Privacy Policy
Table of Contents
- Introduction & Scope
- Definitions
- Data Controller & Contact Information
- Information We Collect
- Information We Do NOT Collect
- Legal Basis for Processing (GDPR)
- How We Use Your Information
- Data Sharing & Disclosure
- Data Retention
- Data Security
- Locally-Generated Artifacts & User Content
- Cookies & Tracking Technologies
- International Data Transfers
- Your Rights Under GDPR
- Your Rights Under CCPA/CPRA
- Your Rights Under Other Privacy Laws
- Children's Privacy (COPPA)
- Third-Party Services & Links
- Data Breach Notification
- Do Not Track Signals
- Automated Decision Making & Profiling
- Data Protection Officer
- Changes to This Privacy Policy
- Governing Law
- Contact Information
1. Introduction & Scope
Quima ("Company," "We," "Us") is committed to protecting the privacy of our users. This master Privacy Policy describes how we collect, use, process, store, share, and protect information across the entire Quima suite — Quima Control, Quima Builder, Quima Loader, Quima Dropper, and Quima LNK Packer — when you visit our website, purchase or license any of our products, create an account, use our Software, contact our support team, or otherwise interact with us.
Each product additionally maintains its own product-specific Privacy Policy (Quima Control, Quima Builder, Quima Loader, Quima Dropper, and Quima LNK Packer); to the extent any product-specific Policy conflicts with this master Policy, the product-specific Policy controls for that product.
This Policy applies worldwide, including the EEA, the UK, California, Brazil, Canada, South Africa, Australia, and all other jurisdictions with applicable data-protection legislation.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data.
- "Data Controller" means the entity that determines the purposes and means of processing.
- "Data Processor" means the entity processing Personal Data on behalf of the Controller.
- "GDPR" means the General Data Protection Regulation (EU) 2016/679.
- "CCPA" means the California Consumer Privacy Act, as amended by the CPRA.
- "COPPA" means the Children's Online Privacy Protection Act.
- "HWID" means Hardware Identification, a unique identifier derived from hardware components.
- "User Content" means any payload content, file content, recipient data, target list, credential, agent communication, server data, uploaded asset, generated hosted page, share link, campaign configuration, visit metric, or other input you supply to or generate with any Quima product or service.
3. Data Controller & Contact Information
For data we collect directly from you (Section 4), the Data Controller is Quima. For Quima Control self-hosted server data and Quima Builder local-only build content, YOU are generally the independent Data Controller. For content you intentionally upload into Quima-hosted workflows such as Loader or Dropper dashboards, Quima may act as a controller or processor for the hosted service data needed to provide that service, while you remain responsible for the lawfulness of the underlying campaign, recipient, or target data you choose to use.
- Telegram: @QuimaDEV
- Email: QuimaDEV@proton.me
4. Information We Collect
4.1 Account & Purchase Information
- Username or display name;
- Email address (if provided);
- Payment transaction IDs (we do NOT store full credit card numbers, CVVs, or banking details);
- Purchase date and subscription type;
- Communication platform identifiers (Discord ID, Telegram username, XMPP address).
4.2 License & Authentication Data
- License key;
- Hardware Identification (HWID) — a hashed identifier derived from your hardware components;
- Authentication timestamps;
- IP address at the time of license authentication;
- License status (active, expired, suspended, revoked).
4.3 Technical & Usage Data
- Software version number;
- Operating system type and version;
- Anonymized error/crash reports (no User Content included);
- Aggregated, anonymous feature-usage statistics (which builder modules are used, in aggregate).
4.4 Communication Data
- Content of your messages to support;
- Communication-platform metadata (timestamps, message IDs);
- Any attachments, screenshots, or files you voluntarily share.
4.5 Website Analytics
- IP address (truncated where applicable);
- Browser type and version, device type, OS;
- Pages visited, referrer, session duration;
- This information is processed in aggregate for site improvement.
