1. Scope and Application
This Privacy Policy explains how PQA Labs Limited (“PQA Labs,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data in connection with the QDay website and related services (the “Service”). PQA Labs is the data controller for personal data described in this Policy and is incorporated in Hong Kong, where this Policy is anchored in the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”). Because QDay is used globally, this Policy also describes additional rights available to users in the European Economic Area, the United Kingdom, and California.
2. Information We Collect
We collect personal data you voluntarily provide, such as your name, email address, and contact details, when you sign up for updates, create a developer account, or contact us. We may also collect technical information such as IP address, browser type, and device information, and, for developers, API usage and log data. Where you interact with QDay directly on-chain (for example, via a wallet address), your public wallet address and transaction data are recorded on the public blockchain and are not personal data under our control.
3. How We Use Your Information
We use personal data to provide the Service, respond to inquiries, operate developer accounts and API access, maintain security, send updates you have opted into, and comply with legal obligations.
4. Legal Bases for Processing
Where applicable law requires a legal basis for processing (including under the GDPR), we rely on: performance of a contract with you (for example, to provide API access); your consent (for example, for marketing communications); our legitimate interests (for example, securing the Service and preventing fraud); and compliance with legal obligations.
5. Data Sharing and Disclosure
We do not sell or rent your personal data. We may share it with service providers who help us operate the Service, bound by confidentiality obligations, or disclose it where required by law, regulation, or a valid legal request.
6. International Data Transfers
Personal data may be stored or processed on servers located outside Hong Kong, including through cloud service providers, and may be transferred internationally in connection with operating a global service. Where we transfer personal data internationally, we take reasonable steps to ensure an appropriate standard of protection, including, where required, standard contractual clauses or equivalent safeguards.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law, after which it is securely deleted or anonymized.
8. Cookies
We use essential, analytics, and, where applicable, functionality and advertising cookies, as described at the point of collection on our website. You may control cookies through your browser settings, though this may affect certain website features.
9. Your Rights
9.1 All Users
You may request access to, correction of, or deletion of your personal data, and may opt out of marketing communications at any time via the unsubscribe link in our emails or by contacting us directly.
9.2 Hong Kong Users (PDPO)
You have the right to make a Data Access Request or Data Correction Request under the PDPO. We may charge a reasonable fee to cover the cost of complying with a data access request, as permitted under the PDPO. If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD).
9.3 EEA and UK Users (GDPR)
If you are located in the European Economic Area or the United Kingdom, you additionally have the right to request erasure or restriction of your data, to object to certain processing, to receive your data in a portable format, and to lodge a complaint with your local data protection supervisory authority.
9.4 California Users (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion of your personal information, and to opt out of any “sale” or “sharing” of personal information, as those terms are defined under the CCPA/CPRA. We do not sell your personal information. We will not discriminate against you for exercising these rights.
10. Data Security
We employ appropriate technical and organizational measures, including encryption and access controls, to protect personal data from unauthorized access, disclosure, alteration, or destruction. No system can be guaranteed completely secure.
11. Children's Privacy
The Service is not directed at individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Third-Party Links and On-Chain Data
Our website may link to third-party sites, wallets, or applications not operated by us, and we are not responsible for their privacy practices. Blockchain transaction data recorded on QDay is public and permanent by design; PQA Labs cannot delete or modify on-chain data at your request.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements, and will post the revised version on this page with an updated date.
14. Contact
Questions about this Privacy Policy can be directed to support@qday.io.