- LEGAL -

Privacy Policy

GDPR & CCPA Compliant

Effective Date: 10/07/2026

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our website, interact with us, or use our services. This policy is designed to align with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended by the CPRA.

By using our website or services, you acknowledge that you have read and understood this Privacy Policy.

1. Definitions

  • Personal Data means any information relating to an identified or identifiable individual.
  • Processing means any operation performed on Personal Data (e.g., collection, use, storage).
  • Controller means the entity that determines the purposes and means of processing Personal Data.
  • Processor means the entity that processes Personal Data on behalf of the Controller.
  • Service Providers means third parties that process data on our behalf.

For most website interactions, Qlidex acts as a Controller. For client service delivery (e.g., handling end-customer data in support systems), Qlidex typically acts as a Processor on behalf of the Client.

2. Information We Collect

A. Information You Provide Directly

We may collect Personal Data you provide, including:

  • Name and contact details (email, phone)
  • Company and role information
  • Inquiry or project details
  • Billing and payment information

B. Information Collected Automatically

When you use our website, we may collect:

  • IP address and approximate location
  • Device, browser, and OS information
  • Pages visited, session duration, referral URLs
  • Cookie identifiers and analytics data

C. Information from Third Parties

We may receive data from analytics providers, payment processors, or publicly available sources where permitted by law.

3. Purposes and Legal Bases (GDPR)

We process Personal Data for the following purposes and legal bases:

  • To provide and manage services (Contractual Necessity)
  • To respond to inquiries and provide support (Legitimate Interests / Contract)
  • To improve website performance and user experience (Legitimate Interests)
  • To send service-related communications (Contract / Legitimate Interests)
  • To process payments and invoices (Contract / Legal Obligation)
  • To comply with legal obligations (Legal Obligation)

Where required, we will obtain your consent before processing (e.g., non-essential cookies or marketing communications).

4. How We Share Personal Data

We do not sell Personal Data.

We may share Personal Data with:

  • Service Providers (e.g., hosting, CRM, analytics, payment processors)
  • Professional advisors (legal, accounting) where necessary
  • Authorities or regulators where required by law

We require Service Providers to process data only on our instructions and to implement appropriate safeguards.

5. International Data Transfers

As a global service provider, we may transfer Personal Data to countries outside your jurisdiction.

Where required (e.g., transfers from the EEA/UK), we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or rely on adequacy decisions.

6. Data Retention

We retain Personal Data only as long as necessary to:

  • Fulfill the purposes described in this policy
  • Comply with legal and regulatory requirements
  • Resolve disputes and enforce agreements

Retention periods vary by data type and service context.

7. Data Security

We implement appropriate technical and organizational measures, including access controls, encryption (where applicable), and staff training, to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.

8. Your Rights (GDPR)

If you are located in the EEA/UK, you have the right to:

  • Access your Personal Data
  • Rectify inaccurate or incomplete data
  • Erase your data (“right to be forgotten”)
  • Restrict processing
  • Data portability
  • Object to processing based on legitimate interests
  • Withdraw consent at any time (where processing is based on consent)

You also have the right to lodge a complaint with your local supervisory authority.

9. Your Rights (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know the categories and specific pieces of Personal Data we collect, use, disclose, or share
  • Request deletion of your Personal Data (subject to exceptions)
  • Correct inaccurate Personal Data
  • Opt out of the “sale” or “sharing” of Personal Data (we do not sell Personal Data)
  • Limit use of sensitive Personal Data (where applicable)
  • Not be discriminated against for exercising your rights

To exercise your rights, contact us using the details below. We will verify your request as required by law.

10. Children’s Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect Personal Data from children. If you believe we have collected such data, please contact us and we will take appropriate action.

11. Data Processing for Client Services

When providing customer support and operational services, Qlidex may process end-customer data on behalf of our clients. In such cases, Qlidex acts as a Processor and processes data strictly in accordance with client instructions and applicable data protection agreements.

12. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their policies independently.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date. Continued use of our services constitutes acceptance of the updated policy.

14. Contact & Data Requests

For privacy inquiries or to exercise your rights, contact:

Email: support@qlidex.com

We will respond within the timelines required by applicable law.

15. Acceptance

By using our website or services, you confirm that you have read and agree to this Privacy Policy.