Legal

Privacy Policy

Please read this document carefully. It explains your rights and our responsibilities when you use Qollectiv.

Last updated September 19, 202625 sections
01

Introduction and Scope

Section 1 of 25

Qollectiv, Inc. ("Qollectiv", "we", "us", or "our") is a Delaware corporation. We operate a research technology platform that connects researchers, organizations, research participants (also called respondents), and data collectors (collectively, the "Platform").

This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal information when you visit our websites, use our applications (including progressive web app / offline features where available), create an account, participate in research, verify your profile, manage an organization, collect field data, or otherwise interact with our services.

This Privacy Policy applies to Platform-level processing by Qollectiv. Individual research studies may also present study-specific privacy disclosures, consent materials, or institutional requirements. Accepting this Privacy Policy does not, by itself, constitute consent to participate in every research study, or consent to every type of data collection that a researcher may later request. Study participation remains subject to the disclosures and choices presented for that study, where applicable.

02

Qollectiv Data-Processing Roles

Section 2 of 25

Qollectiv's role may vary depending on the processing activity, the parties involved, and applicable law. We do not claim a single fixed controller/processor status for all Platform processing.

Platform-directed processing. For many Platform operations, Qollectiv determines the purposes and means of processing. Examples may include account administration, authentication, verification, fraud and security monitoring, payment and incentive administration, Platform analytics, communications preferences, eligibility and matching infrastructure, and general Platform integrity.

Researcher- or organization-directed processing. For study-specific activities, researchers or organizations may determine key purposes and means of processing, while Qollectiv provides the technology to host, transmit, store, or analyze study information on their behalf. Examples may include study questions, study-specific responses, research attachments, study eligibility criteria, study-specific participant information, and study-specific consent or disclosure materials.

In practice, roles may be shared or layered (for example, where Qollectiv processes study responses both to deliver the research service requested by a researcher and to operate fraud prevention, quality controls, or incentive systems). Where required, additional contractual terms such as a data processing agreement may apply between Qollectiv and a researcher or organization.

03

Information We Collect

Section 3 of 25

We collect information in three main ways: information you provide, information generated through use of the Platform, and information obtained from third-party providers that you authorize or that support Platform operations.

Information you provide may include:

  • Account information: name, email address, phone number, profile photo, account type (individual or organization), roles, and authentication credentials (including when you sign in through a third-party provider such as Google).
  • Demographic and profile information: details such as age, gender, education, occupation, languages, interests, sector, location, and similar attributes used for eligibility matching and research targeting.
  • Research data: survey or study responses, eligibility or screening answers, participation history, media or attachments you submit, and related study metadata.
  • Verification data: documents and related information used for phone, identity, education, employment/self-employment, or organization verification (see Section 5).
  • Organization data: organization name, registration details, sector, business address, membership roles, billing activity, wallet balances, and token or credit allocations.
  • Data-collector information: application materials, training acknowledgments, assignment activity, location or interview metadata where collected for authorized field work, and related performance records.
  • Communications information: support messages, feedback, and preference settings.
  • Payment and incentive information: top-up requests, wallet or credit balances, claim or payout requests, raffle records where offered, and transaction history. Full payment-card details are processed by payment providers and are not stored by us in full.

Information generated through use of the Platform may include:

  • Usage, device, and log information: IP address, browser type, device identifiers, session activity, feature interactions, referral sources, performance diagnostics, and security event logs.
  • Eligibility, matching, and integrity signals: verification level, fraud or duplicate-detection indicators, quality flags, and similar operational signals.
  • Locally stored or synchronized study information: where offline or progressive web app collection is supported, study packages, drafts, consent recordings, and responses may temporarily reside on an authorized device before synchronization.

