Qaxal
Privacy PolicyTerms of Use

Privacy Policy

Effective Date: 20 August 2026 Version: 2.7

About this Policy

This Privacy Policy explains how Qaxal s.r.o. ("Qaxal", "we", "us") handles personal data in two situations:

  • Our own websites and accounts (this Policy). When you visit qaxal.com, dip.qaxal.com, or go.qaxal.com, contact us, request a demo, book a call, submit an enquiry or application form, sign up for an account at app.qaxal.com, or hold a paid subscription, Qaxal is the controller of your personal data. The rest of this document tells you what we collect, why, and what your rights are.
  • End-user data flowing through the Digital Identity Platform (the DPA). When our customers deploy the Digital Identity Platform ("DIP") on their own websites and apps, Qaxal acts only as a processor on behalf of that customer. The customer is the controller for their visitors' data. That relationship is governed by our Data Processing Agreement at dip.qaxal.com/legal/dpa, not by this Policy. If you are an end user of a customer's website asking about your data, please contact the operator of that website.

A short cookie notice for our own sites is at the end of this Policy (Section 11).

1. Who we are

Qaxal s.r.o., a limited liability company organised under the laws of the Slovak Republic.

  • Registered seat: Ulica Adama Štrekára 8131/19, 917 08 Trnava, Slovakia
  • Company number (IČO): 55 900 526
  • Tax number (DIČ): 2122126281
  • VAT ID: SK2122126281
  • Commercial Register: District Court Trnava (Okresný súd Trnava), Section Sro, Insert No. 55543/T
  • Contact for all privacy matters: legal@qaxal.com

We have not appointed a Data Protection Officer. We are not a public authority, and we do not process special-category data on a large scale. Whether our processing amounts to regular and systematic monitoring of data subjects on a large scale under Article 37(1)(b) is a question of fact rather than of what the product is called, and we assess it against actual data-subject volumes, reach and retention. On our current assessment the mandatory triggers are not met. We review that assessment as the business grows and will appoint a DPO and say so here if it changes. legal@qaxal.com is the single point of contact for all data-protection questions and rights requests.

EU representative (Article 27 GDPR): none required. Qaxal is established in the European Union.

2. What we collect, why, and on what legal basis

We collect only what we need for the purposes below. The legal basis is the GDPR Article 6(1) ground we rely on for each purpose.

a) Marketing-site visitors (qaxal.com, dip.qaxal.com, go.qaxal.com)

  • What: IP address, request metadata, user-agent, referrer, pages viewed.
  • Why: Operating and securing the sites; aggregate analytics; detecting abuse.
  • Legal basis: Article 6(1)(f) legitimate interests (security, operational integrity) for server logs. Article 6(1)(a) consent for analytics and marketing cookies, recorded through our consent banner (see Section 11).

b) Contact form, demo request, sales enquiries

  • What: Name, business email, company, role, message content.
  • Why: Responding to your enquiry, qualifying the opportunity, sending you a proposal.
  • Legal basis: Article 6(1)(b) steps prior to entering a contract at your request; Article 6(1)(f) legitimate interest in business development for ongoing follow-up.

b2) Booking a call, and enquiry or application forms on go.qaxal.com

We operate a scheduling and enquiry flow on go.qaxal.com using HighLevel (see Section 4), our customer-relationship platform.

  • What: Name, business email, phone number where you give one, company, role, your answers to the qualification questions on the form, your selected appointment time and time zone, and the marketing attribution parameters described below. Where you consent to reminders, we also record delivery and engagement metadata for the reminder messages we send you.
  • Why: Booking and confirming the call, sending you appointment reminders so you do not miss it, preparing for the conversation, and assessing whether we are a fit for the work.
  • Legal basis: Where you book on your own behalf, Article 6(1)(b), steps taken at your request before entering a contract. Where you book as a representative of a company (the usual case, since we sell to businesses), Article 6(1)(f), our legitimate interest in responding to an approach made to us and in arranging the meeting you asked for. The same Article 6(1)(f) interest in business development covers follow-up after a booking is missed or an enquiry goes quiet. Confirmations and reminders for a call you actually booked are transactional, not marketing, and rest on the same basis as the booking. Any message that promotes our services beyond the booking is marketing and is sent only with your Article 6(1)(a) consent, which you can withdraw at any time. Where a reminder is sent by SMS or another electronic channel, we also comply with the electronic-marketing rules of your country, which may require consent independently of the GDPR.
  • Attribution parameters: where you arrive from a campaign, the utm_source, utm_medium, utm_campaign, and utm_content values in the link you followed may be recorded against your enquiry so we know which channel produced it. These values come from the URL itself, so they can reach us even where you decline marketing cookies. Where that happens we rely on Article 6(1)(f), our legitimate interest in understanding which channels produce enquiries; you can object at any time under Section 8. Marketing cookies and any device-storage attribution are separate and are set only with your consent (Section 11).
  • A note on the booking flow: confirming a call is optional. You can always reach us by plain email at legal@qaxal.com or matej@qaxal.com instead, and we will not treat you differently for it.

