ACTIVE
Q-VALIS Privacy Notice
- Version
- 1.1
- Version Date
- 2026-09-20
- Effective Date
- 2026-09-22
- Status
- ACTIVE
- SHA-256
- ad7633e46eed19a3d2dee74f5735bfe66544d219894c3192cadea5d5a529e543
1. Controller and contact
Q-VALIS is operated by IC GLOBALTEST OOD, UIC 130370857, VAT No. BG130370857, 31 Krushovski vrah Str., 1618 Sofia, Republic of Bulgaria. IC GLOBALTEST OOD is the controller for the processing described in this Notice.
Privacy requests may be sent to privacy@q-valis.com. This is Q-VALIS's Privacy Contact and is not a designation of a Data Protection Officer. Privacy mail is forwarded to the monitored support@q-valis.com inbox. General support is also available there. Business telephone: 0700 20 661.
2. Scope and core principles
Q-VALIS offers products for professional and business purposes, not intentionally for private consumer use. This does not reduce the GDPR rights of individual users, learners, representatives or contacts. This Notice explains how Q-VALIS processes personal data relating to personal accounts, Organisation memberships and funded Course seats, purchases, learning, assessment, certificates, support, privacy requests, communications, security and service operation.
Q-VALIS limits processing to defined purposes, uses an appropriate legal basis, restricts access, keeps evidence only for justified periods and does not use acceptance of this Notice as a general consent to operate the platform.
Required and optional information
Information identified as required during account creation, checkout, Organisation access or Course administration is necessary to provide the relevant Q-VALIS service or conclude and perform the applicable contract. If required information is not provided, Q-VALIS may be unable to create the account, process the order, provide access or perform the requested service. Marketing consent and other fields expressly marked optional are not required to create an account or purchase a Q-VALIS product.
3. Processing activities
Account creation and administration — Data: name, email, password credential, verification and account status. Purpose: create and secure a personal account. Legal basis: steps at the person's request and performance of the contract; legitimate interests in account security. Retention: for the active account lifecycle; unnecessary profile/contact data are deleted or anonymised without undue delay after approved deletion, subject to specifically identified legal or credential evidence.
Organisation memberships and Organisation-funded seats — Data: Organisation, role, learner name/email, invitation, allocation, access and completion status, access end date and certificate number/status. Purpose: administer purchased training and permissions. Legal basis: contract and legitimate interests of the Organisation and Q-VALIS in controlled training administration. Retention: for the invitation/allocation lifecycle; after acceptance, expiry or revocation, only the minimum evidence needed to explain seat allocation, a dispute or a security incident is retained.
Orders and payments — Data: purchaser and billing details, Organisation details, product/version, quantity, price, discount, tax-related inputs, order and payment-provider references and status. Q-VALIS does not need to store full card credentials. Purpose: checkout, payment reconciliation, customer service, fraud prevention and commercial/accounting evidence. Legal basis: contract, legal obligations and legitimate interests. Retention: the accounting periods and contractual/dispute criteria explained in Section 9. The legitimate interests are payment reconciliation, preventing fraudulent purchases and establishing or defending legal claims.
Courses, learning and assessment — Data: entitlement, module progress, learning activity, assessment sessions, answers, results, attempts, eligibility and completion. Purpose: deliver the Course, enforce assessment rules and evidence achievement. Legal basis: contract and legitimate interests in course integrity. Retention: for the access lifecycle; expired incomplete progress is reviewed after access closure and any outstanding support/reconciliation issue, then erased or minimised unless a documented claim or integrity investigation requires it. Completion evidence needed for an issued certificate follows its verification lifecycle.
Certificates and verification — Data: learner name snapshot, Course and Product Version, completion and issue dates, certificate number, status and issuing evidence. Purpose: issue and verify credentials and prevent fraud. Legal basis: contract and legitimate interests of the learner, Q-VALIS and persons relying on the certificate. Retention: long-term, while Q-VALIS provides verification of the issued credential and the minimum evidence remains necessary to establish its authenticity; this need is reviewed when verification ceases or the record is corrected.
