PrivacyPolicy.
How TrustCV Ltd collects and uses personal information from customers, their contacts, and other individuals across qsend.cc and the QS·C, QS·L, QS·R, QS·P and QS·Q modules.
About this policy
At Qsend, privacy is a priority. This Privacy Policy explains how TrustCV Ltd collects and uses personal information from customers, their contacts, and other individuals who access or use qsend.cc, our mobile and web applications, our APIs, and the QS·C, QS·L, QS·R, QS·P and QS·Q modules (together, the "Services"). TrustCV Ltd is the data controller in respect of personal data collected through our website and marketing activities, and a data processor in respect of personal data our customers upload into the Services about their own contacts (see P-10 below).
How we use your personal data
This section explains what personal data we hold and process, where we obtained it if not directly from you, the purposes for which we process it, and the legal grounds on which we do so. We will not pass your personal information to any third party except as set out in this document. We use sub-processors and sub-contractors to help us provide the Services (see P-12).
Account and contact data
When you register for an Account, we process your name, business name, email address, phone number, and billing details ("account data"). We use this to create and administer your Account, to provide the Services, to bill you, and to communicate with you about your use of the Services. Legal basis: performance of a contract with you and our legitimate interest in operating our business.
Profile and business card data
Where you use QS·C, QS·L, or similar features, you may upload biographical, professional, and contact information about yourself for the purpose of generating digital business cards, link-in-bio pages, vCards, and QR codes ("profile data"). This data is displayed to third parties at your direction when you share your card or page. You are responsible for its accuracy and for your decision to make it public.
Contact / CRM data you upload
Where you use QS·P, QS·R, or similar features, you may upload personal data about your own business contacts (names, emails, phone numbers, notes, and interaction history) ("customer contact data"). In respect of customer contact data, we act only as a data processor on your instructions; you are the data controller and are responsible for having a lawful basis to collect and process this data, and for responding to any data subject rights requests received from your contacts. Our processing of customer contact data on your behalf is governed by our standard data processing terms, available on request.
Sensitive personal data
You should not upload special category data (health data, biometric data, data revealing racial or ethnic origin, religious beliefs, sexual orientation, criminal records, etc.) to the Services. Please do not supply such data to us or via the Services.
Transaction data
We process information relating to payments made to us, including billing name, address, and payment method details (processed via our payment processor; we do not store full card numbers) ("transaction data"), for collecting payment, preventing fraud, and record-keeping. Legal basis: performance of a contract and our legitimate interest in the proper administration of our business.
Services / usage data
We process data about your use of the website and Services, including IP address, device and browser type, operating system, referral source, pages viewed, and app usage patterns ("services data"), for analysing and improving the Services, ensuring security, and (where you have consented) marketing. Legal basis: our legitimate interest in operating, securing, and improving our Services.
Marketing and notification data
Where you opt in to receive marketing communications or newsletters, we process your contact details for that purpose ("notification data"). Legal basis: consent, which you may withdraw at any time using the unsubscribe link in any marketing email or by contacting us.
Correspondence data
We process the content and metadata of any communication you send us (via our contact form, live chat, or support email) ("correspondence data") for the purpose of responding to you and keeping records. Legal basis: our legitimate interest in the proper administration of our business.
Your role vs. our role
Where personal data relates to you as our customer (account, billing, and usage data), we are the controller. Where personal data relates to your own contacts that you have uploaded into the Services (customer contact data used in QS·C, QS·L, QS·R, QS·P, or QS·Q), you are the controller and we are the processor, acting only on your documented instructions.
Other processing
We may also process personal data where necessary to comply with a legal obligation, or to protect the vital interests of you or another individual.
Sharing your personal data
- Sub-processors and service providers. We use trusted third-party providers to help us operate the Services and our business - for example, cloud hosting providers, email delivery infrastructure, analytics providers, customer support tooling, and payment processors. We only share the minimum data necessary and require these providers to protect your data under appropriate contractual safeguards. A current list of key sub-processors is available on request at support@qsend.cc.
- WhatsApp. Where you use QS·R to draft WhatsApp messages, the content is prepared within the Services but is sent by you, personally, from your own WhatsApp account. We do not transmit messages to WhatsApp or to your contacts on your behalf.
- Professional advisers. We may disclose personal data to our professional advisers (accountants, auditors, lawyers, insurers) where reasonably necessary for managing risk, obtaining advice, or managing disputes.
- Legal and safety disclosures. We may disclose personal data where required to comply with a legal obligation, to enforce our Terms, to protect our rights, property, or safety, or in connection with a merger, acquisition, or sale of assets.
- No sale of data. We do not sell your personal data to third parties.
International transfers
Some of our sub-processors may be located, or process data, outside the UK. Where this is the case, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum, Standard Contractual Clauses, or reliance on an applicable adequacy decision.
Retaining and deleting personal data
We do not keep personal data for longer than necessary for the purpose for which it was collected, save where we are required to retain it to comply with a legal, accounting, or reporting obligation, or to establish, exercise, or defend legal claims. Where you close your Account, we will delete or anonymise your account data and any customer contact data within a reasonable period (currently up to 30 days), except where retention is required by law or for legitimate business archival purposes (e.g. billing records, which we retain for 6 years in line with UK tax law).
Security
We maintain appropriate technical and organisational measures designed to protect your personal data against unauthorised access, alteration, disclosure, or destruction. See our Security Policy for detail. No method of transmission or storage is 100% secure. To the extent permitted by law we accept no liability for unauthorised access resulting from circumstances beyond our reasonable control.
Your rights
Subject to applicable law, you have the following rights in relation to your personal data:
- the right to access the personal data we hold about you;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure of your data in certain circumstances;
- the right to restrict our processing of your data in certain circumstances;
- the right to object to processing based on legitimate interests or for direct marketing;
- the right to data portability, where processing is based on consent or contract and carried out by automated means;
- the right to withdraw consent at any time, where processing is based on consent;
- the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at privacy@qsend.cc. If your query relates to customer contact data uploaded by one of our business customers, we will direct your request to the relevant customer, who is the data controller for that data. If you are in the UK, you can lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Cookies
For information about how we use cookies and similar technologies, see our Cookie Policy.
Children
The Services are intended for business and professional use by adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time by publishing a new version on our website. Where changes are material, we will notify you by email or through the Services.
Limitation of liability in respect of data
To the maximum extent permitted by applicable law, our liability for any claim arising out of or in connection with this Privacy Policy, including any alleged failure to protect personal data, is subject to the limitation of liability set out in our Terms and Conditions.
Contact
TrustCV Ltd, a UK-based software company operating the Qsend platform. Registered in England and Wales, company number 16280940. Registered office: 32 Trafalgar Drive, Brooklands, Milton Keynes, MK10 7ER. Data protection contact: privacy@qsend.cc.