Privacy Policy
This Privacy Policy explains how NAQ Systems Limited (Q•NAQ, we, us, or our) collects, uses, shares, retains, protects, and otherwise processes personal data in connection with qnaq.com and related applications, communications, events, and services that link to this Policy (the Platform).
Controller: NAQ Systems Limited, company number 812051, 18 Mallow Street Upper, Limerick, V94 N12Y, Ireland.
Privacy contact: legal@qnaq.pro
Website: qnaq.com
English (UK) identifies the language of this version, not its territorial reach. This Policy applies globally, subject to mandatory local notices and rights.
1. Scope and roles
1.1 Q•NAQ as controller
Q•NAQ generally acts as a controller, “business,” or equivalent responsible organisation for Account administration, Platform operation, payment records, security, fraud prevention, product analytics, support, moderation, Q•NAQ’s own marketing, and AI Features whose purposes and essential means Q•NAQ determines.
1.2 Employers and other users as independent controllers
An Employer, recruiter, or other user that obtains personal data through the Platform and independently determines the purposes and means of further processing acts, where applicable law so provides, as an independent controller or equivalent responsible organisation for that processing. Its own privacy notice and legal duties apply. For example, an Employer independently decides how to evaluate, contact, and retain Candidate data and how to make recruitment decisions. Merely being able to view a Publication does not authorise a user to collect or use personal data for an unrelated purpose. If Q•NAQ and another party jointly determine the purposes and means of a processing operation, Q•NAQ will identify and allocate their respective responsibilities as required by applicable law.
Q•NAQ does not control an independent user’s off-platform processing and is not responsible for it merely because initial contact occurred on the Platform. Q•NAQ will, however, enforce applicable Platform rules and comply with duties imposed directly on Q•NAQ.
1.3 Q•NAQ as processor
Q•NAQ acts as a processor or service provider only for processing that it carries out on behalf of a customer, in accordance with that customer’s documented instructions, and without determining that customer’s purposes or essential means. That processing must be governed by the applicable enterprise agreement and data-processing addendum. The parties’ factual roles and applicable law, not the agreement’s label alone, determine whether Q•NAQ acts as a controller, joint controller, processor, or service provider.
1.4 User roles and visibility
An Employer Account is available only to a legal entity of any legal or organisational form duly formed or registered under applicable law, or to a natural person lawfully registered or formally recognised as a sole trader, sole proprietor, private or individual entrepreneur, or equivalent. An unregistered natural person and an organisation that is neither a legal entity nor a lawfully registered business are not eligible for Employer status. A Candidate Account is available only to the natural person it concerns. Authorised personnel may administer an Employer Account on the Employer’s behalf.
Once activated and while active, Job Listings and Candidate Profiles are intended to be viewable through the ordinary Platform interface by every authenticated registered user, without any Employer-versus-Candidate role restriction, subject only to Account status, moderation, geographic or legal restrictions, and technical availability. Restricted contact fields, private messages, application materials, billing data, verification data, and other restricted information are not part of that general visibility. Access without an Account or external indexing occurs only if Q•NAQ actually enables it and clearly informs the publishing user.
2. Personal data we collect
The exact data depends on the user, feature, settings, country, and interaction.
2.1 Account and identity data
- Q•NAQ may collect a user's name, username, email address, telephone number, password hash, language, time zone, and Account identifiers.
- Q•NAQ may collect age or date-of-birth confirmation and legal-capacity information.
- Q•NAQ may collect an organisation name, title, role, work contact details, company number, tax number, authority information, and administrator permissions.
- Q•NAQ may collect identity, corporate, authority, sanctions, fraud, or verification records.
- Q•NAQ may collect a profile image, avatar, electronic signature, and communication preferences.
2.2 Candidate and professional data
- Q•NAQ may collect a Candidate's identity and confirmation that the profile concerns the natural person operating the Candidate Account.
- Q•NAQ may collect employment history, education, skills, qualifications, certifications, portfolio information, languages, availability, and professional interests.
- Q•NAQ may collect a preferred role, location, remote-work status, compensation expectations, notice period, and work-authorisation information.
- Q•NAQ may collect a résumé, CV, Candidate Profile, cover letter, application materials, references, links, and uploaded files.
- Q•NAQ may collect nationality or citizenship information only where it is lawfully supplied for work-authorisation purposes.
- Q•NAQ may generate or infer information from profile content, such as skills categories, relevance signals, and suggested matches.
2.3 Employer and Job Listing data
- Q•NAQ may collect the identity, legal form, registration or equivalent status, hiring entity, industry, size, website, location, contact personnel, and verification status of a legal person or registered entrepreneur.
- Q•NAQ may collect a role title, description, qualifications, workplace, compensation, benefits, screening questions, and publication settings.
- Q•NAQ may collect candidate searches, filters, saved results, contacts, application status, notes, and workflow activity.
- Q•NAQ may collect records showing authority to represent an organisation or advertise a role.
2.4 Content and communications
- Q•NAQ may collect User Content, forms, prompts, AI inputs and outputs, translations, feedback, reports, appeals, and moderation submissions.
- Q•NAQ may collect Platform messages and related metadata, such as the sender, recipient, time, status, and abuse signals.
- Q•NAQ may collect support emails, chat records, survey responses, event information, complaints, cancellation or withdrawal statements and acknowledgements, and dispute records.
- Q•NAQ may collect call metadata and recordings where a call is recorded after Q•NAQ has provided any notice and obtained any consent required by applicable law.
2.5 Transaction and billing data
- Q•NAQ may collect order, product, Publication, Publication Package, listing credit, Point, Contact Credit, direct contact unlock, paid Contact Request, Premium, VIP, Highlight, Boost, quantity, price, currency, tax, billing address, country evidence, invoice, refund, and chargeback data.
- Q•NAQ may collect payment-provider customer, payment-method, transaction, authorisation, and fraud identifiers.
- Q•NAQ may collect the last four digits of a payment card, card brand, expiry information, or tokenised details made available by the payment provider.
