This Privacy Policy (the "Policy") explains how the Quorify platform, at usequorify.com and via its associated mobile app (together, the "Platform" or "Service"), collects, uses, discloses, stores and protects personal data, and the rights you have. It applies to website visitors, account holders, organization members, recruitment applicants, Formular 230 donors, and anyone else whose data is processed through the Platform.
1. Who we are and legal framework
1.1. The Platform is operated by Quorify ("Quorify", "we", "us", "the controller"). Contact us at contact@usequorify.com.
1.2. Data Protection Officer (DPO). We have appointed a DPO: Patriciu Roșată, at contact@usequorify.com (mark "attn. DPO"). A DPO is mandatory because the Platform processes the national identification number (CNP) at scale via Formular 230, per Art. 4 of Law 190/2018.
1.3. Applicable law. We process data under: (a) Regulation (EU) 2016/679 ("GDPR"); (b) Romanian Law 190/2018, notably Art. 4 on CNP; (c) Law 506/2004 (e-Privacy); (d) Law 363/2018; and (e) other applicable Romanian and EU law.
1.4. Supervisory authority. The competent authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), Bucharest, tel. +40.318.059.211, anspdcp.ro.
2. Our roles: controller and processor
2.1. The Quorify ecosystem involves several processing roles; our capacity depends on the activity.
2.2. Quorify as controller. We are controller for: your account and profile data; billing and subscription data; public-visitor data (blog, "Discover" marketplace, calculator, contact form); Platform security and audit logs; administrative and, where applicable, marketing communications.
2.3. Quorify as processor. We process on behalf of other, independent controllers where: (a) member data is processed for the member's organization (the organization being controller); and (b) Formular 230 donor data is processed for the beneficiary NGO (the NGO being controller). Such processing is governed by the Data Processing Agreement (or 230 DPA).
2.4. Independent third-party controllers. Certain providers (e.g. Stripe for payment data) act, for their own fraud-prevention and compliance purposes, as independent controllers under their own policies.
3. Categories of data we collect
3.1. Identification & account data. Email; password (stored only as a hash, never in clear text); Google OAuth identifier and tokens (if you use Google sign-in).
3.2. Authentication security data. One-time codes (OTP) sent by email; two-factor (TOTP) secret and recovery codes (if you enable 2FA); session tokens and metadata (device, sign-in time).
3.2.1. Push-notification data. If you enable push notifications in your browser or app, we store your device's push subscription (the browser-provided endpoint and the technical p256dh/auth keys), solely to deliver the notifications you requested. You can disable them anytime in your browser/device settings.
3.3. Profile data. First/last name, phone, photo/avatar, country, city, university/faculty, study year, bio, preferences (theme, language).
3.4. Telemetry & security data. IP address (SHA-256 hashed where feasible for minimization); browser/device type and user-agent; login and session history; data derived for rate limiting and abuse prevention.
3.4.1. Activity & online-status data. To power the optional "online" indicator, we record the timestamp of your last activity on the platform (last seen). Members of your organizations may see a simple online/offline indicator next to your name (online = active in the last few minutes). This is behavioral data processed on the basis of our and your organization's legitimate interest in collaboration; you can turn it off at any time in Settings → Privacy ("Show my online status"), in which case you always appear offline to others. We store only the single most recent timestamp, not a browsing history.
3.4.2. Language detection and approximate location. On your first visit to the public site, we infer the display language (Romanian/English) from the country associated with your IP address, via Vercel's location header (x-vercel-ip-country). We do not store the IP address for this purpose and do not determine a location more precise than country. Your manual language choice always prevails and is remembered in the functional NEXT_LOCALE cookie (see the Cookie Policy). Basis: legitimate interest/functional necessity to display the site in the appropriate language.