Support, complaints, refunds and privacy requests — Data: identity/account context, request text, related order/product/certificate, correspondence, decisions and action evidence. Purpose: respond, exercise rights, resolve disputes and demonstrate compliance. Legal basis: contract, legal obligation and legitimate interests. Retention: until the request is resolved and the applicable accountability, limitation or dispute need ends; unrelated free text is removed when it is no longer needed. The legitimate interests are resolving enquiries, preventing abuse and establishing or defending claims.
Transactional communications — Data: recipient, template/version, necessary variables, send/delivery/bounce/complaint status and provider identifiers. Purpose: account, security, order, access, invitation, certificate and legal communications. Legal basis: contract, legal obligation and legitimate interests. Retention: sensitive action URLs are not retained in delivery snapshots. Eligible completed account/security-email recipient telemetry is minimised in the monthly operational review after a 30-day troubleshooting window, unless a preservation hold applies. Contractual legal confirmations and minimal delivery/replay identifiers are separated from that telemetry and retained only for the underlying contract, verification or security purpose. The legitimate interests are reliable delivery, troubleshooting and abuse prevention.
Optional marketing — Data: email, consent/withdrawal evidence and communication preference. Purpose: send Q-VALIS news and offers requested by the person. Legal basis: consent. Retention: until withdrawal for sending purposes, with minimum consent/withdrawal evidence retained while needed to demonstrate the applicable permission or honour the withdrawal. Registration, purchase and invitations do not automatically subscribe anyone.
Security and technical operation — Data: session identifiers, hashed network identifiers, limited device/user-agent summaries, login/rate-limit events, timestamps and incident evidence. Purpose: authentication, abuse prevention, troubleshooting and system security. Legal basis: legitimate interests and, where applicable, legal obligations. Retention: only while needed for authentication, detection and investigation of abuse. Normal server sessions expire after 12 hours, or 30 days when remembered; expired sessions and login attempts older than 24 hours are removed during login. Records necessary for a documented incident are restricted and retained until the incident and related legal obligations or claims are resolved.
4. Organisation privacy boundaries
OWNER and MANAGER may see only Organisation-funded learner name, email, seat/access status, access end date, completion status and certificate number/status needed to administer training. They cannot see answers, incorrect answers, detailed activity, failed attempts, personal purchases, unrelated Courses or support history.
BILLING may see billing and Organisation purchase information but not learner identity, Course status or certificates. Organisation access never exposes unrelated personal account information.
5. Public certificate verification
There is no public certificate directory or people search. A person must possess the unique verification route or QR code. The page shows limited credential facts and never publishes email, score, attempts, Organisation or account/support information. Verification pages are marked noindex.
A later profile-name change does not alter an issued certificate. Correction or reissue is a controlled Support/Admin process with audit evidence.
6. Recipients and service providers
Personal data may be processed by carefully selected hosting, email, payment, domain/mail and professional service providers where necessary. Current core providers include Cloudflare, AWS SES/SNS, Stripe, PayPal and JUMP.
Payment providers
Q-VALIS uses third-party payment providers to process payments.
For the current PayPal payment relationship, PayPal acts as an independent controller of the personal data it processes under the applicable PayPal terms.
Stripe may act as a processor or as an independent controller depending on the processing activity, as described in its applicable data-processing and privacy terms.
Where these providers act as independent controllers, they determine their own processing for purposes such as payment processing, fraud prevention, anti-money-laundering compliance, identity verification, security and other purposes required by applicable law or their own regulatory obligations. Q-VALIS does not determine or control those independent processing activities.
Further information about their processing is available in the applicable PayPal Privacy Statement and Stripe Privacy Policy.
Data may also be disclosed where required by law, to advisers under confidentiality, or to protect legal claims and platform security. Q-VALIS does not sell personal data.
7. International transfers
Providers may process data in the EEA and outside it, including through support and subprocessors. Transfers, where applicable, are governed by the relevant service-specific provider terms and the applicable GDPR transfer mechanisms. A transfer requiring safeguards must not be enabled without a valid applicable mechanism, such as an adequacy decision or Standard Contractual Clauses with any required supplementary measures. Listing a provider or an EU service region does not mean that all processing is EEA-only or that a specific transfer mechanism has been verified for every service. You may contact privacy@q-valis.com for information about the safeguards applicable to your data and how to obtain a copy, subject to legitimate confidentiality restrictions.