- Q•NAQ may collect acceptance, checkbox, legal-document version, payment, activation, consumption, availability, expiry, cancellation, withdrawal, and acknowledgement timestamps, including the 30-day Publication Period and 90-day package validity.
Under the current architecture, Q•NAQ does not receive or store the complete payment-card number or card security code. Those details are handled by the payment provider.
2.6 Device, network, and usage data
- Q•NAQ may collect an IP address, device and advertising identifiers where permitted, browser type, operating system, application version, language, time zone, screen characteristics, and device characteristics.
- Q•NAQ may collect login, clickstream, search, filter, page, feature, session, referral, campaign, and interaction data.
- Q•NAQ may collect an approximate location inferred from an IP address or payment evidence and a precise location only if a feature requests it with the required permission.
- Q•NAQ may collect cookie, SDK, pixel, local-storage, consent, and preference data.
- Q•NAQ may collect diagnostic, crash, performance, security, bot, abuse, and fraud signals.
2.7 Moderation, safety, and legal data
- Q•NAQ may collect reported Content, evidence, reporter and subject identifiers, legal grounds, decisions, reasons, appeals, and repeat-abuse records.
- Q•NAQ may collect identity-misuse, spam, fraud, sanctions, security, and payment-risk signals.
- Q•NAQ may collect government, court, regulator, rights-holder, and law-enforcement requests and responses.
- Q•NAQ may collect information necessary to establish, exercise, or defend legal claims.
2.8 Sensitive data
User Content may reveal health or disability information, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, sex-life or sexual-orientation information, genetic data, biometric data used for unique identification, criminal-conviction or offence data, or other sensitive data. Q•NAQ does not require such data in an ordinary Publication, and users should not provide it unless the disclosure is necessary, lawful, and appropriately protected.
Q•NAQ does not use sensitive data to infer protected traits or target advertising. Where EU or UK data-protection law applies, Q•NAQ processes special-category data only when both an Article 6 basis and an applicable Article 9(2) condition exist, and it processes criminal-conviction or offence data only under official authority or applicable law providing appropriate safeguards as required by Article 10. Q•NAQ does not rely on contract or legitimate interests alone for those categories. If a feature requires sensitive data, Q•NAQ provides a specific notice and obtains explicit consent or satisfies another applicable statutory condition before the processing begins.
3. Sources of data
Q•NAQ obtains personal data from the sources described below.
- Q•NAQ may obtain personal data directly from users, organisation administrators, and authorised representatives.
- Q•NAQ may obtain personal data from a user's device and interaction with the Platform.
- Q•NAQ may obtain personal data from other users, such as when an employer contacts a candidate or a reporter submits evidence.
- Q•NAQ may obtain personal data from payment, identity, fraud, communications, hosting, analytics, AI, security, and support providers.
- Q•NAQ may obtain personal data from publicly available professional, corporate, sanctions, regulatory, and website sources where lawful.
- Q•NAQ may obtain personal data from integrations that a user chooses to connect.
- Q•NAQ may obtain personal data from authorities, courts, rights holders, advisers, insurers, and dispute-resolution bodies.
If a person provides data about another individual, that person must have authority and provide any legally required notice. Q•NAQ may notify the individual directly where law requires and no exception applies.
4. Purposes and legal bases
The applicable legal basis depends on the purpose and jurisdiction. For EU/EEA and UK personal data, the table below identifies the Article 6 basis for each purpose. Processing of special-category data also requires an applicable Article 9 condition, and processing of criminal-conviction or offence data must satisfy Article 10 and applicable national law. Outside those jurisdictions, Q•NAQ relies on the consent or other lawful authority required for the specific processing under applicable law.
| Purpose | Main data | EU/UK legal basis, where applicable |
| Create and administer Accounts; authenticate users; apply settings and permissions | Account, identity, device, verification | Article 6(1)(b) for requested Account creation, authentication, settings, and permissions; Article 6(1)(f) for secure administration and fraud prevention; Article 6(1)(c) only where a specific legal obligation requires verification |
| Publish, host, search, display, and expire Publications | Candidate, Employer, Content, usage | Article 6(1)(b) for requested publication and display; Article 6(1)(f) for search, safety, and Platform integrity; Article 6(1)(a) only for an optional operation expressly based on consent. An applicable Article 9 condition or Article 10 authorisation is also required for covered data |
| Provide Paid Features, packages, payments, invoices, tax, cancellation, withdrawal, refunds, and disputes | Transaction, billing, Account, activation and cancellation logs | Article 6(1)(b) for orders and Paid Features; Article 6(1)(c) for applicable tax, accounting, consumer-law, and other statutory duties; Article 6(1)(f) for fraud prevention and the establishment, exercise, or defence of legal claims |
| Enable messages, contacts, support, and service notices | Contact, communications, Account | Article 6(1)(b) for requested messages, contacts, and support; Article 6(1)(f) for service operation, safety, and support; Article 6(1)(c) where a specific law requires a notice or response |
| Rank, recommend, match, translate, draft, and provide AI Features | Profile, Listing, searches, usage, prompts, outputs | Article 6(1)(b) for requested AI Features; Article 6(1)(f) for relevant ranking, safety, and service-improvement operations; Article 6(1)(a) only for optional processing expressly based on consent. An applicable Article 9 condition or Article 10 authorisation is also required for covered data |
| Moderate Content; prevent fraud, spam, abuse, security incidents, and unlawful activity | Content, device, network, moderation, payment-risk | Article 6(1)(f) for safety, abuse prevention, security, and enforcement; Article 6(1)(c) where a specific law requires processing. Article 9(2)(f) may additionally apply where special-category data is necessary for legal claims; Article 10 data is processed only where law authorises it |
| Analyse performance and improve the Platform | Usage, diagnostic, de-identified or aggregated data | Article 6(1)(f) for necessary first-party analytics and Platform improvement; Article 6(1)(a) for non-essential cookies or SDKs where consent is required. Data falls outside the GDPR only after genuine anonymisation |
| Send marketing and measure campaigns | Contact, preferences, campaign, optional device data | Consent where required; legitimate interests where direct marketing is lawfully permitted |
| Comply with law, lawful requests, audits, records, and claims | Relevant Account, Content, transaction, legal data | Article 6(1)(c) for specific legal obligations; Article 6(1)(f) for the establishment, exercise, or defence of legal claims. Article 9(2)(f) is an additional condition for special-category data needed for claims; Article 10 data requires applicable legal authorisation |
| Corporate transactions and business continuity | Relevant business, Account, contract, and security data | Article 6(1)(f) for transaction planning, due diligence, business continuity, and completion; Article 6(1)(c) for applicable legal duties |
4.1 Contract necessity
If data is required to create an Account, publish a selected item, process payment, or supply a requested feature, failure to provide it may prevent that service.
4.2 Legitimate interests
Q•NAQ’s legitimate interests include operating and improving a professional Platform, preventing fraud and abuse, securing users and systems, communicating about services, enforcing agreements, defending claims, and understanding service performance. Q•NAQ balances those interests against affected rights and expectations. An eligible person may object as described in Section 12.
4.3 Consent
Where processing depends on consent, consent may be withdrawn prospectively through the relevant control or by contacting Q•NAQ. Withdrawal does not affect prior lawful processing. Acceptance of the Terms is not consent to optional cookies, marketing, or sensitive-data processing where separate consent is required.
4.4 Legal obligations and claims
Q•NAQ may process personal data where necessary to comply with a specific legal obligation that applies to Q•NAQ, or where necessary for Q•NAQ or a third party to establish, exercise, or defend legal claims. For EU/EEA data, Article 9(2)(f) is an additional condition, not a standalone Article 6 legal basis, when special-category data is necessary for legal claims. Article 10 data is processed only where applicable Union or Member State law authorises the processing and provides appropriate safeguards.
5. Publications, registered users, and user disclosures
5.1 Visibility
Once activated and while active, the Platform displays Job Listings and Candidate Profiles through the ordinary Platform interface to every authenticated registered user, without any Employer-versus-Candidate role restriction, subject only to moderation, Account status, technical availability, geographic restrictions, and law. General Publication visibility does not include restricted contact fields, private messages, application materials, billing data, verification data, or other information identified as restricted.
5.2 Indexing and caching
Q•NAQ will permit access without an Account or external search-engine indexing only if that form of visibility is actually enabled and the publishing user is clearly informed. Where external indexing is enabled, search engines and archival services may copy or cache a Publication. Q•NAQ may use technical measures to request deindexing after deletion or expiry, but does not control third-party refresh schedules.
5.3 Other users
Registered users may view Publications through the ordinary interface. A user may download, copy, message, or retain personal data only for a genuine recruiting or work-opportunity purpose, another purpose deliberately authorised by the person concerned, or another lawful purpose clearly identified by Q•NAQ. That user becomes independently responsible for further processing. Users must not scrape, resell, enrich, republish, build a database, or use data for unrelated marketing.
5.4 Private communications
Private messages are not displayed publicly. Q•NAQ personnel and providers may access them only where needed for delivery, support, security, abuse investigation, legal compliance, or another disclosed purpose, subject to role-based controls.
6. AI, matching, and automated processing
6.1 AI Features
Q•NAQ may use AI to assist with drafting, formatting, translating, summarising, recommending, matching, categorising, fraud detection, safety, and moderation. Inputs, outputs, and relevant context may be sent to an AI provider such as OpenAI under contractual and security controls.
6.2 No final hiring decision by Q•NAQ
Q•NAQ does not make an employer’s final decision to hire, reject, promote, terminate, or set compensation. Ranking, suggestions, or matches are decision support and may be reviewed, ignored, or changed by the user.
6.3 Meaningful information
Main ranking and matching inputs may include search terms, filters, location, skills, stated preferences, qualifications, recency, completeness, availability, quality and safety signals, aggregate engagement, and clearly identified paid promotion. The relative weight varies by feature and context.
6.4 Legal or similarly significant decisions
Q•NAQ does not currently make a decision based solely on automated processing that produces legal effects or similarly significant effects on a person. If Q•NAQ proposes to introduce such processing, it will not do so unless an exception under applicable law permits it and all required transparency, impact-assessment, and safeguard measures are in place, including human intervention, an opportunity to express a point of view, and a right to contest the decision where required.
6.5 Training and improvement
Q•NAQ may use limited data to evaluate, secure, debug, and improve its own services. Q•NAQ will not authorise a provider to use identifiable Candidate Profile content or private prompts to train the provider’s general-purpose model unless Q•NAQ has a valid legal basis and provides any separate notice, consent, or choice required by law. Deidentified or aggregated data may be used where it cannot reasonably be linked back to a person. Q•NAQ will not attempt to re-identify de-identified data and, where applicable law requires it, will contractually prohibit recipients from doing so.
6.6 User responsibility
Employers using automated tools remain responsible for applicable employment notices, human review, accessibility, bias audits, impact assessments, retention, explanation, appeal, and anti-discrimination duties. Q•NAQ remains responsible for obligations imposed directly on Q•NAQ.
7. How we disclose personal data
Q•NAQ discloses personal data only as described below, subject to contracts and law.
7.1 Other users and access without an Account
Active Publication Content is disclosed to every authenticated registered user without an Employer-versus-Candidate role restriction. Contact fields are disclosed only through the relevant contact setting, direct contact unlock, accepted Contact Request, or another expressly identified lawful workflow. Access without an Account or disclosure to search engines occurs only if enabled and disclosed as described in Section 5.
7.2 Service providers
Providers may process data for hosting, content delivery, storage, databases, payment, tax, fraud, identity, communications, customer support, call services, email, analytics, consent management, security, error monitoring, AI, translation, and professional advice.
Q•NAQ currently uses the material providers described below for the stated purposes. Depending on the service and applicable law, a recipient may act as Q•NAQ’s processor or service provider, or as an independent controller for specified payment, fraud-prevention, security, or legal-compliance purposes.
