Privacy policy

Appendix 1 – Your Rights

(a) GDPR

For the purpose of this Privacy Policy the controller of personal data is QVALON Inc Pty Ltd or one of its subsidiaries (“QVALON Inc”) and our contact details are set out in the Contact section above.

The Legal Basis for Processing your Information

Under GDPR, the main grounds that we rely upon in order to process personal data collected via our websites and services are the following:

Third Party Service Providers

As mentioned above, we will share your personal information with trusted third parties where we have retained them to provide services that you or our clients have requested, and to perform maintenance or respond to technical incidents affecting our services. Our current third-party service providers are listed in Appendix 2.

Where we disclose personal information to third parties, we require minimum standards of confidentiality and data protection from such third parties.

Processing Outside of the European Economic Area ("EEA")

To the extent that any personal information is provided to third parties outside the EEA, or who will access the information from outside the EEA, we will ensure that approved safeguards are in place to ensure that we comply with GDPR, such as the standard contractual clauses approved by the European Commission or the EU/US Privacy Shield.

QVALON Inc processes personal information on our servers in many countries around the world. We may process your personal information on a server located outside the country where you live. The primary location of user data and data uploaded to our products is a datacentre in the EEA operated by our third-party cloud hosting provider, Microsoft Azure ("Azure"). Azure is a participant in the EU/US Privacy Shield, under which transfers of personal data to the U.S. are authorised.

Retention of Personal Data

We will retain your personal information for the time necessary to provide the services we perform for you, or to achieve other purposes outlined in this Privacy Policy, and you can always request that we stop processing or delete your personal information (see the section below regarding your rights).

Your rights in respect of information we hold about you

You have certain rights in relation to personal information we hold about you. Details of these rights and how to exercise them are set out below. We will require evidence of your identity before we are able to act on your request.

Right of Access

You have the right at any time to ask us for a copy of the personal information about you that we hold. Where we have good reason, and if the GDPR permits, we can refuse your request for a copy of your personal information, or certain elements of the request. If we refuse your request or any element of it, we will provide you with our reasons for doing so.

Right of Correction or Completion

If personal information we hold about you is not accurate, out of date or incomplete, you have a right to have the data rectified, updated or completed. You can let us know by contacting us at info@qvalon.com

Right of Erasure

In certain circumstances, you have the right to request that personal information we hold about you is erased e.g. if the information is no longer necessary for the purposes for which it was collected or processed or our processing of the information is based on your consent and there are no other legal grounds on which we may process the information.

Right to object to or restrict processing

In certain circumstances, you have the right to object to our processing of your personal information by contacting us at info@qvalon.com. For example, if we are processing your information on the basis of our legitimate interests and there are no compelling legitimate grounds for our processing which override your rights and interests. You also have the right to object to use of your personal information for direct marketing purposes.

You may also have the right to restrict our use of your personal information, such as in circumstances where you have challenged the accuracy of the information and during the period where we are verifying its accuracy.

Right of Data Portability

In certain instances, you have a right to receive any personal information that we hold about you in a structured, commonly used and machine-readable format. You can ask us to transmit that information to you or directly to a third party organization.

The above right exists only in respect of personal information that:

While we are happy for such requests to be made, we are not able to guarantee technical compatibility with a third party organization’s systems. We are also unable to comply with requests that relate to personal information of others without their consent.

You can exercise any of the above rights by contacting us using any of the methods in the Contact section above.

Most of the above rights are subject to limitations and exceptions. We will provide reasons if we are unable to comply with any request for the exercise of your rights.

To the extent that we are processing your personal information based on your consent, you have the right to withdraw your consent at any time. You can do this by contacting us using the details in the Contact section above.

Automated decision-making

Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention. It is specifically regulated under GDPR where such decisions are taken which have legal or other significant effects on individuals. It is permitted in the following circumstances:

You will not be subject to decisions that will have a significant impact on you based solely on automated processing, unless we have a lawful basis for doing so, we have notified you and given you a right to challenge the decision or to require that the decision be taken by a person.

Complaints

If you are unhappy about our use of your personal information, you can contact us using the details in the Contact section below. You are also entitled to lodge a complaint with the UK Information Commissioner's Office using any of the below contact methods:

Telephone: 0303 123 11113

Website: https://ico.org.uk/concerns/

Post: Information Commissioner's Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

If you live or work outside the UK or you have a complaint concerning our activities outside the UK, you may prefer to lodge a complaint with a different supervisory authority. A list of relevant authorities in the EEA and the European Free Trade Area can be accessed here.

(b) California Consumer Privacy Act (“CCPA”)

The CCPA grants California residents certain additional rights regarding the personal information that QVALON Inc may collect, disclose or sell. For purposes of this section, “Personal Information” means anything that identifies, relates to, describes, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular California consumer or household. We do not collect, use or sell Personal Information of children age 16 or under.

Individuals with disabilities may access this policy in an alternative format by sending an email to: info@qvalon.com.

Your Disclosure Rights

As provided in this Privacy Policy:

Requests

The CCPA also provides California residents with the right to request additional details about the personal information we collect (including how we use and disclose this information and whether it is sold) and, if necessary, the right to delete your personal information.

California residents may make a request pursuant to your rights under the CCPA by contacting us at info@qvalon.com. To ensure that the request is coming from you and to protect the security of your Personal Information, we will verify your request using 2 out of the following 4 data points to verify your identify: (1) email address; (2) telephone number; (3) description of the product or service you purchased or inquired about, and (4) the security code from your credit card. If you are requesting to delete sensitive information, you must provide us with us with 3 out of the following 4 data points described above to verify your identity. Government identification may be required. We also commit to not discriminate against any California consumers because you exercise any of your rights. To read more about the CCPA please visit California Legislative Information.

Non-discrimination

You have the right to receive our products and services on equal terms regardless of whether or not you exercise your rights under the CCPA.

To read more about the CCPA please visit California Legislative Information.

Appendix 2 - Third Party Service Providers

Third Party

Purpose

Country

Atlassian Issue ticketing system and team collaboration site USA
Zendesk Customer Support System USA
Sentry Code Issue monitoring system USA
Hubspot Customer relationship management USA
Sendgrid Mailing system USA
Microsoft Azure Hosting Provider USA
Google Firebase Mobile Analytic, Crash Tracker USA