Privacy Policy
PRIVACY POLICY
Last updated: 31 August 2026
Effective date: 31 August 2026
1. About this Privacy Policy
1.1 Purpose
This Privacy Policy explains how Quasa International GmbH collects, uses, stores, discloses and otherwise processes personal data in connection with the QUASA Platform.
It also explains:
- what personal data we collect;
- where the data comes from;
- why we process it;
- the legal bases on which we rely;
- who may receive the data;
- how long we retain it;
- how international transfers are protected;
- how automated systems and profiling may be used;
- what rights individuals have; and
- how privacy requests and complaints may be submitted.
1.2 Relationship with the Terms of Use
This Privacy Policy should be read together with:
- the QUASA Terms of Use;
- the QUASA Cookies Policy;
- any advertising order or media proposal;
- any task, escrow or payment conditions;
- any reward or quest rules;
- any token-related disclosure;
- any feature-specific privacy notice; and
- any other policy displayed when you use a particular Platform feature.
Capitalised terms that are not defined in this Privacy Policy have the meanings given to them in the Terms of Use.
1.3 This Policy is not a general consent
Your use of the Platform does not mean that you consent to every form of processing described in this Privacy Policy.
QUASA processes personal data only where it has an appropriate legal basis. Depending on the circumstances, that basis may be:
- performance of a contract;
- steps requested before entering into a contract;
- compliance with a legal obligation;
- QUASA’s or another person’s legitimate interests;
- your consent;
- protection of vital interests in an emergency; or
- another basis permitted by applicable law.
Where consent is required, QUASA will request it separately and, where appropriate, granularly.
1.4 Definitions
For this Privacy Policy:
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on Personal Data, including collection, storage, use, organisation, disclosure, transfer, restriction or deletion.
- “Controller” means the person or organisation that determines why and how Personal Data is processed.
- “Processor” means a service provider that processes Personal Data on behalf of a Controller.
- “Special Category Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data, or data concerning a person’s sex life or sexual orientation.
- “Platform” has the meaning given in Section 3 of this Privacy Policy.
Information that has been irreversibly anonymised so that no individual can reasonably be identified is not Personal Data.
2. Controller and contact details
2.1 Data Controller
Unless a feature-specific notice expressly identifies another Controller, the Controller responsible for the Processing described in this Privacy Policy is:
Quasa International GmbH
Registered seat: Frankfurt am Main, Germany
Business address: An der Welle 4
60329 Frankfurt am Main
Germany
Commercial Register: Amtsgericht Frankfurt am Main
Registration number: HRB 115741
In this Privacy Policy, Quasa International GmbH is referred to as “QUASA,” “we,” “us” or “our.”
2.2 Privacy contact
Questions, requests and complaints concerning Personal Data may be submitted through:
https://quasa.io/support
Privacy email:
Legal email:
2.3 Feature-specific Controllers
A third party may be an independent Controller where, for example:
- you visit an Advertiser’s or Project partner’s website;
- you use a third-party wallet, exchange, bridge or blockchain application;
- you make a payment through an independent payment provider;
- an identity-verification provider is legally required to process data for its own compliance purposes;
- you use an app store or social network;
- a Client or Pro uses information received through Quasa Connect for that person’s own contractual, tax or professional purposes; or
- you communicate directly with an external business.
The third party’s own privacy notice will apply to its independent Processing.
3. Scope of this Privacy Policy
3.1 QUASA services covered
This Privacy Policy applies to Processing in connection with:
- the website available at https://quasa.io and its language versions;
- QUASA mobile applications, including Quasa Connect;
- QUASA user accounts and account dashboards;
- QUASA Media and editorial content;
- QUASA Rewards;
- QUASA Projects and pay-per-click advertising tools;
- sponsored articles, banners, newsletters and other advertising services;
- the Quasa Connect marketplace;
- balances, rewards, payments and blockchain functionality connected with QUA;
- support, moderation, complaint and appeal systems; and
- related interfaces, analytics, communications and services provided by QUASA.
3.2 Website and App accounts
QUASA website accounts and Quasa Connect App accounts are currently maintained in separate technical systems. Creating or deleting one account does not automatically create or delete the other.
If separate systems are used:
- creating an account on the Site may not automatically create an App account;
- deleting one account may not automatically delete another account;
- the same email address may be associated with separate account records; and
- a User requesting complete deletion should identify all relevant accounts.
QUASA will explain account-linking or account-separation in the relevant interface.
3.3 Third-party services not covered
This Privacy Policy does not govern independent Processing by third-party websites, applications, payment services, blockchain protocols, wallets, exchanges, social networks, app stores or advertisers.
A link or technical integration does not make QUASA responsible for all Processing performed by that third party.
4. QUASA’s role in relation to Personal Data
4.1 QUASA as Controller
QUASA generally acts as Controller for Personal Data used to:
- operate the Site and Apps;
- create and manage accounts;
- provide QUASA Rewards;
- review and promote Projects;
- provide advertising services;
- operate the Quasa Connect marketplace;
- facilitate communications between Users;
- maintain internal balances and transaction records;
- connect accounts with blockchain wallets;
- moderate content;
- prevent fraud and protect security;
- provide support;
- send QUASA communications;
- comply with legal obligations; and
- manage QUASA Media and editorial operations.
4.2 Users as independent Controllers
Clients, Pros and Advertisers may become independent Controllers for Personal Data they receive and use for their own purposes.
For example, a Pro may independently process Client information to:
- perform an agreed service;
- issue an invoice;
- comply with tax requirements;
- maintain professional records; or
- defend a legal claim.
A Client may independently process Pro information to administer and document the service contract.
Users must not use Personal Data received through the Platform for unrelated advertising, data brokerage, harassment, discrimination or other unlawful purposes.
4.3 Processing on behalf of a Business User
In limited circumstances, a separate written agreement may specify that QUASA processes particular Personal Data solely on behalf of a Business User.
Where a valid data-processing agreement applies, that agreement will determine the parties’ respective responsibilities for that Processing.
4.4 Public blockchains
A public blockchain is not controlled exclusively by QUASA. Blockchain information may be:
- transmitted to independent nodes;
- replicated across multiple countries;
- indexed by blockchain explorers;
- processed by wallet and analytics providers;
- visible to any person; and
- technically impossible for QUASA to delete or alter.
Section 10 contains additional information about blockchain Processing.
5. Personal Data we collect
The Personal Data collected depends on how you use the Platform. QUASA does not necessarily collect every category listed below from every User.
5.1 Account and contact information
When you create or use an account, we may collect:
- your name;
- email address;
- telephone number, if provided;
- username or account identifier;
- password or other authentication credentials;
- email-verification status;
- age or confirmation that you satisfy the minimum-age requirement;
- country or region;
- preferred language;
- time zone;
- account type;
- communication preferences;
- interests selected for content or Rewards;
- profile image or avatar;
- account status; and
- records of acceptance of the Terms and relevant policies.
Passwords should be stored only in an appropriately protected form. QUASA does not disclose account passwords to other Users.
5.2 Business and professional information
If you use the Platform as a Pro, Client, Advertiser, contributor or other Business User, we may collect:
- business or trading name;
- legal entity name;
- position or role;
- business address;
- professional contact details;
- commercial-register details;
- VAT or tax-identification information;
- trader or non-trader status;
- beneficial-ownership information where required;
- professional experience;
- skills and service categories;
- qualifications and certifications;
- portfolio information;
- work samples;
- rates and proposed prices;
- availability;
- languages;
- licences, permits and insurance information;
- professional memberships;
- information required for an invoice; and
- declarations concerning legal and regulatory compliance.
