Cookies Policy

 

COOKIES AND SIMILAR TECHNOLOGIES POLICY

Last updated: 1 September 2026
Effective date: 1 September 2026

1. About this Policy

1.1 Purpose

This Cookies and Similar Technologies Policy explains how Quasa International GmbH uses cookies and similar technologies in connection with the QUASA Platform.

It explains:

  • what cookies and similar technologies are;
  • which categories of technologies QUASA uses;
  • why those technologies are used;
  • which technologies require consent;
  • how Users can accept, reject or withdraw consent;
  • how long technologies remain active;
  • when information may be received by third parties;
  • how international transfers are protected; and
  • where Users can obtain additional information.

This document is referred to as the “Cookies Policy.”

1.2 Relationship with other QUASA documents

This Cookies Policy should be read together with:

  • the QUASA Terms of Use;
  • the QUASA Privacy Policy;
  • any feature-specific privacy notice;
  • any reward or campaign rules;
  • any advertising order;
  • any mobile-application notice; and
  • the information displayed in the QUASA cookie-consent interface.

The Terms of Use govern access to and use of the Platform.

The Privacy Policy explains how QUASA processes Personal Data, including information collected through cookies and similar technologies.

This Cookies Policy provides more detailed information about technologies that store information on, or obtain information from, a User’s browser, device or application.

Capitalised terms not defined in this Cookies Policy have the meanings given in the Terms of Use or Privacy Policy.

1.3 This Policy is not consent

This Cookies Policy provides information. It does not itself constitute consent to the use of non-essential technologies.

Where consent is legally required, QUASA will request it through a separate consent interface before activating the relevant technology.

Continued browsing, inactivity, closing the cookie banner or merely using the Platform will not be treated as consent to non-essential technologies.


2. Controller and contact details

Unless a feature-specific notice states otherwise, the Controller responsible for the use of cookies and the related Processing of Personal Data is:

Quasa International GmbH
Registered seat: Frankfurt am Main, Germany
Business address: An der Welle 4
60329 Frankfurt am Main
Germany

Commercial Register: Amtsgericht Frankfurt am Main
Registration number: HRB 115741

In this Cookies Policy, Quasa International GmbH is referred to as “QUASA,” “we,” “us” or “our.”

Questions concerning this Cookies Policy may be submitted through:

https://quasa.io/support

Privacy email:

[email protected]

Cookie settings: In development


3. Scope of this Cookies Policy

3.1 Services covered

This Cookies Policy applies to cookies and similar technologies used in connection with:

  1. the website available at https://quasa.io;
  2. QUASA language versions and subpages;
  3. QUASA user accounts and dashboards;
  4. QUASA Media;
  5. QUASA Rewards;
  6. QUASA Projects and PPC campaign tools;
  7. advertising and sponsored-content services;
  8. Quasa Connect web interfaces;
  9. QUASA mobile applications, where similar technologies such as SDKs or mobile identifiers are used;
  10. wallet-connection interfaces;
  11. support and communication tools; and
  12. related QUASA services and interfaces.

Together, these are referred to as the “Platform.”

3.2 Third-party websites

This Cookies Policy does not govern technologies used independently by third-party websites or applications after you leave the QUASA Platform.

For example, a third party may use its own cookies when you:

  • visit an Advertiser’s website;
  • open a Project website;
  • use an external wallet;
  • use a crypto exchange;
  • open a social-media platform;
  • use an external payment service; or
  • access another independently operated service.

The third party’s own cookie and privacy notices apply to its Processing.

3.3 Server-side Processing

Some information is processed when a browser or application connects to QUASA even where no cookie is placed.

This may include:

  • IP address;
  • request date and time;
  • browser or App information;
  • requested page;
  • server logs;
  • security events; and
  • network information necessary to deliver the requested service.

This Processing is described in the Privacy Policy and is not necessarily dependent on a cookie.


4. What cookies and similar technologies are

4.1 Cookies

A cookie is a small text file or data record stored on a browser or device when a website is visited.

A cookie may allow a website or service provider to:

  • recognise a browser;
  • maintain a session;
  • remember a preference;
  • protect an account;
  • measure use of a service;
  • remember a consent choice;
  • attribute an interaction to a campaign; or
  • provide another feature.

Cookies do not necessarily contain a person’s name. However, a cookie identifier may be Personal Data when it can be connected with a User, device, account or other information.

4.2 Local storage and session storage

Browsers may provide local-storage and session-storage functions.

These technologies can store information such as:

  • interface preferences;
  • authentication or session information;
  • wallet-connection status;
  • temporary form information;
  • consent choices;
  • language preferences; or
  • feature state.

Local-storage information may remain after the browser is closed.

Session-storage information is normally removed after the relevant browser tab or session is closed.

4.3 Software development kits

A software development kit, or SDK, is code included in a mobile application or other software to provide a particular feature.

An SDK may support:

  • App functionality;
  • authentication;
  • crash reporting;
  • analytics;
  • fraud prevention;
  • push notifications;
  • payment functions;
  • wallet connectivity; or
  • advertising measurement.

An SDK may receive information about the App, device or User.

4.4 Pixels, web beacons and tags

A pixel, web beacon or tag is a small piece of code or an electronic resource that may record when:

  • a page was viewed;
  • an email was opened;
  • a link was selected;
  • an advertisement was displayed;
  • a campaign interaction occurred; or
  • another event took place.

Some pixels operate together with cookies or device identifiers.

4.5 Referral and campaign parameters

A link may contain a referral, campaign or attribution parameter.

Such a parameter may identify:

  • the campaign;
  • the referring partner;
  • the advertisement;
  • the Project;
  • the reward offer;
  • the traffic source; or
  • another relevant interaction.

A parameter may be stored temporarily or associated with an account or campaign record.

4.6 Mobile and advertising identifiers

A mobile device or operating system may provide identifiers used for:

  • App functionality;
  • security;
  • fraud prevention;
  • analytics;
  • attribution; or
  • advertising.

Where required by law, QUASA will obtain consent before accessing or using a mobile advertising identifier for a non-essential purpose.

Users may also be able to reset, restrict or disable an advertising identifier through device settings.

4.7 Email measurement technologies

QUASA emails may contain measurement technologies that record, where permitted:

  • whether the email was delivered;
  • whether it was opened;
  • whether a link was selected;
  • the date and time of the interaction; and
  • limited device or email-client information.

Marketing email measurement is described further in Section 10.

4.8 Similar technologies

A technology may fall within this Cookies Policy even if it is not technically a cookie.

References to “cookies and similar technologies” include any technology that:

  • stores information on a User’s device;
  • accesses information already stored on a User’s device;
  • recognises a browser or application;
  • records a User’s interaction; or
  • performs a comparable function.

QUASA will not use technical differences between technologies to circumvent a User’s privacy choice.


5. First-party and third-party technologies

5.1 First-party technologies

A first-party technology is placed or controlled directly through a QUASA domain or application.

First-party technologies may be used for purposes such as:

  • maintaining an account session;
  • remembering a language;
  • storing a consent choice;
  • preventing fraud;
  • administering Rewards;
  • remembering campaign information; or
  • measuring use of the Platform.

5.2 Third-party technologies

A third-party technology is provided or controlled by another organisation.

Third parties may provide services such as:

  • analytics;
  • advertising measurement;
  • consent management;
  • embedded video;
  • social-media content;
  • fraud prevention;
  • customer support;
  • payment processing;
  • wallet connectivity;
  • push notifications; or
  • App diagnostics.

A third party may act:

  • as a Processor acting on QUASA’s instructions;
  • as an independent Controller;
  • as a joint Controller with QUASA; or
  • in different roles for different Processing activities.

The current technology list must identify the relevant provider and its role where reasonably possible.

5.3 No “first-party only” representation

QUASA does not represent that every technology used on the Platform is a first-party technology.

Both first-party and third-party technologies may be used, but only as described in this Cookies Policy and the current Cookie Settings interface.


6. Session and persistent technologies

6.1 Session technologies

A session cookie or similar session technology normally expires when:

  • the browser is closed;
  • the App session ends;
  • the User logs out; or
  • the relevant session expires.

Session technologies may be used to:

  • maintain login status;
  • protect forms;
  • preserve navigation state;
  • maintain a transaction session; or
  • provide a requested feature.

6.2 Persistent technologies

A persistent cookie or similar technology remains until:

  • its specified expiration date;
  • it is replaced;
  • the User deletes it;
  • consent is withdrawn and it is removed where technically possible; or
  • the technology is otherwise disabled.

Persistent technologies may be used to remember:

  • consent choices;
  • language;
  • account preferences;
  • campaign attribution;
  • analytics identifiers; or
  • advertising preferences.

The exact duration of each active technology must be stated in the current technology list.

6.3 Cookie duration and server retention are different

The expiration of a cookie does not necessarily determine how long information already received by QUASA or a service provider is retained.

For example:

  • a cookie may expire after one day;
  • an event generated through that cookie may be retained for a longer period;
  • an aggregated report may no longer contain the original cookie identifier.

Applicable server-side retention periods are described in this Policy, the current technology list and the Privacy Policy.


7. Legal rules for storing or accessing device information

7.1 General rule

Where applicable law requires consent before information is stored on or accessed from a User’s device, QUASA will obtain that consent before activating the relevant technology.