- Q•NAQ uses Stripe for payment processing, payment authentication, fraud prevention, and transaction records.
- Q•NAQ uses OpenAI for disclosed AI-assisted generation and other AI Features.
- Q•NAQ uses Google Analytics and Google Tag Manager for analytics and tag management only according to the user’s consent and the deployed configuration.
- Q•NAQ uses Sentry for error, performance, and security diagnostics.
- Q•NAQ uses CloudTalk for telephone or support communications when that channel is used.
Q•NAQ updates this section when a material provider change affects the processing described in this Policy and provides any additional notice or obtains any consent required by applicable law. Cookie Settings describe only Technologies actually deployed in the user’s browser or device; they are not a substitute for this provider disclosure.
7.3 Professional and commercial recipients
Q•NAQ may disclose necessary data to lawyers, accountants, auditors, insurers, banks, card networks, collection providers, corporate advisers, and transaction counterparties subject to confidentiality and lawful purpose.
7.4 Authorities and rights holders
Q•NAQ may disclose data in response to a binding legal request or where reasonably necessary and lawful to protect rights, safety, or security; prevent fraud; investigate abuse; or establish, exercise, or defend legal claims. Q•NAQ reviews requests for legal basis, scope, authority, and proportionality and may challenge or narrow an improper request.
7.5 Corporate events
Data may be disclosed in connection with financing, due diligence, a merger, reorganisation, insolvency, or a sale or transfer of all or part of the business. Q•NAQ will use confidentiality and purpose controls and provide notice where law requires.
7.6 No unrestricted sale
Q•NAQ does not operate as a data broker, sell personal data as an unrestricted standalone data product, or permit Candidate data to be resold or used for unrelated advertising. Q•NAQ does charge for Platform functionality, including controlled direct contact-access events. Because some laws define a “sale,” “sharing,” or targeted-advertising disclosure more broadly than an ordinary monetary sale, a paid disclosure or a deployed analytics or advertising configuration may fall within such a definition unless a consumer-directed intentional disclosure or interaction, or another applicable statutory exception, applies.
Before enabling a paid contact disclosure for a person covered by such a law, Q•NAQ will ensure that the person deliberately selected the relevant contact or visibility setting or otherwise authorised the interaction, or that another valid legal basis permits the disclosure and all applicable notice requirements have been met. Q•NAQ will provide any required notice, opt-in or opt-out, Global Privacy Control recognition, and risk assessment, or will disable the affected disclosure. Payment by another user is never treated by itself as the person’s consent or as a legal basis for disclosure or further processing.
8. International data transfers
Q•NAQ is established in Ireland and uses a global technical and provider infrastructure. Core production data is currently hosted in the United States, so personal data originating in the EEA, the United Kingdom, Switzerland, or another jurisdiction may be transferred to and processed in the United States. Personal data may also be processed in Ireland, the EEA, the United Kingdom, and other countries where Q•NAQ, users, or providers operate. Those countries may provide different levels of data protection.
Before making a restricted transfer, Q•NAQ documents and applies the transfer mechanism appropriate to the recipient, destination, and data. The permitted mechanisms are described below.
- Q•NAQ may rely on an applicable adequacy decision, including an applicable data-privacy framework, only while the recipient’s participation or certification is current and covers the relevant data and transfer.
- For an EEA transfer not covered by adequacy, Q•NAQ uses the European Commission Standard Contractual Clauses, together with a transfer assessment and supplementary measures where required.
- For a restricted UK transfer not covered by UK adequacy regulations, Q•NAQ uses the UK International Data Transfer Agreement or the UK Addendum, together with the required risk assessment and safeguards.
- Q•NAQ uses another approved contractual, certification, or statutory mechanism only where it is valid for the relevant transfer and all of its conditions are satisfied.
- Q•NAQ relies on a statutory derogation only for a specific, non-repetitive transfer where the legal conditions for that derogation are satisfied.
- Q•NAQ applies supplementary technical, organisational, and contractual measures where the transfer assessment shows that they are necessary.
A person may request information about the transfer mechanism applicable to that person’s data and, where required, a copy of the relevant safeguard with confidential or security-sensitive information redacted. A user’s mere use of the Platform is not treated as consent to a restricted transfer where law requires another mechanism.
9. Retention
Q•NAQ retains each category of personal data for the period stated below. If a fixed period cannot reasonably be stated, the table provides the criteria used to determine that period. Q•NAQ retains data beyond the ordinary period only where necessary to comply with a specific legal obligation, preserve evidence during an active dispute or investigation, enforce legal rights, or maintain security. At the end of the applicable period, Q•NAQ deletes or irreversibly anonymises the data unless continued retention is lawfully required.
| Data or record | Typical retention approach |
| Active Account and current profile | For the Account relationship and until deletion or deactivation |
| Expired Publications | Removed from registered-user and any separately enabled public display at expiry; retained in the Account or restricted systems only as needed for reactivation, support, safety, disputes, and law |
| Deleted Account or Content in active systems | Deleted or irreversibly de-identified without undue delay after a verified request, subject to lawful retention, processor deletion cycles, and any mandatory deadline |
| Backups | Isolated from ordinary use and rotated or overwritten under Q•NAQ’s documented backup schedule, subject to legal holds and security requirements |
| Orders, invoices, tax, accounting, and contract records | Generally 6 years after the relevant transaction or longer where tax or legal rules require |
| Acceptance, consent, cancellation, and withdrawal evidence | For the contract or consent period and generally up to 6 years after it ends or longer for an active claim |
| Payment fraud, chargeback, and security evidence | Generally 3 years after closure, or longer where a claim, provider rule, or law requires |
| Security, login, device, and technical logs | Until the relevant security or fraud risk, investigation, and remediation period ends, taking account of incident severity, recurrence, threat lifecycle, and any applicable legal limitation period |
| Support and complaint records | Until the support matter or complaint is closed and for any additional period required by an active dispute, a specific legal obligation, or the applicable limitation period |
| Call recordings | Only after required notice or consent, until the stated support, quality, or security purpose is completed, and longer only for a specific legal obligation or active claim |
| Moderation and repeat-abuse records | For the restriction and appeal period and thereafter only as necessary based on the severity and recurrence of abuse, an active safety risk, a specific legal obligation, or an applicable limitation period |
| Optional analytics identifiers | According to Cookie Settings and the applicable consent, with the item-level expiry and deletion controls stated there |
The table states typical periods, not a promise to retain every record for the maximum period. Q•NAQ may delete earlier where no longer needed.
