IDEAS ARE ASSETS

Privacy Policy

This Privacy Policy was last updated on 13th August 2026 and relates to the operation of the qipvortex.com website (the “website”).

1. Who we are

This Privacy Policy explains how QIPVORTEX LIMITED (“we”, “us”, “our”), a company registered in England and Wales under company number 16238761, with registered office at 2 Beacon Close, Stone, Aylesbury, England, HP17 8YH, collects and uses your personal data when you use qipvortex.com and the QIP Vortex service (the “Service”).

We are the data controller for the personal data described in this policy.

Contact for privacy matters: support@qipvortex.com.

2. What this policy covers

This policy covers the personal data we handle when you create an account, submit content to be certified, pay for the Service, and receive certificates and emails from us. It also explains your rights and how to exercise them.

3. The personal data we collect

Account data

  • Username
  • Email address
  • Full name
  • Phone number
  • The nature of your account (standard user, subscriber, or Genesis founder)
  • A securely hashed version of your password (we never store your password in readable form)
  • Account timestamps (when your account was created and last updated)

Certificate (“Bind”) data — the details you provide when you ask us to certify a piece of work:

  • Creator name, creator email and creator phone (as the claimed creator shown on the certificate)
  • The title and description you give for the work
  • The cryptographic hash (“the Bind”) generated from your file
  • Certificate metadata and timestamps

Payment and account-balance data

  • Your Stripe customer and subscription identifiers
  • Subscription status and billing period information
  • Your remaining certificate credits, coin balance and account balance

Transactional email data

The recipient email address and the type of email sent to you (for example, a welcome email or a response to an email sent to our support@qipvortex.com address).

What we do not collect. We do not use analytics, advertising or tracking technologies including cookies (save as set forth at Section 12), on the website. We do not build profiles of you, and we do not collect your postal address or date of birth although we do ask you to confirm that you are at least 18 years of age when you apply for a User ID. Like most websites, our web servers keep technical logs (which can include IP addresses and browser information) purely for security and troubleshooting. These logs are kept on a limited rolling basis and automatically overwritten, are not linked to your account, and are not used for any other purpose.

4. The content of files you upload — our “zero-storage” approach

When you submit a file to be certified, we read its contents only in short term memory to generate the cryptographic hash and your certificate. We do not retain the content of your uploaded file. Your uploaded file is deleted once your certificate has been generated and, in any event, any unclaimed upload is removed within 24 hours.

We do keep the resulting certificate and the hash, together with the certificate details you provided (such as the creator name and the title/description). We keep these so that we can re-issue your certificate and support verification — but we do not keep the original file's content itself.

5. How we collect your personal data

  • Directly from you — when you register, log in, complete the upload form, or contact us by other means.
  • From our payment provider (Stripe) — customer and subscription identifiers are returned to us when you pay.
  • Automatically — only limited technical data: record timestamps (for example, when your account or a certificate was created) and the server security logs described in section 3. We do not use analytics or tracking technologies.

6. Why we use your personal data, and our lawful basis

What we doPersonal data usedLawful basis (UK GDPR Art. 6)
Create and secure your account; log you inUsername, password hash, roleContract
Provide the certification serviceCreator details, title/description, hashContract
Show the claimed creator on your certificateCreator name/email/phoneContract
Take payment and manage your subscriptionStripe IDs, billing statusContract
Track your credits, coins and balanceBalance fieldsContract
Send you transactional emails (e.g. welcome, certificate delivery)Email addressContract
Keep the Service and accounts secure (including server security logs)Account and session data; technical logsLegitimate interests (a “recognised legitimate interest” for network and information-system security under the Data (Use and Access) Act 2025)
Comply with our legal obligationsAs relevantLegal obligation

7. Who we share your personal data with

We do not sell your personal data or otherwise provide it to third parties for direct marketing purposes. We share it only with the service providers that help us run the Service:

  • Stripe — payment processing. Stripe receives the data needed to take payment (such as your name, email and payment details). Card details are handled by Stripe and are not stored on our servers. See Stripe's own privacy policy for how it processes your data.
  • Microsoft (Microsoft 365 / Microsoft Graph) — email delivery. Receives the recipient email address and the content of the email sent to you.
  • Our hosting provider, Google Cloud — provides the infrastructure on which our servers and database run, under our control.

