone or WhatsApp number — together with a reference code, a source identifier and a timestamp. When a firm's account is provisioned, we collect profile information for each authorised user, such as name, contact details, role and the permissions attached to that role.
- Customer Data. The Services operate as a system of record, and will store and process business records of every kind a customer firm elects to keep in them — including, without limitation, personnel and channel-party profiles, contact, KYC and compliance records, orders, dispatches, deliveries, returns, settlements and write-offs, ledgers, credit terms, limits and exposures, pricing, cost, margin and incentive structures, product catalogues and batch data, field activity, and location information captured by the mobile applications.
- Information collected automatically. We and our service providers may collect technical and usage information in connection with the Services, such as IP address, device and browser characteristics, server logs, and records of actions taken within the Services (including sign-ins, entries, edits, approvals, voids and write-offs, which form part of the audit trail the product maintains by design).
- Information from third-party sources. We work with third parties in the course of providing the Services — including providers of data, information and verification services — and may receive information from them, such as business-registry, identity, credit, mapping or contact information, and combine it with information collected through the Services.
- Derived information. The Services generate further information from the foregoing — analytics, scores, classifications, ratings, patterns, projections and other outputs — which is treated as set out in this Policy.
P.03How we use information
We use the information described in P.02 for the following purposes:
- to provide, operate, maintain, support and secure the Services, including storage, backup, computation of the analytics the product provides, and display to the users a firm authorises;
- to administer the early-access programme and to communicate with you about the Services, including by email, telephone or WhatsApp where you have provided those contact points;
- to carry out research, analysis and product development, including the improvement of existing features, the development of new products, services and features, and the building, testing and refinement of the analytical, statistical and scoring models used in or alongside the Services;
- to prepare aggregated or de-identified information, as described in P.04;
- to detect, investigate and prevent fraud, abuse and security incidents, and to enforce our terms and agreements;
- to comply with applicable law, regulation and legal process; and
- for any other purpose described to you at the point of collection, undertaken with your consent, or otherwise permitted by applicable law.
P.04Aggregated and de-identified information
We may aggregate, de-identify or anonymise information collected through the Services, including Customer Data, so that it no longer reasonably identifies a particular firm or individual. We may use and disclose such aggregated or de-identified information for any lawful business purpose, without further notice to you. Such purposes include, without limitation: statistical analysis; benchmarking; the preparation and commercial offering of market, category, territory and trade research and reports — such as price ranges and indices, volume and movement measures, distribution density and channel-structure analyses; the development, improvement and commercial offering of analytics, insights and intelligence products; use in and across the other products, services and ventures that we or our affiliates operate or may develop; and publication.
We will not attempt to re-identify aggregated or de-identified information, will maintain it in a form that does not name or reasonably identify any firm or individual, and will not represent to any recipient that it is attributable to an identifiable firm.
P.05Customer Data — ownership and processing
As between a customer firm and us, Customer Data belongs to the firm, including the outputs the Services derive from it for that firm's use. We process Customer Data to provide the Services to the firm and as otherwise described in this Policy, including the preparation of aggregated and de-identified information under P.04.
The Services may from time to time include optional programmes or features through which a firm elects to share designated Customer Data with third parties — for example, trade directories, marketplaces, or data-exchange and lead-generation programmes. Participation in any such programme is at the firm's election, on the terms presented at enrolment, and no Customer Data is shared under such a programme unless the firm has opted in.
Outside a programme a firm has opted into, we do not disclose one firm's identifiable Customer Data to another firm, and we do not sell identifiable Customer Data.
P.06Disclosure of information
The Services are delivered with the support of third-party providers that supply services, components of services, information and data used in their operation, and information is shared with such providers for that purpose. We may disclose information in the following circumstances:
- to third-party providers engaged in delivering the Services — including hosting, storage, backup, communications and messaging, identity and document verification, mapping and location, payment and analytics infrastructure — which process that information for the purposes of providing the Services;
- within our corporate group, and to a successor or acquirer in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to this Policy or successor terms;
- where required by law, regulation or legal process, in which case we disclose what is required and, where the law permits, notify the affected firm; and
- in aggregated or de-identified form, as described in P.04.
We do not sell the personal contact information collected through the Site's waitlist to third parties for their own marketing purposes.
P.07Individuals described in Customer Data
Many individuals described in Customer Data have no direct relationship with us — a firm's staff, its channel parties and their staff, and the persons its field team visits. The firm that submits such records is responsible for doing so lawfully: for informing its team that the field application records visits and movement, and for holding contact, KYC, credit and compliance records with the right to do so.
If an individual described in a firm's records contacts us about those records, we will refer them to the firm that maintains the record, and will assist the firm in honouring lawful requests where the product itself does not already provide for them.
P.08Security
Within a firm, access to Customer Data is governed by the roles and permissions the firm configures. Within DistriQT, access to customer systems is limited to personnel who operate the Services, for operational purposes. Data is encrypted in transit, and material actions within the Services are recorded in an audit trail. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
P.09Retention
We retain information for as long as necessary for the purposes described in this Policy. Customer Data is retained for the duration of the firm's agreement; on termination, the firm may take a full export, after which the firm's identifiable data is deleted from the live service within the wind-down period agreed in its contract and falls out of backups on the backup cycle. Aggregated and de-identified information (P.04) may be retained and used after such deletion. Waitlist information is retained for the duration of the early-access programme, or until you ask us to remove it.
P.10Your choices and requests
Firm administrators may add, correct, export and delete their firm's records within the product. For matters an administrator cannot action, the firm may write to us. Individuals may write to hello@distriqt.app — from the registered address, in the case of a waitlist entry — to request access to, correction of, or deletion of information we hold about them; for records maintained by a firm, see P.07.
P.11Artificial intelligence and model training
Certain features of the Services use artificial-intelligence and machine-learning models. These features are optional. Where a firm enables them, it agrees that its Customer Data may be used to develop, train, fine-tune, evaluate, operate and improve the models that provide those features. Where a firm does not enable them, its Customer Data is not used to train models on this basis, except in the aggregated or de-identified form described in P.04.
We use a firm's Customer Data to provide AI features to that firm. A model trained on one firm's identifiable Customer Data to serve that firm is not made available to another firm in a form that would expose the first firm's identifiable Customer Data. Where we train models whose benefits are shared across customers or offered beyond a single firm, we train them on aggregated or de-identified data (P.04) and apply measures designed to prevent the models from reproducing identifiable Customer Data in their outputs.
We do not provide any third party with access to a model that reproduces a firm's identifiable Customer Data, except under a programme the firm has opted into (P.05). A firm remains responsible, as set out in P.07, for holding the rights and consents required for the Customer Data it enables for the purposes described in this section.
P.12Changes to this Policy
We may revise this Policy from time to time. The current version, with its effective date, is always available at this address; material changes take effect under a new effective date. For customer firms, a revision to this page does not override a signed agreement (P.01).
P.13Governing law and contact
This Policy is governed by the laws of Nepal. Questions, requests and complaints may be directed to hello@distriqt.app.