Welcome to QookieQloud™, your trusted platform for privacy intelligence and cookie consent management. This Privacy Policy outlines our practices regarding the collection, use, processing, and protection of data when you use our Consent Management Platform (CMP), customer dashboard, public APIs, and associated web services. Please read this document carefully to understand how we safeguard your information and how privacy responsibilities are partitioned when using our service.
1. Introduction & Legal Framework
QookieQloud™ (“we,” “us,” or “our”) is operated by Qodli AB, a registered company in Sweden (Corporate Identity No. 559488-4206). We are committed to uncompromising privacy standards in accordance with the European Union General Data Protection Regulation (Regulation (EU) 2016/679 - "GDPR"), the ePrivacy Directive (Directive 2002/58/EC), and applicable international privacy frameworks.
Our platform is engineered to facilitate the lawful collection, management, and auditing of cookie consent on modern digital properties. However, customers who install QookieQloud™ (“you,” “your,” or “Customer”) remain the independent Data Controllers for all personal data, cookies, tracking scripts, and marketing pixels deployed on their respective websites.
2. Data Collection
We only collect personal information that is strictly necessary to deliver, maintain, and secure our CMP services. We categorize collected information into two main categories:
a. Information You Provide Directly to Us
- Account & Organization Data: When registering for an account or subscribing to a paid tier, we collect your name, email address, company or agency name, invoicing address, and billing contact details.
- Customer Support Inquiries: When you open a support ticket, request a privacy audit review, or contact our engineering team, we collect your message content, email address, and any technical logs or website URLs you provide to assist in troubleshooting.
- Billing & Payment Data: Financial transactions are processed by certified, PCI-DSS compliant third-party payment gateways. QookieQloud does not store raw credit card numbers or banking secrets on our servers.
b. Information Collected Automatically
- Platform Telemetry: We collect aggregated, non-identifying operational metrics regarding dashboard usage, API latency, error rates, and feature adoption to maintain system reliability and performance.
- Cryptographic Consent Events: When an end-user interacts with the QookieQloud consent banner on your site, our edge network receives an anonymized consent signal (timestamp, pseudonymous consent token, and category selections).
3. Cookies and Tracking Technologies
Our use of cookies is divided into two distinct scopes:
- On QookieQloud.com and Our App Dashboard: We use strictly necessary first-party cookies to manage authentication, maintain your secure logged-in state, protect against Cross-Site Request Forgery (CSRF), and remember interface preferences (such as dark/light mode).
- On Customer Websites (The CMP Script): The QookieQloud script injected on customer properties uses local storage or minimal first-party cookies solely to record the visitor’s chosen consent preference so the banner does not re-appear unnecessarily on subsequent visits.
4. How We Use Your Data
QookieQloud processes collected customer information exclusively for the following lawful business purposes:
- Service Delivery: To provision your account, generate embeddable CMP scripts, record consent audit logs, and process plan subscriptions.
- Service Integrity & Security: To detect, investigate, and prevent fraudulent activity, unauthorized API access, and DDoS attacks.
- Platform Improvements: To analyze aggregate trends, optimize scanner accuracy, and enhance CMP banner performance.
- Account Communications: To send transactional notices, security alerts, invoice receipts, and critical service announcements. We do not send unsolicited third-party marketing spam.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties. Data is shared only under strict contractual terms in the following scenarios:
- Trusted Sub-processors: We engage reputable infrastructure providers (e.g., EU cloud hosting providers, transactional email services, and payment processors) who operate under binding Data Processing Agreements (DPAs) with strict confidentiality and security clauses.
- Legal Requirements: We may disclose information if required to do so by applicable Swedish or European Union laws, a valid court subpoena, or lawful requests by public authorities.
- Business Transfers: If Qodli AB is involved in a merger, corporate acquisition, or asset sale, your information may be transferred as part of the transaction, subject to the continuity of this Privacy Policy.
6. Data Security
We prioritize high-grade security across every layer of our technical architecture:
- Encryption in Transit & at Rest: All web traffic and API communications are encrypted using modern Transport Layer Security (TLS 1.3). Sensitive customer data at rest is protected using industry-standard AES-256 encryption.
- European Union Cloud Infrastructure: All production servers, consent transaction logs, and databases are hosted within certified ISO 27001 data centers located in the European Union.
- Strict Access Governance: Access to customer records is restricted to authenticated engineering personnel through multi-factor authentication (MFA) on a strict need-to-know basis.
7. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy:
- Active Accounts: Customer account data is retained for the lifetime of your active subscription.
- Consent Audit Records: Anonymized consent interaction logs generated on your websites are retained for up to 24 months to satisfy GDPR proof-of-consent requirements (Art. 7(1)), after which they are automatically rotated and purged.
- Account Termination: Upon account closure or termination, your account data is permanently deleted from our live production databases within thirty (30) calendar days, except where statutory retention requirements apply (such as accounting records under the Swedish Bookkeeping Act Bokföringslagen).
8. Your Responsibilities as a Customer
When deploying the QookieQloud CMP on your websites, you acknowledge and agree that:
- Regulatory Compliance: You are responsible for ensuring that your digital properties comply with relevant data protection legislation (such as GDPR in Europe, CCPA/CPRA in California, or LGPD in Brazil).
- Transparency & Disclosures: You must provide your visitors with a comprehensive, transparent Cookie Notice and Privacy Policy detailing all active trackers.
- Prior Consent Enforcement: You must ensure that non-essential scripts and tracking cookies are not loaded prior to obtaining affirmative, unambiguous consent from the visitor.
- Regular Audits: You are advised to run regular privacy scans using QookieQloud’s automated audit tools to detect newly introduced trackers or vendor script updates.
9. Your Privacy Rights
Depending on your geographical jurisdiction (particularly within the European Union / European Economic Area), you have powerful statutory rights regarding your personal information:
- Right of Access (GDPR Art. 15): You have the right to obtain confirmation as to whether your personal data is being processed, and to request a copy of the data.
- Right to Rectification (GDPR Art. 16): You have the right to request the correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to Be Forgotten" (GDPR Art. 17): You may request the deletion of your personal data when it is no longer required for the purposes for which it was collected.
- Right to Restriction of Processing (GDPR Art. 18): You may request the suspension of data processing while a dispute or audit is being investigated.
- Right to Data Portability (GDPR Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON/CSV).
- Right to Object (GDPR Art. 21): You may object to the processing of your data based on legitimate interests.
- Right to Lodge a Complaint: You have the right to lodge a formal complaint with a supervisory authority. In Sweden, the competent authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY, www.imy.se).
To exercise any of these rights, please email our Data Protection Desk at hello@qookieqloud.com or use our Privacy Inquiry Form. We process all legitimate requests within 30 days free of charge.
10. Children’s Privacy
QookieQloud™ is a business-to-business (B2B) SaaS service intended exclusively for professionals and organizations. We do not knowingly solicit or collect personal information from individuals under sixteen (16) years of age. If you believe that a minor has provided us with personal information, please notify us immediately so we can expunge the data from our systems.
11. Changes to This Privacy Policy
We may revise this Privacy Policy periodically to reflect technological advancements, operational changes, or new regulatory guidelines. Any modifications will be posted directly to this page with an updated “Last Updated” date at the top. For substantial changes affecting your rights, we will notify active account holders via email or a prominent banner within the QookieQloud dashboard.
12. Contact Us & Data Controller Information
If you have questions, feedback, or concerns regarding this Privacy Policy, our data handling procedures, or our Data Processing Agreement (DPA), please reach out to our team: