TrustBatch Systems Private Limited ("TrustBatch", "we", "our", or "us") provides cryptographic product verification and compliance architecture to agricultural manufacturers. This Privacy Protocol outlines how we process, store, and route data across our network nodes.
1. Information Collection
We collect information dynamically to facilitate secure onboarding, product deployment, and regulatory compliance. This information is categorized into direct administrative data and systemic operational data.
- Administrative Identity: Names, corporate entities, direct contact numbers, and email addresses provided during initialization or GST compliance.
- Financial Nodes: Transaction IDs, UPI reference numbers (UTRs), and GSTIN details required for legal invoicing. We do not store raw credit card data or banking credentials directly on our servers.
- Compliance Data: FCO Schedule VI Gazette references, CIBRC toxicity classes, and batch metadata uploaded via the dashboard.
2. Scan Telemetry & End-User Devices
When an end-user (e.g., a farmer or field inspector) scans a TrustBatch generated cryptographic QR code, our servers ping specific metadata to verify authenticity and map supply chain health.
- Geospatial Data: Approximate location parameters derived from IP addresses and, where explicitly granted by the user's browser, exact GPS coordinates to map counterfeit hotspots.
- Device Vectors: Operating system (Android/iOS), browser type, and connection latency (e.g., 2G vs 4G) to optimize the delivery of verification pages.
- Time Stamps: Exact chronometric records of when a specific batch node was requested and verified.
Note: We do not require end-users to download an application, nor do we harvest Personally Identifiable Information (PII) from farmers during a standard verification scan unless they explicitly opt into a manufacturer's loyalty module.
3. Protocol Data Usage
The data injected into our architecture is strictly utilized to maintain system integrity, deliver client value, and uphold agricultural regulatory compliance in India.
- To render dynamic, white-labeled verification pages instantly upon scan.
- To populate the manufacturer's telemetry dashboard with real-time geospatial scan heatmaps and velocity charts.
- To flag anomalous scanning behavior (e.g., a single batch code scanned simultaneously in Punjab and Maharashtra), triggering immediate counterfeit alerts.
- To deliver automated GST invoices, API webhooks, and administrative notifications.
4. Node Distribution & Sharing
TrustBatch operates on a principle of absolute data sovereignty. We do not sell, rent, or lease your corporate or scan telemetry data to third-party data brokers under any circumstances.
Information is only routed to external nodes when strictly necessary:
- Infrastructure Partners: Cloud hosting providers (AWS India/GCP Mumbai) utilizing local server nodes to ensure latency stays under 2 seconds.
- Regulatory Authorities: If legally compelled by Indian law enforcement or regulatory bodies (e.g., CIBRC, FCO inspectors) under a valid legal mandate.
- Communication Nodes: Authorized API partners such as WhatsApp Business API (Meta) or email gateways solely for the transmission of system alerts.
5. Cryptographic Security
Our architecture treats agricultural data with military-grade respect. Data at rest is encrypted using AES-256 standards, and data in transit routes exclusively through TLS 1.3 protocols.
Our physical QR codes are generated using proprietary cryptographic hashing, meaning the physical vector printed on your packaging is mathematically impossible to brute-force or predictably sequence by counterfeiters. All server nodes handling Indian manufacturer data are localized within the Republic of India to comply with national data sovereignty guidelines.
6. Administrative Rights
As a network administrator (Manufacturer), you retain full sovereignty over your deployment modules.
- Data Export: You may request a complete JSON/CSV export of your product schema, scan telemetry, and batch logs at any time via the API or dashboard.
- Right to Erasure: Upon termination of your Enterprise or Professional protocol, you may request the hard deletion of your corporate data. Please note that previously printed physical QR codes will default to a basic authenticity state to protect end-users, but active tracking will cease.
7. Regulatory Contact
For questions regarding this Privacy Protocol, compliance data requests, or security disclosures, direct your communications to our data protection node:
Data Protection Officer
TrustBatch Systems Pvt. Ltd.
privacy@trustbatch.com
Bengaluru, Karnataka, India