5.3 Quasa Connect profiles, tasks and offers
When you use Quasa Connect, we may collect:
- public or private profile information;
- service categories;
- task descriptions;
- requested deliverables;
- proposed budgets;
- agreed prices;
- expected and actual performance dates;
- remote-work or physical-location requirements;
- city, region or task address;
- offers and counter-offers;
- instructions;
- files and documents;
- photographs, audio or video submitted by Users;
- information about accepted, completed, cancelled or disputed tasks;
- ratings and reviews;
- response and completion history;
- information concerning complaints and disputes; and
- evidence submitted in relation to performance or non-performance.
5.4 Messages and communications
We may process communications sent through or in relation to the Platform, including:
- messages between Clients and Pros;
- messages relating to Projects or advertising;
- support enquiries;
- moderation notices;
- appeal submissions;
- security reports;
- emails sent to QUASA;
- records of notifications sent by QUASA;
- delivery and bounce status;
- attachments;
- timestamps; and
- associated account information.
QUASA does not treat private messages as public content merely because they are transmitted through the Platform.
5.5 QUASA Rewards information
When you participate in QUASA Rewards, we may collect:
- interests and category preferences;
- offers and quests displayed to you;
- offers viewed or opened;
- Project pages visited;
- referral and campaign identifiers;
- qualifying actions selected or completed;
- date and time of an action;
- device, browser and network signals;
- country or approximate location;
- partner confirmation or rejection of an action;
- previous completion of the same offer;
- reward amount;
- reward status;
- internal reward balance;
- withdrawal history;
- promotional credits;
- referral relationships;
- anti-fraud and duplicate-account signals; and
- evidence submitted in relation to a disputed reward.
5.6 Project and advertising information
When you submit or promote a Project or order advertising, we may collect:
- your name;
- email address;
- Telegram or other business contact identifier;
- company and role;
- Project website address;
- Project name and description;
- category;
- logos, screenshots and other visual materials;
- names and identities of the advertiser, beneficiary and person paying for the advertisement;
- statements and claims supplied for publication;
- advertising creatives;
- campaign budget;
- bid amount;
- targeting or distribution preferences;
- campaign status;
- clicks, impressions and interactions;
- invalid-traffic and fraud indicators;
- conversion or completion reports;
- publication and distribution records;
- correspondence;
- contracts, proposals and insertion orders; and
- billing and invoice information.
Personal Data submitted through an external form provider, such as an online form service, may also be processed by that provider.
5.7 Payment, billing and transaction information
Where paid features are available, we may collect:
- payer and payee information;
- billing address;
- invoice details;
- transaction amount;
- currency or crypto-asset;
- date and time;
- payment status;
- payment-provider reference;
- order or task identifier;
- Platform fees;
- blockchain-network fees;
- refunds;
- reversals;
- disputed payments;
- chargeback information; and
- records required for accounting, tax or compliance purposes.
Where payment-card information is entered directly into a payment provider’s interface, QUASA will normally receive payment status and limited transaction information rather than the complete card number or security code.
The payment provider may process card and payment information as an independent Controller or as QUASA’s Processor, depending on the service arrangement.
5.8 Wallet and blockchain information
When you connect a wallet or use QUA-related functionality, we may collect or otherwise process:
- public wallet address;
- blockchain network;
- token contract;
- wallet-connection status;
- a cryptographic signature used to demonstrate control of a wallet;
- transaction hash;
- transaction amount;
- token balance associated with Platform activity;
- smart-contract interaction;
- transaction timestamp;
- transaction status;
- gas or network fee;
- deposit or withdrawal record;
- internal account-to-wallet association;
- risk or sanctions indicators associated with a wallet; and
- publicly available blockchain history.
QUASA does not require and will not legitimately request your private key or wallet recovery phrase.
5.9 Identity, eligibility and compliance information
Where reasonably necessary under the Terms of Use or applicable law, QUASA or an authorised provider may collect:
- full legal name;
- date and place of birth;
- nationality;
- residential address;
- government-issued identification document;
- document type, number, issuer and expiry date;
- a photograph or video used for verification;
- proof of address;
- proof of business registration;
- information about directors or beneficial owners;
- tax-identification information;
- source-of-funds or source-of-assets information;
- wallet ownership evidence;
- sanctions and politically exposed person screening results;
- fraud or security risk indicators;
- eligibility to perform a regulated service; and
- information requested by a competent authority.
QUASA will not use biometric data for the purpose of uniquely identifying a person unless:
- the Processing is genuinely required;
- a valid legal basis and a condition under Article 9 GDPR or equivalent law applies;
- a separate notice is provided before Processing begins; and
- appropriate safeguards are implemented.
QUASA does not generally seek information about criminal convictions or offences. Such information will be processed only where authorised by applicable law and subject to appropriate safeguards.
5.10 Support, moderation and legal-notice information
When you contact QUASA, report content, appeal a decision or submit a legal notice, we may collect:
- name;
- email address;
- organisation and role;
- subject of the request;
- account or Project identifier;
- URL or location of reported content;
- explanation of the complaint;
- legal basis asserted;
- supporting evidence;
- attachments;
- good-faith declarations;
- records of correspondence;
- identity or authority of a representative;
- actions taken by QUASA;
- decision and reasons;
- appeal outcome; and
- information necessary to prevent repeated abuse of reporting systems.
5.11 Newsletter, marketing and survey data
Where you subscribe, consent or otherwise lawfully receive communications, we may collect:
- email address;
- name;
- company or role;
- preferred language;
- interests;
- subscription source;
- date and time of subscription;
- consent record;
- double-opt-in confirmation where used;
- unsubscribe status;
- email delivery status;
- email opening and link-interaction information where permitted; and
- survey or feedback responses.
5.12 Editorial, contributor and source information
In connection with QUASA Media, we may collect or process:
- author or contributor name;
- biography;
- photograph;
- professional role;
- employer or organisation;
- contact details;
- contract and payment information;
- interview statements;
- press materials;
- publicly available professional information;
- public social-media statements;
- information contained in public registers;
- source communications; and
- Personal Data necessary for editorial research, reporting, correction or legal review.
5.13 Technical and usage data
When you access the Platform, we or our service providers may automatically collect:
- IP address;
- request date and time;
- pages or screens viewed;
- links selected;
- referring and destination addresses;
- browser type and version;
- operating system;
- device type and model;
- app version;
- preferred language;
- screen or interface settings;
- country or approximate location derived from IP address;
- session and account identifiers;
- cookie and similar identifiers;
- mobile advertising identifier, where lawfully available;
- push-notification token;
- crash reports;
- performance and diagnostic information;
- login events;
- security events;
- feature usage;
- time spent on the Platform;
- search and filter selections;
- interaction with content, advertisements and Projects; and suspected automated or fraudulent activity.
5.14 Precise location
The Quasa Connect App may request access to precise or approximate device location where location is needed for:
- nearby-task discovery;
- matching Clients and Pros;
- identifying the general area in which a service is requested;
- navigation or local-service functionality;
- preventing location-based fraud; or
- another feature expressly requested by the User.
Precise location will be accessed only after the relevant device permission has been granted and where an appropriate legal basis exists.
Unless separately and clearly disclosed:
- QUASA will not continuously collect precise background location;
- precise location will not be used for targeted advertising;
- precise location will not be made public automatically; and
- another User will receive only the level of location detail reasonably necessary for the relevant task.
You may revoke location permission through your device settings. Some local-service features may then be unavailable or less accurate.
5.15 Camera, photographs, video and files
The App may request access to a camera, photographs, video or device files when you choose to:
- add a profile image;
- upload a portfolio;
- illustrate a task;
- provide evidence of task completion;
- submit Project materials;
- send an attachment; or
- complete an identity-verification process.
Permission should be requested only when the relevant feature is used. You may manage permission through your device settings.
5.16 Push-notification data
To deliver push notifications, we may process:
- a push-notification token;
- device platform;
- app version;
- account identifier;
- notification preferences;
- delivery status; and
- interaction with the notification.
Operational notifications may concern tasks, messages, security, payments, rewards and account status.
