1. Scope and Who We Are

This Privacy Policy explains how Qordio, referred to as “Qordio”, “we”, “us”, or “our”, collects, uses, discloses, stores, and protects personal information when you visit qordio.com, create or use a Qordio account, access a workspace or client portal, connect Google Drive, subscribe to a paid plan, communicate with us, or otherwise use our websites, applications, and related services, collectively the “Services”.

For account, billing, security, website, and product usage information, Qordio generally acts as the data controller or business. For project, task, client, comment, attachment, and other workspace content submitted by an organization or workspace customer, Qordio generally acts as a service provider or data processor on that customer’s instructions. The customer remains responsible for the lawfulness of the information it submits and for providing any notices required to its users, employees, clients, or other individuals.

By using the Services, you acknowledge the practices described in this Privacy Policy. This Privacy Policy should be read together with Qordio’s Terms and Conditions and any additional notice displayed when a particular feature is used.

2. Information We Collect

2.1 Account and profile information

  • Name, email address, password hash, profile image, job title, organization name, time zone, language, and other profile details you choose to provide.

  • Account role, workspace membership, permissions, invitations, and authentication information.

  • Information received when you use a supported single sign on or third party login method, such as your name, email address, profile identifier, and profile image, according to the permissions you approve.

2.2 Workspace and service content

  • Workspace names, project information, tasks, subtasks, statuses, priorities, due dates, sprints, boards, templates, comments, mentions, notifications, time and activity records, and custom fields.

  • Client portal information, including client names, email addresses, messages, shared project information, and access permissions.

  • Files, attachments, file names, links, metadata, and other content uploaded to Qordio managed storage or connected from a third party storage provider.

  • Support requests, feedback, survey responses, product suggestions, and communications with us.

2.3 Billing and transaction information

When you purchase a paid plan or add on, we collect billing contact details, subscription plan, invoice information, payment status, transaction identifiers, tax information, and limited payment method details. Full card numbers are generally collected and processed by our payment processor and are not stored by Qordio.

2.4 Device, usage, and log information

  • Internet Protocol address, browser type, device type, operating system, referring page, approximate location derived from an Internet Protocol address, and device identifiers.

  • Login times, pages and features used, clicks, searches, actions performed, error logs, crash reports, performance data, and security events.

  • Cookie identifiers and similar technology data, as described in Section 11.

2.5 Information from other users and sources

Workspace owners, administrators, or other users may provide your information when they invite you, assign work, mention you, add you as a client, or otherwise use the Services. We may also receive business contact information from service providers, integration partners, public sources, and fraud prevention providers where permitted by law.

3. Google Drive and Google API Data

Qordio allows users to connect Google Drive as an optional integration. Qordio does not access Google Drive until a user initiates the connection and grants permission through Google’s authorization screen. The exact permission scopes requested are shown by Google before authorization. Qordio seeks to use the minimum permissions reasonably necessary to provide the selected Drive features.

3.1 Google information Qordio may access

  • Basic Google account information, such as your name, email address, profile image, and Google account identifier, when required to identify or display the connected account.

  • OAuth authorization tokens and related connection information needed to maintain the integration.

  • Google Drive file and folder identifiers, names, types, sizes, web links, ownership or permission metadata, modification timestamps, and other metadata required to display, select, organize, or synchronize files.

  • The content of files that you select, create, upload, download, preview, attach, or otherwise instruct Qordio to process through the integration.

3.2 How Google information is used

  • To connect your Google Drive account to Qordio and confirm which Google account is connected.

  • To let you select, create, upload, download, preview, link, attach, organize, or manage Drive files and folders within Qordio.

  • To maintain file links and metadata associated with tasks, projects, comments, and workspaces.

  • To synchronize user requested changes, diagnose integration errors, prevent abuse, and provide support.

3.3 Storage and handling of Google Drive data

When Google Drive is selected as the storage destination for a file, the file is stored in the user’s Google Drive. Qordio may store the file identifier, file name, link, type, size, and related metadata in Qordio’s database so that the file can remain associated with the relevant workspace item. File content may pass temporarily through Qordio’s systems to complete an action requested by the user, such as an upload, download, or preview. Qordio does not permanently copy Google Drive file content into Qordio managed storage solely because Google Drive is connected, unless the user separately chooses a feature that clearly creates or uploads a copy to Qordio managed storage.

OAuth tokens are treated as confidential credentials and are stored using access controls and encryption or equivalent security protections. We do not disclose tokens to workspace users or unrelated third parties.

