Privacy Policy
1. Scope and purpose of this policy
This Privacy Policy applies to the public website at qusmos.com, including its publication and blog pages, general contact form, and demo-access form. It describes the nature, scope and purposes of processing personal data through the website and explains the rights of the people whose data is processed.
“Personal data” means information relating to an identified or identifiable natural person. “Processing” covers any operation involving personal data, such as collecting, recording, storing, using, disclosing or deleting it.
2. Controller
The controller responsible for deciding why and how personal data is processed through this website is:
Dr. Hamzeh Alavirad
QUSMOS project
Douglasstraße 36
76133 Karlsruhe
Germany
Email: h.alavirad@qusmos.com
QUSMOS is currently a project name and is not an incorporated or registered company. Dr. Hamzeh Alavirad is therefore identified as the individual controller of this website.
3. Categories of personal data
Depending on how you use the website, we may process:
- Technical and usage data: IP address, request date and time, requested page or file, referrer URL, HTTP status, data volume, browser type and version, operating system, device information and internet service provider.
- General enquiry data: name, email address, message and any other information you voluntarily include.
- Demo-request data: first name, last name, company, email address, optional telephone number, message and any other information you voluntarily include.
- Communication data: correspondence history, requested follow-up, and information needed to respond to or manage a possible business relationship.
- Consent and preference data: records showing whether and when consent was provided or withdrawn, where consent is used.
Please do not submit confidential information or special categories of personal data—such as health, biometric, political or religious information—unless it is genuinely necessary and you have agreed the appropriate communication method with us.
4. Website hosting and server log files
When you visit this website, the web server processes technical data needed to establish the connection, deliver the requested content, maintain the website, detect faults, and protect the website and underlying systems against misuse or attacks.
The categories of log data may include the technical and usage data listed in section 3. We do not use ordinary server log information to identify a visitor unless this is necessary to investigate a security incident, misuse or a legal claim.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of the website, troubleshooting, and the protection of our systems and users.
The website is hosted by IONOS SE, which processes hosting data on our behalf. For its WebHosting service, IONOS states that visitor information, including the IP address, is anonymised when collected and retained for eight weeks. IONOS also states that this visitor data is not transferred to a country outside the European Union. IONOS may perform anonymised SiteAnalytics processing as part of the hosting service.
5. General contact form and email enquiries
The general contact form currently asks for your name, email address and message. If you contact us through that form or directly by email, we process the information you submit, the time of the communication, and any technical information required to transmit and protect the form.
We use this data to understand and answer your enquiry, communicate with you, prevent misuse of the form, and document the communication where necessary.
If the enquiry is intended to enter into or perform a contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interests are responding to communications addressed to us, developing professional relationships, and keeping an appropriate record of the correspondence.
6. Demo-access requests
The demo-access form currently requests your first name, last name, company and email address. A telephone number and message may also be provided. We use this information to assess your request, contact you, prepare a relevant demonstration, arrange follow-up discussions, and manage a possible pre-contractual or business relationship.
Processing needed to respond to a demo request or take steps at your request before entering into a contract is based on Article 6(1)(b) GDPR. Where the request does not relate to a potential contract, processing is based on Article 6(1)(f) GDPR. Our legitimate interests are presenting the QUSMOS project, evaluating genuine business enquiries, and protecting the form against misuse.
The forms are provided using the Otter Blocks plug-in for WordPress. Valid submissions are stored in the WordPress database before delivery actions are performed. Depending on the form configuration, a submission may also be sent as an email notification to the configured QUSMOS recipient. Website and database storage is hosted by IONOS.
Email addressed to @qusmos.com, including form notifications sent to a QUSMOS mailbox, is received and processed using Google Workspace, provided in the European Economic Area by Google Cloud EMEA Limited.
Enquiry and demo-request data is retained only for as long as necessary to respond, manage the requested follow-up, and document a possible business relationship. It is then deleted unless a contractual relationship develops, a legal retention obligation applies, or continued storage is necessary to establish, exercise or defend legal claims.
7. Email updates and direct marketing
Messages needed to answer an enquiry or arrange a requested demo are not marketing messages. Promotional email is sent only where there is a valid legal basis. Where we rely on consent, processing is based on Article 6(1)(a) GDPR. Consent is voluntary and may be withdrawn at any time with effect for the future by emailing h.alavirad@qusmos.com or using an unsubscribe method provided in the message.
Where direct marketing is permitted on another legal basis, you may object at any time. After an objection, the relevant personal data will no longer be used for direct marketing.
8. Images delivered through Lovable
At the time this policy was reviewed, some images on qusmos.com were loaded from a lovable.app domain provided by Lovable. The relevant European provider is Lovable Labs AB.
To display these images, your browser connects directly to Lovable’s infrastructure. Lovable and its service providers may therefore receive technical data such as your IP address, browser information, referring page, requested file, and the date and time of the request.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is displaying and delivering website content efficiently. Further information is available in Lovable’s privacy information.
9. Links to LinkedIn and other external websites
The website contains ordinary links to LinkedIn profiles and may link to other third-party websites. No embedded LinkedIn feed or social-media plug-in was identified when this policy was prepared. A connection to the external provider is generally made only after you choose to follow the link.
The operator of the destination website is independently responsible for its processing. Its own privacy policy applies after you leave qusmos.com. An external link does not by itself mean that we control or endorse the destination provider’s data-processing practices.
