QClean privacy policy

Last updated: September 26, 2026

This privacy policy applies to the QClean mobile app for Android and iOS, the web portal at qclean.qlink.de and the related QClean services. It explains what personal data is processed, why it is processed and the rights available to data subjects.

QClean is a multi-tenant work platform for facility-services companies. We do not use advertising networks, and personal data is not sold or used for cross-app advertising or tracking.

1. Responsibility and roles

For most data a company processes in QClean about its employees, customers, properties and workflows, that company (your employer or contracting organisation, referred to below as the “QClean customer”) is the controller. The QClean customer determines the purposes, access rights and retention periods in particular. QLINK GmbH generally processes this data as a processor under Article 28 GDPR and on the QClean customer's instructions.

Where QLINK GmbH determines purposes and means itself—particularly for secure technical operation, administration of self-registered customer accounts, support, prevention of misuse and the public QClean pages—QLINK GmbH is the controller. For questions about employment or work data, please first contact your employer or QClean customer; QLINK assists them with your request.

2. Provider and privacy contact

QLINK GmbH, Anton-Schmidt-Straße 36, 71332 Waiblingen, Germany. Managing director: Özay Solak. Phone: +49 7151 250547-0. Email: info@qlink.de.

Privacy enquiries can be sent informally to info@qlink.de. Your employer or administrator can provide the contact details of the relevant QClean customer and, where applicable, its data protection officer.

3. Sources of data

Data comes from you, your employer or an authorised administrator, your actions in the app and web portal, the device you use and—where enabled by the QClean customer—connected communication services such as WhatsApp. Required fields are identified in the relevant form. The relevant functions cannot be provided without required account and work data.

4. Categories of data processed

  • Account and contact data: first and last name, email address, phone number, company affiliation, profile image and language.
  • Authentication and permission data: cryptographic password hash, access and refresh tokens, roles, groups, property assignments, permissions and sign-in times. QLINK does not store a readable password.
  • Employment and organisational data: company affiliation, contract type, monthly target hours, property and team assignment, and shift planning.
  • Working-time and location data: check-in and check-out, property, timestamps, notes and—where permission is granted—precise GPS coordinates at the relevant check-in or check-out.
  • Work and user content: tickets, descriptions, comments, tasks, status changes, photos and other attachments, documents, reports, quality inspections, findings, signatures, leave requests, schedules and asset assignments.
  • Leave and absence data: requested periods, type, status, reasons, notes, attachments and leave balances.
  • Communication data: support enquiries, email, notifications and, where the WhatsApp integration is enabled, phone number, messages and submitted media.
  • AI data in the web portal: questions to the assistant, chat histories, answers, tools used and their results. The AI assistant is currently not part of the mobile app.
  • Mobile voice input: voluntarily recorded audio and the transcripts created for voice-assisted ticket functions.
  • Device and technical data: push token, platform and device label, app/browser version, operating system, IP address, request time, function accessed, and error and security events.

5. Location and device permissions

  • Location: QClean requests the current location for check-in and check-out and stores submitted coordinates with the working-time event. The app does not continuously track routes or location in the background.
  • Camera, photos and files: to capture, select, crop and upload ticket, quality, leave or document attachments.
  • Microphone: to record voice input for ticket descriptions. The recording is sent to the QClean server and the transcription service used.
  • Notifications: for updates about tickets, quality processes, working time, shifts, documents and leave requests.

Permissions can be denied or later withdrawn in the device settings. The related feature may then be unavailable. Withdrawal does not delete data that was previously transmitted lawfully.

To display a readable address, the mobile app sends existing check-in/check-out coordinates and technically necessary connection data to the OpenStreetMap Foundation's Nominatim service. This happens when relevant working-time views are loaded, not as continuous location collection.

7. Recipients and services used

Within each QClean customer, only authorised people receive access according to their roles and permissions. QLINK uses carefully selected service providers and enters into data-processing agreements where required. Depending on the features used, the following recipients may be involved:

  • Amazon Web Services (AWS): hosting, database, file storage, email delivery, realtime events and logs. The primary QClean infrastructure operates in AWS Frankfurt (eu-central-1).
  • Google: Firebase Cloud Messaging for push notifications, Google Maps in the web portal and Google Docs Viewer to display PDF files on Android. The Android PDF viewer sends the document URL to Google, and Google can retrieve the file to render it.
  • Apple: Apple Push Notification Service (APNs) for notifications to iOS devices.
  • OpenAI: the optional AI assistant in the web portal and audio transcription for mobile voice input. In the web portal, prompts and QClean results needed for the answer may be transmitted; for mobile transcription, the voluntarily recorded audio file is transmitted.
  • OpenStreetMap Foundation/Nominatim: converting check-in/check-out coordinates into addresses.
  • Open-Meteo: optional weather and place search in the web portal; the searched place or selected coordinates and connection data are transmitted.
  • Meta Platforms/WhatsApp: only where the QClean customer enables optional WhatsApp communication and the data subject uses that channel.
  • Authorities, courts, legal advisers and auditors: only where required by law or necessary to establish, exercise or defend legal claims.

