Cookie Policy
This Cookie Policy explains how NAQ Systems Limited (Q•NAQ, we, us, or our) uses cookies, software development kits (SDKs), pixels, tags, local storage, session storage, device identifiers, and similar technologies (collectively, Technologies) on qnaq.com and related applications that link to this Policy (the Platform).
It should be read with the Privacy Policy. English (US) identifies the language of this version, not its territorial reach.
1. What these technologies do
A cookie is a small file stored by a browser. SDKs, pixels, tags, and local storage can perform similar functions in websites or applications. A Technology may be set by Q•NAQ (first party) or by a provider whose service Q•NAQ uses (third party).
Technologies may recognize a browser or device, maintain a secure session, remember preferences, prevent fraud, process payment, diagnose errors, measure performance, understand use, or support advertising where deployed and lawfully enabled.
2. Categories
| Category | Purpose | Default treatment where consent is required |
| Strictly necessary | Authentication, session continuity, security, fraud prevention, load balancing, consent records, checkout, payment routing, and features expressly requested by the user | Active because the Platform or requested feature cannot operate securely without them |
| Functional | Remember language, display, accessibility, workflow, or other optional convenience settings | Off until consent if local law requires consent |
| Analytics and performance | Measure use, diagnose journeys, understand feature performance, and improve the Platform | Off until consent where required |
| Advertising and targeting | Measure campaigns, limit frequency, create or use audiences, or support cross-context behavioral advertising if deployed | Off until valid consent or opt-in where required |
| Social or external media | Enable optional embedded content or sharing functionality if deployed | Off until consent where required |
Classifying a Technology as necessary depends on its actual purpose and configuration, not its provider or label. Q•NAQ does not treat optional analytics or advertising as necessary merely because it benefits the business.
3. Current technology register
The Platform’s Cookie Settings serve as the current user-facing, item-level register of Technologies deployed for the relevant configuration. Before Q•NAQ activates a nonessential Technology where consent is required, the register provides the information described below for each relevant item.
- The register identifies the cookie, SDK, tag, pixel, storage key, or comparable identifier.
- The register identifies the provider and states whether the Technology is first-party or third-party.
- The register identifies the Technology's category and specific purpose.
- The register describes the information the Technology reads or writes.
- The register states whether the Technology is session-based or persistent.
- The register states the Technology's maximum duration or expiration.
- The register identifies the available consent or opt-out control.
The register must reflect the live Platform configuration. A generic provider list does not replace an item-level register where law requires one.
4. Providers that may use technologies
Depending on the feature actually deployed and the user’s choices, Q•NAQ may use the Technologies and providers described below.
- Q•NAQ may use its own Technologies for authentication, security, preferences, consent records, and Platform functions.
- Q•NAQ may use Technologies provided by Stripe for secure checkout, payment authentication, fraud prevention, and payment continuity.
- Q•NAQ may use Technologies provided by Google Analytics for optional analytics and measurement.
- Q•NAQ may use Google Tag Manager to deploy and control tags, but only according to the consent state and configured purpose of each underlying tag.
- Q•NAQ may use Technologies provided by Sentry for error, performance, security, and diagnostic monitoring, configured to minimize unnecessary personal data.
- Q•NAQ may use Technologies provided by CloudTalk if an optional call or support widget is deployed.
- Q•NAQ may use Technologies provided by OpenAI only if an AI Feature uses browser-side Technologies or an embedded component. Ordinary server-to-server AI processing is described in the Privacy Policy and is not automatically classified as a cookie.
Not every listed provider necessarily sets a cookie or uses another Technology for every user. The item-level register in Cookie Settings controls for the actual deployment, purpose, category, provider, and duration.
5. Consent and choice
5.1 Prior consent
In countries that require prior consent, Q•NAQ will not set or access nonessential Technologies until the user makes an affirmative choice. Continuing to browse, accepting the Terms, or using a necessary feature is not consent to optional Technologies.
5.2 Consent banner
The banner or first-layer control will provide clear, equally accessible choices to accept or reject nonessential Technologies and a route to granular settings. Optional categories will not be preselected where prohibited.
5.3 Withdrawal
A user can revisit Cookie Settings through the persistent Cookie Settings link or a comparable application control. Withdrawing consent is as easy as giving it and operates prospectively. After withdrawal, Q•NAQ stops future optional storage or access and deletes or expires stored identifiers where technically feasible and legally required.