4.6 Hosted Service Data
- Files, templates, or artifacts you upload to Quima-hosted Loader or Dropper workflows;
- Generated hosted pages, share links, build metadata, and dashboard configuration tied to your account;
- Basic delivery and visit telemetry such as timestamps, IP address, browser/user-agent, referrer, status, and view/download counters for hosted links or pages;
- Operational logs required to secure, troubleshoot, and maintain hosted service availability.
5. Information We Do NOT Collect
To preserve user privacy, the Company does NOT collect by default:
- The contents of any Quima Control self-hosted server data or Quima Builder local-only artifacts that never pass through Quima-operated infrastructure;
- Recipient lists, target lists, or credentials beyond the data you intentionally upload or configure inside a hosted Quima workflow;
- Payload commands or embedded configurations beyond what is required to store, render, deliver, or troubleshoot a hosted Loader or Dropper workflow you explicitly create;
- Full credit-card numbers, CVVs, or banking credentials;
- Government-issued identification numbers (SSN, passport number, etc.);
- Biometric data;
- Health, religious, political, or sexual-orientation data;
- Browsing activity outside of our website.
6. Legal Basis for Processing (GDPR)
Where GDPR applies, we process your Personal Data on the following bases:
- Contract: Processing necessary to perform our license agreement with you (account, license, support).
- Legitimate Interests: Anti-fraud measures, license enforcement, abuse detection, security, product improvement.
- Consent: Where applicable (e.g., voluntary feedback or marketing communications).
- Legal Obligation: Compliance with applicable laws, tax, or law-enforcement requests.
7. How We Use Your Information
- To provide, maintain, and improve the Software and Service;
- To process your purchase and manage your license;
- To authenticate your installation via HWID and license key;
- To detect, prevent, and investigate abuse, fraud, license sharing, or violation of the Terms;
- To respond to support inquiries and communicate updates;
- To comply with legal obligations and respond to lawful requests from authorities.
8. Data Sharing & Disclosure
We do not sell your Personal Data. We may share information only in the following limited circumstances:
- Service Providers: Payment processors (e.g., Sell.app), license-management providers, hosting providers, and similar processors operating under contract;
- Legal Requirements: When required by law, court order, or to respond to a valid governmental request;
- Protection of Rights: To protect the rights, property, or safety of the Company, our users, or others;
- Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality obligations.
9. Data Retention
We retain Personal Data only for as long as necessary for the purposes for which it was collected, including:
- Account & license data: for the duration of the license plus a reasonable post-termination period for tax, accounting, and dispute-resolution purposes;
- Payment records: as required by applicable financial and tax laws (typically 5·10 years);
- Communication records: typically 24 months from last contact;
- Hosted Loader/Dropper assets, links, and dashboard data: until you delete them, your account is terminated, or a shorter operational retention window applies;
- Hosted service security and access logs: typically up to 12 months unless a longer period is required for abuse prevention or legal compliance;
- Anonymized analytics: indefinitely.
10. Data Security
We implement appropriate technical and organizational measures to protect Personal Data, including encryption in transit (TLS 1.2+), hashed credentials, restricted access, and routine security review. No method of transmission or storage is 100% secure, however, and we cannot guarantee absolute security.
11. Product-Specific User Content & Controller Roles
The Quima suite includes a mix of self-hosted, local-first, and hosted workflows:
- Quima Control runs on your self-hosted infrastructure. Quima does not have access to your Control server data unless you separately provide it to support.
- Quima Builder is a local desktop workflow. Artifacts that remain on your own device are not automatically accessible to Quima.
- Quima Loader and Quima Dropper may include hosted dashboards, uploaded assets, generated links/pages, and delivery telemetry tied to your account. Quima may store and process that hosted service data to operate the service.
Where User Content includes Personal Data of third parties, you remain responsible for establishing a lawful basis for the collection, upload, delivery, or monitoring activity you initiate, and for complying with all applicable privacy, employment, and communications laws.
Depending on the product flow, you may be the sole controller, or Quima may act as a controller or processor for the hosted service layer while you remain responsible for the underlying campaign or target data. In all cases, you are solely responsible for:
- Establishing a valid legal basis for processing;
- Providing required notices to the data subjects;
- Honoring data-subject rights (access, rectification, erasure, etc.);
- Implementing appropriate security and retention controls;
- Reporting any breach of that data to the appropriate authorities.
