Legal

Privacy Policy

How we handle personal data for the QData Projects marketing website and related service communications. Application workspace data is governed by your customer agreement and, where applicable, the DPA.

Last updated: 10 August 2026

This Privacy Policy applies to the public website operated at projects.qdata.cloud (the "Website") under the product name QData Projects, provided by the QData organization operating the qdata.cloud services ("QData", "we", "us").

1. Roles

For the Website (pages you browse and contact requests you submit), QData acts as a data controller.

For customer workspace / application data processed in the QData Projects SaaS service operated by QData, roles are defined in the customer agreement and the Data Processing Agreement (DPA). QData Projects is offered only as SaaS — we do not process customer workspace content from on-premises installs because we do not offer that delivery model.

2. Data we collect on the Website

  • Contact / demo requests: name, work email, organization, message content, and optional topic (e.g. security, pricing, SaaS onboarding, preferred data region).
  • Technical logs: IP address, user agent, request path, timestamps, and coarse diagnostics needed to operate HTTPS reverse proxies, rate limiting and abuse prevention.
  • Cookies and similar storage: strictly necessary and functional preference technologies described in our Cookie Policy. We do not use advertising cookies on the Website as of the date above.

We do not sell personal data. We do not run third-party advertising trackers on the Website as of the date above.

3. Purposes and legal bases (GDPR)

  • Responding to inquiries and scheduling demos — legitimate interests (Art. 6(1)(f)) and/or steps prior to a contract (Art. 6(1)(b)).
  • Securing and operating the Website — legitimate interests (Art. 6(1)(f)).
  • Remembering language / theme preferences — legitimate interests and/or consent where required for non-necessary storage (see Cookie Policy).
  • Compliance with legal obligations — Art. 6(1)(c), where applicable.

4. Retention

  • Contact requests: retained as long as needed to handle the inquiry and related sales/security follow-up, then deleted or minimized (typical working retention up to 24 months unless a longer period is required for an active contract or dispute).
  • Server logs: retained for a limited operational window (typically up to 90 days) unless needed longer for security investigations.
  • Preference cookies / local storage: until you clear them or they expire (see Cookie Policy).

5. Recipients and hosting

Website and application infrastructure for QData-operated offerings is hosted on servers under QData operational control. Access is limited to authorized operators.

If we engage subprocessors for a managed processing service, they are listed in the DPA / Trust Center materials for that offering. We do not invent vendor names here.

6. International transfers and data location

For the SaaS service, primary data location and server colocation are available in Europe and North America. Customers choose a region at onboarding; the choice is confirmed in the contract / DPA schedule.

The public Website may be served via edge networks for performance and security. If processing involves transfers outside your applicable region, safeguards required by law (such as SCCs where applicable) are addressed in the relevant agreement or this policy as updated.

7. Your rights

Where GDPR (or equivalent law) applies, you may request access, rectification, erasure, restriction, portability and objection, withdraw consent where processing is consent-based, and lodge a complaint with a supervisory authority.

To exercise rights related to Website data, contact us via the contact form with subject "Privacy request". We may need to verify your identity before fulfilling a request.

8. Children

The Website and SaaS offering are directed to organizations and professionals. We do not knowingly collect personal data from children through the Website. If you believe a child provided data, contact us and we will delete it where appropriate.

9. Application (workspace) data

Project content, attachments, membership and authentication data inside a customer workspace are not governed solely by this Website policy. See your agreement and the DPA.

10. Security

We apply administrative and technical measures appropriate to the Website and operated services (TLS in transit at the edge, access control, backups for operated environments). No method of transmission or storage is perfectly secure; we do not make absolute security guarantees.

11. Changes

We may update this policy. The "Last updated" date will change when we do. Material changes to managed processing will also be reflected in customer communications / DPA updates where required.

12. Contact

Privacy and security contact: use Talk to an expert / security topic on this Website.

Related: Cookie Policy · Terms of Use · DPA