5.4 Necessary Technologies
Strictly necessary Technologies cannot generally be disabled through the Preference Center because they support a requested service, security, or consent record. A user can block them in browser settings, but parts of the Platform may not function.
Necessary does not mean anonymous. Authentication, security, payment, fraud-prevention, load-balancing, and consent Technologies may process an Account identifier, IP address, device or session signal, transaction reference, or another item that is personal data under applicable law. Q•NAQ’s interface will not state categorically that necessary Technologies never process personally identifiable or personal data.
5.5 Legitimate interests and equivalent bases
Q•NAQ relies on legitimate interests or another non-consent basis for a Technology only where local law permits that basis for the actual purpose. Q•NAQ does not rely on legitimate interests to bypass EU/EEA or UK consent requirements for nonessential storage or access.
6. Global Privacy Control and U.S. state opt-outs
Where an applicable U.S. state law requires it, Q•NAQ treats a valid Global Privacy Control or other recognized opt-out preference signal as a request to opt out of sale, sharing, targeted advertising, or comparable covered processing for the browser or device and, where Q•NAQ can reasonably associate it, the Account.
Q•NAQ does not operate as a data broker or sell personal data as an unrestricted standalone data product. Some U.S. laws define sale or sharing broadly enough to cover particular analytics, advertising, or controlled paid-disclosure configurations even when personal data is not sold as a conventional data product. Q•NAQ addresses controlled contact disclosures in the Privacy Policy. For each covered configuration, Q•NAQ determines whether a statutory exception applies. If no exception applies, Q•NAQ provides the required Do Not Sell or Share My Personal Information or equivalent control, honors a valid preference signal, and completes any required assessment. Q•NAQ does not require unnecessary identity verification for a browser-level opt-out.
7. Duration
Session Technologies expire when the browser or application session ends. Persistent Technologies remain until their stated expiration, deletion by the user, withdrawal-driven deletion where applicable, or replacement by a newer record.
Q•NAQ configures durations according to necessity and data minimization. Exact current durations are displayed in Cookie Settings. Q•NAQ does not use a vague range such as “session to several years” as a substitute for item-level disclosure.
Consent and refusal records may be retained longer than an optional analytics identifier because Q•NAQ needs to remember the user’s choice and demonstrate compliance. The Privacy Policy gives further retention information.
8. Browser, device, and provider controls
A user can delete or block cookies through browser or device settings. Blocking all cookies may prevent login, checkout, security, and preference functions. Browser “Do Not Track” signals are handled only where a law or published Q•NAQ setting gives them legal or operational effect; Global Privacy Control is treated as described in Section 6.
Third-party providers may offer their own controls. Using a provider opt-out does not necessarily remove existing cookies from the device, and deleting cookies may also delete the recorded Q•NAQ preference, requiring the user to choose again.
9. Mobile applications and SDKs
If Q•NAQ offers a mobile application, it may use SDKs or device permissions for authentication, security, notifications, diagnostics, analytics, camera or file upload, or other requested functionality. The application will request operating-system permission where required. Optional analytics, advertising, precise location, microphone, camera, contacts, or similar access will follow applicable consent and platform rules.
10. Security and fraud technologies
Q•NAQ and its providers may use necessary device, network, authentication, rate-limit, bot, and payment-risk Technologies to protect Accounts, users, and transactions. These controls may assess IP address, device configuration, session behavior, prior abuse, payment signals, and authentication results.
Such processing is limited to security, fraud prevention, compliance, and service integrity and is further described in the Privacy Policy. Where a law gives a right to explanation or human review of a significant automated decision, Q•NAQ will provide it.
11. Changes to technologies or this policy
Q•NAQ may change providers, Technologies, categories, purposes, or durations. Q•NAQ updates the item-level register before or when a change is deployed. If a change materially expands an optional purpose or makes prior consent insufficient, Q•NAQ requests a new choice before the changed use where required.
The effective date of this Policy will be updated for material revisions. A change to this Policy does not by itself authorize a new optional Technology.
12. Regional cookie, tracking, and marketing rules
The rules below are non-exhaustive and apply only where their territorial and material scope is met. References include amendments, implementing measures, official decisions, and replacement rules in force from time to time. A country not named is governed by its own mandatory law.
