1. Introduction
Kontraq ("we", "us", or "our") operates a B2B digital marketplace connecting Builders, Contractors, and Suppliers in the Indian civil construction industry. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).
By using Kontraq, you consent to the data practices described in this policy. If you do not agree, please do not use the platform.
2. Data Controller
Kontraq acts as the Data Fiduciary (as defined under DPDPA 2023) for all personal data collected through the platform. For any data-related queries, contact us at privacy@kontraq.com.
3. Information We Collect
3.1 Information You Provide
- Account Information: Full name, email address, phone number (via Google OAuth sign-in)
- Business Information: Company name, GST number, business address, areas of operation, skills, and service categories
- Profile Information: Profile photos, business descriptions, certifications
- Transaction Data: Job postings, bids, material requirements, pricing details, and project information
- User Content: Photos, documents, reviews, ratings, and messages shared on the platform
3.2 Information Collected Automatically
- Device Information: Browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, time spent on the platform
- Push Notification Tokens: Web push subscription details for delivering notifications
4. How We Use Your Data
- Authentication: Verifying your identity via Google OAuth
- Platform Operations: Facilitating job postings, bids, material requirement matching, and project management
- AI-Powered Features: Using Google Gemini AI to classify construction skills from job descriptions (Bill of Quantities). This is used solely for improving job-skill matching and does not make automated decisions affecting your account
- Communication: Sending push notifications about bids, job updates, and platform announcements
- Verification: Reviewing profiles for authenticity and trustworthiness
- Analytics: Understanding platform usage to improve our services
- Legal Compliance: Meeting obligations under Indian law
5. Legal Basis for Processing
Under the DPDPA 2023, we process your personal data based on:
- Consent: Your explicit consent provided during registration and platform usage
- Contractual Necessity: Processing required to provide our marketplace services
- Legitimate Uses: As permitted under the DPDPA for platform safety, fraud prevention, and service improvement
6. Data Storage & Security
Your data is stored on secure cloud infrastructure with industry-standard encryption for data in transit (TLS/SSL) and at rest. We implement reasonable security practices and procedures as required under the SPDI Rules 2011, including:
- Encrypted database connections
- Row-Level Security (RLS) policies on all database tables
- Secure authentication via OAuth 2.0
- Regular security reviews
We retain your data for as long as your account is active or as needed to provide services. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.
7. Data Sharing
We do not sell your personal data to third parties. Your data may be shared in the following limited circumstances:
- Platform Users: Your business profile, ratings, and reviews are visible to other users as part of the marketplace functionality
- Service Providers: With trusted infrastructure providers (cloud hosting, authentication services) who process data on our behalf
- Legal Requirements: When required by Indian law, court order, or government authority
- Safety: To prevent fraud, abuse, or threats to platform safety
8. Your Rights
Under the DPDPA 2023, you have the following rights:
- Right to Access: Request a summary of your personal data and processing activities
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Right to Withdraw Consent: Withdraw consent at any time by contacting us or deleting your account
- Right to Grievance Redressal: File complaints with our Grievance Officer or the Data Protection Board of India
To exercise any of these rights, contact privacy@kontraq.com.
9. Google OAuth & Third-Party Services
We use Google OAuth for authentication. When you sign in with Google, we receive your name, email address, and profile picture. We do not access your Google contacts, calendar, or other Google services. Our use of Google user data complies with Google API Services User Data Policy, including the Limited Use requirements.
10. AI & Automated Processing
We use Google Gemini AI to analyse job descriptions (Bill of Quantities) and classify required construction skills. This automated processing:
- Is used only for improving job-contractor matching
- Does not make decisions about your account status or eligibility
- Can be manually corrected — you can edit inferred skills on your job postings
11. Cookies & Local Storage
We use essential cookies and local storage for authentication session management, user preferences (theme, language), and push notification subscriptions. We do not use third-party advertising or tracking cookies.
12. Children's Privacy
Kontraq is a B2B platform for business professionals. We do not knowingly collect data from individuals under 18 years of age. If you believe a minor has provided us with personal data, contact us immediately for deletion.
13. Data Breach Notification
In the event of a data breach, we will notify the Data Protection Board of India and affected users as required under the DPDPA 2023, within the prescribed timeframe.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via platform notifications. Continued use of Kontraq after changes constitutes acceptance of the updated policy.
15. Contact Us
For privacy-related queries, data requests, or grievances: