Privacy Policy
Last updated: 2026-10-04
This policy explains which personal data Qlyne, operated by [company name], handles and why. It covers two groups of people: account holders, and the visitors of the sites that use Qlyne.
Account holders (we are the controller)
- Data: account ID, site name, your e-mail, dashboard users (name, e-mail and password hash) and the settings you save. Our servers also keep technical logs (IP address, time, request) for security.
- Purpose: create and run your account, send service e-mails (confirmation, password, important changes) and keep the Service secure. Legal basis: performing our contract with you and our legitimate interest in security.
- Retention: while the account exists. After it is closed, we delete the data within 30 days; backups roll over within another 30 days. Data the law requires us to keep is kept for as long as required.
Visitors of the sites that use Qlyne (we are the processor)
The owner of the site is the controller of this data. On the owner's behalf, and only to provide the Service, we process:
- the IP address (for IPv6, often only the /64 prefix) and the browser's user agent, to count requests per address, keep a visitor's place in line, tie tokens to the browser and check challenges;
- random session identifiers and signed tokens, in the waiting room and in cookies on the site:
qlyne_pass_<event>(waiting room pass) andqlyne_clr(challenge clearance). These cookies are needed for the protection to work; - one-way hashes of the IP address, and of the IP address with the user agent, when the site limits how many visitors are on it at once;
- what the site sends with a queue entry, such as a user ID.
Counters shown in the dashboard are totals per hour and do not contain IP addresses. Retention: a place in line lasts at most 2 hours; tokens and per-address counters expire with their time window (from seconds to a few hours); hourly counters are kept for 8 days and queue snapshots for 30 days.
Visitors should send questions about their data to the site they visited; we help the site owner answer them. The connector runs in the site owner's own Cloudflare account, where Cloudflare's processing is covered by the owner's agreement with Cloudflare.
Sharing
We do not sell personal data or use it for advertising. We share it only with the providers we need to run the Service (hosting and e-mail delivery), under contracts that protect it, and when the law requires it. The current list of providers is available on request.
International transfers
Our providers may process data outside your country. When that happens, we rely on the safeguards the law provides, such as standard contractual clauses.
Security
Connections are encrypted (HTTPS), secrets are stored encrypted, access to the servers is restricted, and we keep only the data the Service needs.
Your rights
You can ask to access, correct, export or delete your data, and to object to or restrict its use, under laws such as Brazil's LGPD and the European Union's GDPR. Write to [contact e-mail]. You can also complain to your data protection authority.
Changes
Changes are published on this page, and account holders are told by e-mail about material ones.
Contact: [company name], [contact e-mail].