8. AI and special-category data
Q-VALIS does not send personal data to external AI providers by default. AI-related Courses, Guides or Tools do not mean customer data is processed by AI. Future functionality that processes user content with AI requires a separate privacy assessment and documentation.
Q-VALIS does not intentionally request special-category or other sensitive personal data. Please do not include sensitive personal information in free-text fields unless it is necessary for your request.
9. Retention, deletion and backups
Retention depends on the documented purpose and any applicable preservation duty. Under Article 12(1) of the Bulgarian Accounting Act, accounting registers, financial statements and documents for tax control, audit and subsequent financial inspections are retained for 10 years; other accounting information is retained for 3 years where that category applies. These periods run from 1 January of the reporting period following the period to which the information relates. They are not blanket periods for every personal record. A specific longer legal obligation or documented proceeding takes precedence where applicable. Non-statutory retention ends when the stated service, verification, consent, security or claims purpose no longer requires the data.
Account deletion is controlled and assessed by an administrator. Submitting the dedicated account-deletion request stops marketing immediately; approved deletion/anonymisation also requires marketing to remain disabled. Unnecessary profile/contact data are removed without undue delay after approval, but accounting, contract, legal, certificate and completed-course evidence may need to remain. Deleting an account therefore does not necessarily erase every record.
Deletion or anonymisation in active systems does not require surgical editing of historical backups. Backups expire under their limited lifecycle, are not used for ordinary access, and restored data must have deletion/anonymisation actions reapplied where necessary. The provider recovery lifecycle is limited; backups are not a separate reason for indefinite retention.
10. Rights
Subject to applicable law, individuals may request access, rectification, erasure, restriction, portability, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing. Requests can be submitted through the authenticated Privacy Request workflow or to privacy@q-valis.com. Submission records a request; it does not by itself mean that the requested action has been completed. An administrator verifies and records the action or reasoned refusal and response. Marketing consent can be withdrawn directly in Communication Preferences. A request to withdraw consent is not marked fulfilled while that preference remains enabled.
Identity documents are not required by default. Proportionate additional verification may be requested only where reasonably necessary. Individuals may complain to the Bulgarian Commission for Personal Data Protection or another competent supervisory authority.
11. Age, security and breaches
Q-VALIS is intended for adults aged 18 or over and records an age confirmation without collecting date of birth for that purpose.
Q-VALIS uses access controls, encryption in transit, protected credentials, audit evidence, data minimisation, recovery controls and provider security measures appropriate to risk. No system is risk-free. Suspected personal data breaches are contained, documented, assessed and notified to authorities or affected persons where legally required.
12. Changes
Material changes create a new version with preserved historical evidence. Users may be notified where appropriate. A Privacy Notice update is not automatically treated as a new consent; separate consent is requested only when the processing legally requires it.
13. Sources of personal data
Data come directly from individuals when they register, purchase, learn, change preferences or contact us; from an Organisation that purchases or assigns access, including a learner email initially provided for invitation and seat administration; from Stripe, PayPal and other service providers supplying necessary payment, delivery or security results; and from Q-VALIS-generated order, learning, assessment, certificate, consent and security records. An invitation does not itself create marketing consent.
Where an Organisation initially provides a learner’s email address, Q-VALIS provides the relevant privacy information in connection with the first invitation or other communication to that learner.
14. Automated processing and local learning state
Q-VALIS does not use personal data for profiling or solely automated decision-making producing legal or similarly significant effects. Automated Course assessment scoring administers predetermined Course completion rules; it is not an employment, admission or professional-licensing decision. Questions or corrections concerning an assessment or record may be raised with Support for controlled review.
Q-VALIS does not persist Course progress or module quiz results in localStorage or IndexedDB. Learning progress, partial module quiz results, module completion and assessment-related state are stored server-side within the authenticated learner’s Course lifecycle. Temporary in-memory interface state may be lost when a page is closed, but saved server-side learning records remain authoritative and are restored after authenticated access. Q-VALIS does not use browser learning storage for marketing, profiling or behavioural advertising.