Marketing push notifications will be sent only where permitted by law and may be disabled in the App or device settings.
6. Sources of Personal Data
We may obtain Personal Data from the following sources.
6.1 Directly from you
This includes information you:
- enter into a form;
- provide when creating an account;
- add to a profile;
- include in a task, offer or message;
- submit with a Project;
- provide for advertising;
- upload as a file;
- give to support;
- provide during verification;
- submit in a privacy or legal request; or
- provide when connecting a wallet.
6.2 From other Users
Other Users may provide information about you through:
- task descriptions;
- offers;
- messages;
- ratings and reviews;
- dispute submissions;
- reports;
- referrals;
- evidence of service performance; or
- information required to complete a transaction.
6.3 From Advertisers and reward partners
Advertisers, Projects and reward partners may provide:
- confirmation that an action was completed;
- conversion status;
- campaign identifier;
- referral status;
- reason for rejecting a claimed action;
- fraud or duplication information;
- information about a Project or advertisement; and
- campaign-performance information.
Where possible, this information should be connected through a pseudonymous campaign or account identifier rather than directly identifying information.
6.4 From service providers
We may receive information from:
- hosting and infrastructure providers;
- analytics providers;
- security and fraud-prevention providers;
- payment providers;
- identity-verification providers;
- sanctions-screening providers;
- email and notification providers;
- support systems;
- app stores;
- content-delivery networks;
- external form providers; and
- professional advisers.
6.5 From public sources
We may collect Personal Data from:
- public websites;
- public social-media profiles;
- press releases;
- company websites;
- professional directories;
- commercial and public registers;
- regulatory databases;
- sanctions lists;
- public blockchain records;
- public court or authority information where lawful; and
- other publicly accessible sources.
Public availability does not remove the requirement for QUASA to have an appropriate purpose and legal basis.
6.6 From blockchains
QUASA may read or receive public blockchain information directly or through:
- wallet software;
- blockchain nodes;
- blockchain explorers;
- smart contracts;
- blockchain analytics providers; and
- transaction-monitoring services.
6.7 Article 14 notices
Where QUASA obtains Personal Data about you from another source, we will provide any notice required by applicable law within the legally required period, unless an exception applies.
An exception may apply, for example, where:
- you already have the relevant information;
- providing the notice is impossible or would involve disproportionate effort in a legally recognised context;
- collection or disclosure is expressly required by law; or
- legal professional secrecy or a valid journalistic exemption applies.
7. How and why we use Personal Data
The applicable legal basis depends on the feature, the type of data and the relationship between you and QUASA.
Where more than one basis is listed below, QUASA will apply the basis appropriate to the particular Processing.
7.1 Providing the Site and public content
We process technical and usage data to:
- deliver webpages and media;
- select an appropriate language version;
- maintain sessions;
- respond to requests;
- protect the Site;
- diagnose errors; and
- measure basic service availability.
Legal bases:
- legitimate interests in operating, securing and improving the Site;
- performance of a contract where the request relates to an account or paid service;
- compliance with legal obligations.
7.2 Creating and managing accounts
We process account, contact and authentication information to:
- register an account;
- verify an email address;
- authenticate access;
- maintain account settings;
- provide a dashboard;
- administer balances and activity;
- send operational notices;
- prevent duplicate or unauthorised accounts; and
- close or restore an account where appropriate.
Legal bases:
- performance of a contract;
- steps requested before entering into a contract;
- legitimate interests in maintaining secure and accurate account records;
- compliance with legal obligations.
7.3 Providing Quasa Connect
We process profile, task, offer, message, location and transaction information to:
- publish or distribute a task;
- identify potentially relevant Pros;
- display profiles, prices, ratings and reviews;
- enable Users to communicate;
- record accepted offers;
- support task performance;
- facilitate payment or escrow features;
- provide notifications;
- support dispute resolution;
- protect Users; and
- maintain transaction evidence.
Legal bases:
- performance of QUASA’s contract with the User;
- steps requested before entering into that contract;
- legitimate interests in operating and protecting the marketplace;
- compliance with consumer, tax, platform and other legal obligations;
- consent for optional location or device access where required.
The service contract between a Client and a Pro is separate from QUASA’s contract with each User.
7.4 Operating QUASA Rewards
We process account activity, Project interactions, completion data and fraud signals to:
- display relevant reward opportunities;
- verify eligibility;
- determine whether conditions were completed;
- calculate and credit rewards;
- prevent repeat completion;
- detect bots and manipulated traffic;
- review disputed rewards;
- administer promotional credits;
- facilitate withdrawals; and
- report campaign performance.
- Legal bases:
- performance of a contract;
- legitimate interests in operating a genuine reward system and preventing fraud;
- compliance with legal, tax, sanctions and accounting obligations;
- consent for non-essential cookies or cross-site attribution technologies where required.
7.5 Reviewing and promoting Projects
We process Project and Advertiser information to:
- receive and review submissions;
- verify the identity and authority of the submitter;
- assess legal, security and editorial suitability;
- create and publish Project pages;
- provide editing access;
- administer review fees and promotional credits;
- operate PPC campaigns;
- rank Projects;
- measure traffic;
- provide campaign analytics;
- send publication notices; and
- handle refunds.
Legal bases:
- steps requested before entering into a contract;
- performance of a contract;
- legitimate interests in maintaining the integrity, security and commercial operation of the Project directory;
- compliance with advertising, consumer, tax, platform and other legal obligations.
7.6 Providing media advertising and sponsored content
We process business contacts, advertising materials and campaign information to:
- prepare proposals;
- conclude advertising orders;
- produce or edit content;
- publish and label advertisements;
- distribute sponsored content;
- administer newsletters and social distribution;
- provide reports;
- invoice the Advertiser; and
- maintain evidence of the advertising relationship.
Legal bases:
- steps requested before entering into a contract;
- performance of a contract;
- legitimate interests in managing business relationships;
- compliance with advertising, tax and accounting obligations;
- consent where a person receives optional marketing or is identifiable in promotional material and consent is required.
7.7 Processing payments and transactions
We process payment and transaction data to:
- accept or confirm payment;
- maintain transaction records;
- calculate fees;
- issue invoices;
- process refunds;
- investigate failed payments;
- respond to chargebacks;
- reconcile balances;
- administer escrow where available; and
- prevent payment fraud.
Legal bases:
- performance of a contract;
- compliance with tax, accounting, payment and financial obligations;
- legitimate interests in fraud prevention and financial reconciliation.
7.8 Providing QUA and blockchain features
We process wallet and blockchain information to:
- connect a wallet;
- verify control of a wallet;
- display transaction information;
- facilitate a deposit or withdrawal;
- interact with a smart contract;
- associate an on-chain transaction with an account;
- calculate network or Platform fees;
- prevent duplicate payments;
- monitor transaction status; and
- investigate fraud, theft or sanctions exposure.
Legal bases:
- performance of a contract;
- steps requested by the User;
- compliance with legal and regulatory obligations where applicable;
- legitimate interests in security, fraud prevention and transaction integrity.
7.9 Identity, eligibility and compliance checks
We may process verification and compliance information to:
- verify age or identity;
- verify authority to represent a business;
- determine trader or professional status;
- confirm licences or registrations;
- establish wallet or payment ownership;
- carry out sanctions or fraud screening;
- comply with anti-money-laundering obligations where applicable;
- respond to an authority; and
- protect Users and QUASA from unlawful activity.
Legal bases:
- compliance with a legal obligation;
- performance of a contract where verification is objectively necessary;
- legitimate interests in preventing fraud, abuse and unlawful transactions;
- establishment, exercise or defence of legal claims;
- explicit consent or another valid Article 9 condition where Special Category Data is processed.
Consent will not be used as the basis for a mandatory legal verification where refusal would necessarily prevent QUASA from complying with the law.
