- No advertising trackers. No retargeting.
- No optional analytics cookies. Only strictly necessary security/session technologies.
- For Workspace Data, the verified Workspace Owner determines the purposes of processing as Controller, and SOMEPASS acts as Processor (see DPA).
1. Who we are
This Privacy Policy describes how SOMEPASS (“we”, “us”) processes personal data when you use Qualigio at https://www.qualig.io, its tenant subdomains, related pages and any native companion application we provide.
SOMEPASS — 58 rue Lycette Darsonval, 50000 Saint-Lô (France) — SAS (société par actions simplifiée) — SIREN: 837 519 404 — SIRET: 837 519 404 00029 — RCS: Coutances 837 519 404
2. Controller and Processor roles
Depending on the context, we may act as:
- Controller for public website visitors, direct subscribers, account administration, billing and direct contacts.
- Processor for Workspace Data processed on behalf of the verified Workspace Owner.
The Workspace Owner may be an individual professional or an organization and is responsible for deciding which business, quality or compliance records are entered into the Services.
For Processor obligations and procurement details, see our DPA.
3. Data we process
We process data depending on how you use the Services:
| Category | Examples | Typical source |
|---|---|---|
| Account & identity | Name, email, username, Workspace affiliation and role (such as member or Administrator) | Provided by you, the Workspace Owner or a selected sign-in provider |
| Workspace content | Forms, quality records, evidence, workflows, actions, reviews, dashboards and attachments | Provided by users within the workspace |
| Subscription & billing | Plan, subscriber identity, billing contact, invoices and payment status; payment credentials are handled by the selected payment provider when enabled | Provided by the subscriber and generated through the Services |
| Support & contact | Form messages, support requests, metadata needed to respond | Provided by you |
| Technical & security | IP address, device/browser info, request logs, timestamps, security signals | Collected automatically (server/CDN/security) |
| Mobile application | Session tokens, operating system, application version, locale and device label , encrypted local cache and push-notification registration token | Generated by the application and your device when you sign in or enable the relevant feature |
Sensitive data: We do not intentionally collect special-category data. Please avoid entering sensitive information into free-text fields unless strictly necessary and lawful.
4. Purposes & legal bases
We process personal data for:
- Service delivery (accounts, access control and Workspace features).
- Security & abuse prevention (bot protection, fraud prevention, DDoS mitigation, incident investigation).
- Reliability & maintenance (debugging, performance, operational monitoring).
- Support communications (responding to requests, service-related emails).
- Legal compliance (responding to lawful requests, accounting obligations where applicable).
GDPR legal bases (when applicable): contract, legitimate interests (security/reliability), legal obligations, and consent only if we introduce optional features requiring it.
5. Sessions, sign-in providers & Cloudflare
We use cookies and similar technologies only when strictly necessary for security and service delivery. We do not use advertising cookies and we do not set optional analytics cookies.
Sign-in providers
If you choose Apple, Google, Microsoft, LinkedIn, SomePass or an institution-provided identity service, we exchange the identifiers, email address, profile attributes and security tokens needed to authenticate you. The selected provider also processes data under its own terms and privacy policy. Apple Private Relay addresses are accepted; a separate verified academic address may be requested only when an academic domain or institution relationship must be confirmed.
Native companion applications
A native application stores session credentials in encrypted storage on your device so that it can restore your session. Access and refresh tokens are limited in duration and can be revoked.
Recently accessed Workspace records may also be cached in encrypted device storage. These cached records expire after no more than 14 days and are cleared when you sign out through the application. Camera or photo-library access is used only when you choose to capture or attach an image.
Biometric unlocking is performed by the operating system; we do not receive or store your fingerprint, face template or other raw biometric data.
If notifications are enabled, Firebase Cloud Messaging processes a device registration token and the technical data needed to deliver a notification. We also retain the platform, application version, locale and optional device label associated with that token. The token is removed from your account when you sign out successfully and may also be removed when it is invalid or stale. Notification content is limited to what is needed to alert you and route the application.
Cloudflare
We use Cloudflare for DNS/CDN and security (WAF, DDoS mitigation, bot protection). Cloudflare processes technical data (e.g., IP address, request headers, security signals) to deliver and protect the Services. As a global provider, some processing may occur outside the EEA; where required, appropriate safeguards apply (e.g., SCCs).
6. Sharing & subprocessors
We share personal data only as necessary to operate the Services:
- Service providers (processors) used for hosting, transactional email and CDN/security.
- Administrators and authorized members of your Workspace, according to their roles and the Workspace Owner’s instructions.
- Sign-in or optional integration providers selected by you or the Workspace Owner, under their own terms where applicable.
- Legal requirements (lawful requests, enforcement of rights).
We do not sell personal data. For Workspace Data processing and our subprocessor list, see the DPA.
7. Retention
We retain data only as long as necessary for the purposes above, Controller instructions and contractual or legal obligations. The Workspace Owner controls the active lifecycle of Workspace Content.
- Account data: while the account is active, followed by a restricted closure period needed to process deletion, disputes and security.
- Workspace Content: while the Workspace is active and afterwards only as instructed by the Controller, required by the agreement, or needed for a documented export/deletion process.
- Billing and accounting records: for the statutory period applicable to the relevant transaction.
- Support requests and security logs: for a limited period proportionate to follow-up, fraud prevention and incident response.
- Mobile sessions and local data: access tokens normally expire after one hour and refresh tokens after 30 days unless revoked sooner; encrypted cached Workspace records expire after no more than 14 days.
- Backups: until overwritten through the documented backup lifecycle; restored data remains subject to the same deletion controls.
8. Your rights & how to contact us
Depending on your location, you may have rights such as access, rectification, deletion, restriction, portability, and objection. Where we rely on consent, you may withdraw it.