We do not use a content-delivery network, analytics provider, or third-party tracking scripts. We may also disclose personal data where the law requires us to.

8. International data transfers

Some of our providers are based outside the UK. In particular, Stripe is a US-headquartered company (with UK and EU entities), and Microsoft processes data across its global infrastructure.

Where personal data is transferred outside the UK, it is protected by UK-approved safeguards: Stripe under its Data Processing Agreement and Microsoft under its Data Protection Addendum, in each case incorporating the UK International Data Transfer Agreement and/or the UK Addendum to the EU Standard Contractual Clauses. This means your data receives protection that is not materially lower than under UK law.

9. How long we keep your personal data

  • Uploaded file content — never retained. It is deleted once your certificate has been generated and, for any unclaimed upload, within 24 hours (see section 4).
  • Certificates, Binds and certificate details — retained indefinitely, including after your account is closed. The purpose of a Certificate is durable, independently verifiable proof: we must keep the Bind record to verify certificates already issued and to protect the integrity of the Service for everyone who relies on it.
  • Account data — kept while your account is open. When your account is closed, we delete or anonymise your account data within 30 days, except data we must keep longer (payment records below, and certificate records above).
  • Server security logs — kept on a limited rolling basis and automatically overwritten as new entries arrive.
  • Payment records — retained as required for accounting and tax purposes (ordinarily 6 years under UK law).

We review our retention approach periodically.

10. Your rights

Under UK data protection law you have the right to:

  • Access the personal data we hold about you and request a copy of the personal data which we hold (a Data Subject Access Request).
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”), in certain circumstances.
  • Restrict or object to our processing, in certain circumstances.
  • Data portability — receive certain data in a portable format.
  • Withdraw consent, where we rely on consent (we generally rely on contract, not consent).

To exercise any of these rights, contact us at support@qipvortex.com. We will respond as soon as reasonably possible. In the case of a Data Subject Access Request we will normally respond within 30 days. However we may ask you to verify your identity, and — where the law allows — we may ask for clarification to carry out a reasonable and proportionate search; if we do, the time limit of thirty days pauses until you respond. In exceptional circumstances we reserve the right to extend the 30 day time limit to a maximum of 90 days.

11. Complaints

If you are unhappy with how we have handled your personal data, please contact us first at support@qipvortex.com so we can try to put things right. We will acknowledge your complaint within 7 days and respond to the detail of your complaint without undue delay.

You also have the right to complain to the UK regulator, the Information Commissioner's Office (ICO): ico.org.uk · helpline 0303 123 1113.

12. Cookies

We use only strictly necessary cookies to run the Service:

CookiePurposeLifetimeType
qip_tokenKeeps you logged in (user session)24 hoursStrictly necessary
qip_admin_tokenKeeps administrators logged in24 hoursStrictly necessary

These cookies are essential for the Service to work, so they are exempt from the consent requirement and we do not show a cookie banner. We do not use analytics, advertising or tracking cookies. If we ever introduce non-essential cookies, we will ask for your consent first.

13. Security

We take the security of your data seriously. Measures include:

  • Passwords stored using strong one-way hashing (bcrypt); we never store passwords in readable form.
  • Session tokens delivered as HttpOnly cookies, with separate, isolated administrator sessions.
  • Internal system endpoints blocked from public access.
  • Encrypted connections (HTTPS/TLS) for data in transit.

No system is completely secure, and we cannot guarantee absolute security, but we work to protect your data using appropriate technical and organisational measures.

14. Children

The Service is not intended for children. You must be 18 or over to use it. We do not knowingly collect personal data from children.

15. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the “Last updated” date. Significant changes will be highlighted on the site and, where appropriate, notified to you by email.

16. Contact us

QIPVORTEX LIMITED · Email: support@qipvortex.com