7.10 Providing support
We process contact, account, task, campaign and correspondence information to:
- answer questions;
- resolve technical problems;
- investigate account access;
- assist with payments or rewards;
- correct information;
- process account deletion;
- document a complaint; and
- improve support quality.
- Legal bases:
- performance of a contract;
- steps requested by the individual;
- legitimate interests in providing effective support;
- compliance with legal obligations.
7.11 Content moderation and enforcement
We process User Content, reports, account activity and security information to:
- identify illegal or prohibited content;
- review reports;
- detect spam, malware and manipulation;
- investigate possible Terms violations;
- restrict content or accounts;
- explain moderation decisions;
- administer appeals;
- prevent repeated misuse; and
- comply with the Digital Services Act and other applicable laws.
Legal bases:
- compliance with legal obligations;
- performance and enforcement of the Terms of Use;
- legitimate interests in maintaining a safe, lawful and trustworthy Platform;
- establishment, exercise or defence of legal claims.
7.12 Security and fraud prevention
We process account, technical, device, network, transaction and behavioural data to:
- detect unauthorised account access;
- prevent account farming and duplicate accounts;
- detect bot activity;
- identify manipulated clicks and reward claims;
- protect payment and wallet functionality;
- identify malware and phishing;
- enforce rate limits;
- investigate cybersecurity events; and
- maintain audit and security logs.
Legal bases:
- legitimate interests in protecting Users, QUASA and third parties;
- compliance with security and legal obligations;
- performance of a contract where security is necessary to provide the service.
Where access to information on a User’s device is not strictly necessary, QUASA will obtain consent when required by applicable cookie or device-privacy law.
7.13 Personalisation, matching and recommendations
We may process preferences, interests, location, usage history, skills, prices, ratings and engagement information to:
- recommend editorial content;
- order reward opportunities;
- recommend tasks or Pros;
- improve search results;
- select a language or region;
- personalise the dashboard; and
- reduce irrelevant content.
Legal bases:
- performance of a contract where personalisation is part of the requested service;
- legitimate interests in providing relevant and usable results;
- consent where personalisation depends on non-essential tracking technology or where otherwise required.
Section 9 explains automated processing in more detail.
7.14 Analytics, research and service improvement
We may process usage, performance, campaign and feedback information to:
- understand use of the Platform;
- measure feature performance;
- investigate errors;
- improve interface design;
- assess aggregate audience characteristics;
- develop matching and fraud-prevention tools;
- prepare internal and commercial reports;
- conduct surveys; and
- create aggregated or anonymised statistics.
Legal bases:
- legitimate interests in improving and managing the Platform;
- consent for non-essential analytics technologies;
- performance of a contract where analytics is necessary to provide a requested campaign report.
Where reasonably possible, analysis will use aggregated or pseudonymised data.
7.15 Service communications
We process contact and account information to send:
- security warnings;
- email-verification messages;
- password-reset messages;
- task and message notifications;
- Project publication notices;
- reward and withdrawal notices;
- payment and transaction notices;
- moderation decisions;
- changes to legal terms;
- information required by law; and
- other operational communications.
Legal bases:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests in administering the Platform.
Operational communications are not marketing and may be necessary while an account remains active.
7.16 Marketing
Subject to applicable law, we may process contact details, language, business role, interests and interaction information to:
- send newsletters;
- announce Platform features;
- promote QUASA products and services;
- invite participation in surveys or promotions;
- contact business leads;
- measure communication effectiveness; and
- suppress communications after an opt-out.
Legal bases:
- consent where required;
- legitimate interests in business-to-business marketing or marketing similar services to existing customers where applicable law permits;
- compliance with the individual’s objection or withdrawal request.
You may object to direct marketing at any time.
7.17 Editorial and journalistic purposes
QUASA may process Personal Data to:
- research and prepare editorial content;
- verify facts;
- contact sources;
- publish news and analysis;
- identify authors and contributors;
- respond to correction requests;
- defend editorial independence;
- protect confidential sources; and
- exercise freedom of expression and information.
Legal bases:
- legitimate interests in publishing editorial and journalistic content;
- freedom of expression and information;
- performance of a contributor agreement;
- consent where appropriate;
- compliance with applicable media law;
- establishment, exercise or defence of legal claims.
To the extent permitted by applicable law, certain data-protection rights or disclosure duties may be restricted where necessary to protect journalism, editorial freedom or confidential sources.
7.18 Legal claims and regulatory compliance
We may process relevant Personal Data to:
- comply with a legal obligation;
- respond to lawful orders;
- establish or defend legal claims;
- enforce contracts;
- obtain legal advice;
- maintain evidence;
- cooperate with regulators;
- investigate unlawful conduct; and
- protect the rights and safety of QUASA, Users and third parties.
Legal bases:
- compliance with legal obligations;
- legitimate interests in protecting legal rights;
- establishment, exercise or defence of legal claims;
- protection of vital interests in an emergency.
7.19 Corporate transactions
We may process and disclose limited Personal Data in connection with:
- financing;
- due diligence;
- restructuring;
- merger;
- acquisition;
- asset sale;
- insolvency;
- transfer to an affiliated operator; or
- another corporate transaction.
Legal bases:
- legitimate interests in managing and reorganising the business;
- compliance with legal obligations;
- performance of contracts affected by the transaction.
Confidentiality and data-minimisation measures will be used where appropriate.
8. Platform-specific disclosures
8.1 QUASA Media
When you read public editorial content, QUASA may process technical and consented analytics information.
When you comment, subscribe, contact an author or participate as a contributor, QUASA may additionally process your contact details, User Content and interaction history.
Information published in editorial content may be:
- publicly accessible;
- translated;
- indexed by search engines;
- distributed through newsletters;
- displayed in other QUASA language editions;
- shared through QUASA social-media channels; and
- retained in editorial archives.
8.2 QUASA Rewards and partner attribution
To confirm a reward, QUASA may use:
- a campaign identifier;
- a pseudonymous account or activity identifier;
- the date and time of the interaction;
- the relevant offer;
- technical anti-fraud signals;
- a referral parameter; and
- a confirmation returned by the partner.
Where permitted, an Advertiser or partner may receive pseudonymous information needed to determine whether a qualifying action occurred.
Advertisers will normally receive aggregated or campaign-level reporting rather than directly identifying information.
Directly identifying information will be disclosed to an Advertiser only where:
- it is necessary for a transaction expressly requested by the User;
- the User separately submits the information to the Advertiser;
- the User has given valid consent;
- a lawful data-sharing arrangement applies; or
- disclosure is required by law.
Once you visit a partner’s external site, that partner may independently collect information under its own privacy policy.
8.3 QUASA Projects and PPC
Project information intended for publication may be:
- displayed publicly;
- translated;
- indexed by search engines;
- used in the QUASA directory;
- distributed through newsletters or social channels;
- included in campaign analytics; and
- retained as part of the publication and commercial record.
The identity of the person or entity on whose behalf an advertisement is displayed, and the person paying for it where different, may be disclosed where required by law.
Campaign analytics may include:
- impressions;
- clicks;
- interactions;
- general location;
- device category;
- referral information;
- invalid-traffic filtering; and
- aggregated conversion data.
8.4 Quasa Connect
A Client and Pro may receive information about each other when reasonably necessary to:
- assess a task or offer;
- communicate;
- enter into a service contract;
- perform a service;
- make or receive payment;
- provide a review;
- manage a dispute; or
- comply with legal obligations.
Depending on the stage of the transaction, shared information may include:
- name or profile name;
- profile photograph;
- skills and qualifications;
- rates;
- ratings and reviews;
- task information;
- messages;
- approximate location;
- exact service address where necessary;
- agreed price and timing; and
- transaction status.
Users should not include more Personal Data in a public task description than is necessary.
Exact addresses, access details, identity documents, private contact information and sensitive task information should be disclosed only through an appropriate private channel and only when necessary.