This applies regardless of whether the information:

  • directly identifies the User;
  • is pseudonymous;
  • is encrypted;
  • is later aggregated; or
  • is technically classified as Personal Data.

7.2 Strictly necessary exception

Consent may not be required where storing or accessing information is strictly necessary:

  1. solely to transmit a communication over a public telecommunications network; or
  2. to provide a digital service expressly requested by the User.

A technology is not strictly necessary merely because it:

  • is useful to QUASA;
  • improves advertising revenue;
  • makes analytics easier;
  • provides additional commercial insight;
  • improves personalisation; or
  • is commonly used by other websites.

7.3 Non-essential technologies

Functional, analytics, advertising, remarketing and attribution technologies will be treated as consent-based where applicable law requires consent.

QUASA will not rely on legitimate interests as a substitute for consent to place or read a non-essential technology where device-access law requires consent.

7.4 Subsequent Processing of Personal Data

After information has been obtained through a cookie or similar technology, its subsequent Processing is governed by applicable data-protection law.

Depending on the purpose, the relevant GDPR legal basis may include:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation; or
  • legitimate interests.

For consent-based analytics, advertising or personalisation, QUASA will normally rely on Article 6(1)(a) GDPR for the related Personal Data Processing.

For strictly necessary security and service technologies, QUASA may rely, as appropriate, on:

  • Article 6(1)(b) GDPR;
  • Article 6(1)(c) GDPR; or
  • Article 6(1)(f) GDPR.

Further information is provided in the Privacy Policy.

7.5 No non-essential technology before consent

Before valid consent has been obtained, QUASA will not intentionally activate technologies requiring consent.

This includes technologies loaded through:

  • tag managers;
  • embedded content;
  • analytics scripts;
  • advertising pixels;
  • remarketing tags;
  • social-media integrations;
  • mobile SDKs; or
  • similar third-party components.

7.6 No recreation of rejected identifiers

QUASA will not use fingerprinting, local storage, cache identifiers or another method to recreate an identifier that the User has rejected or deleted for analytics or advertising purposes.

Security and fraud-prevention signals may be used where strictly necessary and proportionate, but they will not be repurposed to create advertising profiles.


8. Categories of technologies used by QUASA

QUASA classifies technologies according to their primary purpose.

Category Main purpose Default status Consent normally required?
Strictly necessary Security, authentication, consent records and delivery of requested services Active where genuinely necessary No, where the legal necessity exception applies
Functional Remembering optional choices and providing enhanced features Inactive until permitted, unless strictly necessary for a specifically requested feature Usually yes
Analytics Measuring traffic, content use, performance and errors Inactive until permitted Yes where required
Advertising and attribution Campaign measurement, referral attribution, frequency control, remarketing and personalised advertising Inactive until permitted Yes where required

The classification of a particular technology depends on its actual purpose and configuration, not solely on the provider’s description.

A single provider may supply technologies falling into different categories.


9. Strictly necessary technologies

9.1 Purposes

Strictly necessary technologies may be used to:

  • deliver the Site or App;
  • route network traffic;
  • maintain a secure session;
  • authenticate a User;
  • keep a User signed in;
  • process a form requested by the User;
  • prevent cross-site request forgery;
  • detect malicious requests;
  • protect an account;
  • apply security rate limits;
  • support checkout or transaction state;
  • remember a cookie-consent choice;
  • connect a wallet after the User requests the connection;
  • maintain a requested task, reward or campaign workflow;
  • prevent duplicate submissions;
  • provide another digital function expressly requested by the User.

9.2 Consent records

QUASA may use a strictly necessary cookie or similar record to remember:

  • whether the cookie banner was shown;
  • which categories the User accepted;
  • which categories the User rejected;
  • when the choice was made;
  • which version of the consent notice applied; and
  • whether the User later changed the choice.

Without this record, QUASA might repeatedly request consent or fail to respect the User’s previous choice.

9.3 Security and fraud prevention

Strictly necessary security technologies may process limited information such as:

  • IP address;
  • session identifier;
  • device or browser characteristics;
  • login events;
  • failed authentication attempts;
  • request frequency;
  • suspicious network signals; and
  • indicators of automated activity.

Security technologies must not be used for unrelated advertising or general cross-site profiling.

9.4 Effect of blocking necessary technologies

A browser or device may allow a User to block all cookies.

Blocking strictly necessary technologies may prevent:

  • account login;
  • maintenance of a secure session;
  • use of a dashboard;
  • submission of a form;
  • use of Rewards;
  • operation of campaign tools;
  • use of Quasa Connect;
  • wallet connection; or
  • another requested Platform feature.

10. Functional technologies

10.1 Purposes

Functional technologies may be used to remember optional choices such as:

  • preferred language;
  • region;
  • interface layout;
  • font or accessibility setting;
  • video preferences;
  • content display preferences;
  • saved filters;
  • recently viewed content;
  • support-chat state;
  • profile preferences; or
  • other convenience settings.

10.2 Language and interface preferences

A technology used solely to remember a language or interface choice expressly selected by the User may, in some circumstances, qualify as strictly necessary for that requested function.

Where the technology is not strictly necessary, it will remain within the Functional category and will require consent where applicable.

10.3 Embedded functionality

An embedded third-party feature may include:

  • a video player;
  • an interactive chart;
  • a map;
  • a social-media post;
  • a support chat;
  • an external form;
  • a wallet interface; or
  • another interactive component.

Where the component can access a device or set non-essential identifiers, QUASA will normally:

  • block the component until consent is provided;
  • use a privacy-enhanced configuration where available; or
  • provide a click-to-load mechanism.

The third-party provider may process information independently after the component is activated.

10.4 Effect of rejecting Functional technologies

Rejecting Functional technologies should not prevent access to public editorial content.

However, optional features may:

  • not remember preferences;
  • require repeated configuration;
  • display a placeholder;
  • operate with reduced functionality; or
  • remain unavailable until the relevant choice is made.

11. Analytics technologies

11.1 Purposes

Analytics technologies may be used to understand:

  • how many visits the Platform receives;
  • which pages or screens are viewed;
  • how Users navigate;
  • which language versions are used;
  • how long sessions last;
  • which features are used;
  • whether errors occur;
  • how quickly pages load;
  • which general device categories are used;
  • which traffic sources lead to QUASA;
  • how content and Projects perform; and
  • whether Platform changes improve usability.

11.2 Information that may be processed

Depending on the technology and configuration, analytics information may include:

  • cookie or analytics identifier;

  • IP address or IP-derived country;

  • browser type;
  • operating system;
  • device category;
  • App version;
  • page or screen viewed;
  • referring page;
  • selected link;
  • session start and duration;
  • event date and time;
  • general geographic region;
  • interaction event;
  • error or crash event;
  • campaign parameter; and
  • account or pseudonymous identifier where appropriate.

11.3 Google Analytics and other analytics providers

QUASA may use Google Analytics or another analytics provider only where:

  • the provider is identified in the current technology list;
  • the purposes and settings are accurately described;
  • the applicable data-processing agreement is in place;
  • international-transfer requirements are addressed;
  • the technology is blocked until consent where consent is required; and
  • the User can withdraw consent.

The presence of a provider in an older policy or source code does not by itself mean that the provider is currently active.

11.4 Aggregated reports

QUASA may use analytics information to create aggregated reports.

An aggregated report may include information such as:

  • total visits;
  • general country distribution;
  • device categories;
  • page popularity;
  • campaign performance; or
  • error frequency.

Where information has been irreversibly anonymised, it is no longer Personal Data.

11.5 No sensitive analytics profiles

QUASA will not use analytics technologies to create profiles based on:

  • private messages;
  • identity documents;
  • payment-card credentials;
  • private wallet keys;
  • recovery phrases;
  • precise location;
  • Special Category Data; or
  • data known with reasonable certainty to relate to a minor.

12. Advertising and attribution technologies

12.1 Purposes

Advertising and attribution technologies may be used, subject to consent and applicable law, to:

  • identify the general source of a visit;
  • determine whether an advertisement was viewed or selected;
  • attribute an interaction to a Project or campaign;
  • measure campaign performance;
  • prevent duplicate attribution;
  • limit how often an advertisement is displayed;
  • prepare aggregate campaign reports;
  • measure QUASA advertising displayed on another service;
  • show relevant QUASA advertising;
  • support remarketing; or
  • detect invalid or manipulated advertising traffic.

12.2 QUASA Projects and PPC

In connection with QUASA Projects and PPC campaigns, relevant technologies may process:

  • Project identifier;
  • campaign identifier;
  • referral source;
  • pseudonymous click identifier;
  • date and time;
  • landing page;
  • general country;
  • device category;
  • interaction status;
  • invalid-traffic indicator; and
  • conversion or completion status.

Advertisers will ordinarily receive aggregated or campaign-level information rather than directly identifying information.

A QUASA User’s identity will not ordinarily be disclosed to an Advertiser merely because the User viewed or selected a Project or advertisement.

12.3 QUASA Rewards attribution

Some optional Rewards offers may require attribution to determine whether a qualifying action was completed.