3.4 Limited Use and prohibited uses

Qordio’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Qordio does not sell Google user data. We do not use Google Drive data for advertising, retargeting, unrelated marketing, credit decisions, surveillance, or the creation of advertising profiles. We do not use Google Drive content to train general purpose artificial intelligence or machine learning models. We do not allow human access to Google user data except when necessary with the user’s affirmative consent for support, to investigate security or abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations in a way that cannot reasonably identify an individual.

3.5 Disconnecting and deleting Google data

You may disconnect Google Drive from Qordio through the integration settings, where available, or revoke Qordio’s access through your Google Account permissions. Disconnecting stops future access and causes Qordio to delete or invalidate the stored authorization token within a reasonable period. Workspace records that contain a Drive file name, link, or activity history may remain until the relevant record or account is deleted, but the linked file may no longer be accessible through Qordio.

Deleting a Qordio account or requesting deletion results in deletion of Google authorization tokens and Google derived metadata in accordance with Section 7. Files stored in your Google Drive are controlled by you and generally remain in Google Drive unless you delete them or explicitly instruct an authorized feature to delete them.

4. How We Use Information

  • Provide, operate, maintain, and improve accounts, workspaces, boards, tasks, collaboration, client portals, storage, integrations, exports, and other requested features.

  • Authenticate users, manage permissions, process invitations, and protect accounts.

  • Process subscriptions, payments, invoices, credits, plan changes, storage or seat add ons, and account administration.

  • Send service messages, security alerts, billing notices, product updates, support responses, and communications requested by users.

  • Personalize settings and remember preferences.

  • Monitor performance, troubleshoot errors, analyze feature usage, conduct quality assurance, and develop new features using aggregated or appropriately protected data.

  • Detect, prevent, investigate, and respond to fraud, misuse, security threats, policy violations, and unlawful activity.

  • Comply with legal obligations, enforce agreements, resolve disputes, and protect the rights, safety, and property of Qordio, users, and others.

  • Send marketing communications where permitted by law. You may opt out of marketing emails at any time, but you will continue to receive essential service communications.

5. Legal Bases for Processing

Where data protection law requires a legal basis, Qordio relies on one or more of the following:

  • Performance of a contract, to provide the Services requested by you or your organization.

  • Legitimate interests, such as operating and improving Qordio, securing the Services, communicating with customers, preventing fraud, and supporting business operations, provided those interests are not overridden by your rights.

  • Consent, including when you connect an optional integration, accept certain cookies, or choose to receive particular marketing communications. You may withdraw consent at any time, without affecting prior lawful processing.

  • Compliance with legal obligations, including tax, accounting, regulatory, law enforcement, and dispute related requirements.

  • Protection of vital interests or other lawful grounds recognized under applicable law.

6. How We Share Information

We may share information only as reasonably necessary for the purposes described in this Privacy Policy:

  • With workspace owners, administrators, members, clients, and invited users according to the permissions and sharing choices configured in the Services.

  • With cloud hosting, storage, content delivery, authentication, communications, analytics, customer support, error monitoring, security, billing, and payment service providers that process information for us under contractual or other safeguards.

  • With integration providers when you direct us to connect or exchange information with their services. Their own privacy terms also apply.

  • With professional advisers, auditors, insurers, and financing partners where reasonably necessary and subject to confidentiality obligations.

  • With courts, regulators, law enforcement, government authorities, or other parties when required by law or reasonably necessary to protect rights, safety, security, prevent fraud, or enforce agreements.

  • In connection with a merger, financing, acquisition, reorganization, sale of assets, insolvency, or similar business transaction, subject to appropriate confidentiality and notice where required.

  • With your consent or at your direction.

We may use and disclose aggregated or deidentified information that cannot reasonably be used to identify you. We do not sell personal information in exchange for money. We do not sell or share Google user data for advertising purposes.

7. Data Storage, Retention, and Deletion

7.1 Storage locations

Qordio and its service providers may process and store information in countries where they operate. Qordio managed file storage may use cloud object storage, such as Amazon Simple Storage Service or an equivalent provider. Google Drive files remain subject to the storage location and controls of the user’s Google account when Google Drive is selected.

7.2 Retention

We retain personal information for as long as necessary to provide the Services, maintain legitimate business records, comply with legal obligations, resolve disputes, enforce agreements, and protect security. Retention depends on the data type, the account status, workspace settings, contractual requirements, and applicable law.

  • Active account and workspace data is generally retained while the account or workspace remains active.

  • When an account or workspace is deleted, associated active data is generally scheduled for deletion within 30 days, unless a longer period is required by law, needed to resolve a dispute, or requested by the customer under an agreed retention setting.

  • Encrypted backups may retain deleted information for up to 90 days before being overwritten or securely removed. Backup data is isolated from normal use and restored only for disaster recovery, security, or legal purposes.

