Qualex Privacy Policy
This Privacy Policy explains what personal data Qualex collects, why we process it, how long we keep it, and what rights you may have.
1. Controller and Contact
Qualex is operated by Individual Entrepreneur Andrii Dmytrovych Mahas, registration/tax ID Tax ID 3885812390, located in Ukraine. For privacy requests, contact [email protected]. Support requests can be sent to [email protected].
2. Important Note About Resumes and Related Materials
Qualex lets users upload resumes and role-related information into a workspace for structured resume text review, saved result cards, private notes, and exports. Resumes may contain personal data and may reveal sensitive information. If you upload someone else's resume or information, you are responsible for making sure you have a lawful basis, required notices, and any permissions needed to process that data.
When you use Qualex for recruiting or on behalf of an organization, you may be the controller of the personal data in the resumes and related role materials you upload. We process that data to provide the Service to you.
3. Data We Process
| Category | Examples |
|---|---|
| Account data | Email address, login/name, password hash, registration date, account status, language preference. |
| Authentication and security data | Verification challenges, failed login attempts, IP address, user agent, trusted-device token, active sessions, anti-abuse checks. |
| Workspace data | Role workspaces; role titles and descriptions; uploaded files and extracted resume text; requirement review cards; saved results; labels; private notes; exports; and result history. |
| Processing metadata | Analysis job status, progress, logs, processed/failed file counts, region routing metadata, errors, quota state. |
| Payment and purchase data | Plan code, payment schedule, Paddle customer, subscription, and transaction IDs, payment sessions, consent records, invoices shown in payment history, Analysis Pack purchases, and the additional analysis ledger. |
| Refund and support data | Refund request message, reply email, review status, usage snapshots, admin decisions, contact-form messages, support email metadata. |
| Marketing attribution data | UTM parameters, referrer domain, landing path, anonymous visitor ID, first-seen date, and registration link when a visitor creates an account. |
| Restriction and deletion records | Account restriction events, restoration events, renewal cancellation attempts, deletion request records, hashed deleted-email tombstone. |
4. Why We Process Data
| Purpose | Legal basis where GDPR applies |
|---|---|
| Create and manage accounts; provide the role workspace, resume text review, payment pages, and paid features. | Contract performance; legitimate interests in operating the Service. |
| Process uploaded resumes, role requirements, saved result cards, private notes, exports, and related workspace records. | Contract performance for the user; where a user uploads another person's resume data, the user must have their own lawful basis. |
| Handle payments, subscriptions, taxes, invoices, Analysis Pack purchases, refunds, and purchase consent records. | Contract performance; legal obligations; legitimate interests in payment integrity and fraud prevention. |
| Security, anti-abuse, authentication, account restrictions, fraud prevention, logs, and service protection. | Legitimate interests; legal obligations where applicable. |
| Support, contact requests, refund review, and administrative communication. | Contract performance; legitimate interests; legal obligations where applicable. |
| Measure campaigns using first-party attribution and, in the future, possible analytics or advertising tools. | Legitimate interests for limited first-party measurement where allowed; consent where required for non-essential cookies, pixels, or similar technologies. |
5. Assisted Resume Text Processing
We use Google Cloud/Vertex AI/Gemini or similar infrastructure to process resume text and role-related content and generate structured review results. Data sent for processing may include resume text, role requirements, uploaded file context, and instructions for identifying relevant text snippets, unclear points, or requirements not found in the uploaded text. The Service does not decide whether a person should be hired, rejected, interviewed, ranked, or approved.
Outputs are provided for human review only. They are not intended to infer a person's character, culture fit, protected traits, health, beliefs, personality, or overall suitability for employment. Users remain responsible for all review steps, notes, labels, communications, and employment decisions.
6. Payments and Paddle
Paddle acts as the official seller (merchant of record) for paid purchases. Paddle may collect and process payment details, the address provided for payment, tax information, card information, invoices, receipts, payment disputes, and refunds under Paddle's own terms and privacy notice. We receive limited payment metadata needed to provide access, reconcile subscriptions, display payment history, review refunds, and keep legal records.