Before the User begins such an offer, QUASA should disclose:

  • whether a cookie or comparable technology is required;
  • whether a third-party partner is involved;
  • what action is measured;
  • the relevant consent category;
  • the available reward;
  • the applicable time period; and
  • what happens if the technology is rejected or deleted.

Where attribution requires consent:

  • the technology will not be activated before consent;
  • the User may refuse consent;
  • refusal will not prevent general access to the Platform;
  • refusal may mean that the particular optional reward cannot be verified or credited.

First-party session or anti-fraud technologies that are genuinely necessary to provide a Reward expressly requested by the User may be classified as strictly necessary. Cross-site advertising, remarketing and unrelated partner tracking will not be classified as strictly necessary.

12.4 Remarketing

Where consent is provided, a provider may use an identifier or browsing event to show QUASA advertising after the User leaves the Site.

Remarketing may involve:

  • recognition of a browser or device;
  • creation of an interest or interaction segment;
  • selection of an advertisement;
  • frequency control; and
  • campaign reporting.

All active remarketing providers must be identified in the current technology list.

12.5 Prohibited advertising inputs

QUASA will not disclose or use the following information for remarketing or targeted-advertising profiles:

  • identity documents;
  • private messages;
  • exact task addresses;
  • precise device location;
  • payment-card credentials;
  • private keys;
  • wallet recovery phrases;
  • Special Category Data;
  • biometric-identification data; or
  • information known with reasonable certainty to relate to a minor.

12.6 No monetary sale of Personal Data

QUASA does not sell or rent Personal Data for monetary consideration.

Certain advertising or attribution disclosures may nevertheless be legally defined as a “sale,” “sharing” or “targeted advertising” in some jurisdictions.

Where such law applies, QUASA will provide the required notice and opt-out mechanism.

Privacy choices: Request


13. Email measurement

13.1 Operational emails

QUASA may process delivery information for operational messages concerning:

  • account security;
  • authentication;
  • tasks;
  • campaigns;
  • payments;
  • Rewards;
  • moderation;
  • legal notices; or
  • privacy requests.

Basic delivery records may be necessary to determine whether an important service message was successfully sent.

13.2 Marketing emails

Where permitted by applicable law, marketing emails may use measurement technologies to record:

  • delivery;
  • opening;
  • link selection;
  • campaign identifier;
  • interaction date and time; and
  • limited device or email-client information.

13.3 Marketing choices

A User may object to marketing email measurement by:

  • unsubscribing from the relevant marketing communication;
  • changing available communication settings;
  • contacting QUASA; or
  • using another control stated in the message.

Unsubscribing from marketing does not prevent necessary operational messages.


14. Mobile applications and SDKs

14.1 Application technologies

QUASA mobile applications may use:

  • SDKs;
  • local application storage;
  • push-notification tokens;
  • session identifiers;
  • device identifiers;
  • crash-reporting tools;
  • analytics tools;
  • security tools;
  • wallet-connectivity tools; and
  • other similar technologies.

14.2 App consent

Where an App technology requires consent, QUASA may request consent through:

  • an in-App consent interface;
  • an operating-system permission prompt;
  • App privacy settings; or
  • a combination of those mechanisms.

Consent given on the Site does not necessarily apply to the App, and App consent does not necessarily apply to every website browser.

14.3 Device permissions

Permissions for:

  • precise or approximate location;
  • camera;
  • photographs;
  • files;
  • microphone;
  • notifications; or
  • another device resource

are separate from general cookie consent.

A permission should be requested when the relevant feature is used and may be changed through device settings.

The Privacy Policy contains further information about App permissions.

14.4 Mobile advertising identifiers

QUASA will not access or use a mobile advertising identifier for non-essential advertising or attribution purposes before obtaining any consent required by law.

Where supported, Users may reset or restrict the identifier through operating-system settings.

14.5 App-provider disclosures

The current technology list must identify the SDKs actually included in each active App version.

App-store Data Safety or privacy disclosures must be consistent with:

  • the SDK inventory;
  • this Cookies Policy;
  • the Privacy Policy; and
  • the App’s actual behaviour.

15. Wallet connections and blockchain functionality

15.1 Wallet-connection technologies

A wallet-connection interface may use local storage, session storage or another identifier to:

  • remember that a wallet was connected;
  • maintain connection state;
  • determine the selected blockchain network;
  • request a signature;
  • associate a transaction with the relevant Platform action; or
  • display transaction status.

Where the User expressly requests wallet connection, technology strictly necessary to provide that connection may be used without separate cookie consent where the legal exception applies.

15.2 External wallet providers

An external wallet provider may independently process:

  • public wallet address;
  • IP address;
  • device information;
  • transaction request;
  • selected blockchain network; and
  • other information under the provider’s own privacy policy.

