Privacy Policy
Effective Date: 25 November 2025
About this Policy
This Privacy Policy explains how Qaxal s.r.o. ("Qaxal", "we", "us") handles personal data in two situations:
- Our own websites and accounts (this Policy). When you visit
dip.qaxal.comorqaxal.com, contact us, request a demo, sign up for an account atapp.qaxal.com, or hold a paid subscription, Qaxal is the controller of your personal data. The rest of this document tells you what we collect, why, and what your rights are. - End-user data flowing through the Digital Identity Platform (the DPA). When our customers deploy the Digital Identity Platform ("DIP") on their own websites and apps, Qaxal acts only as a processor on behalf of that customer. The customer is the controller for their visitors' data. That relationship is governed by our Data Processing Agreement at
dip.qaxal.com/legal/dpa, not by this Policy. If you are an end user of a customer's website asking about your data, please contact the operator of that website.
A short cookie notice for our own sites is at the end of this Policy (Section 11).
1. Who we are
Qaxal s.r.o., a limited liability company organised under the laws of the Slovak Republic.
- Registered seat: Ulica Adama Štrekára 8131/19, 917 08 Trnava, Slovakia
- Company number (IČO): 55 900 526
- Tax number (DIČ): 2122126281
- VAT ID: SK2122126281
- Commercial Register: District Court Trnava (Okresný súd Trnava), Section Sro, Insert No. 55543/T
- Contact for all privacy matters: legal@qaxal.com
We have not appointed a Data Protection Officer. We do not meet the mandatory triggers in Article 37 GDPR (we are not a public authority; our core activity is providing a SaaS platform, not large-scale monitoring of individuals or large-scale processing of special-category data). legal@qaxal.com is the single point of contact for all data-protection questions and rights requests.
EU representative (Article 27 GDPR): none required. Qaxal is established in the European Union.
2. What we collect, why, and on what legal basis
We collect only what we need for the purposes below. The legal basis is the GDPR Article 6(1) ground we rely on for each purpose.
a) Marketing-site visitors (dip.qaxal.com, qaxal.com)
- What: IP address, request metadata, user-agent, referrer, pages viewed.
- Why: Operating and securing the sites; aggregate analytics; detecting abuse.
- Legal basis: Article 6(1)(f) legitimate interests (security, operational integrity) for server logs. Article 6(1)(a) consent for analytics and marketing cookies, recorded through our consent banner (see Section 11).
b) Contact form, demo request, sales enquiries
- What: Name, business email, company, role, message content.
- Why: Responding to your enquiry, qualifying the opportunity, sending you a proposal.
- Legal basis: Article 6(1)(b) steps prior to entering a contract at your request; Article 6(1)(f) legitimate interest in business development for ongoing follow-up.
c) Newsletter and product updates
- What: Name, email, engagement metadata (opens, clicks).
- Why: Sending the communications you signed up for.
- Legal basis: Article 6(1)(a) consent. You can withdraw at any time using the unsubscribe link in every email.
d) Account holders at app.qaxal.com
- What: Name, business email, hashed password, role, billing contact details, audit logs of account activity, billing and payment records.
- Why: Providing the subscription Service, account security, customer support, billing, sending service notifications.
- Legal basis: Article 6(1)(b) performance of the contract with your organisation (in your representative capacity); Article 6(1)(c) compliance with accounting and tax obligations; Article 6(1)(f) legitimate interest in account security.
e) Vendor and supplier contacts
- What: Name, business contact details, payment metadata.
- Why: Procurement, paying invoices, tax reporting.
- Legal basis:
- Article 6(1)(b) - performance of contract - for vendor-side contractual administration and invoice payment to vendors with whom we have a direct contract.
- Article 6(1)(c) - legal obligation - for processing necessary for tax reporting and statutory accounting record retention.
- Article 6(1)(f) - legitimate interest - for relationship management with vendor contacts where no direct contract exists with the individual, including procurement evaluation and ongoing vendor selection.
f) Prospect research from public sources and referrals
Where we collect personal data about you from sources other than you directly, the following applies (Article 14 GDPR):
- Categories of data: business contact information (name, role, company, professional email, public LinkedIn profile data) and other public business-register entries.
- Sources: Slovak and EU business registers, publicly accessible LinkedIn profiles, referrals from existing clients or partners.