Quima is not responsible for unlawful targeting, unauthorized monitoring, or any third-party data you process without a valid legal basis, even where a hosted service component is used.
12. Cookies & Tracking Technologies
Our website uses minimal cookies and similar technologies, limited to: strictly necessary cookies (session management, security), preference cookies (theme, language), and aggregated analytics. We do not use cross-site advertising trackers. You may disable non-essential cookies via your browser settings.
13. International Data Transfers
Your Personal Data may be transferred to and processed in countries other than your own. Where required, we rely on appropriate transfer mechanisms (Standard Contractual Clauses, adequacy decisions) to ensure equivalent protection.
14. Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights:
- Right of Access — request a copy of your Personal Data;
- Right to Rectification — request correction of inaccurate data;
- Right to Erasure ("Right to Be Forgotten") — request deletion of your data;
- Right to Restrict Processing;
- Right to Data Portability;
- Right to Object to processing based on legitimate interests;
- Right to Withdraw Consent at any time, where processing is based on consent;
- Right to Lodge a Complaint with a supervisory authority.
To exercise any of these rights, contact us using the channels in Section 25.
15. Your Rights Under CCPA/CPRA
If you are a California resident, you have:
- The right to know what Personal Information is collected;
- The right to know whether Personal Information is sold or disclosed (we do not sell);
- The right to "say no" to the sale of Personal Information (not applicable — we do not sell);
- The right to access your Personal Information;
- The right to request deletion;
- The right to non-discrimination for exercising privacy rights.
16. Your Rights Under Other Privacy Laws
Residents of Brazil (LGPD), Canada (PIPEDA), South Africa (POPIA), Australia (Privacy Act), and other jurisdictions enjoy substantially similar rights. We will honor lawful requests in accordance with applicable local law.
17. Children's Privacy (COPPA)
The Software and Service are not directed to children under 18. We do not knowingly collect Personal Data from children under 18. If you believe we have inadvertently done so, please contact us and we will delete it.
18. Third-Party Services & Links
Our website and Service may contain links to or integrations with third-party services (e.g., payment processors, communication platforms). Those services have their own privacy policies; we are not responsible for their practices.
19. Data Breach Notification
In the event of a Personal Data breach affecting your data, we will notify affected users and the appropriate supervisory authorities without undue delay, as required by applicable law (typically within 72 hours under GDPR).
20. Do Not Track Signals
Our website does not currently respond to "Do Not Track" browser signals due to the lack of an industry-wide standard. We do, however, minimize tracking by default.
21. Automated Decision Making & Profiling
We do not engage in automated decision-making that produces legal or similarly significant effects on you. Limited automated systems are used for license enforcement and fraud detection.
22. Data Protection Officer
For data-protection-related inquiries, please contact us using the channels in Section 25 with the subject "DPO".
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the website or in-app notification. The "Last Updated" date at the top reflects the most recent changes. Continued use after changes constitutes acceptance.
24. Governing Law
This Privacy Policy is governed by the laws of the jurisdiction in which the Company is established, without regard to conflict of laws principles, except that local mandatory data-protection laws applicable to your residence will continue to apply where required. Furthermore, unauthorized access to accounts or systems without explicit target consent is strictly prohibited and unlawful. Such actions:
- Constitute a crime under the Turkish Penal Code Article 244 (Cybercrimes).
- Violate the CFAA (US), Computer Misuse Act (UK), and similar international cyber laws.
25. Contact Information
- Telegram: @QuimaDEV
- Email: QuimaDEV@proton.me
For product-specific privacy questions, please use the relevant product's contact channels (Quima Control, Quima Builder, Quima Loader, Quima Dropper· Quima LNK Packer). For privacy-related inquiries, please include "PRIVACY" in the subject of your message.
BY USING ANY PRODUCT IN THE QUIMA SUITE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.
© 2026 Quima. All rights reserved.