Information from third parties may include:

  • Authentication providers (for example, account identifiers and basic profile details when you choose social sign-in).
  • Payment, communications, hosting, analytics, AI, identity-verification, and support providers that process information as needed to deliver their services.
  • Organization administrators or researchers who invite you, assign roles, or configure study participation.
04

Sensitive Personal Information

Section 4 of 25

Some research studies may involve sensitive or specially protected categories of personal information, depending on applicable law and the design of the study. Qollectiv does not necessarily request all such categories itself, and the examples below are illustrative rather than a statement that every category is currently collected.

Depending on the study and jurisdiction, sensitive categories may include health or disability information; ethnicity or race; religion; political opinions; sexual orientation or sexual-life information; financial circumstances; biometric information; precise location; government identifiers; employment information; or other categories protected by applicable law.

Researchers and organizations are responsible for ensuring they have an appropriate research purpose and a lawful basis or required consent before collecting sensitive personal information through the Platform. Where Qollectiv processes such information, we do so to operate the Platform, support the requested research workflow, provide verification or integrity controls, comply with law, or as otherwise described in this Privacy Policy.

05

Verification Documents

Section 5 of 25

Verification may be optional for basic use, or required for specific features, studies, incentive claims, payouts, raffles, organizational roles, or compliance needs. When you verify, we may ask you to upload documents or complete checks so we can confirm that profile information is accurate and to support fraud prevention.

Individual accounts may submit, where applicable:

  • Phone verification: confirmation of a phone number through one-time codes or similar methods (which may be delivered by SMS, WhatsApp, or other available channels).
  • Identity documents: government-issued national ID, passport, driver's licence, or country-specific identity documents such as Fayda or Kebele ID where accepted.
  • Education documents: degree or diploma certificate, transcript, school leaving certificate, or professional qualification certificate.
  • Employment or self-employment documents: employment contract, employer letter, pay stub, work permit, business or trade licence, commercial registration, or self-employment registration.
  • Other supporting documents we expressly accept for eligibility or integrity review.

Organization accounts may submit, where applicable:

  • Business licence, commercial registration, certificate of incorporation, or equivalent legal-standing documentation.
  • VAT registration certificate.
  • Taxpayer Identification Number (TIN) certificate.
  • Power of attorney or similar authorization documents where needed to confirm authority to act for the organization.

Documents may be submitted in supported formats (for example JPEG, PNG, WebP, HEIC, or PDF) subject to size and quality limits shown in the Platform. We and our service providers may use automated extraction and AI-assisted review to read fields such as name, date of birth, gender, address, education level, employer, registration numbers, and document validity indicators. Extracted information may be compared against your profile, phone verification, and other verification or integrity signals.

Automated verification is not guaranteed to be error-free. Uncertain, incomplete, or disputed results may be subject to further review, rejection, or a request that you resubmit documents. We may request reverification when reasonably necessary for fraud prevention, account security, eligibility, compliance, or material changes in account information.

Raw verification documents are not provided to researchers by default. Researchers and organizations may receive verification status or verification level where needed for eligibility, quality, or study configuration. Verification records may be retained after account closure where needed for disputes, fraud prevention, audits, accounting, or legal obligations.

07

Respondent Identity and Researcher Access

Section 7 of 25

The amount of respondent information available to a researcher or organization can depend on study configuration, research requirements, guest or account-based participation, and disclosures made to participants.

Conceptually, research may be designed so that participants are more anonymous, identified only through limited or pseudonymous identifiers, or identifiable for follow-up or longitudinal research. Qollectiv may support related controls through features such as guest participation, anonymized researcher views or exports, eligibility matching, and study-specific disclosures, but the exact visibility settings depend on how a study is configured and what the Platform currently offers.

Raw identity-verification documents are not automatically provided to researchers. Researchers may receive verification status or level, eligibility attributes, and study responses according to study design and Platform rules. Fraud-prevention and Platform-integrity processing may still use identifying or technical signals even where a researcher view is anonymized.