When a subscription payment fails, Paddle and we process status and limited payment data to recover payment, update payment details, prevent duplicate purchases, and reconcile access. We do not receive your full card details.
7. Cookies, Analytics, and Advertising
We use cookies and similar technologies for login sessions, CSRF protection, language preference, trusted-device recognition, security, and service operation. These are needed for the Service to work.
At the moment, Qualex also uses first-party marketing attribution to remember campaign information such as UTM parameters, referrer domain, landing path, and an anonymous visitor ID for up to 90 days. This helps us understand which campaigns lead to registrations or purchases.
We currently use the following cookies and similar technologies:
| Cookie or technology | Purpose | Category |
|---|---|---|
sessionid |
Keeps you signed in and maintains your session. | Required |
csrftoken |
Protects forms and authenticated actions against CSRF attacks. | Required |
qualex_lang |
Stores your selected interface language. | Functional |
qualex_device |
Recognizes a trusted device for account security and login verification. | Security |
qualex_cookie_consent |
Stores your optional cookie choice so we do not ask on every visit. | Required |
qualex_marketing_id |
Stores first-party campaign and referrer attribution for up to 90 days. | Marketing attribution |
| Cloudflare Turnstile or similar checks | Helps detect bots and abuse on login, registration, contact, and payment pages where enabled. | Security |
We may add analytics or advertising technologies in the future, such as conversion tracking or advertising pixels. Where the law requires consent for non-essential cookies, pixels, or similar technologies, we will ask for the required consent or provide the legally required choice before using them. You can also control cookies through your browser settings, but blocking necessary cookies may prevent parts of the Service from working.
8. Who We Share Data With
- Paddle, for payment pages, payments, invoices, taxes, subscription status, refunds, and payment records.
- Brevo or similar email providers, for verification, contact, refund, restriction, and support emails.
- Google Cloud/Vertex AI/Gemini or similar providers, for resume text processing and role-requirement review.
- Cloudflare Turnstile or similar anti-abuse providers, where enabled.
- Hosting, database, storage, and infrastructure providers, currently Contabo GmbH, Cloud VPS 30 NVMe, Hub Europe / European Union.
- Professional advisers, authorities, payment partners, or legal recipients where needed for compliance, disputes, fraud prevention, or rights protection.
We do not sell user workspace data or uploaded resumes.
8A. Subprocessors and Infrastructure
We use the following subprocessors and infrastructure providers to operate the Service. We limit provider access to what is needed for the listed purpose.
| Provider | Role | Data involved | Notes |
|---|---|---|---|
| Paddle | Official seller (merchant of record) for payment pages, payments, invoices, taxes, refunds, and subscription status. | Payment contact details, transaction IDs, subscription metadata, invoice and tax records, and refund metadata. | Paddle processes payments under its own payment, tax, and buyer terms. |
| Brevo or similar email provider | Email delivery for verification, account, support, restriction, contact, and refund messages. | Email address, message metadata, and email content needed to send service messages. | Used only for service and support communications configured by us. |
| Google Cloud / Vertex AI / Gemini | Infrastructure for resume text processing and role-requirement review. | Resume text, role context, review instructions, and prompts needed to provide structured result cards. | Outputs must be reviewed by users and are not hiring, rejection, ranking, or approval decisions. |
| Cloudflare Turnstile or similar anti-abuse provider | Bot, abuse, and payment-page/login protection where enabled. | Challenge tokens, IP address, browser/device signals, and validation metadata. | Used to protect login, registration, contact, and payment flows. |
| Hosting, database, storage, and infrastructure provider | Runs the application, database, file storage, and related infrastructure. | Account, workspace, payment metadata, uploaded files, extracted resume text, logs, and security metadata. | Current provider/region: Contabo GmbH, Cloud VPS 30 NVMe, Hub Europe / European Union. |
We may update this list when providers, regions, or backup practices change.