10. Cookies and similar technologies
No public analytics, advertising, behavioural-tracking or social media plug-in was identified on the QUSMOS website when this policy was reviewed. WordPress, security measures and form functionality may nevertheless use technically necessary cookies, tokens or comparable storage to provide requested functions, maintain security, balance requests, or prevent forged submissions.
Where storing information on or accessing information from your device is strictly necessary to provide a service you explicitly request, this is permitted under § 25(2) no. 2 TDDDG. If optional analytics, advertising, embedded media, CAPTCHA, marketing or other non-essential technology is added, we will request consent in advance where required, offer appropriate settings, and update this policy.
The technical configuration is reviewed when the website or its plug-ins are changed. If a new service uses non-essential cookies or other device storage, its use and provider will be disclosed here and an appropriate consent choice will be provided before activation.
11. Recipients and service providers
Personal data is made available only to people and organisations that need it for the purposes described in this policy. Depending on the relevant processing, recipients may include:
- IONOS SE as website, WordPress and database hosting provider;
- Google Workspace as the QUSMOS email provider;
- CRM, scheduling, anti-spam or automation providers, if used;
- authorised QUSMOS project members handling the enquiry;
- professional advisers such as legal or tax advisers; and
- courts, regulators or public authorities where disclosure is legally required.
Service providers acting on our instructions process personal data under appropriate contractual arrangements, including an Article 28 GDPR agreement where required. We do not sell personal data.
12. International data transfers
If a provider processes personal data outside the European Economic Area, the transfer must be supported by a lawful mechanism. Depending on the destination and provider, this may include an adequacy decision of the European Commission, the EU Standard Contractual Clauses, or another safeguard permitted by Chapter V GDPR.
IONOS states that visitor data processed through its WebHosting service is not transferred outside the European Union. Google Workspace may use Google group companies and approved subprocessors in countries outside the EEA. Where such processing involves an international transfer, Google relies on the safeguards described in its Cloud Data Processing Addendum, including adequacy decisions or Standard Contractual Clauses where applicable. Google’s current subprocessor list provides further information.
13. Legal bases used for processing
Depending on the activity, processing may be based on:
- Article 6(1)(a) GDPR — consent: for an optional activity where you have freely provided specific consent.
- Article 6(1)(b) GDPR — contract or pre-contractual steps: for enquiries and demo requests connected with a possible or existing contractual relationship.
- Article 6(1)(c) GDPR — legal obligation: where processing is required by applicable law.
- Article 6(1)(f) GDPR — legitimate interests: for secure website operation, responding to other communications, preventing misuse, documenting business correspondence and protecting or defending legal claims, provided your interests and fundamental rights do not override those interests.
14. Retention and deletion
We retain personal data only for as long as it is needed for the purpose for which it was collected. We then delete or anonymise it unless continued storage is required by law or is necessary to establish, exercise or defend legal claims.
The applicable period depends on the data and context. Relevant factors include whether an enquiry remains active, whether a business or contractual relationship develops, statutory commercial and tax retention duties, limitation periods, and the need to investigate a security incident. IONOS states that WebHosting visitor data is retained for eight weeks. Enquiry and demo-request data is deleted when the relevant communication and any reasonable follow-up have concluded, unless one of the longer-retention reasons described above applies.
Data deleted from the active WordPress database or webspace may remain temporarily in restricted technical backups until the backup is overwritten. IONOS states that its recoverable webspace backups are available for no more than 14 days.
15. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected with regard to the nature, scope and purposes of processing, the available technology, implementation costs and the risks to individuals.
The website uses HTTPS encryption in transit. Access to personal data should be limited to authorised recipients on a need-to-know basis. No method of electronic transmission or storage can, however, guarantee absolute security.
16. Your data-protection rights
Subject to the conditions and limitations in the GDPR, you may exercise the following rights:
Access and confirmation
You may ask whether we process personal data concerning you and request access to that data and the information required by Article 15 GDPR.
Rectification
You may request correction of inaccurate personal data and completion of incomplete data under Article 16 GDPR.
Erasure
You may request deletion under Article 17 GDPR, for example where data is no longer needed, consent has been withdrawn and no other basis applies, or the data was processed unlawfully. The right does not apply where continued processing is legally permitted or required.
Restriction of processing
You may request restriction under Article 18 GDPR, including while the accuracy of data or the grounds for processing are being checked.
Data portability
Where processing is automated and based on consent or contract, you may have the right under Article 20 GDPR to receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller.
Withdrawal of consent
You may withdraw consent at any time with effect for the future under Article 7(3) GDPR. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise a right, email h.alavirad@qusmos.com. We may need to request information reasonably necessary to verify your identity and protect personal data from unauthorised access.
17. Right to object
If personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
You may object to processing for direct marketing at any time and without giving reasons. Personal data will no longer be processed for direct marketing after such an objection.
18. Right to lodge a complaint
If you believe that processing of your personal data infringes the GDPR, you may lodge a complaint with a competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the alleged infringement.
19. Whether you must provide personal data
You are not legally required to use the contact or demo forms. However, the fields marked as required are needed to transmit and respond to the relevant request. Without the required contact information, we may be unable to answer your enquiry, arrange a demo, or take requested steps toward a possible contract. Optional fields may be left blank.
20. Automated decision-making and profiling
Personal data collected through this public website is not used for decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
21. Changes to this policy
We may update this policy when the website, forms, service providers, processing activities or legal requirements change. The version published on this page is the current version. Material changes affecting an existing processing activity will be communicated where required.