  • Billing, tax, audit, fraud prevention, and transaction records may be retained for the period required by applicable law or legitimate business needs.

  • Google authorization tokens are deleted or invalidated after disconnection or account deletion within a reasonable period, subject to short term logs and backups.

7.3 Deletion and export

Account owners may use available export and deletion controls or contact us. Workspace administrators may be able to delete content created by members. Deleting a Qordio record does not necessarily delete a file stored in a third party service such as Google Drive, and deleting a third party file may leave an inaccessible link or activity entry in Qordio.

8. Security

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. Measures may include encryption in transit, encryption or equivalent protections for sensitive credentials, access controls, least privilege practices, logging, monitoring, backups, vulnerability management, and incident response procedures.

No system can be guaranteed completely secure. You are responsible for using a strong password, protecting authentication devices and codes, reviewing workspace permissions, and promptly notifying us of suspected unauthorized access. If a security incident affects personal information and notification is required, we will provide notice in accordance with applicable law.

9. International Data Transfers

Your information may be transferred to and processed in countries other than the country where you live. Those countries may have different data protection laws. Where required, Qordio uses appropriate safeguards for international transfers, which may include contractual protections, recognized transfer mechanisms, access controls, and data minimization. You may contact us for more information about applicable safeguards.

10. Your Privacy Rights and Choices

Depending on your location and applicable law, you may have rights to access, correct, update, delete, restrict, object to, or obtain a portable copy of personal information. You may also have the right to withdraw consent, opt out of certain marketing, complain to a data protection authority, or appeal a decision concerning a privacy request.

  • Account details may be reviewed or updated through your profile and settings.

  • Marketing emails may be disabled using the unsubscribe option in the message.

  • Google Drive access may be revoked through Qordio integration settings or your Google Account permissions.

  • Cookie choices may be managed through the cookie banner, where available, and browser settings.

  • Account deletion or other privacy requests may be submitted to support@qordio.com.

We may need to verify your identity and authority before completing a request. For workspace content controlled by an organization, we may refer the request to the relevant workspace customer or administrator. Rights are subject to exceptions under applicable law, including security, legal claims, record retention, and the rights of others. We will not discriminate against you for exercising a privacy right.

11. Cookies and Similar Technologies

Qordio may use cookies, local storage, pixels, software development kits, and similar technologies to operate the Services, keep users signed in, remember preferences, measure performance, understand product usage, prevent fraud, and support communications. These technologies may be set by Qordio or by service providers acting on our behalf.

  • Strictly necessary technologies support login, security, load balancing, and core functions.

  • Preference technologies remember settings such as language, time zone, and interface choices.

  • Analytics technologies help us understand how the Services perform and which features are used.

  • Marketing technologies, if used, support campaign measurement and are enabled only as permitted by law and available consent controls.

Blocking some technologies may affect functionality. Browser based “Do Not Track” signals are not interpreted consistently across the industry. Where required by applicable law and technically supported, Qordio will honor recognized opt out preference signals.

12. Workspace Administrators and Customer Data

A workspace owner or administrator may control membership, permissions, content, integrations, retention, exports, and account access. Administrators may be able to access, modify, export, suspend, or delete information associated with a managed workspace. If your Qordio account is provided by an employer, client, school, or other organization, that organization’s policies and instructions may apply to your use of the workspace.

Customers must not use Qordio to collect or process personal information unlawfully. Customers are responsible for obtaining required permissions, providing privacy notices, responding to individuals, and configuring access appropriately. Qordio processes customer controlled workspace data according to the customer’s instructions, the agreement, and applicable law.

13. Children’s Privacy

The Services are designed for business and professional use and are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information without appropriate authorization, contact us and we will take reasonable steps to delete it.

14. Third Party Services and Links

The Services may contain links to, embed, or integrate with third party websites and services, including Google Drive, payment processors, and communication tools. Qordio does not control their privacy practices. Information you provide directly to a third party is governed by that third party’s terms and privacy policy. Review those policies before authorizing an integration or submitting information.

15. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Services, legal requirements, security practices, or data handling. The updated version will be posted with a revised effective date. If a change materially affects how we use personal information, including Google user data, we will provide additional notice and obtain consent where required before using the information for a materially different purpose.

16. Contact Us

Questions, privacy requests, complaints, and requests concerning Google Drive data may be sent to:

Service

Qordio

Website

https://qordio.com

Email

support@qordio.com

Please include enough information for us to identify the relevant account and understand your request. Do not send passwords, full payment card information, OAuth tokens, or other authentication secrets by email.