QRda · Legal

Privacy policy

How QRda processes personal data for workplace activity records.

Effective date and policy version: September 12, 2026

Who is responsible

Data operator: ТОО Dala Loom, BIN 260840015544 (“Dala Loom”, “we”, or “us”).

Dala Loom provides QRda to customer organizations. The customer organization supplies employee records, configures workplace activities, and authorizes its administrators. Depending on the processing activity and the applicable agreement, Dala Loom and the customer organization may each have responsibilities under Kazakhstan personal-data law.

Privacy contact: admin@dalaloom.com.

Scope

This policy applies to the QRda mobile app, its Dala Loom-hosted backend, and the QRda administrative portal. QRda is a workplace service for authorized personnel and is not intended for children.

Personal data we process

  • Organization and employee data: organization ID, employee ID, tab or pass ID, name, position, account status, and workplace association.
  • Authentication data: login identifiers, encrypted or hashed administrative credentials, authentication tokens, session expiry, and related security records.
  • Activity records: scan ID, employee ID, registered QR-code ID, activity type and tag, applicable rule, workplace location, scan date and time, outcome, and the message returned by the service.
  • Consent evidence: consent-event ID, policy version, selected language, date and time, device operating system, and IP address.
  • Local app data: the mobile app stores its authentication token and saved organization/login identifiers in device secure storage and stores the selected language on the device.

The app requests camera access only to read QR codes. Camera frames are processed on the device; QRda does not store or transmit photos, video, or audio.

Why and how we use data

We collect, record, organize, store, update, retrieve, use, provide authorized access to, block, anonymize, and delete personal data as necessary to:

  • authenticate users and administer authorized accounts;
  • verify and record cafeteria visits or other activities configured by the customer organization;
  • apply activity rules, prevent duplicate or unauthorized scans, and return a clear result;
  • provide tenant-scoped records and reports to authorized customer administrators;
  • secure, maintain, troubleshoot, audit, and improve the reliability of QRda; and
  • comply with applicable law and establish, exercise, or defend legal claims.

QRda does not use personal data for advertising, behavioral tracking, data brokerage, or automated decisions that create, change, or terminate a user’s legal rights.

Legal basis and consent

Where consent is required, QRda asks the identified employee to accept a versioned consent before activity records can be submitted. We record evidence of that action. A customer organization may also have an independent legal basis for processing employment or operational records. Refusing or withdrawing consent prevents further use of QRda where consent is the applicable basis; the customer organization should provide information about any alternative process.

Access and service providers

Personal data may be accessed only by authorized Dala Loom personnel, authorized administrators of the relevant customer organization, and contracted service providers acting under instructions and confidentiality obligations. The current architecture uses Yandex Cloud infrastructure, including Yandex Managed Service for YDB, in Kazakhstan. We do not sell personal data or share it with third parties for their own marketing.

Storage location, public sources, and cross-border transfers

The current QRda architecture stores operational personal data in a database located in the Republic of Kazakhstan. It does not publish personal data in publicly accessible sources and does not transfer operational personal data outside Kazakhstan. If this changes, Dala Loom will update this policy and obtain separate consent or establish another lawful basis where required before the new processing begins.

Retention and deletion

We retain account and activity data only while needed for the stated purposes, the customer relationship, applicable retention requirements, and the establishment, exercise, or defense of legal claims. Consent and activity records may be kept as immutable audit evidence for the applicable retention period. When data is no longer required, it is deleted or anonymized. Device-side tokens and saved login identifiers are removed when the app’s local data is cleared; signing out removes the authentication token.

Your rights

Subject to Kazakhstan law, a person may request confirmation and information about processing, access to their data, correction or supplementation, blocking, deletion where processing is unlawful or no longer required, and withdrawal of consent. A person may also complain to the competent authority or a court.

Send a request to admin@dalaloom.com or contact the administrator of your customer organization. We may need to verify identity and coordinate with the customer organization before acting. Following withdrawal, processing will stop within the period required by law unless continued storage or processing is legally required.

Security

We use organizational and technical safeguards designed to protect personal data, including encrypted network transport, authenticated and tenant-scoped access, limited administrative permissions, signed QR payloads, protected secret storage, audit records, and infrastructure monitoring. No system can guarantee absolute security.

Changes to this policy

We may update this policy to reflect changes in QRda, its data flows, or legal requirements. The effective date and version above will be updated. If a change requires renewed consent, QRda will request it before processing under the new terms.