- Purpose: identifying and reaching out to potential business customers; pre-qualifying outreach.
- Legal basis: Article 6(1)(f) GDPR - our legitimate interest in growing the business and reaching decision-makers at potential client companies. The legitimate-interest balancing test favours processing because the data concerns individuals in their professional capacity and is publicly available.
- Retention: 24 months from last interaction, then anonymised.
- Right to object: recipients of outreach may object by replying to the outreach email or emailing
legal@qaxal.com; Qaxal will stop processing for outreach and add the contact to a suppression list.
Is providing data required?
For (a) you can browse without providing personal data beyond what is technically necessary to load the site. For (b), (c), and (d) the data is required to respond to you, send what you asked for, or operate your account; without it we cannot provide the relevant Service. For (e) the data is needed to engage you as a counterparty.
Special categories of data
We do not knowingly collect special-category personal data (Article 9 GDPR). Please do not include health, political, religious, or similar information in messages to us.
Automated decision-making
We do not carry out automated decision-making that produces legal effects or similarly significantly affects you (Article 22 GDPR). Sales-pipeline routing and similar internal scoring are operated under human supervision and do not produce binding decisions.
3. Where the data comes from
Most personal data we hold comes directly from you (you fill in a form, sign up, email us, or visit our sites). We also process limited data from publicly available sources (business registers, public LinkedIn profiles) for prospect research, and from referrals where a third party introduces you to us with your knowledge.
4. Who we share data with
We share personal data only as needed to operate the Service, comply with the law, or protect our rights and the rights of others. The categories of recipients are:
- Cloud infrastructure and operational vendors that host our sites, run our backend, deliver email, support our team, and process payments.
- Professional advisers (lawyers, auditors, accountants) under duties of confidentiality.
- Public authorities where required by enforceable legal process.
- Successors in interest in a corporate transaction (merger, acquisition, asset sale), subject to equivalent confidentiality.
The current named list of our sub-processors is published at dip.qaxal.com/legal/sub-processors. We update that page when sub-processors change.
We do not sell personal data and we do not share it with advertising networks for cross-site targeted advertising.
5. International transfers
Some of our sub-processors are located outside the European Economic Area, or may process limited data from servers outside the EEA. Where that happens, we rely on:
- European Commission adequacy decisions under Article 45 GDPR, where the recipient country has one;
- Standard Contractual Clauses (SCCs) adopted by the European Commission in Implementing Decision (EU) 2021/914, using Module 2 (controller-to-processor) or Module 3 (processor-to-processor) as appropriate. The text of the SCCs is published at https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en;
- the UK International Data Transfer Addendum (IDTA) for transfers from the United Kingdom; and
- the Swiss FDPIC SCC variant for transfers from Switzerland.
We apply supplementary measures (encryption in transit and at rest, access controls, contractual restrictions on access by foreign authorities) consistent with EDPB Recommendations 01/2020. The per-recipient transfer mechanism is recorded on the Sub-processors page. A copy of the SCCs executed with a specific recipient is available on written request to legal@qaxal.com.
6. How long we keep data
We keep personal data only for as long as we need it for the purposes above, then delete or anonymise it. Specific retention periods:
| Category | Retention |
|---|---|
| Account holder data | Duration of the subscription + 12 months after termination, then deleted (longer where law requires, e.g. accounting records, see below) |
| Marketing contacts (newsletter, demo requests, inbound leads) | 24 months from last interaction, then anonymised |
| Server logs and security telemetry | 90 days |
| Marketing-site analytics on the device | Per cookie category (see Section 11): functional ~12 months, analytics ~14 months, marketing 6-13 months |
| Billing and accounting records | 10 years (Slovak Act 431/2002 on Accounting; Slovak Act 222/2004 on VAT) |
After the applicable period we delete or anonymise the data. Backups roll off on their own schedule; backed-up data is isolated from active processing until the backup cycles out.
7. How we keep data safe
We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR, cross-referenced in Annex II of the DPA. These include encryption in transit and at rest, access controls, audit logging, and personnel confidentiality undertakings.
We do not use Customer Personal Data, Customer Content, or end-user data processed through the DIP service to train, improve, or fine-tune any AI or machine-learning model, whether ours or a third party's.