8.5 Ratings and reviews
Ratings and reviews may be displayed publicly with:
- the reviewer’s profile name;
- the reviewed User’s profile;
- rating value;
- review text;
- date; and
- indication that the interaction was verified, where applicable.
QUASA may retain evidence of the underlying interaction to assess whether a review is genuine.
8.6 Moderation notices and appeals
When a person reports illegal or prohibited content, QUASA may process the reporter’s identity, contact information and evidence.
QUASA may provide the affected User with information needed to understand and appeal a decision. QUASA will not disclose a reporter’s identity where disclosure is prohibited, unnecessary or would create an unreasonable risk.
8.7 Business User access to data
A Business User may have access through the relevant dashboard to information such as:
- the Business User’s own profile;
- submitted Project information;
- campaign settings;
- campaign analytics;
- task information;
- transaction records;
- ratings;
- messages; and
- account balances.
A Business User does not receive a general right to access Personal Data relating to other Users.
9. Automated processing, profiling and AI-assisted systems
9.1 General
QUASA may use automated, algorithmic or AI-assisted systems to:
- rank editorial content;
- recommend reward offers;
- rank Projects;
- match Clients, Pros and tasks;
- detect spam or malware;
- identify duplicate accounts;
- identify manipulated traffic;
- assess possible reward fraud;
- screen blockchain addresses;
- identify unusual payment activity;
- prioritise content for human moderation; and
- protect Platform security.
9.2 Editorial recommendations
Editorial recommendations may consider:
- language;
- category;
- publication date;
- search terms;
- popularity;
- previous interactions;
- selected interests;
- approximate location; and
- editorial relevance.
The result may affect the order in which content is displayed.
9.3 Project ranking
Project ranking may consider:
- Advertiser bid;
- campaign balance;
- category and search relevance;
- language;
- location;
- content quality;
- landing-page availability;
- recency;
- engagement;
- invalid-traffic signals;
- fraud signals; and
- policy compliance.
Payment may materially improve a Project’s position, while safety, legal and fraud controls may override a bid.
9.4 Reward recommendations and validation
Reward systems may consider:
- eligibility;
- country;
- language;
- interests;
- device compatibility;
- previous completion;
- available campaign budget;
- reward amount;
- offer availability;
- network and device signals; and
- fraud indicators.
These factors may affect which reward opportunities are shown and whether an action is sent for additional review.
9.5 Quasa Connect matching
Matching may consider:
- service category;
- remote or local availability;
- location and distance;
- price;
- ratings and reviews;
- experience;
- qualifications;
- language;
- availability;
- response rate;
- previous completion;
- profile completeness;
- task relevance;
- Client preferences; and
- safety or fraud signals.
The system may affect the order in which tasks, Clients or Pros are recommended.
9.6 Fraud and security scoring
QUASA may derive security or activity indicators from information such as:
- login patterns;
- IP and network information;
- device identifiers;
- account relationships;
- repeated activity;
- task or reward history;
- payment status;
- wallet risk information;
- invalid-click patterns; and
- suspected automation.
A security score or flag may result in:
- additional verification;
- delayed reward validation;
- temporary transaction review;
- reduced visibility;
- rate limiting;
- referral to a human reviewer; or
- another proportionate protective measure.
9.7 Significant solely automated decisions
QUASA does not intend to make decisions based solely on automated Processing that produce legal effects or similarly significantly affect an individual unless:
- the decision is necessary for entering into or performing a contract;
- the decision is authorised by applicable law; or
- the individual has given explicit consent,
and all additional legal requirements have been satisfied.
QUASA does not currently make decisions based solely on automated processing that produce legal or similarly significant effects.
Where Article 22 GDPR or an equivalent rule applies, QUASA will provide:
- meaningful information about the logic involved;
- information about the significance and expected consequences;
- an opportunity to obtain human intervention;
- an opportunity to express your point of view; and
- an opportunity to challenge the decision.
Automated fraud signals may support a decision, but eligible moderation and account appeals will receive human review where required by law.
9.8 Sensitive information and advertising
QUASA will not use the following information to create targeted-advertising profiles:
- identity documents;
- private messages;
- precise location;
- payment-card credentials;
- private keys or recovery phrases;
- Special Category Data; or
- data known with reasonable certainty to relate to a minor.
QUASA will not present advertisements based on profiling that uses Special Category Data where such practice is prohibited.
9.9 New AI uses
If QUASA proposes to use non-public User Content for a materially new AI-training or model-development purpose, QUASA will first:
- assess whether the purpose is compatible with the original collection;
- identify a lawful basis;
- provide any additional notice required by law;
- implement data-minimisation and security measures; and
- obtain consent where consent is required.
10. Cookies and similar technologies
10.1 Technologies used
The Site and Platform may use:
- cookies;
- local storage;
- software development kits;
- pixels or web beacons;
- session identifiers;
- mobile identifiers;
- analytics tags;
- referral parameters;
- conversion tags; and
- similar technologies.
10.2 Categories
These technologies may be used for:
- Strictly necessary purposes, such as authentication, security, session management, fraud prevention and remembering a privacy choice.
- Functional purposes, such as remembering language, preferences and interface settings.
- Analytics purposes, such as measuring visits, content performance and errors.
- Advertising and attribution purposes, such as measuring campaigns, recording referrals and, where permitted, displaying relevant advertising.
10.3 Legal basis for device access
Technologies that store information on or access information from a User’s device will be used:
- without consent only where strictly necessary to transmit a communication or provide a digital service expressly requested by the User; or
- with consent where consent is required by applicable law.
Personal Data obtained through those technologies will be processed under an appropriate GDPR legal basis.
10.4 Cookie choices
Where required, QUASA will provide a consent-management interface allowing Users to:
- accept or reject non-essential technologies;
- make granular choices;
- withdraw consent;
- review vendor information; and
- change preferences later.
Cookie settings:
[In development]
Withdrawing consent does not affect the lawfulness of Processing that occurred before withdrawal.
10.5 Analytics
Subject to the User’s consent where required, QUASA may use analytics providers, including Google Analytics or a successor service, to understand use of the Site.
Analytics information may include:
- IP-derived country;
- device and browser type;
- viewed pages;
- referring page;
- session duration;
- interaction events;
- errors; and
- campaign attribution.
The current Cookies Policy must identify the actual analytics provider, cookie names, purposes, retention periods and transfer safeguards.
10.6 Advertising and remarketing
Subject to consent and applicable law, online identifiers and browsing events may be disclosed to advertising or measurement providers to:
- measure an advertisement;
- limit repetition;
- attribute a visit;
- create aggregate campaign reports; or
- display QUASA advertising on another service.
QUASA does not disclose identity documents, private messages or precise location for remarketing.
10.7 Email measurement
Where permitted by law, QUASA emails may contain measurement technologies that indicate whether a message was delivered, opened or selected.
You may object to marketing measurement by:
- unsubscribing from the relevant marketing communication;
- changing available communication settings; or
- contacting QUASA.
10.8 Cookie Policy
The Cookies Policy must provide an accurate and current list or description of:
- first-party and third-party technologies;
- provider;
- purpose;
- category;
- duration;
- legal basis;
- international transfers; and
- withdrawal or opt-out method.
11. How we disclose Personal Data
QUASA does not disclose every category of Personal Data to every recipient.
11.1 Other Users
Personal Data may be disclosed to other Users where necessary to:
- display a profile;
- present a task or offer;
- facilitate communication;
- perform a service;
- complete payment;
- provide a rating or review;
- manage a complaint; or
- comply with the law.
11.2 The public
Information may be publicly disclosed where you submit it for public publication, including:
- public profiles;
- Project pages;
- advertisements;
- sponsored materials;
- articles;
- author profiles;
- comments;
- ratings and reviews; and
- public portfolio information.
Public content may be copied, indexed, translated, cached or redistributed by search engines and third parties.