Push messages are limited to content needed for delivery. Sensitive details should not be included in notification text visible on a locked screen.

8. Transfers outside the EEA

Some providers are established or operate technical locations outside the European Economic Area, particularly in the United States. Where data is processed outside the EEA, this is based on a European Commission adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified), the EU Standard Contractual Clauses or another permitted safeguard under Articles 44 et seq. GDPR. Additional technical and organisational measures are agreed where required.

9. Local storage, cookies and logs

  • The mobile app stores authentication tokens in protected secure device storage and keeps user, property and ticket data in a local cache for offline use. The app clears this data on sign-out or account deletion; uninstalling removes app data according to the operating system's rules.
  • The web portal stores authentication data and the signed-in user in browser local storage. Temporary password-change data may be held in session storage. Signing out removes authentication data from the QClean web portal.
  • A technically necessary language cookie (NEXT_LOCALE) remembers the selected language. QClean currently uses no advertising, audience-measurement or marketing cookies.
  • Server and application logs may contain IP address, time, route, status, device/browser information, and error and security context. They are used only for operation, diagnosis, security and evidence.

10. Retention and deletion

Data is stored only for as long as required for its purpose, while the QClean contract remains in force, or while statutory and contractual retention and evidence duties apply. The controller QClean customer generally sets the specific period for employee, working-time, quality, leave and other business records. Data is then erased or anonymised unless legal obligations or claims require continued retention.

  • Push tokens are deactivated or deleted on sign-out or account deletion; invalid tokens are deactivated once detected.
  • Short-lived audio files for voice input are processed for transcription; the resulting text may be processed further as ticket content or input.
  • Technical security and error logs are erased after the log-retention periods configured for the relevant environment. Audit metadata for the web-based AI assistant is ordinarily purged after 30 days; chat messages and tool results remain part of the chat session until deleted on the QClean customer's instruction or at contract end.
  • Backups and obsolete file versions are overwritten or erased according to fixed backup and lifecycle schedules; non-current S3 file versions are ordinarily removed after 90 days.

Self-service deletion immediately disables access, replaces the email address and removes the password, phone number, profile image, push tokens, personal notifications, drafts, personal permissions and assignments. The name and operational records such as working times, tickets, quality inspections, leave processes, past shifts, signed documents and audit references may remain with the QClean customer for documentation. Open tickets and future shifts are released for reassignment. Retention permitted by law remains unaffected by a deletion request. If the user is the only user of a company they registered themselves in the app, the entire company is deleted instead, with all its data and files.

Delete a QClean account and submit a deletion request

11. Data security

QLINK uses appropriate technical and organisational measures. These include encryption in transit, server-side encryption of stored files, tenant-, role- and permission-based access controls, secure password hashing, protected mobile token storage, logging of security-relevant events, backups and regular updates to components. No transmission or storage system can, however, guarantee absolute security.

12. AI features in the web portal

The optional AI assistant is currently available only in the QClean web portal; the mobile app does not contain this assistant. It answers questions using QClean data available to the signed-in user. Available tools are restricted according to that user's permissions. AI output can be inaccurate and must be reviewed before a business decision is made. QClean does not use this AI output to make solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.

Only enter information in free-form AI prompts in the web portal that is necessary for the task. Particularly sensitive content should be used only where authorised by the QClean customer and legally permitted. Mobile audio transcription for ticket descriptions is a separate function.

13. Data-subject rights

Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21). Consent can be withdrawn at any time for the future. You also have the right to lodge a complaint with a data-protection supervisory authority, particularly in the place where you live or work, or with the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.

For data controlled by your employer or another QClean customer, please direct your request to that organisation. Requests sent to info@qlink.de will be reviewed and, where necessary, forwarded to the responsible QClean customer. Proof of identity may be requested to prevent unauthorised disclosure.

14. Apple App Store and Google Play

When you obtain QClean through the Apple App Store or Google Play, the relevant store processes its own account, purchase, device, usage and diagnostic data as an independent controller. QLINK receives only the information made available by the store. Apple's or Google's privacy notices apply to that processing. The App Store privacy details and Google Play Data safety disclosures are maintained based on the QClean features described in this policy.

Apple privacy policy

Google privacy policy

15. Changes to this privacy policy

This policy will be updated when QClean, the services used or legal requirements change. The date above shows the current version. Where required, we will notify users of material changes in the app, in the web portal or through the contact method associated with the account.