8. Your rights
Under GDPR you have the following rights for the personal data we hold about you as controller:
- Access (Article 15) - a copy of your data and information about how we process it.
- Rectification (Article 16) - correction of inaccurate or incomplete data.
- Erasure (Article 17) - deletion in defined circumstances.
- Restriction (Article 18) - temporary suspension of processing in defined circumstances.
- Data portability (Article 20) - your data in a structured, commonly used, machine-readable format (typically JSON or CSV), where processing is based on consent or contract and carried out by automated means.
- Objection (Article 21) - to processing based on legitimate interests, including direct marketing. We will stop unless we can demonstrate compelling overriding grounds.
- Withdraw consent (Article 7) - at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Not be subject to automated decisions (Article 22) - not applicable here; we do not carry out such processing.
How to exercise these rights: email legal@qaxal.com. We respond within one month of receiving your request (Article 12(3) GDPR), extendable by a further two months for complex or numerous requests, in which case we will tell you within the first month. The first request in a given period is free; manifestly unfounded or excessive requests may be charged a reasonable fee or refused.
Identity verification: before we act on a rights request we may need to verify your identity, in which case we will ask for additional information reasonably necessary to confirm who you are. We use that information only for verification.
9. Complaints
If you believe we have processed your data unlawfully, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). Our lead supervisory authority is:
Úrad na ochranu osobných údajov Slovenskej republiky (UOOÚ) Hraničná 12, 820 07 Bratislava 27, Slovak Republic Email: statny.dozor@pdp.gov.sk Web: https://dataprotection.gov.sk
You may also complain to the supervisory authority of the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement.
We would always prefer to hear from you first at legal@qaxal.com so we have a chance to put things right.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe we hold such data, contact legal@qaxal.com and we will delete it without undue delay.
11. Cookies and similar technologies on our own sites
This section covers cookies on dip.qaxal.com, qaxal.com, and app.qaxal.com. The DIP product itself is a server-side tag-management service that customers deploy on their own websites; cookies set in that context are the customer's responsibility under the customer's own privacy policy, and are out of scope here.
Categories we use:
- Strictly necessary - required for the site to work (session, security, load balancing). Always on; no consent required. Example: session cookie, anti-CSRF token. Retention: session or up to 12 months.
- Functional - remember your preferences (language, accepted cookie state). Set with consent. Example: cookie banner state, retention up to 12 months.
- Analytics - help us understand aggregate usage. Google Analytics 4 with Consent Mode v2 wired (no analytics tags fire without consent; once granted, GA4 is loaded with first-party identifiers). Retention on the device up to 14 months; aggregate analytics data retained 14 months.
- Marketing - measure the effectiveness of our paid campaigns (LinkedIn Insight, Google Ads conversion tag, Meta Pixel where used). Set only with consent. Retention 6-13 months depending on the provider.
How consent works: the cookie banner offers Accept all, Reject all, and Customise. Strictly necessary cookies load regardless; all other categories require your consent. Your choice is stored and we re-ask after no more than 13 months.
Withdrawing consent: click the small "Cookie settings" link in the site footer to re-open the banner and change your choice. You can also clear cookies through your browser settings, or use your browser's built-in tracking controls. Withdrawing consent does not affect the lawfulness of processing that took place while consent was valid.
A full per-cookie inventory (provider, name, purpose, lifetime) is shown inside the consent banner's "Customise" view.
12. Changes to this Policy
We may update this Policy from time to time. For material changes affecting active customers, we notify the email address on file at least 30 days before the change takes effect. The current version is always published at dip.qaxal.com/legal/privacy with the effective date at the top of the document. Continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
13. Contact
For any privacy question, to exercise your rights, or to raise a concern:
- Email: legal@qaxal.com
- Post: Qaxal s.r.o., Ulica Adama Štrekára 8131/19, 917 08 Trnava, Slovakia
Revision history
| Version | Effective date | Summary |
|---|---|---|
| 2.0 | 25 November 2025 | Initial v2. Rewritten for self-serve SaaS scale: shorter, plainer language; single privacy + cookie document; pointer to DPA for processor-side processing; sub-processor list referenced by URL; SCCs referenced by European Commission URL; tightened retention table; single contact mailbox (legal@qaxal.com). |
Last updated: 29 May 2026