Qualigio — Privacy Policy

Version 2026-09-05.1 · Effective : 2026-09-05

This policy describes how SOMEPASS processes personal data for Qualigio at https://www.qualig.io, workspace subdomains and companion applications. We do not sell personal data or use advertising trackers, retargeting or optional analytics cookies. Necessary session and security technologies support access and service protection.

1. Identity and contact

The provider is SOMEPASS, 58 rue Lycette Darsonval, 50000 Saint-Lô, France. Use the privacy contact form for questions or rights requests. Our legal information page contains the company’s registration details.

SOMEPASS · SAS (société par actions simplifiée) · SIREN 837 519 404 · SIRET 837 519 404 00029 · RCS Coutances 837 519 404

2. Controller and processor roles

We act as controller for our public website, direct contacts, account administration, billing, contractual evidence and service security. For workspace data processed on an Owner’s instructions, that Owner is the Controller and we are the Processor. The DPA defines this relationship. Roles depend on the actual processing and authority, not merely on an email address or an administrator label.

3. Data and sources

Account data includes names, email addresses, usernames, roles, workspace affiliation and identifiers supplied by users, administrators or selected identity providers. Billing data includes subscriber and billing contacts, plan, invoices and payment status; the payment provider handles payment credentials. Support data includes messages and contact details. Technical data includes IP addresses, browser/device information, request timestamps and security logs. Signup contractual evidence includes accepted versions, language, date and the accepting account identifier.

Workspace data can include employees, contractors, reviewers, auditors, suppliers, customers and other persons represented in configured forms, quality records, evidence, actions, reviews, attachments and reporting data.

The service is not intended to collect special categories of personal data. Avoid entering sensitive information unless strictly necessary and lawful. Required fields are indicated in forms; without them we may be unable to create an account, provide a requested feature or respond. Optional fields can be left blank.

4. Purposes and legal bases

For our own processing, providing the subscribed service and handling pre-contract enquiries rely on the contract or steps taken at your request. Security, abuse prevention, reliability and proportionate operational support rely on our legitimate interest in operating a secure service. Accounting and legal duties rely on applicable legal obligations. Where a feature legally requires consent, it is requested separately and can be withdrawn. Workspace processing follows the Controller’s instructions and the legal basis it determines.

5. Sessions, sign-in and mobile applications

We use cookies and similar technologies necessary for sessions, sign-in and security. We do not set optional advertising or analytics cookies. Blocking necessary technologies can prevent sign-in or security features from working. If optional trackers are introduced, their use will be assessed and consent requested where required before activation.

If you choose Apple, Google, Microsoft, LinkedIn, SomePass or an institutional identity provider, we exchange the identifiers, email addresses, profile attributes and security tokens needed for sign-in. That provider also processes data under its own policy. Apple Private Relay is accepted; a separate academic address may be verified when needed to establish an institution relationship.

A companion application stores session credentials in encrypted device storage. Session metadata can include operating system, application version, locale and a device label. Biometric unlocking is performed by the operating system; we do not receive fingerprint or face templates. Access tokens normally last one hour and refresh tokens 30 days, unless revoked sooner.

Recently accessed workspace records may be cached in encrypted device storage for no more than 14 days and are cleared when you sign out through the application. Camera or photo access is used when you choose to attach an image. If push notifications are enabled, Firebase Cloud Messaging receives a device registration token and routing data. We retain associated platform, version, locale and optional device label. The token is detached on successful sign-out and may be removed when invalid or stale; notification content is limited to alerting and routing.

6. Recipients, optional AI and transfers

Recipients include providers needed for hosting, email delivery and service protection, authorized administrators and members, and optional integration providers you select. For education, authorized inter-institution activities can share necessary data with invited partners. Data may also be disclosed to comply with lawful requirements. Cloudflare provides DNS, CDN and security and processes traffic-related data such as IP addresses, headers and security signals.

An optional external assistant connection to Qualigio through MCP lets that client receive schemas and records accessible under the account’s enabled modules, permissions, fields and visibility rules. The MCP service described here is read-only. Requested content is transmitted to the connected client and may be processed by its provider under the agreement selected by the organisation. The organisation must assess recipients, purposes, retention and any transfers outside the EEA. Interconnection with PB Learning is limited to associated accounts, enabled functions and the corresponding permissions.

Technical, commercial, legal, teaching and privacy contact details, together with document references, decisions, declared capacities, dates and notification records, support contractual management, security, legal obligations and evidence of exchanges. SomePass acts as controller for this management, based on a contract where the individual is a party, applicable legal obligations and legitimate interests in managing and defending the relationship with the organisation. Access is restricted to authorised persons. Data is retained during the relationship and, where necessary, in a restricted archive for applicable statutory or legal-claims periods; retention is reviewed and deletion must respect evidentiary obligations. Acknowledging this notice does not constitute consent to processing.

Where Stripe is offered at checkout, Stripe receives the billing and payment information needed to process the transaction, manage the subscription and prevent fraud. Its role depends on the processing: it may process data on instructions or for its own regulatory and fraud-prevention duties. Its privacy policy explains these roles and international processing.

Stripe — Privacy Policy

Core hosting is in France. Some providers operate globally, including outside the EEA. Where required, transfers use an adequacy decision or Standard Contractual Clauses and additional safeguards. The DPA identifies our workspace subprocessors. You can request information about the applicable destinations, safeguards and a copy of the relevant transfer arrangements through the privacy form.

7. Retention and closure

Account and workspace records remain available for the active service and according to the Controller’s instructions. On closure, data needed for an agreed return is retained during that process, then deleted according to the DPA. Data required by a specific legal duty or a documented dispute is restricted to that purpose until the applicable obligation or limitation period ends. Contractual acceptance records follow those evidence requirements.

Accounting records follow the statutory retention period applicable to the transaction. Support records are retained for the handling of the request and any documented follow-up or dispute; security logs follow the operational rotation settings, with restricted preservation of records needed to investigate an incident or meet a legal duty. For procurement or a rights request, contact us to obtain the schedule applicable to your workspace, including return formats, deletion steps and backup rotation.

Protected backups follow the documented rotation cycle and are isolated from ordinary use. Deletion instructions are reapplied if data is restored. Mobile session and device-cache durations are described above; they do not define server-side workspace retention.

8. Your rights and complaints

Depending on the processing and applicable law, you can request access, rectification, erasure, restriction, portability or object to processing. Consent can be withdrawn without affecting earlier lawful processing. Contact the workspace Controller for processing it determines; we assist it under the DPA. For our own processing, use our privacy form. We may request proportionate identity verification to protect other users.

You may lodge a complaint with the CNIL in France or the competent supervisory authority, including in the EEA country where you live or work. This right does not require you to contact us first.

CNIL