GDPR Compliance
quiXzoom is fully committed to the EU General Data Protection Regulation. We process personal data lawfully, transparently, and with your rights at the center.
Data We Process
As a crowdsourced field data platform, quiXzoom processes the following categories of personal data:
- Account Data: Name, email address, phone number, date of birth, national ID (for KYC), and profile photo
- Observation Data: Geotagged photos, videos, GPS coordinates, timestamps, and device sensor data submitted during missions
- Payment Data: Bank account details, Stripe Connect account information, and payout history
- Device Data: Camera model, OS version, app version, and device identifiers
- Usage Data: App interactions, mission history, and support tickets
Legal Basis for Processing
We process personal data based on the following legal grounds under GDPR Article 6:
- Contract (Art. 6(1)(b)): Processing necessary to perform our contract with you (providing the quiXzoom platform)
- Legal Obligation (Art. 6(1)(c)): Tax reporting, anti-money laundering, and other statutory requirements
- Legitimate Interests (Art. 6(1)(f)): Fraud prevention, platform security, and service improvement
- Consent (Art. 6(1)(a)): Marketing communications and optional data sharing
Your Data Subject Rights
Right to Access
Request a copy of all personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your data ("right to be forgotten").
Right to Restriction
Request limited processing of your data in certain circumstances.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, contact us at privacy@quixzoom.com. We respond within 30 days.
Data Retention
We retain personal data only as long as necessary for the purposes outlined above:
- Account Data: Retained for the duration of your account plus 7 years (tax/legal requirements)
- Observation Data: Retained per mission contract terms; typically 3–7 years depending on client requirements
- Payment Data: Retained for 7 years per Swedish bookkeeping laws
- Deleted Accounts: Personal identifiers are pseudonymized within 30 days; full erasure within 90 days where legally permissible
Data Protection Officer
Contact our DPO
Email: dpo@quixzoom.com
Postal: quiXzoom / Landvex AB, Data Protection Officer, Box 1234, 111 22 Stockholm, Sweden
For complaints, you also have the right to contact the Swedish Authority for Privacy Protection (IMY).
Data Processing Agreement (DPA)
Enterprise clients can request our standard Data Processing Agreement, which covers:
- Subject matter, duration, nature and purpose of processing
- Type of personal data and categories of data subjects
- Technical and organizational security measures (TOMs)
- Subprocessor list and notification procedures
- Audit rights and breach notification timelines
Request a DPA: legal@quixzoom.com
International Transfers
EU customer and Zoomer data is stored exclusively in the European Economic Area (EEA). Where third-country transfers are necessary (e.g., US-based subprocessors), we rely on:
- EU Commission adequacy decisions where applicable
- Standard Contractual Clauses (SCCs) with Transfer Impact Assessments
- Additional safeguards including encryption and pseudonymization