10. Security and incident response
Q•NAQ uses risk-based technical and organisational measures designed to protect personal data, including access controls, authentication, encryption in transit, provider review, logging, backup, vulnerability management, least-privilege practices, and incident response. No system is completely secure, and users must protect their credentials and devices.
Q•NAQ investigates suspected incidents and will notify affected persons, regulators, customers, or other parties when and within the time required by applicable law. Notice may be delayed or limited where law enforcement or another lawful restriction requires it.
11. Marketing, communications, and preferences
Q•NAQ sends necessary service, legal, billing, security, and Account messages based on contract, legal obligation, or legitimate interests. These messages are not optional while relevant to an active Account or order.
Marketing email, SMS, telephone, push, or similar communications are sent only where Q•NAQ has the permission or other lawful basis required in the recipient’s country. A recipient may unsubscribe through the message or Account settings. Q•NAQ may retain a suppression record to respect the opt-out.
Cookie and SDK choices are controlled through Cookie Settings. Optional consent may be withdrawn as easily as it was given.
12. Rights and requests
Depending on the person’s location and applicable law, the rights described below may apply.
- A person may ask Q•NAQ to confirm whether it processes that person’s personal data and to explain the processing.
- A person may ask Q•NAQ to provide access to or a copy of that person’s personal data.
- A person may ask Q•NAQ to correct inaccurate personal data or complete incomplete personal data.
- A person may request erasure of personal data.
- A person may request restriction of processing or object to processing, including objecting at any time to direct marketing.
- A person may receive personal data that the person provided in a structured, commonly used, and machine-readable format and, where applicable, have it transmitted to another controller.
- A person may withdraw consent at any time for future processing.
- A person may opt out of covered sale, sharing, targeted advertising, or profiling.
- A person may limit covered uses of sensitive personal data.
- A person may have the right not to be subject to certain solely automated decisions and, where applicable, to obtain human intervention, express a point of view, and contest the decision.
- A person may appeal a denied privacy request where local law provides that right.
- A person may use an authorised agent where local law permits it.
- A person may complain to a competent supervisory authority or seek a judicial remedy.
12.1 Submitting a request
Send a request to legal@qnaq.pro or use an available privacy control. Identify the right, Account email, country or state, and relevant data. Q•NAQ may verify identity and authority in a proportionate manner and will not request more data than reasonably necessary.
12.2 Response
Q•NAQ responds within the deadline and in the manner required by applicable law. Q•NAQ may extend a deadline, charge a permitted reasonable fee, or refuse to act only where applicable law allows it. Q•NAQ may protect another person’s rights or retain data under a lawful exception. Where required, Q•NAQ will explain the basis for its decision and any available appeal or complaint route.
12.3 Authorised agents
An agent must provide legally sufficient proof of authority. Q•NAQ may verify the person’s identity or confirm authorisation directly except where law prohibits that step.
12.4 Non-discrimination
Q•NAQ will not unlawfully discriminate against a person for exercising a privacy right. A feature may be unavailable where the requested processing is objectively necessary to provide it.
13. Regional information
The following regional provisions supplement the general Policy. They identify principal frameworks, not every law or regulator. References include amendments, implementing regulations, binding guidance, replacement legislation, and local rules in force from time to time. Applicability depends on territorial scope, targeting, establishment, thresholds, data, and activity. A country not named remains covered by its mandatory law.
13.1 Ireland, European Union, and EEA
Q•NAQ is established in Ireland and is generally supervised for its own cross-border processing under Regulation (EU) 2016/679 (GDPR) by the Irish Data Protection Commission, without limiting another authority’s competence. The GDPR rights, legal bases, transparency rules, data-protection-by-design duties, processor controls, security, incident notification, automated-decision safeguards, and Chapter V transfer restrictions apply where in scope. Directive 2002/58/EC and national laws separately govern cookies and electronic marketing.
Restricted transfers are governed by the mechanisms and safeguards described in Section 8. A person may request information about the mechanism applicable to that person’s data, subject to lawful protection of confidential and security-sensitive information.
Irish Data Protection Commission: dataprotection.ie
13.2 United Kingdom
The UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 apply where in scope. Individuals may complain to the UK Information Commissioner’s Office at ico.org.uk. Restricted transfers may rely on UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum, or another lawful mechanism.
If Article 27 UK GDPR requires Q•NAQ to appoint a UK representative, Q•NAQ must appoint one and publish the representative’s identity and contact details in the Platform’s representative directory and UK-facing notice before processing that requires the appointment. This sentence is not a substitute for the appointment.
13.3 Switzerland
Where the Swiss Federal Act on Data Protection and its Ordinance apply, Q•NAQ will provide required transparency, handle access, correction, deletion and related claims, evaluate high-risk processing and transfers, and notify the Federal Data Protection and Information Commissioner or individuals where required. Any Swiss representative or local contact must be appointed and published before the legal duty arises.
13.4 United States — California and other states
Where an applicable U.S. state privacy law covers Q•NAQ, residents receive the access, correction, deletion, portability, opt-out, sensitive-data, appeal, and non-discrimination rights provided by that law. Potentially relevant laws include the California Consumer Privacy Act as amended by the CPRA and regulations and comprehensive privacy statutes in Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states as they become effective or are amended.
