Privacy Policy
Last updated: 2026-10-10b
This policy explains which personal data Qlyne, operated by [company name], handles and why. It covers two groups of people: account holders, and the visitors of the sites that use Qlyne.
Account holders (we are the controller)
- Data: account ID, site name, your e-mail, dashboard users (name, e-mail and password hash) and the settings you save. Our servers also keep technical logs (IP address, time, request) for security.
- Purpose: create and run your account, send service e-mails (confirmation, password, important changes) and keep the Service secure. Legal basis: performing our contract with you and our legitimate interest in security.
- Retention: while the account exists. After it is closed, we delete the data within 30 days; backups roll over within another 30 days. Data the law requires us to keep is kept for as long as required.
Visitors of the sites that use Qlyne (we are the processor)
The owner of the site is the controller of this data. On the owner's behalf, and only to provide the Service, we process:
- the IP address (for IPv6, often only the /64 prefix) and the browser's user agent, to count requests per address, keep a visitor's place in line, tie tokens to the browser and check challenges;
- random session identifiers and signed tokens, in the waiting room and in cookies on the site:
qlyne_pass_<event>(waiting room pass),qlyne_clr(challenge clearance) andqlyne_bs(bot score). These cookies are needed for the protection to work; - one-way hashes of the IP address, and of the IP address with the user agent, when the site limits how many visitors are on it at once;
- what the site sends with a queue entry, such as a user ID;
- with login protection, when the site owner turns it on: the username typed, only as a hash, to count tries per account; and the password, which never leaves the connector and is never stored: the connector computes its SHA-1 and sends Have I Been Pwned only the first 5 characters, shared by hundreds of passwords (k-anonymity), to learn whether it appears in breaches;
- with the bot score, when the site owner turns it on: a summary the script on the page sends about the browser (whether it reports automation; how many languages, plugins, processor cores and touch points; screen size; whether it has a time zone) and counts of pointer moves, clicks, keys, scrolls and touches. It holds no keys, text or pointer positions. The score made from it stays in the
qlyne_bscookie for 30 minutes, tied to the IP and the browser, and is not stored on our servers; the form captcha uses the same counts to decide whether to ask for a click; - with the form captcha (Qlyne Verify): the IP address (the /64 for IPv6), the time and the page's origin, kept with the token for 5 minutes, only so the site can check the token once and compare the IP;
- examples of protection decisions (block, challenge, limit, sent to the waiting room), so the site owner can check the rules on the Events screen: time, action, rule, method, host and path (without the query string), IP address, user agent and, with the Cloudflare connector, country and autonomous system number (ASN). At most 5 of each action every 10 seconds, not every request, and only the account owner sees them.
Counters shown in the dashboard are totals per hour. Besides the action, they count requests by page path (without the query string), user agent and IP address (the /64 network for IPv6) and, with the Cloudflare connector, by country and network (ASN), so the site owner can see where traffic goes and comes from on the Analytics screen and block an address that abuses the site. Only the account owner sees them. Retention: a place in line lasts at most 2 hours; tokens and per-address counters expire with their time window (from seconds to a few hours); decision examples are kept for 7 days, up to 1,000 per account; hourly counters are kept for 8 days, except the counts per IP address, kept for 7 days and queue snapshots for 30 days.
Shared reputation, where we are the controller: while a site reports attacks (on by default, and the owner can turn it off), we keep the IP address (the /64 for IPv6) of visitors caught there by the scanner trap or the managed rules, with a high bot score, driving an automated browser or refused by the form captcha, together with the identifier of the site owner's account, for 24 hours. Addresses reported by at least two accounts go on a list sent to the connectors of the sites that use it, without the reporting site, the account or what happened. Legal basis: our legitimate interest in preventing fraud and keeping networks and systems secure (LGPD, articles 7, IX and 10; GDPR, article 6(1)(f) and recital 49). To object, or to ask about an address, write to [contact e-mail].
Visitors should send questions about their data to the site they visited; we help the site owner answer them. The connector runs in the site owner's own Cloudflare account, where Cloudflare's processing is covered by the owner's agreement with Cloudflare.
Sharing
We do not sell personal data or use it for advertising. We share it only with the providers we need to run the Service (hosting and e-mail delivery), under contracts that protect it, and when the law requires it. The current list of providers is available on request.
International transfers
Our providers may process data outside your country. When that happens, we rely on the safeguards the law provides, such as standard contractual clauses.
Security
Connections are encrypted (HTTPS), secrets are stored encrypted, access to the servers is restricted, and we keep only the data the Service needs.
Your rights
You can ask to access, correct, export or delete your data, and to object to or restrict its use, under laws such as Brazil's LGPD and the European Union's GDPR. Write to [contact e-mail]. You can also complain to your data protection authority.
Changes
Changes are published on this page, and account holders are told by e-mail about material ones.
Contact: [company name], [contact e-mail].