b2b) The chat widget on our website

We run a live-chat widget on qaxal.com, provided by HighLevel (see Section 4).

  • What: whatever you type into the chat, the name, email address and mobile number you choose to give, the consent choices you make, and basic technical data needed to deliver the conversation.
  • Why: answering you, and continuing the conversation if you ask us to.
  • Legal basis: Article 6(1)(b) or Article 6(1)(f) as described in Section 2(b2), depending on whether you are acting for yourself or for a company. Article 6(1)(a) consent for any promotional messaging you separately opt into.
  • The widget loads only to display the chat. It sets no advertising or analytics cookies of its own, and it does not track you across other websites. Anything you type is sent to HighLevel, who host the conversation for us.
  • Giving a phone number is optional. You can use the chat without one, and consent to messaging is never a condition of getting a reply.

b3) Text messages (SMS) and mobile phone numbers

Giving us a mobile number is always optional, and we never require it to book a call, to get a reply, or to buy anything from us. Consent to receive text messages is not a condition of purchase.

  • What: your mobile number, the consent choices you made and when you made them, and delivery and reply metadata for the messages we send.
  • Why: two separate purposes, which you consent to separately:
  • Customer care and transactional messages, for example confirming a call you booked, appointment reminders, rescheduling, and replies to a support request or an enquiry you started.
  • Promotional messages, for example offers, events, and service announcements.
  • How consent works: where we offer SMS, each purpose has its own separate, unticked checkbox. We never pre-tick them, we never bundle SMS consent with email consent, and opting into one does not opt you into the other. You may choose either, both, or neither.
  • Legal basis: Article 6(1)(a) consent for promotional messages. For transactional messages tied to a booking you made, Article 6(1)(b) or the Article 6(1)(f) basis described in Section 2(b2), together with the separate consent we collect where local electronic-marketing law requires it.
  • Message frequency varies and depends on what you asked for. Message and data rates may apply, depending on your mobile plan and carrier.
  • How to stop: reply STOP to any message to opt out, or HELP for help. You can also email legal@qaxal.com. Opting out of SMS does not affect your account, any booking you have made, or anything else you get from us.
  • We do not sell, rent, or share mobile numbers or SMS consent with anyone. The only parties that see your number are the platforms that deliver the message on our behalf, listed in Section 4, and they act on our instructions only.

Mobile information and text-messaging consent. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

  • Retention: as set out in Section 6 for the enquiry or booking the number belongs to. We keep a minimal record of an opt-out for as long as necessary to keep honouring it, as described in Section 2(f).

c) Newsletter and product updates

  • What: Name, email, engagement metadata (opens, clicks).
  • Why: Sending the communications you signed up for.
  • Legal basis: Article 6(1)(a) consent. You can withdraw at any time using the unsubscribe link in every email.

d) Account holders at app.qaxal.com

  • What: Name, business email, hashed password, role, billing contact details, audit logs of account activity, billing and payment records.
  • Why: Providing the subscription Service, account security, customer support, billing, sending service notifications.
  • Legal basis: Where you are personally a party to the contract (for example a sole trader), Article 6(1)(b) performance of that contract. Where you use the account as a representative of your employer or another organisation, we rely on Article 6(1)(f), our legitimate interest in administering and performing our contract with that organisation and in keeping the account secure. Article 6(1)(c) applies to compliance with accounting and tax obligations.

e) Vendor and supplier contacts

  • What: Name, business contact details, payment metadata.
  • Why: Procurement, paying invoices, tax reporting.
  • Legal basis:
  • Article 6(1)(b) - performance of contract - for vendor-side contractual administration and invoice payment to vendors with whom we have a direct contract.
  • Article 6(1)(c) - legal obligation - for processing necessary for tax reporting and statutory accounting record retention.
  • Article 6(1)(f) - legitimate interest - for relationship management with vendor contacts where no direct contract exists with the individual, including procurement evaluation and ongoing vendor selection.

f) Prospect research from public sources and referrals

Where we collect personal data about you from sources other than you directly, the following applies (Article 14 GDPR):

  • Categories of data: business contact information (name, role, company, professional email, public LinkedIn profile data) and other public business-register entries.
  • Sources: Slovak and EU business registers, publicly accessible LinkedIn profiles, referrals from existing clients or partners.
  • Purpose: identifying and reaching out to potential business customers; pre-qualifying outreach.
  • Legal basis: Article 6(1)(f) GDPR - our legitimate interest in growing the business and reaching decision-makers at potential client companies. The legitimate-interest balancing test favours processing because the data concerns individuals in their professional capacity and is publicly available.
  • Retention: 24 months from last interaction, then anonymised.
  • When we tell you: we include this information, or a direct link to it, in our first outreach to you, and in any event within one month of collecting your data, as Article 14(3) requires.
  • Right to object: recipients of outreach may object by replying to the outreach email or emailing legal@qaxal.com; Qaxal will stop processing for outreach and add the contact to a suppression list.
  • Suppression records: honouring an objection means we must keep a minimal record (email address or domain, and the date) after the prospect record itself is deleted, otherwise we could contact you again by mistake. We keep that minimal record for as long as necessary to keep honouring your objection, on the basis of Article 6(1)(c) and Article 6(1)(f). It is never used for any other purpose.

Is providing data required?

For (a) you can browse without providing personal data beyond what is technically necessary to load the site.

For (b), (c), and (d) the data is required to respond to you, send what you asked for, or operate your account; without it we cannot provide the relevant Service.

For (b2), only your name, a contact email, and a chosen time are needed to book a call. Your phone number, your company and role, and the qualification answers are optional: leave them blank and we will still hold the meeting, we will simply know less going in. Marketing consent is never a condition of booking. Attribution parameters come from the link you clicked and are not something you supply.

For (e) the data is needed to engage you as a counterparty. For (f) you provide nothing at all; the data comes from public sources or a referral.

Special categories of data

We do not knowingly collect special-category personal data (Article 9 GDPR). Please do not include health, political, religious, or similar information in messages to us.

Automated decision-making

We do not carry out automated decision-making that produces legal effects or similarly significantly affects you (Article 22 GDPR). Sales-pipeline routing and similar internal scoring are operated under human supervision and do not produce binding decisions.

3. Where the data comes from

Most personal data we hold comes directly from you (you fill in a form, sign up, email us, or visit our sites). We also process limited data from publicly available sources (business registers, public LinkedIn profiles) for prospect research, and from referrals where a third party introduces you to us with your knowledge.

4. Who we share data with

We share personal data only as needed to operate the Service, comply with the law, or protect our rights and the rights of others. The categories of recipients are:

  • Cloud infrastructure and operational vendors that host our sites, run our backend, deliver email, support our team, and process payments.
  • Our customer-relationship platform. Enquiries, bookings, and the contact records that come out of them are held in HighLevel (contracting entity HighLevel, Inc., Dallas, Texas, United States; its privacy policy also refers to HighLevel LLC and to LeadConnector), which we use as our CRM, scheduling tool, live-chat widget on qaxal.com, and the sender of appointment confirmations, reminders and any SMS you opt into. It receives the data described in Section 2(b2) and processes it only on our documented instructions, under HighLevel's Data Processing Agreement, which is incorporated into their Terms of Service and covers sub-processing, security and international transfers.

Transfer mechanism: that Agreement incorporates the European Commission's Standard Contractual Clauses, Module Two for controller-to-processor transfers and Module Three for processor-to-sub-processor transfers, together with the UK Addendum, and the parties are deemed to have executed them. HighLevel additionally states that it is certified under the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. DPF. HighLevel publishes its own sub-processor list at gohighlevel.com/sub-processors.

  • Professional advisers (lawyers, auditors, accountants) under duties of confidentiality.
  • Public authorities where required by enforceable legal process.
  • Successors in interest in a corporate transaction (merger, acquisition, asset sale), subject to equivalent confidentiality.

The named list of our DIP sub-processors, together with a transparency list of the controller-side vendors we use for our own operations (HighLevel among them), is published at dip.qaxal.com/legal/sub-processors. The two are listed in separate sections there because only the first are sub-processors under the DPA. We update that page when either changes.

We do not sell personal data and we do not share it with advertising networks for cross-site targeted advertising.

5. International transfers

Some of our sub-processors are located outside the European Economic Area, or may process limited data from servers outside the EEA. Where that happens, we rely on:

  • European Commission adequacy decisions under Article 45 GDPR, where the recipient country has one;
  • Standard Contractual Clauses (SCCs) adopted by the European Commission in Implementing Decision (EU) 2021/914, using Module 2 (controller-to-processor) or Module 3 (processor-to-processor) as appropriate. The text of the SCCs is published at https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en;
  • for transfers from the United Kingdom, either the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, whichever the relevant recipient has executed; and
  • the Swiss FDPIC SCC variant for transfers from Switzerland.

We apply supplementary measures (encryption in transit and at rest, access controls, contractual restrictions on access by foreign authorities) consistent with EDPB Recommendations 01/2020. The per-recipient transfer mechanism is recorded on the Sub-processors page. A copy of the SCCs executed with a specific recipient is available on written request to legal@qaxal.com.

6. How long we keep data

We keep personal data only for as long as we need it for the purposes above, then delete or anonymise it. Specific retention periods:

CategoryRetention
Account holder dataDuration of the subscription + 12 months after termination, then deleted (longer where law requires, e.g. accounting records, see below)
Marketing contacts (newsletter, demo requests, inbound leads)24 months from last interaction, then anonymised
Booking and enquiry records in our CRM (Section 2(b2))24 months from last interaction, then deleted from the CRM. Records that become a client engagement move to the account-holder and accounting rows below
Server logs and security telemetry90 days
Marketing-site analytics on the devicePer cookie category (see Section 11): functional ~12 months, analytics ~14 months, marketing 6-13 months
Billing and accounting records10 years (Slovak Act 431/2002 on Accounting; Slovak Act 222/2004 on VAT)

After the applicable period we delete or anonymise the data. Backups roll off on their own schedule; backed-up data is isolated from active processing until the backup cycles out.

7. How we keep data safe

We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR. For the DIP service the specific measures are set out in Annex II of the DPA. For the systems covered by this Policy, meaning our websites, our CRM, our mailboxes and our billing records, the measures we apply are access control on every account, multi-factor authentication where the provider supports it, encryption in transit and at rest as provided by the underlying platforms, and confidentiality undertakings from our personnel. Not every measure listed in the DPA Annex applies to every controller-side system, and we do not claim otherwise.

We do not use Customer Personal Data, Customer Content, or end-user data processed through the DIP service to train, improve, or fine-tune any AI or machine-learning model, whether ours or a third party's.

8. Your rights

Under GDPR you have the following rights for the personal data we hold about you as controller:

  • Access (Article 15) - a copy of your data and information about how we process it.
  • Rectification (Article 16) - correction of inaccurate or incomplete data.
  • Erasure (Article 17) - deletion in defined circumstances.
  • Restriction (Article 18) - temporary suspension of processing in defined circumstances.
  • Data portability (Article 20) - your data in a structured, commonly used, machine-readable format (typically JSON or CSV), where processing is based on consent or contract and carried out by automated means.
  • Objection (Article 21) - to processing based on legitimate interests, including direct marketing. We will stop unless we can demonstrate compelling overriding grounds.
  • Withdraw consent (Article 7) - at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Not be subject to automated decisions (Article 22) - not applicable here; we do not carry out such processing.

How to exercise these rights: email legal@qaxal.com. We respond within one month of receiving your request (Article 12(3) GDPR), extendable by a further two months for complex or numerous requests, in which case we will tell you within the first month. Exercising these rights is free. Only where we can demonstrate that a request is manifestly unfounded or excessive, in particular because it is repetitive, may we charge a reasonable fee reflecting our administrative costs, or refuse to act (Article 12(5) GDPR). If we do either we will tell you why, and how to complain or seek a judicial remedy.

Identity verification: before we act on a rights request we may need to verify your identity, in which case we will ask for additional information reasonably necessary to confirm who you are. We use that information only for verification.

9. Complaints

If you believe we have processed your data unlawfully, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). Our lead supervisory authority is:

Úrad na ochranu osobných údajov Slovenskej republiky (UOOÚ) Hraničná 12, 820 07 Bratislava 27, Slovak Republic Email: statny.dozor@pdp.gov.sk Web: https://dataprotection.gov.sk

You may also complain to the supervisory authority of the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement.

We would always prefer to hear from you first at legal@qaxal.com so we have a chance to put things right.

10. Children

The Service is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe we hold such data, contact legal@qaxal.com and we will delete it without undue delay.

11. Cookies and similar technologies on our own sites

This section covers cookies on qaxal.com, dip.qaxal.com, go.qaxal.com, and app.qaxal.com. The DIP product itself is a server-side tag-management service that customers deploy on their own websites; cookies set in that context are the customer's responsibility under the customer's own privacy policy, and are out of scope here.

Categories we use:

  • Strictly necessary - required for the site to work (session, security, load balancing). Always on; no consent required. Example: session cookie, anti-CSRF token. Retention: session or up to 12 months.
  • Functional - remember your preferences (language, accepted cookie state). Set with consent. Example: cookie banner state, retention up to 12 months.
  • Analytics - help us understand aggregate usage. Google Analytics 4 with Consent Mode v2 wired (no analytics tags fire without consent; once granted, GA4 is loaded with first-party identifiers). Retention on the device up to 14 months; aggregate analytics data retained 14 months.
  • Marketing - measure the effectiveness of our paid campaigns (LinkedIn Insight, Google Ads conversion tag, Meta Pixel where used). Set only with consent. Retention 6-13 months depending on the provider.

How consent works: the cookie banner offers Accept all, Reject all, and Customise. Strictly necessary cookies load regardless; all other categories require your consent. Your choice is stored and we re-ask after no more than 13 months.

Withdrawing consent: click the small "Cookie settings" link in the site footer to re-open the banner and change your choice. You can also clear cookies through your browser settings, or use your browser's built-in tracking controls. Withdrawing consent does not affect the lawfulness of processing that took place while consent was valid.

A full per-cookie inventory (provider, name, purpose, lifetime) is shown inside the consent banner's "Customise" view.

12. Changes to this Policy

We may update this Policy from time to time. For material changes affecting active customers, we notify the email address on file at least 30 days before the change takes effect. The current version is always published at qaxal.com/legal/privacy with the effective date at the top of the document. The former address dip.qaxal.com/legal/privacy redirects here and continues to work. Continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.

13. Contact

For any privacy question, to exercise your rights, or to raise a concern:

  • Email: legal@qaxal.com
  • Post: Qaxal s.r.o., Ulica Adama Štrekára 8131/19, 917 08 Trnava, Slovakia

Revision history

VersionEffective dateSummary
2.025 November 2025Initial v2. Rewritten for self-serve SaaS scale: shorter, plainer language; single privacy + cookie document; pointer to DPA for processor-side processing; sub-processor list referenced by URL; SCCs referenced by European Commission URL; tightened retention table; single contact mailbox (legal@qaxal.com).
2.120 August 2026Canonical home moved from dip.qaxal.com/legal/privacy to qaxal.com/legal/privacy, old URL redirects. Added services.qaxal.com and go.qaxal.com to scope in the header, Section 2(a) and Section 11. New Section 2(b2) covering the booking, enquiry and application flow on go.qaxal.com, including UTM attribution capture and reminder messaging. Named HighLevel as our CRM and scheduling recipient in Section 4. Added a CRM retention row to Section 6. No change to legal bases, rights, retention of existing categories, or the DPA relationship.
© 2026 Qaxal s.r.o. · IČO 55 900 526Trnava, Slovakialegal@qaxal.com