Q•NAQ does not operate as a data broker or sell personal data as an unrestricted standalone data product. Controlled paid contact access and deployed advertising, analytics, disclosure, or profiling configurations will be assessed under the broad statutory definitions of sale, sharing, targeted advertising, and covered profiling. Where no consumer-directed intentional disclosure or interaction, or other applicable statutory exception, applies and the law covers Q•NAQ, Q•NAQ will provide the required Do Not Sell or Share My Personal Information or equivalent control, honour a valid Global Privacy Control or other legally recognised signal, and complete any required risk assessment. Q•NAQ will not require Account creation or disproportionate identity verification for a browser-level opt-out when prohibited.
Where California law covers Q•NAQ, the California-facing notice will also identify the categories of personal information collected, sold or shared, and disclosed for a business purpose during the preceding 12 months, the relevant purposes and recipient categories, or state accurately that no category was sold or shared. Q•NAQ will not publish a “no sale or sharing” statement unless the actual paid-contact, analytics, advertising, and provider configurations support it.
Where required, Q•NAQ will complete and retain a risk assessment for covered sensitive data, sale or sharing, targeted advertising, profiling, or automated decision-making; provide pre-use notices and access or opt-out controls; and support appeals. Employment-related AI or ranking may also trigger state or local impact, audit, notice, accommodation, and human-review duties. This Policy does not claim that Q•NAQ meets a statutory revenue, data-volume, or other threshold unless it actually does.
13.5 Canada
Where applicable, Q•NAQ will comply with PIPEDA and substantially similar provincial law, including Alberta and British Columbia private-sector privacy statutes and Québec’s private-sector privacy law as modernised by Law 25. Q•NAQ remains accountable for service providers, uses meaningful consent or another lawful authority, limits collection and retention, provides access and correction, manages breach records and notices, and identifies any required privacy contact. Electronic marketing also follows Canada’s Anti-Spam Legislation.
13.6 Mexico
Where Mexican law applies, this Policy is a general privacy notice and will be supplemented by any required Spanish-language simplified or integral notice. Applicable frameworks include the Federal Law on the Protection of Personal Data Held by Private Parties as currently enacted and amended, its Regulation, and official criteria.
Individuals may exercise access, rectification, cancellation, and opposition (ARCO) rights; revoke consent; or limit use or disclosure through legal@qnaq.pro or a local mechanism published before launch. Sensitive-data processing, transfers, financial or patrimonial data, marketing, and consent will follow the form and exceptions required by law. Q•NAQ will identify any required local responsible person or procedure rather than relying on a generic global notice.
13.7 Brazil
Where Law No. 13,709/2018 (LGPD) applies, Q•NAQ will identify an appropriate legal basis, provide confirmation and access, correct, anonymise, block or delete data where required, support portability according to regulation, provide information about recipients and consent, handle objection or review rights, maintain security and incident procedures, and use an authorised transfer mechanism.
Q•NAQ will publish the identity and contact details of a required data-protection channel or person before the covered processing. The role and contact will not be invented or treated as satisfied solely by this statement.
13.8 Other Latin American and Caribbean countries
Country-specific duties may arise under Argentina Law No. 25,326; Chile Law No. 19,628 and enacted reforms according to their effective dates; Colombia Law 1581 of 2012; Peru Law 29733 and its current Regulation; Uruguay Law 18,331; Ecuador’s Organic Personal Data Protection Law; Panama Law 81 of 2019; Costa Rica Law 8968; and privacy, habeas-data, telecommunications, consumer, and cybersecurity rules elsewhere in Latin America and the Caribbean.
Q•NAQ will implement required database registration, local contact, Spanish or Portuguese notice, consent, international-transfer basis, breach notification, rights procedure, and regulator cooperation before covered processing. A general global email does not replace a legally prescribed filing or local appointment.
13.9 Australia and New Zealand
Where the Australian Privacy Act 1988 applies, Q•NAQ will follow the Australian Privacy Principles, including open management, notice, collection, use and disclosure, direct marketing, cross-border disclosure, security, access, and correction, and the Notifiable Data Breaches scheme. Complaints may be escalated to the Office of the Australian Information Commissioner. Marketing also follows the Spam Act 2003.
Where the New Zealand Privacy Act 2020 applies, Q•NAQ will follow the information privacy principles, offshore-disclosure requirements, access and correction rights, and notifiable privacy breach duties. If a New Zealand privacy officer or another local function is required, it must be operational before the covered activity. Complaints may be escalated to the Office of the Privacy Commissioner.
13.10 India and South Asia
India is a separate major jurisdiction, not part of a generic “other Asia” clause. Relevant frameworks may include the Information Technology Act 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 while applicable, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 as amended, and the Digital Personal Data Protection Act 2023 and Digital Personal Data Protection Rules 2025 according to their phased commencement notifications.
As of this Policy’s effective date, Q•NAQ will not describe an Indian DPDP provision as operative before its notified commencement. During transition, Q•NAQ will maintain duties under the rules that remain in force and prepare notices, consent, security, rights, erasure, grievance, child-data, breach, significant-data-fiduciary, and cross-border controls before the corresponding DPDP duties commence.
Where Indian e-commerce or intermediary law requires an appointed grievance officer, nodal contact, compliance officer, resident officer, or other named function, Q•NAQ must assess the precise classification, appoint the required person, and publish accurate name, designation, address, telephone and email details before the covered launch. legal@qnaq.pro alone is not a substitute where the law requires named details.
Users in Pakistan, Bangladesh, Sri Lanka, Nepal, Bhutan, and Maldives receive the rights provided by applicable constitutional, privacy, cybercrime, electronic-transactions, telecommunications, and sectoral laws. Q•NAQ may provide a country notice, registration, consent, localisation control, or local contact before making a feature available.
13.11 Japan and South Korea
Where Japan’s Act on the Protection of Personal Information (APPI) applies, Q•NAQ will specify utilisation purposes, maintain security and processor supervision, handle disclosure, correction, cessation and deletion requests, keep required third-party transfer records, provide information about foreign recipient systems or safeguards, and report qualifying incidents. The current consolidated APPI, Cabinet Order, and Personal Information Protection Commission Rules apply according to their terms.