11.3 Advertisers and Project partners
Advertisers and partners may receive:
- aggregated campaign statistics;
- pseudonymous campaign identifiers;
- general device or country information;
- confirmation that a qualifying action occurred;
- invalid-traffic information;
- conversion or attribution information; and
- information voluntarily submitted by a User directly to that partner.
Advertisers do not ordinarily receive a QUASA User’s directly identifying information merely because the User viewed or selected an advertisement.
11.4 Service providers
We may use service providers for:
- website and application hosting;
- cloud storage;
- content delivery;
- database management;
- authentication;
- security monitoring;
- fraud prevention;
- analytics;
- consent management;
- email delivery;
- push notifications;
- customer support;
- online forms;
- payment processing;
- invoicing;
- identity verification;
- sanctions screening;
- blockchain infrastructure;
- wallet connectivity;
- smart-contract interfaces;
- document management;
- translation; and
- professional consulting.
Processors may use Personal Data only under QUASA’s instructions and appropriate contractual safeguards.
Some providers may act as independent Controllers for particular Processing required by law or inherent in their service.
Current provider information should be maintained at:
[In development]
11.5 Payment and financial-service providers
Payment, banking or billing information may be disclosed to:
- payment processors;
- banks;
- card networks;
- invoicing providers;
- fraud-prevention providers;
- auditors; and
- tax or financial authorities.
The disclosure is limited to information reasonably necessary for the relevant transaction, verification or legal obligation.
11.6 Identity and compliance providers
Where verification is required, information may be disclosed to:
- identity-verification providers;
- sanctions and politically exposed person screening providers;
- fraud-prevention services;
- blockchain analytics providers;
- professional-register providers; and
- competent authorities.
Before biometric identification is used, QUASA will provide an additional notice where required.
11.7 Blockchain participants
When a blockchain transaction is initiated, information may be disclosed to or accessible by:
- wallet providers;
- nodes;
- validators;
- smart contracts;
- blockchain explorers;
- analytics providers;
- exchanges; and
- any member of the public.
QUASA cannot restrict downstream use of data lawfully published to a public blockchain.
11.8 App stores and device-platform providers
App stores and device-platform providers may receive:
- app installation information;
- device or account identifiers;
- crash information;
- subscription or purchase status;
- push-notification information; and
- data necessary for app distribution and security.
Their independent Processing is governed by their own privacy policies.
11.9 Professional advisers
We may disclose Personal Data to:
- lawyers;
- tax advisers;
- accountants;
- auditors;
- insurers;
- consultants; and
- cybersecurity specialists
where reasonably necessary and subject to confidentiality or professional duties.
11.10 Public authorities and legal proceedings
We may disclose Personal Data where reasonably necessary to:
- comply with applicable law;
- respond to a binding court or authority order;
- cooperate with a lawful regulatory investigation;
- report suspected criminal activity;
- protect vital interests;
- establish or defend legal claims; or
- protect the rights and safety of Users, QUASA or third parties.
Where legally permitted, QUASA will assess whether a request is valid, sufficiently specific and proportionate.
11.11 Corporate transactions
Personal Data may be disclosed to prospective or actual investors, purchasers, successors or advisers in connection with a corporate transaction.
Appropriate confidentiality and data-protection measures will be applied.
11.12 With your direction or consent
We may disclose Personal Data where you:
- direct us to do so;
- request an integration;
- expressly consent;
- choose to publish the information; or
- initiate a transaction requiring disclosure.
11.13 Sale and independent marketing use
QUASA does not sell or rent Personal Data for monetary consideration.
QUASA does not disclose Personal Data to third parties for their own unrelated direct-marketing purposes without an appropriate legal basis and, where required, your consent.
Certain consent-based advertising or attribution disclosures may be defined as a “sale,” “sharing” or “targeted advertising” under the laws of some jurisdictions even where no money is paid for the data.
Where such law applies, QUASA will provide the required notice and opt-out mechanism.
12. Public information and User responsibility
12.1 Information intended to be public
Before publishing information, consider whether it contains:
- an exact home address;
- telephone number;
- personal email address;
- identity-document information;
- financial information;
- confidential business information;
- Special Category Data;
- another person’s Personal Data; or
- information that could create a safety risk.
Do not place such information in a public profile, task, review or Project page unless publication is necessary and lawful.
12.2 Information about other people
If you provide Personal Data about another person, you must have an appropriate legal basis and authority to do so.
Where required, you must provide that person with appropriate privacy information.
12.3 Search engines and caches
Removing public content from QUASA may not immediately remove:
- search-engine results;
- cached copies;
- archived pages;
- third-party reposts;
- social-media shares; or
- screenshots created by other persons.
QUASA may request removal from a third party where appropriate but cannot guarantee that every external copy will be deleted.
13. International transfers
13.1 Global operation
QUASA’s audience, Users, service providers, Advertisers, Pros, Clients and blockchain infrastructure may be located in different countries.
Personal Data may therefore be processed outside the country in which it was collected.
13.2 Transfers outside the EEA
Where Personal Data protected by the GDPR is transferred outside the European Economic Area, QUASA will use an appropriate transfer mechanism, such as:
- an adequacy decision;
- the European Commission’s Standard Contractual Clauses;
- Binding Corporate Rules;
- another legally recognised safeguard; or
- a specific derogation permitted by law in an exceptional case.
Where appropriate, QUASA will assess the destination country and implement supplementary technical, contractual or organisational safeguards.
13.3 Obtaining information about safeguards
You may request information about the applicable transfer mechanism or a copy of the relevant safeguards by contacting the privacy email in Section 2.
Commercially confidential information and information affecting security may be redacted.
13.4 Transfers initiated by the User
Some transfers occur because you expressly request a global or decentralised service, for example when you:
- contact a User in another country;
- hire a Pro in another country;
- submit content for global publication;
- visit an international Project;
- use an external wallet;
- initiate a public blockchain transaction; or
- request international advertising distribution.
13.5 Public blockchain distribution
Public blockchain information may be replicated globally without a central destination country.
Before initiating an on-chain transaction, you should understand that transaction information may become permanently public and internationally accessible.
Do not include names, contact details, messages or other unnecessary Personal Data in a blockchain transaction input or memo.
14. Data retention
QUASA retains Personal Data only for as long as reasonably necessary for the relevant purpose, including contractual, legal, accounting, security, fraud-prevention and dispute-resolution purposes.
The following periods describe the intended retention framework.
14.1 Website and security logs
Routine server, access and security logs are normally retained for no longer than 12 months.
Logs may be retained longer where necessary to:
- investigate a security incident;
- prevent repeated abuse;
- comply with law; or
- establish or defend a legal claim.
14.2 Cookie and analytics data
Cookie and similar-technology retention periods are specified in the Cookies Policy and consent interface.
Non-essential analytics event data should normally be retained for no longer than 14 months, unless it has been aggregated or anonymised.
14.3 Account data
Core account information is retained while the account remains active.
Following a valid account-deletion request, information not subject to another retention requirement should normally be deleted or irreversibly anonymised from active systems within 30 days.
Encrypted or isolated backup copies may remain until overwritten under the backup cycle, which should not exceed 13 months.
14.4 Public profiles and content
Public profiles, reviews, Project pages and other public content may be retained:
- while the relevant account or publication remains active;
- for the agreed publication period;
- until validly deleted or removed; or
- for a longer period where editorial, archival, legal or contractual grounds apply.
Search-engine and third-party copies are outside QUASA’s direct control.
14.5 Quasa Connect tasks, offers and messages
Task, offer, contract, message and dispute records are normally retained for the duration of the transaction and for up to three years after completion, cancellation or account closure.
Relevant records may be retained longer where:
- a dispute remains open;
- a longer statutory limitation period applies;
- tax or accounting law applies;
- there is suspected fraud; or
- an authority requires retention.