3.5. Consent records. Your cookie category choices, with the IP hash and timestamp, to evidence consent.
3.6. Organization & member data (where Quorify is generally a processor): membership of organizations/federations/departments, role and join date; member tags; internal admin notes about members (visible to administrators); governance data (events and sessions, attendance recorded via dynamic QR codes, votes - including secret or nominal ballots, quorum rules and records, minutes, Google Calendar/Meet integrations); financial data (fee structures, payments and fee status, organization bank/IBAN details); recruitment data (forms, answers, CVs, stage decisions); tasks and projects; communications (announcements, feed posts, notifications); uploaded documents and resources, including private member documents (e.g. volunteer agreement, ID document).
3.7. Formular 230 data (high-risk). Donor's national ID number (CNP), stored encrypted (AES-256-GCM); name, father's initial; full address; phone; email; the 2-year option; the donor's signature; the generated PDFs. See Sections 5.7 and 9.
3.8. Payment & billing data. Payments are processed by Stripe; Quorify does not see or store full card data. We retain billing and subscription data (name, payment status, transaction history, invoices).
3.9. Public-visitor data. Contact forms (name, email, message, IP hash); emails collected via the savings calculator; blog view counts and rate limiting; banner and modal interactions.
3.10. Special categories. Except CNP (see Section 9), the Platform is not designed to process special categories of data under Art. 9 GDPR. Please do not upload such data in free-text fields or documents unless strictly necessary and legally permitted.
4. Purposes and legal bases
4.1. We process only for specified purposes with an appropriate basis (Art. 6 / Art. 9 GDPR):
- Providing the Service - Art. 6(1)(b), performance of a contract.
- Security, fraud/abuse prevention, integrity of attendance and voting - Art. 6(1)(f), legitimate interest.
- Legal obligations (accounting, tax, archiving, authority requests) - Art. 6(1)(c).
- Proof of cookie consent - Art. 6(1)(c) with 6(1)(f).
- Analytics/marketing cookies, marketing communications, calculator leads - Art. 6(1)(a), consent (withdrawable anytime).
- Formular 230 - CNP processing - Art. 6(1)(a), the donor's explicit consent, with Art. 4 of Law 190/2018.
- Member data - on the organization's (controller's) instructions under the DPA.
4.2. Where we rely on legitimate interest, we ensure it does not override your rights; request our balancing assessment at contact@usequorify.com.
4.3. Aggregated and anonymized data. We may create and use aggregated, anonymized data (that does not identify you) for statistics, benchmarks, developing new features and improving the Service, including automated and artificial-intelligence features. This data is not personal data under the GDPR. Basis: legitimate interest (Art. 6(1)(f) GDPR).
5. Retention periods
5.1. We keep data only as long as necessary (Art. 5(1)(e) GDPR); then securely delete or anonymize it. Full detail: Data Retention Policy.
5.2. Account/profile data: life of account; deleted on account deletion.
5.3. OTP/session tokens: max 30 days.
5.4. Audit / activity logs: tiered retention, between 12 months and 5 years depending on the type of event (routine 12 months; noteworthy changes 24 months; critical events — security, financial, governance, destructive actions — 5 years).
5.5. Financial data/invoices: 10 years (fiscal).
5.6. Member documents & admin notes: until member removal, then secure deletion.
5.7. Formular 230 data (CNP, PDFs): 5 fiscal years + 1 year, then automatic secure deletion; earlier on donor request.
5.8. Unsuccessful recruitment applicants: 6 months after decision.
5.9. Contact forms: 12 months.
5.10. Calculator leads: 24 months or until consent withdrawal.
5.11. Consent records: 3 years.
5.12. Push-notification subscriptions: until disabled or the subscription expires.
6. Disclosure and access
6.1. Quorify staff - strictly necessary, role-based access, under confidentiality and access controls.
6.2. Organizations you belong to - independent controllers of member data; their administrators may access your member data to administer the organization.