Where South Korea’s Personal Information Protection Act and Enforcement Decree apply, Q•NAQ will provide granular Korean notice and consent where required, minimise collection, disclose retention, manage processors and overseas transfers, honour access, correction, deletion, suspension, and portability rights where applicable, and comply with incident, representative, and automated-decision requirements. Marketing and communications follow separate Korean rules.
13.12 Mainland China, Hong Kong, Macao, and Taiwan
Where mainland China’s Personal Information Protection Law (PIPL), Cybersecurity Law, Data Security Law, and related measures apply, Q•NAQ will identify a statutory basis, provide separate consent where required, minimise processing, conduct personal-information protection impact assessments, maintain entrusted-processor controls, implement rights, and complete the applicable security assessment, standard contract filing, certification, localisation, or other transfer mechanism.
If PIPL Article 53 or another rule requires an entity or representative in mainland China, Q•NAQ must establish or appoint one and publish and file the accurate details before covered processing. This statement is not a substitute. Algorithmic recommendation, deep-synthesis, generative-AI, content, and human-resources rules may impose separate notices, labels, filings, opt-outs, or security duties.
Hong Kong’s Personal Data (Privacy) Ordinance, Macao’s Personal Data Protection Act, and Taiwan’s Personal Data Protection Act are distinct regimes. Q•NAQ will provide their required collection statements, use limitations, access and correction procedures, direct-marketing controls, security, cross-border safeguards, and local contacts according to scope.
13.13 Singapore and Southeast Asia
Where Singapore’s Personal Data Protection Act 2012 applies, Q•NAQ will maintain an accountable data-protection function, notify purposes, use consent or a permitted exception, provide access and correction, protect personal data and cease retaining it when retention is no longer necessary, assess overseas transfers, notify qualifying breaches, and follow the Do Not Call and Spam Control regimes where applicable.
Country-specific rules also include Indonesia Law No. 27 of 2022 on Personal Data Protection and electronic-system regulations; Malaysia’s Personal Data Protection Act 2010 as amended, including operative 2024 reforms and implementing measures; the Philippines Data Privacy Act of 2012 and implementing rules; Thailand’s Personal Data Protection Act B.E. 2562; and Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP effective from 1 January 2026.
Q•NAQ will separately assess local representative or data-protection-officer duties, electronic-system registration, breach deadlines, consent form, localisation, transfer filing, data-subject rights, language, and regulator contact in Indonesia, Malaysia, the Philippines, Thailand, Vietnam, Brunei, Cambodia, Laos, Myanmar, and Timor-Leste before covered processing.
13.14 Türkiye
Where Personal Data Protection Law No. 6698 (KVKK) applies, Q•NAQ will provide the Article 10 disclosure, identify an Article 5 or 6 processing condition, address special-category data, honour Article 11 rights, implement current international-transfer mechanisms, assess controller registration, and cooperate with the Personal Data Protection Authority. Turkish notice and consent will be separated where required.
13.15 Middle East and North Africa
Relevant regimes may include the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection and distinct DIFC or ADGM rules where applicable; Saudi Arabia’s Personal Data Protection Law and Implementing Regulations; Israel’s Privacy Protection Law 5741-1981 as amended, including Amendment 13 from its effective date; Qatar Law No. 13 of 2016; Bahrain Law No. 30 of 2018; and privacy or electronic-transactions rules in Kuwait, Oman, Jordan, Egypt, Morocco, Algeria, and Tunisia.
Q•NAQ will assess local controller or representative registration, Arabic, Hebrew or French notice, consent, data-protection officer, localisation, government access, security, marketing, child-data, sensitive-data, and transfer-approval requirements. Where local law requires prior approval or infrastructure that is not in place, Q•NAQ will restrict the affected processing rather than rely on this Policy alone.
13.16 Central Asia and the Caucasus
Applicable frameworks include Kazakhstan’s personal-data and informatisation laws, Uzbekistan’s Law on Personal Data and localisation measures, Georgia’s 2023 Law on Personal Data Protection, and privacy or personal-data rules in Kyrgyzstan, Tajikistan, Turkmenistan, Armenia, and Azerbaijan. Q•NAQ will implement required consent, notice, database registration, localisation, local contact, security, rights, and cross-border controls before covered processing.
13.17 Africa
Where South Africa’s Protection of Personal Information Act 4 of 2013 (POPIA) applies, Q•NAQ will meet the processing conditions, provide notice, maintain security and operator contracts, handle access, correction, objection and deletion, comply with cross-border rules, direct-marketing restrictions, breach notification, and applicable Information Regulator registration or Information Officer duties.
Where Nigeria’s Data Protection Act 2023 applies, Q•NAQ will implement lawful basis, transparency, data-subject rights, security, incident, impact assessment, data-protection officer, registration, and transfer duties according to classification and guidance. Where Kenya’s Data Protection Act 2019 applies, Q•NAQ will assess controller or processor registration, rights, impact assessment, breach, sensitive-data, child-data, and transfer requirements.
Q•NAQ will also assess applicable privacy and data laws in Ghana, Rwanda, Uganda, Tanzania, Senegal, Côte d’Ivoire, and other African countries before targeted processing. A regional reference does not merge distinct national regimes.
13.18 Other jurisdictions and legal change
Q•NAQ will provide a country-specific notice, consent, representative, localisation, registration, assessment, language, or rights mechanism where required before the relevant processing. If a mandatory local rule conflicts with this Policy, it prevails for the covered person and processing. A future Policy update does not retroactively validate processing that lacked a required legal basis or control when it occurred.
14. Children
The Platform is intended for adults aged 18 or older and is not directed to children. Q•NAQ does not knowingly collect personal data from a child through an Account. If Q•NAQ learns that a child used the Platform contrary to this rule, Q•NAQ will take appropriate steps to restrict the Account and delete data unless retention is legally required.
