Legal

Privacy policy

Qbiky processes the data required to create and manage accounts, provide contracted products, protect the platform and handle data-related requests.

01

Data we process

Data may include account and organizer user information, the responses or records each organizer configures in their events, and technical security data. Anonymous products do not require participants to create an account.

02

Security and minimization

IP addresses used to prevent abuse are stored as hashes where applicable, not in plain text. Session tokens and temporary keys expire, and public responses do not expose internal account identifiers.

03

Retention

The default retention period for participation data after an event closes is 30 days and can be configured by the organizer. Rejected questions are deleted 30 days after creation and, once a closed event reaches its retention limit, voting tokens are anonymized and votes are deleted.

  • Audit logs are kept for 2 years.
  • Refresh tokens expire automatically after 7 days.
  • Usage-limiting keys expire within one hour.
  • Logos and assets are retained while the account exists and deleted with it.
04

Control of your data

Organizers manage the data collected by their events from the dashboard, including export and deletion where the product allows it. Deleting an account starts deletion of its associated data and resources.