6.3. Sub-processors. We use third-party providers under processing agreements and security safeguards: Supabase (database, auth, storage), Vercel (compute, CDN, edge), Resend (transactional email), Upstash (Redis cache, rate limiting), Google LLC (OAuth; Analytics, Ads, Tag Manager, Search Console; Calendar and Meet APIs), Microsoft Corporation (Office document rendering on preview) and Stripe Inc. (payment processing). Full, maintained list with roles and transfer mechanisms: Sub-processor List.
6.4. Authorities and legal requirements. We may disclose data where legally required, on a legitimate authority request, or to defend our rights, prevent fraud, or protect the safety of persons.
6.5. Reorganizations. On a merger, acquisition or asset transfer, data may pass to the new entity, maintaining the protection level and informing you as required.
6.6. We do not sell your personal data.
7. International transfers
7.1. Data is hosted primarily in the European Union / EEA (Supabase; Upstash - Ireland).
7.2. For US-based sub-processors (Vercel, Resend, Google, Microsoft, Stripe), transfers rely on the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, supplemented by additional technical and organizational measures (encryption in transit and at rest, minimization/pseudonymization, access controls). Request a copy of the safeguards at contact@usequorify.com.
8. Your rights
8.1. Under GDPR you have the rights of access (15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), to withdraw consent at any time (without affecting prior lawful processing), and not to be subject to automated decisions, incl. profiling (22).
8.2. Automated decisions. Quorify makes no automated decisions producing legal or similarly significant effects on you. Platform reports/statistics are aggregate and are not individual profiling with legal effect.
8.3. Exercising rights. (a) In-platform - profile editing (rectification), data export (access/portability) and account deletion (erasure) in Settings; (b) via contact@usequorify.com. We may request reasonable information to verify your identity. We respond within one month, extendable by two months for complex requests, with notice.
8.4. Data processed by your organization or the 230 NGO. Where Quorify is processor, exercise your rights toward that controller; we will forward the request and assist.
8.5. Complaints. You may complain to ANSPDCP (anspdcp.ro) and seek judicial remedy.
9. Formular 230 and CNP processing (Law 190/2018 Art. 4)
9.1. The Formular 230 feature lets donors redirect a share of income tax to a non-profit.
9.2. Roles. The beneficiary NGO is the controller of donor data; Quorify is processor, generating and transmitting the form. Quorify does not file with ANAF and does not handle money.
9.3. Basis. CNP is processed solely on the donor's explicit consent (Art. 6(1)(a) GDPR), per Art. 4 of Law 190/2018.
9.4. Specific safeguards. AES-256-GCM encryption with an isolated key; role-based access restriction; access logging; data minimization; a designated DPO; limited retention (Section 5.7). The full donor notice is shown at CNP entry: 230 Donor Privacy Notice.
10. Minors
10.1. The Platform is for persons aged at least 18 and is not intended for minors. We do not knowingly collect data of persons under 18. If you learn a minor has provided data, contact contact@usequorify.com for deletion.
11. Data security
11.1. We implement appropriate technical and organizational measures: AES-256-GCM encryption for CNP; TLS in transit; row-level security (RLS) and access controls; pseudonymization (IP hashing); audit logging; backup and recovery; two-factor authentication available. Details: Security page and Security & Responsible Disclosure Policy.
11.2. Breach notification. For a breach likely to risk individuals' rights, we notify ANSPDCP within 72 hours and data subjects where legally required; as processor, we notify the controller without undue delay.
12. Cookies
12.1. We use strictly necessary, functional and - on consent only - analytics/marketing cookies, via a banner with equally easy accept/reject and no pre-ticked boxes. Full detail: Cookie Policy.
13. Changes to this Policy
13.1. We may update the Policy periodically; version and effective date appear in the header. Material changes are communicated via the Platform and/or email at least 15 days before taking effect. Continued use after the effective date constitutes acceptance.
14. Contact
14.1. Controller: Quorify · usequorify.com · contact@usequorify.com. DPO: Patriciu Roșată · contact@usequorify.com. Supervisory authority: ANSPDCP · anspdcp.ro · +40.318.059.211.