14.6 Project and advertising records
Project-submission, campaign and advertising records are normally retained for:
- the life of the Project or campaign;
- the publication period;
- up to three years after the commercial relationship ends; and
- any longer period required for accounting, tax or legal claims.
Business correspondence may be retained for a legally required period, commonly up to six years.
Accounting records and transaction evidence may be retained for eight years or another period required by applicable tax or commercial law.
14.7 Reward and transaction records
Reward-credit, withdrawal, payment and campaign records may be retained for:
- the life of the account;
- up to three years after the relevant activity where needed for disputes or fraud prevention; and
- six to ten years where the information forms part of a legally required accounting, tax or compliance record.
14.8 Identity and compliance records
Where anti-money-laundering or comparable statutory retention requirements apply, identity and transaction records may generally be retained for five years after the end of the relevant business relationship and, where legally required, for up to ten years.
Where identity verification is not subject to a statutory retention obligation, copies of identification documents should be deleted as soon as they are no longer necessary, normally within 90 days after verification, unless:
- verification is disputed;
- fraud is suspected;
- the account remains subject to a compliance review;
- a transaction remains open; or
- another legal basis requires retention.
A verification result may be retained longer than the underlying document.
14.9 Support, moderation and legal requests
Support correspondence, moderation decisions, illegal-content reports, appeals and privacy requests are normally retained for up to three years after closure.
A longer period may apply where necessary for:
- repeated-abuse prevention;
- regulatory reporting;
- an active dispute;
- a legal claim; or
- a binding legal obligation.
14.10 Marketing records
Marketing contact information is retained until:
- consent is withdrawn;
- the person objects;
- the subscription is cancelled;
- the address repeatedly fails; or
- QUASA determines that continued retention is no longer necessary.
A minimal suppression record may be retained for as long as reasonably necessary to ensure that the person is not contacted again.
Evidence of consent or withdrawal may be retained for up to three years after the relevant consent ends, or longer where necessary to establish legal compliance.
14.11 Fraud and security records
Information concerning fraud, account abuse, chargebacks, wallet risks and security incidents may normally be retained for up to three years after the last relevant event.
Limited identifiers may be retained longer where strictly necessary and proportionate to prevent repeated serious abuse or comply with law.
14.12 Public blockchain data
Information already recorded on a public blockchain may remain available indefinitely.
QUASA may delete or restrict the internal association between an account and wallet where legally possible, but cannot delete the underlying public blockchain transaction.
14.13 Legal holds
Where information is relevant to actual or reasonably anticipated proceedings, investigation or regulatory request, deletion may be suspended until the matter is resolved.
14.14 Anonymised data
QUASA may retain genuinely anonymised or aggregated data for statistical, research, security and business purposes because it no longer identifies an individual.
15. Data security
15.1 Security measures
QUASA uses technical and organisational measures appropriate to the nature of the Personal Data and the risks of Processing.
Measures may include:
- encryption in transit;
- access controls;
- authentication controls;
- role-based permissions;
- secure development practices;
- vulnerability management;
- system monitoring;
- backup and recovery procedures;
- logging;
- fraud detection;
- vendor assessments;
- confidentiality obligations;
- incident-response procedures; and
- staff awareness and training.
15.2 Access limitation
Access to Personal Data should be limited to personnel and service providers who need it for an authorised purpose.
Such persons are subject to contractual, professional or statutory confidentiality requirements where appropriate.
15.3 User security
You are responsible for protecting:
- your password;
- email account;
- mobile device;
- authentication methods;
- wallet;
- private keys;
- recovery phrase; and
- access to your account.
You should notify QUASA promptly if you suspect unauthorised account or wallet activity.
15.4 No absolute security guarantee
No online service, storage system or blockchain interface can be guaranteed to be completely secure.
QUASA cannot promise that a security incident will never occur, but will investigate and address incidents in accordance with applicable law.
15.5 Personal-data breaches
Where a Personal Data breach creates a legally reportable risk, QUASA will notify the competent supervisory authority without undue delay and, where required, notify affected individuals.
A notification may include:
- the nature of the incident;
- likely consequences;
- measures taken;
- recommended protective steps; and
- contact information.
16. Your privacy rights
The rights available to you depend on the applicable law and circumstances.
16.1 Right of access
You may request confirmation of whether QUASA processes your Personal Data and obtain:
- a copy of relevant Personal Data;
- purposes of Processing;
- categories of data;
- recipients or recipient categories;
- expected retention period;
- source of the data where not collected from you;
- information concerning applicable automated decision-making; and
- information about international-transfer safeguards.
16.2 Right to rectification
You may request correction of inaccurate Personal Data and completion of incomplete Personal Data.
Some information may be corrected directly through account settings.
16.3 Right to erasure
You may request deletion of Personal Data where, for example:
- the data is no longer necessary;
- consent has been withdrawn and no other legal basis applies;
- you successfully object to Processing;
- the data was processed unlawfully; or
- deletion is required by law.
The right to erasure is not absolute. QUASA may retain information where necessary for:
- legal obligations;
- freedom of expression and information;
- establishment, exercise or defence of legal claims;
- fraud and security prevention;
- performance of an unresolved transaction;
- public-interest archiving permitted by law; or
- another valid legal ground.
QUASA cannot delete information from a public blockchain that it does not control.
16.4 Right to restriction
You may request restriction of Processing where:
- you contest the accuracy of the data;
- the Processing is unlawful but you oppose deletion;
- QUASA no longer needs the data but you need it for a legal claim; or
- you have objected and the balancing assessment remains pending.
16.5 Right to data portability
Where Processing is based on consent or contract and is performed by automated means, you may request relevant data you provided in a structured, commonly used and machine-readable format.
Where technically feasible and legally required, you may request direct transmission to another Controller.
16.6 Right to object
You may object, on grounds relating to your particular situation, to Processing based on:
- legitimate interests; or
- performance of a task carried out in the public interest.
QUASA will stop the relevant Processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or the Processing is needed for legal claims.
16.7 Direct-marketing objection
You may object to direct marketing at any time.
Where you object, QUASA will stop using your Personal Data for that marketing, including related profiling.
16.8 Withdrawal of consent
Where Processing is based on consent, you may withdraw consent at any time.
Withdrawal:
- must be as easy as giving consent;
- applies to future Processing;
- does not affect the lawfulness of Processing before withdrawal; and
- does not require QUASA to delete data that must be retained under another legal basis.
16.9 Automated-decision rights
Where you are subject to a legally significant decision based solely on automated Processing, you may have the right to:
- obtain human intervention;
- express your point of view;
- receive meaningful information about the logic involved; and
- challenge the decision.
16.10 Right to complain
You may lodge a complaint with a competent data-protection supervisory authority.
You may generally complain to an authority in:
- the EU or EEA country of your habitual residence;
- the country in which you work;
- the country in which the alleged infringement occurred; or
- the country of QUASA’s main establishment.
16.11 Rights under other laws
Depending on your country or state of residence, you may have additional rights, including rights to:
- know the categories of data collected;
- request correction or deletion;
- receive a portable copy;
- opt out of targeted advertising;
- opt out of a legally defined sale or sharing of data;
- limit certain uses of sensitive data;
- opt out of specified profiling;
- appeal a refusal of a privacy request; and
- receive equal service without unlawful discrimination for exercising a privacy right.
These rights apply only where the relevant law applies to QUASA and the particular Processing.
17. Exercising your rights
17.1 Submission method
Privacy requests may be submitted through:
or by email to:
A dedicated request form may be made available at:
17.2 Information to include
To help us identify and process the request, please provide:
- your name;
- account email;
- whether the request concerns the Site, App or both;
- relevant account, Project, task or wallet identifier;
- the right you wish to exercise;
- the Personal Data or Processing concerned; and
- sufficient information to verify your identity.
Do not send a private key, wallet recovery phrase or unnecessary identification document.
