Last updated: 24 August 2026
This notice explains what personal data Qualify Innovation (“Qi”, “we”) collects when you use the web application or the Microsoft Teams app, why we collect it, how long we keep it and what rights you have. It covers both the enterprise and the free tier, and both the browser and the Teams tab.
A separate document, Privacy and Confidentiality, sets out the mutual confidentiality obligations between us and our customers. It is a contractual clause, not this privacy notice.
The controller within the meaning of Art. 4(7) GDPR is:
We have not appointed a data protection officer, as we are not required to under Art. 37 GDPR. Responsibility for data protection rests with Peter Fürst and Máté Magy, who are reachable at the contact address above.
When an account is created — by you registering, or by your organisation’s administrator creating one for you — we process your name, email address, company name, job position and, if supplied, telephone number. If you use a password, we store it only as a one-way hash; we never store the password itself and cannot recover it.
When you open the app as a tab in Microsoft Teams, Teams asks Microsoft Entra ID for a token on your behalf. We verify that token cryptographically and read from it your email address and your organisation’s tenant ID. We use the email address to match you to an existing account, and the tenant ID to check that your organisation is permitted to use the app. We do not receive your Microsoft password, and we do not read your mail, files, calendar or Teams messages.
Ideas, projects, evaluations, scores, comments, deadlines, the project members you assign, and any files or photos you upload. In the Teams project-profiling flow this also includes the criteria you select, the evaluators you invite (their email addresses) and the scores each evaluator submits.
Server access logs (IP address, time, requested address, browser identification) kept for security and troubleshooting, and application logs recording authorisation decisions.
We use cookies that are strictly necessary to operate the service — there are no advertising or analytics cookies, and no tracking across other websites. They hold your session identifiers, the email address you signed in with, and small interface preferences such as which page you came from. Session cookies are cleared when you sign out. Because they are strictly necessary, no consent banner is required under § 165(3) TKG 2021 / Art. 5(3) ePrivacy.
| Purpose | Legal basis |
|---|---|
| Providing the service to you or your organisation, including sign-in and the evaluation workflow | Art. 6(1)(b) GDPR — performance of a contract |
| Sending transactional email: magic-link sign-in, evaluator invitations, notifications | Art. 6(1)(b) GDPR — performance of a contract |
| Keeping the service secure: access logs, authorisation checks, abuse prevention | Art. 6(1)(f) GDPR — our legitimate interest in a secure service |
| Meeting legal obligations, for example accounting records | Art. 6(1)(c) GDPR — legal obligation |
Where your employer bought the enterprise tier, they decide what happens in their workspace and we act as their processor under Art. 28 GDPR. For the free tier we are the controller ourselves.
We do not sell personal data, we do not share it for advertising, and we do not use it to train machine-learning models. No decision with legal or similarly significant effect is made about you by automated means.
We use the following processors, each under a data processing agreement:
| Processor | What they do | Where |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Ltd.) | Hosting of the application, database and uploaded files | Germany West Central, EU |
| Brevo (formerly Sendinblue) | Delivery of transactional email — magic-link sign-in, evaluator invitations, notifications | EU |
| Microsoft Entra ID | Single sign-on inside Microsoft Teams. Entra verifies the identity and issues the token; we receive the email address and tenant ID. | The customer's own Microsoft 365 tenant |
Beyond these, we disclose personal data only where the law requires it.
Application data, the database and uploaded files are hosted on Microsoft Azure in Germany West Central (European Union). Data stays within the European Union; we do not transfer it to third countries. Connections to the service are encrypted with TLS, and the storage underlying the servers is encrypted at rest.
Under the GDPR you have the right to:
To ask for a copy of your data: write to the privacy address below from the address your account uses. We confirm it is you, then send back your account details and project content in a machine-readable format, with any files you uploaded as you uploaded them. This is free of charge. To ask for deletion: write to the same address. Once we have confirmed it is you, we disable the account straight away and then erase the account record, your uploaded files and your profile photo, and remove your address from any evaluator list it appears on. Records we are legally required to keep — invoices, for example — are kept for the statutory period and used for nothing else. Copies held in routine backups are not edited; they fall out of the backup cycle within 30 days. We answer within 30 days. If your account was created by your employer, we may need to refer your request to them, and we will tell you if we do.
You may also complain to a supervisory authority. Ours is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at.
Access to your account requires authentication, and every request is checked against your role and your membership of the project concerned. Passwords are stored as one-way hashes. Traffic is encrypted in transit. Administrative access to the servers is restricted to named accounts using key-based authentication. We keep an incident response procedure and, in the event of a personal data breach that is likely to result in a risk to you, we notify the supervisory authority within 72 hours as required by Art. 33 GDPR, and notify you directly where Art. 34 requires it.
The service is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
We update this notice when the service changes. The date at the top always reflects the current version, and we notify account holders of material changes by email before they take effect.
Questions about this notice or about your data: privacy@go4qi.com, or contact support.