Qards

Try for free
Back to Home

Privacy Policy

PRIVACY POLICY

§ 1. Data Controller

  1. The Controller of your personal data is Kamil Homernik, conducting business activities at the address: ul. Willowa 5, 80-299 Gdańsk, Poland (hereinafter: "Controller").

  2. You can contact the Controller regarding any matter related to your personal data by sending an email to: [email protected].

§ 2. What data do we process, for what purpose, and on what basis?

We process your data solely to the extent necessary for the operation of the Qards Application.

1. Provision of Services (Application Operation)

  • Purpose: To enable you to create an account, log in, and use the Application (including creating boards, audits, and reporting issues).

  • Data: E-mail address, password (stored in encrypted form by the authentication provider), first and last name (if provided), operational data (entered in audit forms).

  • Legal basis: Performance of the contract (acceptance of the Terms of Service) – Art. 6(1)(b) GDPR.

2. System and Technical Communication

  • Purpose: Sending notifications about important changes to the Application, e.g., the end of the Beta phase, the release of a stable version (Release Candidate), changes to the Terms of Service, or technical maintenance.

  • Data: E-mail address.

  • Legal basis: Performance of the contract and the legitimate interest of the Controller (informing users about the service status) – Art. 6(1)(b) and (f) GDPR.

3. Payments (For Paid Accounts)

  • Purpose: Processing subscriptions and issuing invoices.

  • Data: Payment card details (processed directly by the payment operator Stripe), invoice data (Tax ID/VAT ID, company name, address).

  • Legal basis: Performance of the contract and legal obligations (tax/accounting) – Art. 6(1)(b) and (c) GDPR.

4. Contact and Support

  • Purpose: Responding to your inquiries sent via email or contact forms.

  • Data: E-mail address, content of the correspondence.

  • Legal basis: Legitimate interest of the Controller (customer service) – Art. 6(1)(f) GDPR.

§ 3. Data Recipients

To ensure the Application operates correctly, we use the services of trusted technology providers. Your data may be entrusted to:

  1. Hosting and Database Providers (Vercel, Neon) – for the purpose of storing Application data.

  2. Authentication Service Providers (Clerk) – for secure login and identity management.

  3. Payment Operators (Stripe) – for processing payments (the Controller does not see your full card number).

  4. Accounting Services – for fulfilling tax obligations (only if you receive an invoice).

§ 4. Data Transfers Outside the EEA

Most of our servers are located within the European Economic Area (EEA). However, due to the use of global service providers (e.g., Clerk, Stripe), your data may be transferred to third countries (e.g., the USA) to the necessary extent.
We ensure that in such cases, data transfer takes place on the basis of Standard Contractual Clauses (SCCs) adopted by the European Commission or other legal instruments guaranteeing data security (e.g., Data Privacy Framework).

§ 5. Your Rights

In accordance with the GDPR, you have the right to:

  1. Access your data and receive a copy of it.

  2. Rectify (correct) your data.

  3. Delete data ("right to be forgotten").

  4. Restrict data processing.

  5. Data portability.

  6. Object to data processing.

  7. Lodge a complaint with a supervisory authority (in Poland: the President of the Personal Data Protection Office - PUODO) if you believe that we are processing your data unlawfully.

§ 6. Data Retention Period

  1. Data related to the account in the Application is stored for the duration of the agreement (existence of the account), and after its termination for the limitation period of claims (usually 3 or 6 years).

  2. Billing data (invoices) is stored for 5 years from the end of the calendar year (tax requirement).

  3. If you delete your account during the Beta phase, your data will be removed from the production database immediately (subject to backups, which are overwritten cyclically).

§ 7. Cookies

  1. The Application uses cookies solely for purposes essential to its proper operation (e.g., maintaining a login session, remembering language settings).

  2. We do not use tracking or marketing cookies from third parties without your explicit consent.

  3. You can manage cookie settings in your web browser.

§ 8. Changes to the Privacy Policy

We may update this Privacy Policy, for example, in the event of adding new features to the Application. We will inform you of significant changes via email or a notification within the Application.

Qards

Operational discipline in control, without the effort.

Privacy Policy