The current technology list must identify an active wallet provider where the provider places or reads information on the User’s device through the Platform.

15.3 Public blockchain records

Public blockchain records are not cookies.

Deleting cookies or withdrawing cookie consent does not delete:

  • wallet addresses;
  • transaction hashes;
  • token transfers;
  • smart-contract interactions; or
  • other information already recorded on a public blockchain.

Blockchain Processing is explained in the Privacy Policy and Terms of Use.

15.4 Private keys

QUASA does not use cookies to collect wallet private keys or recovery phrases and will never legitimately request that information.


16. Current technology list

16.1 Authoritative list

The current list of cookies, SDKs, pixels, local-storage items and related technologies used by QUASA uses through:

COOKIE SETTINGS: In development

The live list forms part of this Cookies Policy.

It must be updated when a technology, provider, purpose, duration or transfer arrangement materially changes.

16.2 Information included in the list

For each technology, the list should identify, where applicable:

Field Required information
Name Exact cookie, SDK, local-storage key, pixel or technology name
Provider QUASA or the relevant third party
Domain or App Domain, subdomain or App in which it operates
Type Cookie, local storage, SDK, pixel, identifier or other technology
Party First-party or third-party
Category Necessary, Functional, Analytics, or Advertising and Attribution
Purpose Clear description of what it does
Data Main information collected or accessed
Duration Session period or exact maximum lifetime
Device-access basis Strict necessity or consent
GDPR basis Applicable Article 6 legal basis
Recipient Person or organisation receiving the information
Processing location EEA or relevant third country
Transfer safeguard Adequacy decision, Standard Contractual Clauses or other mechanism
Control Cookie Settings, browser setting, App setting, unsubscribe or other method

16.3 Live declaration placeholder

The following component must be replaced by an automatically maintained or manually verified technology declaration before publication:

EMBED LIVE COOKIE AND SDK DECLARATION HERE: In development

The declaration should contain separate sections for:

  1. Strictly Necessary Technologies;
  2. Functional Technologies;
  3. Analytics Technologies; and
  4. Advertising and Attribution Technologies.

If a category contains no active technology, the declaration should state: No technologies are currently active in this category.

16.4 Example table structure

Technology Provider Category Purpose Duration Legal basis Processing location and safeguards
[EXACT NAME] [PROVIDER] [CATEGORY] [PURPOSE] [DURATION] [BASIS] [COUNTRY AND SAFEGUARD]
[EXACT NAME] [PROVIDER] [CATEGORY] [PURPOSE] [DURATION] [BASIS] [COUNTRY AND SAFEGUARD]

16.5 Technologies not listed

A non-essential technology that is not included in the current list should not be activated until:

  • its purpose has been assessed;
  • the relevant contracts have been reviewed;
  • the Privacy Policy and Cookies Policy have been updated where necessary;
  • the consent interface has been configured; and
  • valid consent has been obtained where required.

17. Cookie consent and settings

17.1 First visit

Where consent is required, the first layer of the consent interface should allow the User to:

  • accept all optional categories;
  • reject all optional categories; or
  • open granular settings.

The rejection option must be clear and should not be hidden in ordinary body text.

17.2 No pre-selected optional categories

Functional, Analytics, and Advertising and Attribution categories must not be pre-selected where affirmative consent is required.

Strictly necessary technologies may remain active because they do not depend on consent where the necessity exception applies.

17.3 Granular choice

Users should be able to make separate choices for:

  • Functional technologies;
  • Analytics technologies; and
  • Advertising and Attribution technologies.

Where necessary, the interface may also allow choices by individual provider or purpose.

17.4 Accepting consent

Consent requires an affirmative action, such as selecting:

  • Accept All;
  • Save Selected Preferences; or
  • another clearly labelled consent control.

Silence, inactivity or continued browsing does not constitute consent.

17.5 Rejecting consent

Selecting Reject Non-Essential means that only strictly necessary technologies may remain active.

Rejecting non-essential technologies will not ordinarily prevent access to public QUASA Media content.

Some optional features may remain unavailable or may function with reduced capability.

17.6 Withdrawing or changing consent

Consent may be withdrawn or changed at any time through:

COOKIE SETTINGS: In development

The Cookie Settings control should be:

  • available from the Site footer or another consistently accessible location;
  • available without creating an account;
  • usable on mobile and desktop devices; and
  • no more difficult to use than the original consent mechanism.

Withdrawal applies to future use and does not affect the lawfulness of Processing carried out before withdrawal.