12.1 European Union and EEA
Under national laws implementing Directive 2002/58/EC, storing or accessing information on a user’s device generally requires prior informed consent unless the operation is strictly necessary to transmit a communication or provide a service expressly requested by that user. Regulation (EU) 2016/679 applies to the related personal-data processing. Consent must be freely given, specific, informed, unambiguous, demonstrable, and as easy to withdraw as to give. Reject and accept choices will be presented without deceptive design or an unnecessary imbalance.
12.2 United Kingdom and Switzerland
The UK Privacy and Electronic Communications Regulations 2003, UK GDPR, and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, apply where in scope. Q•NAQ obtains prior consent for nonessential storage or access unless a current statutory exception applies to the specific Technology and all conditions for that exception are met. Swiss telecommunications, data-protection, and unfair-competition rules apply according to the actual Technology and communication. Q•NAQ does not assume that an EU configuration automatically satisfies every UK or Swiss requirement.
12.3 United States
Where a U.S. state defines a Technology-enabled disclosure as sale, sharing, targeted advertising, profiling, or processing of sensitive data, Q•NAQ will provide the applicable notice, opt-out or opt-in, appeal, and signal recognition. A valid Global Privacy Control will be honored where legally required. Q•NAQ will assess children’s and teen data separately and will not use this Policy to claim parental or age-specific consent that was not actually obtained.
State wiretap, session-replay, biometric, precise-location, health-data, and employment-monitoring rules may impose consent or notice beyond a general cookie banner. Q•NAQ will not deploy such a Technology based solely on generic analytics consent.
12.4 Canada and Latin America
Canadian consent, privacy, anti-spam, and provincial requirements apply to the actual identifier and purpose. In Mexico, Brazil, Argentina, Chile, Colombia, Peru, Uruguay, Ecuador, Costa Rica, Panama, and other Latin American markets, the Privacy Policy and any required Spanish or Portuguese notice will identify cookies and comparable identifiers, purposes, recipients, choices, and international transfers. Consent will be obtained where the applicable data or communications law requires it.
12.5 Australia and New Zealand
The Australian Privacy Act and Australian Privacy Principles, Spam Act, New Zealand Privacy Act, and Unsolicited Electronic Messages Act apply according to scope. Q•NAQ will provide transparency and direct-marketing controls and will not treat consent to a cookie category as consent to receive electronic marketing where separate permission is required.
12.6 India and South Asia
Indian processing through cookies and comparable identifiers is governed by the Information Technology regime and by the Digital Personal Data Protection Act 2023 and Rules 2025 as their provisions commence. Q•NAQ will update notices, consent records, withdrawal, child-data, security, erasure, and grievance controls by each statutory commencement date. Applicable electronic-communications, cybercrime, and privacy rules in Pakistan, Bangladesh, Sri Lanka, Nepal, Bhutan, and Maldives also apply before targeted deployment.
12.7 Japan, South Korea, and Greater China
Japan’s APPI and telecommunications rules, South Korea’s PIPA and communications laws, mainland China’s PIPL and related consent and cross-border rules, Hong Kong’s Personal Data (Privacy) Ordinance, Macao’s Personal Data Protection Act, and Taiwan’s Personal Data Protection Act apply according to scope. Separate consent, local-language notice, domestic transfer records, overseas-transfer information, or local controls will be used where required.
12.8 Singapore and Southeast Asia
Singapore’s PDPA and Spam Control Act, Indonesia’s Personal Data Protection Law and electronic-system rules, Malaysia’s PDPA as amended, the Philippines Data Privacy Act, Thailand’s PDPA, and Vietnam’s Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP apply to covered identifiers and transfers. Q•NAQ will not deploy a nonessential tag in a market until required consent, notice, registration, localization, or transfer controls are configured.
12.9 Türkiye, Middle East, and Africa
Türkiye’s KVKK and electronic-commerce rules, UAE and Saudi data-protection laws, Israel’s privacy and communications laws, Qatar and Bahrain data laws, South Africa’s POPIA, Nigeria’s Data Protection Act, Kenya’s Data Protection Act, and other local regimes may regulate device identifiers, direct marketing, cross-border processing, and consent. Q•NAQ will implement any required local-language notice, representative appointment, data protection officer appointment, registration, or opt-out before covered deployment.
13. Contact
Send questions or complaints about Technologies to the contact below.
NAQ Systems Limited
18 Mallow Street Upper, Limerick, V94 N12Y, Ireland
Company number: 812051
Email: legal@qnaq.pro
Website: qnaq.com