Privacy Policy

PRIVACY POLICY & DIGITAL PERSONAL DATA PROTECTION DIRECTIVE
Last Updated: August 27, 2026
Data Fiduciary: QREST (“QREST”, “we”, “us”, or “our”)


1. OVERVIEW & LEGAL FRAMEWORK

QREST operates a premium wealth intelligence network, alternative asset repository, and closed-door private community. This Privacy Policy governs the collection, storage, processing, and erasure of your personal data in strict accordance with the Indian Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”).

Under the DPDP Act, QREST operates as a Data Fiduciary, and you are recognized as a Data Principal.


2. SENSITIVE PERSONAL DATA & INFORMATION (SPDI) WE COLLECT

To provide elite, high-yield asset matching and verify user credentials for exclusive deal flows, we collect and process the following classifications of digital personal data:

A. Data Provided Voluntarily by the Data Principal

  • Identity Details: Full legal name, Permanent Account Number (PAN), professional designation, corporate entity alignment, and Aadhaar/Passport documentation (where mandatory for strict KYC/AML compliance for private equity access).
  • Sensitive Financial & Wealth Credentials: Self-certified financial status, investor tiering data (e.g., Crores allocated for deployment), bank account operational routing metadata, and transactional history.
  • Communication Records: Contact telephone numbers, corporate email footprints, and physical communication addresses.

B. Telemetry Processed Automatically

  • Network Artifacts: IP addresses, browser digital fingerprints, device cryptographic tokens used for secure dashboard access, and chronological engagement logs across our Market Insights grids.

3. NOTICE AND SPECIFIC PURPOSE OF PROCESSING

In absolute compliance with Section 5 of the DPDP Act, your personal data will only be processed for specific, lawful, and pre-defined purposes:

  • To Deliver Requested Services: Managing your private community membership profile and providing restricted access to the Investment Opportunities platform.
  • To Complete Mandatory Verifications: Conducting anti-money laundering (AML) sweeps and verifying accredited investor status for high-ticket alternative real estate asset onboarding.
  • To Send Highly Targeted Communications: Dispatching structural Market Insights reports, provided you have granted unconditional, explicit consent.

4. THE LAWFUL BASIS FOR PROCESSING

We process your digital personal data under the following statutory provisions:

  • Explicit Consent: Clear, affirmative, unconditional action taken by you when registering an account, subscribing to analytical material, or filling out a property inquiry module.
  • Certain Legitimate Uses: Processing strictly necessary to prevent financial fraud, protect network cybersecurity perimeters, or fulfill statutory requirements under the Securities and Exchange Board of India (SEBI) or Reserve Bank of India (RBI) directives.

5. RIGHT TO WITHDRAW CONSENT

You retain the absolute right to withdraw your consent for data processing at any given moment.

  • Mechanism: Withdrawal can be initiated dynamically via your member dashboard preferences or by notifying our Data Protection Officer.
  • Consequence: Upon formal withdrawal notification, QREST will cease data processing workflows within 7 business days, save where legal frameworks require retention. Please note that withdrawing consent will result in the immediate forfeiture of your Private Community membership access.

6. DATA SECURITY AND BREACH NOTIFICATION COMPLIANCE

QREST implements strict physical and technical safeguards to shield your high-net-worth profile from data leak liabilities:

  • Technical Controls: Absolute end-to-end encryption using AES-256 protocols at rest and TLS 1.3 encryption across all communication networks.
  • Breach Directives: In the unexpected event of a systemic data security compromise, QREST will fulfill its statutory obligations under Section 8(6) of the DPDP Act. We will instantly notify the Digital Personal Data Protection Board of India (DPDP Board) and the Indian Computer Emergency Response Team (CERT-In), followed by an immediate encrypted alert to the impacted Data Principals.

7. DATA SHARING & DOMESTIC/CROSS-BORDER TRANSFERS

We do not trade your structural data assets to consumer advertising companies. Your data is shared exclusively with:

  • Regulated Financial Stakeholders: SEBI-registered alternative investment funds (AIFs), real estate asset developers, or luxury deal originators, only when you explicitly request a legal introduction profile.
  • Cross-Border Controls: Data storage nodes reside primarily on secure servers within the territory of India. Any cross-border data transfer to international cloud infrastructure will adhere fully to the restriction frameworks and whitelists outlined by the Government of India.

8. RIGHTS OF THE DATA PRINCIPAL (YOUR STATUTORY POWERS)

Under Chapter III of the DPDP Act, you possess powerful, legally enforceable rights regarding your data:

  • Right to Summary & Confirmation: Obtain an easily readable index of all data processed, alongside summaries of tracking histories.
  • Right to Correction, Completion, & Erasure: Update broken metadata fields, fill out missing documentation parameters, or order the absolute deletion of your historical data.
  • Right to Grievance Redressal: Lodge formal performance or operational inquiries regarding your privacy with our internal grievance team before approaching regulatory boards.
  • Right to Nominate: Nominate a qualified individual to execute your data rights in the event of death or severe medical incapacitation.

9. MANDATORY GRIEVANCE REDRESSAL & CONTACT NODE

If you suspect an operational breach or want to exercise your legal data rights, contact our statutory Grievance Officer directly. Under Indian law, we are committed to acknowledging your issue within 48 hours and settling any valid complaint within 30 days.


Scroll to Top