08

How We Use Information

Section 8 of 25

We use personal information for purposes that include:

  • Operating, maintaining, securing, and improving the Platform.
  • Creating and managing accounts, authenticating users, and enforcing our Terms.
  • Matching respondents and data collectors with eligible studies or assignments.
  • Enabling study participation, research administration, and related workflows.
  • Conducting verification and maintaining verification levels.
  • Processing payments, tokens/credits, wallets, organizational allocations, incentives, claims, and raffles where offered.
  • Detecting, investigating, and preventing fraud, duplicate participation, abuse, and security incidents.
  • Providing customer support and resolving disputes.
  • Sending operational and, where permitted, marketing communications.
  • Performing analytics and developing Platform features.
  • Supporting AI-assisted functionality described in Section 9.
  • Generating aggregated or appropriately de-identified research insights.
  • Complying with legal obligations and establishing, exercising, or defending legal claims.
  • Enforcing Platform policies and protecting the rights, safety, and integrity of Qollectiv, users, and the public.
09

AI and Automated Processing

Section 9 of 25

Qollectiv uses automated processing and, where available, AI-assisted features to support Platform operations and research workflows. Depending on the features you use, this may include:

  • AI-assisted study or questionnaire design and related recommendations.
  • AI-assisted research analysis, summarization, classification, pattern detection, cleaning, or insight generation.
  • Automated or AI-assisted verification and document extraction.
  • Eligibility matching and related scoring or filtering.
  • Fraud, duplicate, authenticity, or integrity detection.
  • Moderation, support tooling, and similar operational systems.

AI outputs and automated assessments may contain errors, omissions, or biases. Users should independently evaluate AI-generated study designs, analyses, insights, and verification outcomes where appropriate. We do not guarantee that automated results are accurate, complete, scientifically valid, or suitable for a particular decision.

Automated systems may affect verification outcomes, eligibility, feature access, incentive review, or fraud review. Where results are uncertain or disputed, or where applicable law requires it, we may offer human review or reconsideration. Not every automated decision receives manual review as a matter of course.

We do not use verification documents or sensitive profile data for unrelated automated advertising profiling.

10

Service Providers and Third-Party Processing

Section 10 of 25

We use service providers (sometimes called subprocessors) to help operate the Platform. These providers may process personal information to support functions such as:

  • Cloud hosting and infrastructure.
  • Databases and storage.
  • Authentication.
  • Artificial intelligence and machine-learning services.
  • Email, SMS, WhatsApp, or other communications delivery.
  • Analytics.
  • Identity verification and document processing.
  • Payments and payouts.
  • Customer support.
  • Security and monitoring.

Service providers are authorized to process personal information only as needed to provide their services to us and are subject to contractual confidentiality and security obligations appropriate to the services they provide. We may maintain a separate subprocessor list or provide additional disclosures to researchers or organizations under contract. This Privacy Policy intentionally does not hard-code a vendor roster so that operational providers can change over time.

11

Data Collectors and Offline Collection

Section 11 of 25

Authorized data collectors may collect responses and related research information on behalf of researchers or organizations using Platform tools, including progressive web app or offline collection features where available.

Where offline collection is supported, study materials, drafts, consent recordings, and responses may temporarily reside on an authorized device and later synchronize with Qollectiv when connectivity becomes available. Local copies should be handled carefully and deleted or cleared when required by Platform workflows, researcher instructions, or applicable agreements after successful synchronization or assignment completion.

Data collectors are expected to use collected information only for authorized research purposes, protect devices and credentials, refrain from fabricating or improperly duplicating interviews, and comply with confidentiality, security, and authorized-use requirements. Qollectiv may process collector activity, device or sync metadata, and related integrity signals to operate assignments, quality controls, and payouts.

12

Marketing Communications and Preferences

Section 12 of 25

Where permitted by law, we may send marketing or promotional messages about Qollectiv features, research opportunities, product updates, events, or related offerings. Depending on what the Platform supports in your market, communications may be delivered by email, SMS, WhatsApp, push notification, in-app message, or similar channels.

You can control marketing communications by:

  • Updating available notification and marketing preferences in your account settings.
  • Using an unsubscribe link in marketing emails where provided.
  • Contacting us at privacy@qollectiv.app to opt out of marketing messages.