17.3 Identity verification
QUASA may request information reasonably necessary to verify:
- your identity;
- control of the relevant account;
- control of an email address or wallet; or
- authority to act for another person.
QUASA will not request disproportionate verification information.
17.4 Authorised representatives
Where permitted by law, an authorised representative may submit a request for you.
QUASA may require evidence of the representative’s authority and may verify the request directly with you.
17.5 Response period
Where the GDPR applies, QUASA will normally respond without undue delay and within one month after receiving a valid request.
That period may be extended by up to two additional months where necessary due to complexity or the number of requests. QUASA will notify you of an extension and its reason within the initial one-month period.
17.6 Fees and abusive requests
Privacy requests are normally processed free of charge.
Where a request is manifestly unfounded or excessive, particularly because it is repetitive, QUASA may, where permitted by law:
- charge a reasonable administrative fee; or
- refuse to act on the request.
QUASA will explain the decision.
17.7 Appeals under other privacy laws
Where applicable law gives you a right to appeal the denial of a privacy request, the response will explain how to submit that appeal.
18. Account deletion
18.1 Deletion methods
Where available, you may close an account through account settings.
You may also request account deletion through:
Dedicated deletion page: https://quasa.io/insights/how-to-delete-your-quasa-account
18.2 Site and App accounts
If Site and App accounts are technically separate, specify whether you want to delete:
- the Site account;
- the App account; or
- all QUASA accounts associated with you.
Where reasonably possible, QUASA will identify and process all relevant account records covered by a complete deletion request.
18.3 Before closing an account
Before requesting deletion, you should review:
- active tasks;
- unresolved disputes;
- pending campaigns;
- outstanding fees;
- available rewards;
- eligible withdrawals;
- connected wallets; and
- records you may need to download.
Account deletion may not reverse a completed payment or blockchain transaction.
18.4 Information retained after account closure
After closure, QUASA may retain limited information where necessary for:
- accounting and tax obligations;
- unresolved transactions;
- fraud prevention;
- sanctions or compliance obligations;
- legal claims;
- moderation history;
- consent or opt-out evidence;
- security;
- public editorial archives;
- previously agreed advertising publications; or
- other legal obligations.
Public blockchain information remains unaffected.
19. Marketing and communication choices
19.1 Email marketing
You may unsubscribe from marketing emails by using the unsubscribe mechanism included in the message or by contacting QUASA.
An unsubscribe request does not prevent operational emails necessary for:
- account security;
- payments;
- tasks;
- rewards;
- legal notices;
- moderation; or
- service administration.
19.2 Push notifications
You may manage push notifications through:
- the App settings, where available; or
- your device settings.
Disabling all push notifications may prevent timely receipt of task, message or security notices.
19.3 Cookie and advertising choices
You may change non-essential cookie and advertising preferences through:
[In development]
19.4 Location choices
You may revoke location access in your device settings.
You may also choose to provide a city, region or task location manually where that option is available.
19.5 Profile visibility
Where supported, account settings may allow you to control:
- profile visibility;
- availability;
- location precision;
- portfolio visibility;
- communication preferences; and
- other public-profile elements.
Information necessary for an active public Pro profile or Project listing may remain public until the profile or listing is disabled.
20. Children and minimum age
20.1 Account minimum age
The Platform’s account, commercial, reward, marketplace, wallet and blockchain features are intended only for persons who are at least 18 years old, or the higher age of legal majority in their jurisdiction.
20.2 Public editorial content
Public editorial content may be viewed without an account.
QUASA does not intentionally use public access to collect unnecessary Personal Data from children.
20.3 No knowing collection from underage account holders
QUASA does not knowingly permit a person below the applicable minimum age to maintain an account or participate in Rewards, Projects, Quasa Connect or QUA-related features.
If QUASA reasonably believes that an underage person has created an account, it may:
- restrict the account;
- request age verification;
- delete the account and associated data; or
- take another measure required by law.
20.4 Parent or guardian requests
A parent or legal guardian who believes that QUASA has unlawfully collected a child’s Personal Data may contact the privacy email in Section 2.
20.5 Advertising to minors
QUASA will not use profiling to present targeted advertising to a person it knows with reasonable certainty is a minor where such practice is prohibited.
21. Special Category Data
21.1 Not generally required
QUASA does not generally require Users to submit Special Category Data.
Users should avoid including such information in:
- public tasks;
- public profiles;
- Projects;
- reviews;
- comments;
- portfolio materials; or
- support messages
unless it is genuinely necessary and lawful.
21.2 Incidental sensitive information
A task or communication may incidentally reveal sensitive information, for example where the service concerns health, accessibility, religion or another personal circumstance.
Where possible, such information should be:
- shared privately;
- limited to what is necessary;
- disclosed only to the relevant person; and
- removed when no longer required.
21.3 Processing conditions
Where QUASA must process Special Category Data, it will rely on an applicable condition, such as:
- explicit consent;
- information manifestly made public by the individual;
- establishment, exercise or defence of legal claims;
- protection of vital interests;
- substantial public interest under applicable law; or
- another legally permitted condition.
21.4 No sensitive-data advertising profiles
QUASA will not use Special Category Data to create targeted-advertising profiles.
22. Editorial and journalistic data
22.1 Freedom of expression
QUASA Media may process Personal Data for journalistic and editorial purposes in connection with freedom of expression and information.
This may include Personal Data concerning:
- authors;
- contributors;
- interviewees;
- public officials;
- company representatives;
- persons referred to in public records;
- persons involved in newsworthy events; and
- confidential sources.
22.2 Corrections
A person may submit a correction or privacy concern concerning editorial content through:
QUASA will assess:
- factual accuracy;
- public interest;
- freedom of expression;
- source protection;
- passage of time;
- the person’s role;
- applicable media law; and
- applicable data-protection rights.
22.3 Possible legal limitations
Certain privacy rights may be limited where and to the extent necessary under applicable law to protect:
- journalism;
- editorial independence;
- confidential sources;
- freedom of expression;
- freedom of information; or
- legitimate archival interests.
Any limitation will be applied only where legally justified.
23. Changes to this Privacy Policy
23.1 Updates
QUASA may update this Privacy Policy to reflect:
- changes to Platform features;
- changes to data practices;
- new service providers;
- legal or regulatory developments;
- security requirements;
- organisational changes; or
- clarification of existing information.
23.2 Notice of material changes
Where a change materially affects Users, QUASA will provide reasonable notice through one or more of the following:
- email;
- account notification;
- App notification;
- prominent Site notice; or
- another durable electronic method.
23.3 New consent
Continued use of the Platform does not replace consent where new consent is legally required.
Where an update introduces Processing that requires consent, QUASA will request that consent separately before beginning the Processing.
23.4 Effective date
The date at the beginning of this Privacy Policy indicates when the current version became effective.
Materially different versions should be archived where reasonably possible.
24. Language
This Privacy Policy is written in English.
Translations may be provided for accessibility and convenience.
QUASA should ensure that translated versions accurately communicate the same purposes, legal bases, rights and material disclosures.
For Business Users, the English version may prevail in the event of an inconsistency to the extent permitted by law.
This does not limit mandatory rights relating to transparency, language or interpretation available to Consumers or data subjects.
25. Supervisory authority
Without limiting your right to contact another competent authority, the supervisory authority associated with QUASA’s registered establishment in Frankfurt am Main is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7
65185 Wiesbaden
Germany
Postal address:
Postfach 3163
65021 Wiesbaden
Germany
Email:
Telephone:
+49 611 1408-0
You are encouraged, but not required, to contact QUASA first so that we have an opportunity to address the issue.
26. Contact us
Privacy questions and requests may be sent to:
Quasa International GmbH
An der Welle 4
60329 Frankfurt am Main
Germany
Commercial Register: Amtsgericht Frankfurt am Main
Registration number: HRB 115741
Support:
Privacy email:
Legal email:
Security reports: