Back

Cyberexpert Privacy Policy

This Privacy Policy outlines the manner in which QIMA Limited together with its Affiliates ( “QIMA” or “Data Controller”), collects, uses, maintains, and discloses information within Cyberexpert platform. For more information on QIMA Privacy Policy please check out our Group Privacy Policy .

By accessing or using Cyberexpert platform, users acknowledge and agree to the terms outlined in this Privacy Policy. QIMA is committed to ensuring the privacy and protection of all User information collected. This document serves as a guide to understand how personal data is handled by the Data Controller in the course of providing its services.

1. Definitions

For the purposes of this Privacy Policy, the following terms shall have the meanings ascribed to them below:

Data Subject: means is any identified or identifiable natural person whose personal data is collected, held, or processed by QIMA on Cyberexpert platform.

Affiliates: entities that control, are controlled by, or are under common control with QIMA Limited, where “control” means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for election of directors or other managing authority.

2. Data Controller

For the purposes of this Privacy Policy, QIMA Limited alongside with its Affiliates, namely: CCLab Kft (collectively named herein as QIMA) are designated as the Data Controllers.

As the Data Controller QIMA is responsible for determining the purposes and means of processing personal data of Data Subjects. QIMA is committed to safeguarding the privacy and security of the personal data it processes in compliance with applicable data protection laws and regulations, including but not limited to the General Data Protection Regulation (GDPR).

In its capacity as Data Controller, QIMA may engage various third parties to process personal data on its behalf. These third parties are carefully selected to ensure they comply with the high standards of data protection and security as required by QIMA and relevant legislation. Furthermore, QIMA may share personal data with its Affiliates for legitimate business purposes, under the condition that such data sharing conforms to the applicable data protection laws.

3. Personal Data Collected

In the course of providing services through Cyberexpert Platform, QIMA may collect certain types of personal data from Data Subjects. This data is essential for delivering our services and for maintaining the integrity and security of our services. The types of personal data collected include, but are not limited to:

  • Contact information, such as name, email address, and title, related to the User of the Platform

4. Purpose of Data Processing

The purpose of processing personal data of Data Subjects by QIMA and its Affiliates is primarily to provide services to clients through the Cyberexpert platform. This includes, but is not limited to, managing accounts, facilitating transactions, and offering customer support.

QIMA may process your data for our legitimate business purposes. We make efforts to consider and balance any potential impact on you (both positive and negative), and your rights under applicable data protection laws.

5. Security Measures

In compliance with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR) and any national implementing laws, regulations, and secondary legislation, QIMA has implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk associated with the processing of personal data of Data Subjects.

These measures are designed to prevent unauthorized or unlawful processing, accidental loss, destruction, or damage to personal data, such as:

  • Infrastructure. QIMA’s infrastructure meets the requirements of global security standards, we have regular audits based well known certifications. QIMA’s infrastructure is protected by anti-malware and extensive network and security monitoring systems.
  • Encryption. All QIMA data in transit and data at rest are encrypted.
  • Security Awareness. All QIMA employees are required to undertake Security Awareness Training.

6. Rights of Data Subjects

In accordance with the GDPR, Data Subjects have the following rights regarding their personal data that is processed by the Data Controller:

  • Right to Access: Data Subjects have the right to request access to their personal data and to obtain information about how their personal data is being processed.
  • Right to Rectification: Data Subjects have the right to request the correction of inaccurate personal data concerning them.
  • Right to Erasure: Data Subjects have the right to request the erasure of their personal data under certain circumstances.
  • Right to Restriction of Processing: Data Subjects have the right to request the restriction of processing of their personal data under certain conditions.
  • Right to Data Portability: Data Subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
  • Right to Object: Data Subjects have the right to object to the processing of their personal data under certain circumstances, including processing for direct marketing purposes.
  • Right to Not be Subject to Automated Decision-making: Data Subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
  • Right to Withdraw Consent: Where the legal basis for processing is consent, Data Subjects have the right to withdraw their consent at any time.
  • Right to Lodge a Complaint: Data Subjects have the right to lodge a complaint with a supervisory authority if they believe that the processing of their personal data violates the GDPR or other relevant data protection laws.

Data Subjects may exercise these rights by contacting the Data Controller directly. The Data Controller will provide information on the action taken on a request concerning the rights of Data Subjects without undue delay and in any event within one month of receipt of the request.

7. Data Sharing and Transfers

QIMA may share personal data among its Affiliates for internal administrative purposes, including but not limited to processing and storage.

Except as required by law or for the legitimate business purposes of managing and improving the services offered to Data Subjects, the Data Controller shall not share personal data with any third parties outside the QIMA group. Any such data sharing or transfers will be conducted in compliance with applicable legal requirements, ensuring the protection of Data Subjects’ rights and privacy.

All data transfers outside the European Economic Area (EEA) will be carried out in accordance with the General Data Protection Regulation (GDPR), ensuring that adequate levels of protection are maintained and that appropriate safeguards are in place to protect the privacy and fundamental rights of the Data Subjects.

8. Data Retention Policy

QIMA is committed to retaining personal data of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed. The retention period for personal data varies depending on the specific type of data in question and the purposes for which it is processed. The Data Controller will ensure that personal data are securely deleted or anonymized when no longer needed.

Upon the expiration of the data retention period, personal data shall be securely deleted or anonymized, unless further processing is required for compliance with a legal obligation to which the Data Controller is subject, or for the establishment, exercise, or defense of legal claims.

9. Changes to the Privacy Policy

We may amend or simply update all or part of this Privacy Policy when amendments are made to laws or regulations that govern protection of personal data and your rights. Changes and updates to this Privacy Policy shall be binding once posted on the Site in this section. We therefore recommend you access this section regularly in order to check the most recent and updated version of this Privacy Policy. You can check the “effective date” posted at the top to see when the Privacy Policy was last updated.

10. Contact Information

You are entitled to exercise your rights at any moment in time, within the terms and conditions provided by the law, sending such requests by e-mail to privacy@qima.com.

QIMA Limited is committed to protecting the privacy and security of Data Subjects’ personal data and will respond to all legitimate requests in accordance with applicable data protection laws.

Back