Operational or service communications are different from marketing. Opting out of marketing does not stop messages we need to send to operate your account or the Platform, such as security alerts, verification results, payment or payout confirmations, study or assignment notices you have requested, or material updates to our Terms or this Privacy Policy. Where local law requires prior consent for marketing, we will seek that consent before sending promotional messages on the relevant channel.

13

Sharing of Information

Section 13 of 25

We may share personal information in the following circumstances:

  • With researchers and organizations when you participate in their studies, subject to study configuration, disclosures, and Platform rules. This sharing is to operate the study you join, not for unrelated disclosure.
  • With organization administrators and other authorized organization members for membership, billing, wallet, assignment, and research-administration purposes.
  • With authorized data collectors to the extent needed to perform assigned field collection.
  • With service providers and subprocessors as described in Section 10.
  • With authentication providers when you choose to sign in through them.
  • With payment and payout providers to process top-ups, claims, and related transactions.
  • With professional advisers, auditors, or insurers where reasonably necessary.
  • With authorities when required by law, legal process, or governmental request, or when we believe disclosure is necessary to protect rights, safety, or Platform integrity.
  • With parties involved in a legitimate corporate transaction such as a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections and notice where required by law.

We distinguish study-related sharing needed to operate research from unrelated sale or disclosure of personal information.

14

Sale of Personal Information

Section 14 of 25

Qollectiv does not sell identifiable personal information.

We may generate, use, license, publish, or commercialize aggregated, statistical, anonymized, or appropriately de-identified research insights where individuals are not reasonably identifiable and where permitted by applicable law and our contractual commitments. Such activities are described further in Section 15 and are not a sale of identifiable personal information.

15

Aggregated and De-identified Information

Section 15 of 25

We may create aggregated, statistical, anonymized, or de-identified information from Platform and research data and use it for lawful business purposes. Potential uses include benchmarking, research reports, market insights, trend analysis, analytics, product development, public reporting, and commercial research products or licensed insights, where permitted.

We do not claim that information is legally anonymous merely because identifiers have been removed in a superficial way. Where we treat information as anonymized or de-identified, we intend that individuals are not reasonably identifiable, taking into account available means and applicable legal standards. Information that remains personal information continues to be handled under this Privacy Policy.

16

Cookies and Similar Technologies

Section 16 of 25

We and our service providers use cookies, local storage, authentication and session technologies, and similar tools to keep you signed in, remember preferences, measure usage, support security, and operate Platform features (including offline or progressive web app functionality where available).

You can control cookies through your browser settings, but disabling certain cookies or storage may limit Platform functionality. Where required by law, we will provide additional cookie disclosures or consent mechanisms. The existence of this section does not mean a separate cookie-consent banner is currently displayed in every market.

17

Data Retention

Section 17 of 25

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including Platform operations, contractual needs, legal compliance, dispute resolution, fraud prevention, security, accounting, and researcher or project requirements. Retention periods vary by category and context. Without limiting that framework:

  • Account data is generally retained while your account is active and for a reasonable period afterward as needed for the purposes above.
  • Verification information and documents may be retained to support reverification, audits, fraud prevention, disputes, and legal obligations, even if you later remove documents from active profile display.
  • Study responses and related research materials may be retained according to project settings, researcher or organization requirements, Platform integrity needs, and applicable research or legal rules.
  • Transaction, payment, payout, and accounting records may be retained for financial, tax, and legal periods.
  • Fraud, security, and integrity logs may be retained for investigation and protection purposes.
  • Communications records may be retained for support, compliance, and operational history.
  • Offline or local study responses may remain on a device until synchronized, cleared, or deleted according to Platform workflows and collector obligations.
  • Backups and disaster-recovery copies may persist for a limited period after primary deletion or anonymization. We do not promise immediate erasure from all backup systems.