9. Retention
We keep data only for as long as needed for the purposes described above, unless a longer period is required or permitted by law. Current product-level retention includes:
| Data | Typical retention |
|---|---|
| Pending upload batches | About 3 minutes if upload is not completed. |
| Temporary/stale resume batches | About 1.0 hours for unfinished or stale upload sessions, unless converted into saved result cards or deleted earlier. |
| Saved result cards and related uploaded files | Free and Starter keep saved result cards with the role workspace and remove source PDFs after processing. Basic and Pro may keep related source PDFs with saved results for up to about 14 days, unless deleted earlier by the user, account deletion, retention sync, or account restriction purge. |
| Processing job metadata and processing logs | Terminal processing job records are normally deleted after about 24 hours. |
| Payment-recovery and frozen role workspaces after a cancellation or access change | During payment recovery, existing workspace data is retained while new paid use is restricted. If Paddle confirms cancellation and data no longer fits the Free plan, affected workspaces are generally held for up to 10 additional days before cleanup, unless restored or deleted earlier. |
| Restricted-account workspace data | Role workspaces, uploaded files, saved result cards, notes, exports, and processing records may be deleted after 14 days if the account is not restored. |
| Payment sessions and payment webhook events | Normally up to 180 and 180 days respectively, while limited payment, tax, consent, fraud-prevention, and legal records may be retained longer where required or permitted by law. |
| Trusted-device cookie | Up to 120 days, unless removed earlier. |
| Deleted-account email tombstone | A hashed record may be retained for 5 years to prevent re-registration with the same email during the retention period and to protect against abuse. |
Excel exports are generated on request and sent to you; we do not intentionally keep a separate export copy beyond the request lifecycle.
10. Account Deletion
When you delete your account, we remove or anonymize product data such as workspace data, role workspaces, uploaded files, saved result cards, private notes, exports, the additional analysis balance, trusted devices, sessions, activity logs, and active resume jobs. Any active Paddle subscription linked to the account must be cancelled immediately before deletion; if cancellation fails, deletion does not complete.
Open in-account refund requests may be closed inside the product. After deletion, questions about payments or refunds can only be handled through support using your Paddle receipt, transaction ID, or other sufficient proof of purchase. We do not send a separate post-deletion email with transaction IDs. Limited records may be retained where required or permitted by law.
Account deletion may be paused while a payment session or payment is still being finalized. If a payment completes after deletion is requested, we may need to cancel the associated subscription or handle the purchase or refund with Paddle and support before deletion can be completed.
11. Account Restrictions
If an account is restricted, product access is blocked and renewal cancellation may be requested. Refund history and payment records may remain available for manual review. If you want to restore or delete a restricted account, contact [email protected]. We aim to respond within a few business days.
12. International Transfers
We may process data in countries outside your country of residence, including through providers such as Paddle, Google Cloud, Brevo, Cloudflare, and hosting providers. Where required, we rely on appropriate safeguards such as contractual protections, provider data-processing terms, adequacy decisions, or other transfer mechanisms available under applicable law.
13. Security
We use technical and organizational measures intended to protect personal data, including password hashing, authentication controls, CSRF protection, rate limits, file validation, anti-abuse checks, access controls, logging, and retention cleanup. No system can be guaranteed to be completely secure.
14. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent where processing is based on consent. To make a request, contact [email protected]. We may need to verify your identity before acting on a request.
You may also have the right to complain to a data protection authority. If you are in the EEA, you can contact your local supervisory authority.
15. No Automated Hiring Decisions
Qualex provides a workspace for resume text review and role-requirement organization. It does not make fully automated hiring, rejection, ranking, approval, compensation, or employment decisions. Users must review the materials themselves and decide any next step outside the Service.
16. Changes to This Policy
We may update this Privacy Policy when the Service, providers, legal requirements, retention periods, or data practices change. The effective date will show when the current version applies.