A person who believes a child’s data has been submitted should contact legal@qnaq.pro.
15. Third-party links and integrations
A user may choose to follow a link or connect an independent service. The third party’s privacy notice controls its independent processing. Q•NAQ is not responsible for that processing, although Q•NAQ remains responsible for integrations and processors to the extent law imposes that responsibility.
16. Changes to this policy
Q•NAQ may update this Policy for legal, product, provider, security, or operational reasons. The effective date will change. Q•NAQ will provide reasonable notice of a material change and obtain new consent where law requires it. A change will not retroactively make previously unlawful processing lawful.
17. Contact and complaints
NAQ Systems Limited
18 Mallow Street Upper, Limerick, V94 N12Y, Ireland
Company number: 812051
Email: legal@qnaq.pro
Website: qnaq.com
Please write Privacy Request in the subject line. Q•NAQ will try to resolve a complaint directly. A person may also contact the competent regulator or court without first complaining to Q•NAQ where the law allows.
Appendix A — detailed processing record
This Appendix gives additional transparency about standard processing. It is not a substitute for Q•NAQ’s internal record of processing activities, data-protection impact assessment, transfer assessment, security documentation, or product-specific notice.
| Activity | Data ordinarily involved | Purpose and expected result | Typical recipients | Typical retention reference |
| Account registration and login | Name, email, role, credentials, authentication and device signals | Create an Account, authenticate, prevent takeover, apply settings | Hosting, authentication, security, email providers | Account relationship; security logs under Section 9 |
| Employer verification | Legal person or registered entrepreneur, authority, domain, contact and verification evidence | Confirm Employer eligibility; reduce impersonation, fraud, unlawful Listings, and payment abuse | Verification, fraud, support, professional advisers | While verified and for a reasonable evidence period |
| Candidate Profile | Natural-person identity, professional history, skills, education, location, preferences, uploaded Content, visibility | Publish and make the profile searchable through the registered-user interface | Registered users; public or search engines only if separately enabled and disclosed; hosting and search providers | Active period; archive and deletion under Section 9 |
| Job Listing | Employer identity, role, requirements, location, compensation if supplied, Content | Publish and make the Listing searchable and manageable | Registered users; public or search engines only if separately enabled and disclosed; hosting and search providers | Active period; archive and deletion under Section 9 |
| Contact unlock and Contact Request | User identifiers, contact fields, visibility or authorisation setting, credit or order, request, approval or rejection log | Deliver controlled paid access only where legally authorised, or transmit and administer a discretionary request | Relevant users, payment/support systems | Contract, authorisation, privacy-control and dispute evidence under Section 9 |
| Messaging and applications | Sender, recipient, message, attachment, timestamps, delivery and abuse signals | Deliver communications and maintain safety | Relevant users, hosting, communications, moderation providers | Account need, complaint or legal hold under Section 9 |
| Paid Features and credits | Product, target Publication, price, currency, tax, provider ID, acceptance, activation, consumption, expiry | Form and perform the order; issue invoices; calculate and report tax; prevent fraud; and resolve or defend disputes | Stripe or payment provider, tax, accounting, fraud, advisers | Contract, tax, fraud and consent periods under Section 9 |
| Cancellation or withdrawal | Consumer name, order or service identifier, electronic confirmation channel, statement content, submission date and time, acknowledgement and outcome | Receive and prove a cancellation or withdrawal request; acknowledge it; stop or reverse affected performance and payment where required | Support, email, billing and payment providers; advisers or authorities where lawfully required | Contract, cancellation, tax, refund and claim periods under Section 9 |
| Premium, VIP, Highlight, Boost | Product status, target, start/end or event, ranking/display logs | Apply the selected visibility treatment and prove delivery | Search/ranking, hosting, analytics limited by consent | Order and dispute evidence under Section 9 |
| AI generation and assistance | Prompt, selected Content, output, safety and quality signals | Generate or improve requested text or other assistive output | AI provider, hosting, safety providers | Until the requested output is delivered and any user-requested history ends; safety or evaluation records only for the period required by the documented risk and legal purpose |
| Matching and ranking | Search, filters, profile or Listing attributes, relevance, recency, quality, safety, promotion status | Order or recommend relevant Content and maintain marketplace integrity | Search, analytics, safety providers | Operational logs under Section 9 |
| Moderation and notices | Content, report, legal basis, reviewer notes, decision, appeal, repeat-abuse signals | Address unlawful or prohibited Content and provide redress | Affected users, moderators, advisers, authorities where lawful | Appeal, safety, legal and DSA periods under Section 9 |
| Customer support and calls | Account, correspondence, issue, recordings only after required notice or consent | Diagnose issues, respond, train support where lawfully disclosed | Support, communications, professional providers | Support and call periods under Section 9 |
| Analytics and cookies | Consent, device or browser ID, page, event, campaign, diagnostic data | Measure performance or campaigns only according to category and choice | Analytics, tag, error-monitoring providers | Cookie register and consent records |
| Security and fraud | IP, device, login, rate, payment and behaviour signals, alert, investigation | Prevent attacks, bots, fake Accounts, unauthorised payments and abuse | Security, payment, hosting, advisers, authorities where lawful | Risk-based log and investigation periods under Section 9 |
Appendix B — privacy request verification standard
Q•NAQ will verify a request proportionately to the sensitivity and risk of disclosure or deletion. Verification may include confirmation from the Account email, a logged-in control, order or Publication identifiers, and narrowly tailored additional evidence. Q•NAQ will not request an identity document merely because it is convenient, and will redact or delete verification evidence when no longer needed.
Q•NAQ will search systems reasonably likely to contain responsive data, coordinate with processors, protect another person’s rights, explain a full or partial refusal, and provide an appeal or regulator route where required. Removal from registered-user or separately enabled public display, deletion from active systems, expiry from isolated backups, and continued lawful retention of fraud, tax, or claim records may occur on different timelines. Q•NAQ will not represent that a backup was immediately overwritten if it was instead isolated from ordinary use pending scheduled rotation.