When information is no longer required, we delete, anonymize, de-identify, or otherwise handle it according to our operational processes and applicable requirements. Account deactivation or deletion features may result in restricted access and retention rather than immediate irreversible erasure of all records, particularly where soft-deletion, recovery options, financial records, verification history, or legal holds apply.

18

Your Rights and Choices

Section 18 of 25

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal information, and to request portability or withdraw consent where processing is consent-based.

You can update much of your profile information and available communication preferences in account settings. To exercise other rights, contact us at privacy@qollectiv.app. We may need to verify your identity before fulfilling a request and may decline or limit requests where permitted by law (for example, where disclosure would affect the rights of others, interfere with fraud prevention, conflict with legal retention duties, or where research integrity or contractual obligations reasonably require continued processing).

If you are located in a jurisdiction with a supervisory authority for data protection, you may also have the right to lodge a complaint with that authority.

19

Security

Section 19 of 25

We implement administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, and restricted access to verification documents and similar sensitive materials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

This Privacy Policy does not claim specific certifications (such as SOC 2 or ISO 27001), end-to-end encryption of all research content, or particular encryption-at-rest implementations unless separately confirmed in a written agreement.

You are responsible for safeguarding your account credentials and for uploading verification documents and research materials only through official Platform channels.

20

International Data Transfers

Section 20 of 25

Qollectiv operates internationally. Personal information may be processed in Ethiopia, the United States, and other countries where we, our users, or our service providers operate. Those countries may have data-protection laws that differ from the laws of your country of residence.

Where legally required, we use appropriate transfer safeguards, which may include contractual protections, standard contractual clauses or equivalent mechanisms, or other lawful transfer tools. The specific mechanism used can vary by provider, transfer, and legal requirement.

21

Ethiopia Privacy Framework

Section 21 of 25

Qollectiv has significant operations and users in Ethiopia. Processing connected with Ethiopian operations or Ethiopian data subjects may be subject to Ethiopia's Personal Data Protection Proclamation No. 1321/2024 and other applicable Ethiopian laws and implementing measures, as they develop.

This section does not claim that Qollectiv holds a particular Ethiopian certification or regulatory approval. Rights, obligations, lawful bases, cross-border transfer rules, and regulatory requirements will be handled according to applicable Ethiopian law as it applies to the relevant processing. We will adapt our practices as implementing regulations and regulatory guidance evolve.

22

United States and Delaware Privacy

Section 22 of 25

Qollectiv, Inc. is incorporated in Delaware and may process personal information in or from the United States. Incorporation in Delaware does not, by itself, mean that every U.S. state privacy statute automatically applies to every user or every processing activity.

Where a U.S. federal or state privacy law applies to Qollectiv's processing of your personal information, we will honor applicable rights and obligations under that law. This includes, where required, rights of access, deletion, correction, appeal, or opt-out of certain processing, subject to verified identity and legal exceptions. Our practices will remain flexible as Delaware and broader U.S. privacy requirements evolve.

23

Children and Minors

Section 23 of 25

The general Platform is intended for individuals 18 years of age or older. We do not knowingly collect personal information through ordinary Platform accounts from individuals under 18.

If we learn that we have collected personal information from a person under 18 through an ordinary account without appropriate authorization, we will take steps to delete or restrict that information as required.

Qollectiv may, in the future, support specially authorized research involving minors only where appropriate parental or guardian consent, researcher responsibility, legal requirements, and additional safeguards are implemented. That specialized functionality is not enabled merely by this Privacy Policy, and researchers remain responsible for any such research they lawfully conduct.

24

Changes to This Policy

Section 24 of 25

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will post the revised policy on this page and update the "Last updated" date.

For material changes, we may provide reasonable notice through the Platform, by email, or by other reasonable means where required by law. Where applicable law requires affirmative consent to a material change, we will seek that consent rather than relying solely on continued use.

25

Contact Us

Section 25 of 25

If you have questions about this Privacy Policy, verification documents, marketing preferences, or your personal information, contact us at privacy@qollectiv.app.