17.7 Removal after withdrawal

After consent is withdrawn, QUASA will:

  • stop activating the affected technologies;
  • communicate the updated choice to relevant providers where technically supported;
  • delete affected first-party identifiers where reasonably possible; and
  • no longer use previously collected identifiable information for the withdrawn consent-based purpose, unless another valid legal basis or retention obligation applies.

Some third-party cookies may remain on the device until:

  • they expire;
  • the User deletes them through browser settings; or
  • the third party removes them.

17.8 Consent record

QUASA may retain a limited consent record to demonstrate:

  • what choice was made;
  • when it was made;
  • which notice version was presented;
  • which browser or pseudonymous consent identifier was involved; and
  • whether the choice was later withdrawn.

The consent record is not used for advertising.

17.9 Renewing consent

QUASA may request consent again where:

  • the purposes materially change;
  • a material new provider is introduced;
  • the consent interface changes substantially;
  • the existing record expires;
  • the User deletes the consent record;
  • applicable law or regulatory guidance requires renewal; or
  • QUASA cannot reliably determine the previous choice.

17.10 Consent on different devices and browsers

Cookie choices may apply only to the particular:

  • browser;
  • device;
  • App;
  • domain;
  • language version; or
  • profile

through which the choice was made.

A User may need to repeat the choice when:

  • using another browser;
  • changing devices;
  • clearing cookies;
  • using private-browsing mode;
  • reinstalling the App; or
  • accessing another technical environment.

Where QUASA can lawfully and reliably synchronise a preference through an account, it may do so.


18. Browser and device controls

18.1 Browser settings

Most browsers allow Users to:

  • view stored cookies;
  • delete cookies;
  • block all cookies;
  • block third-party cookies;
  • receive a warning before a cookie is stored; or
  • restrict storage in another way.

Browser instructions vary by provider and version.

18.2 Limitations of browser blocking

Blocking all cookies may:

  • prevent login;
  • terminate a session;
  • prevent consent choices from being remembered;
  • affect task or campaign functionality;
  • interfere with wallet connection;
  • prevent Rewards from being verified;
  • disable preferences; or
  • cause parts of the Platform to function incorrectly.

18.3 Clearing cookies

Clearing cookies may:

  • sign the User out;
  • reset preferences;
  • delete the consent record stored on the device;
  • require the cookie banner to be shown again;
  • break campaign or reward attribution; and
  • disconnect a remembered wallet session.

Clearing a cookie does not necessarily delete information already stored on QUASA’s servers.

A request to access or delete server-side Personal Data may be submitted under the Privacy Policy.

18.4 App controls

App Users may be able to manage:

  • analytics consent;
  • advertising identifiers;
  • push notifications;
  • location access;
  • camera access;
  • file access; and
  • other permissions

through the App or operating-system settings.

19. Third-party providers

19.1 Service providers acting for QUASA

QUASA may use Processors to provide:

  • consent management;
  • analytics;
  • hosting;
  • security;
  • fraud prevention;
  • App diagnostics;
  • email delivery;
  • push notifications;
  • customer support;
  • payment functions;
  • wallet connectivity; or
  • advertising measurement.

A Processor may use information only under QUASA’s documented instructions and the applicable contract.

19.2 Independent Controllers

A third-party provider may act as an independent Controller where it determines its own purposes and means of Processing.

Examples may include:

  • social-media platforms;
  • app stores;
  • external wallets;
  • external payment providers;
  • advertising networks;
  • video platforms; or
  • other independent services.

The provider’s own privacy notice applies to its independent Processing.

19.3 Provider policies

The current technology list should include access to the relevant provider’s privacy information where reasonably possible.

QUASA does not rely solely on a provider’s policy as a substitute for providing its own transparent information.

19.4 Advertisers and reward partners

Advertisers and reward partners may receive:

  • aggregated campaign statistics;
  • pseudonymous campaign identifiers;
  • general country information;
  • device category;
  • confirmation of a qualifying action;
  • invalid-traffic information; or
  • attribution information.

They do not ordinarily receive directly identifying account information merely because a User viewed or selected an advertisement.


20. International transfers

20.1 Processing outside the EEA

Some technology providers may process Personal Data outside the European Economic Area.

The processing location must be identified in the current technology list where reasonably possible.

QUASA will not state that all cookie information is processed in one country unless that statement has been technically and contractually verified.

20.2 Transfer mechanisms

Where Personal Data protected by the GDPR is transferred outside the EEA, QUASA will use an appropriate transfer mechanism, such as:

  • an adequacy decision;
  • the European Commission’s Standard Contractual Clauses;
  • Binding Corporate Rules;
  • another legally recognised safeguard; or
  • an applicable legal derogation in an exceptional case.

Where appropriate, supplementary contractual, organisational or technical measures will be applied.

20.3 Information about safeguards

Additional information concerning an applicable transfer mechanism may be requested through:

https://quasa.io/support

or:

[email protected]

Information may be redacted where necessary to protect security or commercially confidential information.


21. Retention

21.1 Technology lifetime

The expiration period of each cookie or similar technology must be stated in the current technology list.

The period should be limited to what is reasonably necessary for the stated purpose.

21.2 Consent records

Records needed to demonstrate a consent choice may normally be retained:

  • while the choice remains active;
  • for up to three years after withdrawal or expiry; or
  • longer where necessary to establish, exercise or defend a legal claim.

The consent record will be limited to information reasonably necessary to demonstrate compliance.

21.3 Analytics information

Non-essential analytics event data should normally be retained for no longer than 14 months, unless:

  • a shorter period is stated in the current technology list;
  • the information has been irreversibly anonymised or aggregated;
  • a legal claim requires longer retention; or
  • applicable law requires another period.

21.4 Advertising and attribution information

Advertising and attribution identifiers should be retained only for the period necessary to:

  • measure the relevant campaign;
  • validate the relevant action;
  • prevent duplicate attribution;
  • investigate invalid traffic;
  • prepare agreed reporting; or
  • comply with applicable law.

The exact lifetime must be identified in the current technology list.

21.5 Security information

Security and fraud-prevention information may be retained for the periods stated in the Privacy Policy.

Information may be retained longer where necessary to investigate a security incident, prevent repeated serious abuse or defend a legal claim.

21.6 Anonymised information

QUASA may retain irreversibly anonymised or aggregated statistics after the original identifier has been deleted because such information no longer identifies an individual.


22. Children

The account, commercial, Rewards, marketplace, wallet and blockchain features of the Platform are intended only for persons who are at least 18 years old, or the higher age of legal majority in their jurisdiction.

QUASA does not knowingly:

  • use advertising cookies to profile a person known with reasonable certainty to be a minor;
  • use Special Category Data for advertising;
  • request consent from an underage account holder for commercial tracking; or
  • permit a child to circumvent the Platform’s minimum-age requirements.

Public editorial content may be viewed without creating an account.

A parent or guardian who believes that QUASA has unlawfully used tracking technology in relation to a child may contact QUASA through the privacy contact stated in Section 2.


23. Privacy rights

Where information collected through cookies or similar technologies constitutes Personal Data, applicable privacy rights may include the right to:

  • request access;
  • request correction;
  • request deletion;
  • request restriction;
  • receive portable data where applicable;
  • object to Processing based on legitimate interests;
  • object to direct marketing;
  • withdraw consent;
  • challenge certain automated decisions; and
  • complain to a competent supervisory authority.

These rights and the available request process are explained in the QUASA Privacy Policy.

Privacy requests may be submitted through:

https://quasa.io/support

or:

[email protected]

Withdrawing cookie consent through Cookie Settings is generally the fastest way to stop future consent-based technologies.


24. Changes to this Cookies Policy

24.1 Updates

QUASA may update this Cookies Policy to reflect:

  • changes to technologies;
  • changes to providers;
  • changes to Platform features;
  • changes to purposes;
  • legal or regulatory developments;
  • changes to consent mechanisms;
  • security requirements; or
  • clarification of existing information.

24.2 Material changes

Where a change materially affects consent-based Processing, QUASA will:

  • update this Cookies Policy;
  • update the current technology list;
  • update the consent interface;
  • provide notice where required; and
  • request new consent where existing consent does not validly cover the change.

24.3 No retrospective expansion of consent

QUASA will not treat an existing consent as permission for a materially different purpose that was not clearly disclosed when consent was obtained.

24.4 Version information

The date at the beginning of this Cookies Policy identifies the current version.

Previous materially different versions should be archived where reasonably possible.


25. Language

This Cookies Policy is written in English.

Translations may be provided for accessibility and convenience.

QUASA should ensure that translated versions accurately describe:

  • the same technologies;
  • the same purposes;
  • the same providers;
  • the same legal bases;
  • the same retention periods; and
  • the same User choices.

For Business Users, the English version may prevail in the event of an inconsistency to the extent permitted by law.

This does not limit mandatory transparency, language or interpretation rights available to Consumers or data subjects.


26. Contact us

Questions concerning cookies and similar technologies may be submitted to:

Quasa International GmbH
An der Welle 4
60329 Frankfurt am Main
Germany

Commercial Register: Amtsgericht Frankfurt am Main
Registration number: HRB 115741

Support:

https://quasa.io/support

Privacy email:

[email protected]

Legal email:

[email protected]

Cookie settings:

In development

Privacy Policy:

PRIVACY POLICY

Terms of Use:

TERMS OF USE