ShopQuery
  • How It Works
  • Pricing
Sign inEarly Access
Legal

Public Authority Data Request Policy

Last updated: August 24, 2026

Ask AI to explain
ChatGPT↗Claude↗Gemini↗

1. Purpose and Scope

This policy explains how Barika Technologies Limited receives, evaluates, responds to, records, and reports requests for customer, merchant, employee, or other personal data from law-enforcement agencies, regulators, courts, and other public authorities.


It applies to all personnel, systems, products, and services operated by Barika Technologies Limited, including ShopQuery, and to requests directed to processors acting on our behalf.

2. Guiding Principles

Barika Technologies Limited will:


—Protect the rights and confidentiality of affected individuals
—Disclose data only where legally required and after appropriate review
—Verify the identity and authority of the requesting body
—Interpret requests narrowly and disclose no more data than is necessary
—Challenge requests that are unlawful, invalid, disproportionate, vague, or overly broad where there are reasonable grounds to do so
—Notify affected customers or individuals unless prohibited by law or where notification would create a demonstrable risk of harm
—Maintain an auditable record of requests and our response

We do not provide public authorities with voluntary, indiscriminate, or direct access to our systems, encryption keys, or customer data.

3. Approved Request Channels

Requests must be submitted in writing through a designated Barika Technologies Limited legal or privacy contact. Personnel who receive a request through another channel must preserve it and promptly refer it to the Privacy and Security Lead.


Personnel must not confirm whether relevant data exists or disclose data before the request has been reviewed.

4. Identity and Authority Verification

Before considering disclosure, we take reasonable steps to verify:


—The identity, agency, and contact details of the requester
—The legal authority relied upon
—The jurisdiction and territorial reach of that authority
—The authenticity and validity of any warrant, court order, subpoena, or equivalent instrument
—The categories of data, accounts, people, and time period covered
—Any secrecy, preservation, or notification restriction

Where verification is incomplete, we will request clarification or decline to act until the request is validated.

5. Legal Review and Challenge

Every request must be reviewed by the Privacy and Security Lead and, where appropriate, qualified legal counsel. The review considers whether the request has a valid legal basis, is binding on Barika Technologies Limited, respects applicable data-protection and human-rights requirements, and is necessary and proportionate to its stated purpose.


We will seek clarification, narrow the scope, object to, or challenge a request where there are reasonable grounds to believe it is unlawful, invalid, overbroad, disproportionate, or inconsistent with applicable law. The reasons for any decision not to challenge a concerning request will be documented.

6. Data Minimisation and Disclosure

If disclosure is legally required, we will identify and produce only the data expressly covered by the validated request. Where practicable, irrelevant or out-of-scope information will be redacted, aggregated, or withheld.


Disclosure must be approved by the Privacy and Security Lead and, for sensitive, unusual, or high-risk requests, by a company director or qualified legal counsel. Data must be transmitted using an authenticated and appropriately secure method.

7. Customer and Individual Notice

We will notify the affected customer or individual before disclosure when legally permitted and operationally reasonable. The notice will describe the request and the data sought with sufficient detail to allow the recipient to seek advice or challenge it.


If notice is prohibited or delayed, the restriction and its expiry will be recorded. We will reassess the restriction and provide notice when it is no longer prohibited, unless doing so would create a demonstrable risk of harm or remain unlawful.

8. Emergency Requests

An emergency request involving an imminent risk of death or serious physical harm may be handled urgently, but it does not bypass verification, necessity, or data-minimisation requirements. The requester must explain the emergency, identify the threatened harm, specify the data sought, and provide a lawful basis for disclosure.


Emergency disclosures require approval from the Privacy and Security Lead or, if unavailable and delay would materially increase the risk of harm, a company director. The decision and rationale will be documented and reviewed as soon as possible afterward.

9. Preservation Requests

A preservation request does not authorise disclosure. We may preserve identified data where the request is valid and legally effective.


Preserved data will remain access-controlled, be retained only for the legally required period, and be deleted when the obligation expires unless another lawful retention requirement applies.

10. Requests Involving Processors

Processors and subprocessors must promptly refer public-authority requests relating to Barika Technologies Limited data to us unless legally prohibited.


We will coordinate the response, seek the minimum necessary disclosure, and require the processor to maintain appropriate confidentiality and security.

11. Records, Metrics, and Transparency

We maintain a restricted request register containing, as applicable:


—The date, requesting authority, and jurisdiction
—The legal instrument and stated legal basis
—The accounts, people, data categories, and period requested
—Verification, review, challenge, and approval steps
—The data disclosed or reasons for refusal
—Notice restrictions and later notifications
—Relevant deadlines and closure date

We periodically review aggregate request metrics and may publish transparency information where lawful, useful, and unlikely to compromise security or privacy.

12. Security, Confidentiality, and Access

Request records and responsive data are confidential and limited to personnel with a need to know. Collection, review, transfer, and retention must follow our access-control, incident-response, retention, and security requirements.


Any suspected unauthorised disclosure must be escalated under our incident-response process.

13. Training and Accountability

Personnel likely to receive or handle public-authority requests must receive appropriate training. Failure to follow this policy may result in disciplinary action and, where applicable, contractual or legal consequences.


The Privacy and Security Lead is responsible for maintaining this policy, overseeing request handling, and arranging periodic review. Company leadership is responsible for ensuring that the roles, contacts, and escalation paths described here remain operational.

14. Contact

Public authorities and customers with questions about this policy may contact:


Barika Technologies Limited

[email protected]

ShopQuery

Live catalog infrastructure for your store. Connect once. Publish everywhere.

Product
How It WorksPricingEarly Access
Company
AboutPrivacy PolicyTerms of ServiceUser Data DeletionPublic Authority Data Requests
Resources
DocsDevelopers
© 2026 Barika Technologies Limited
PrivacyTermsData DeletionData Requests