How QandR complies with the AVG and does not store privacy-sensitive data
We comply with the AVG and do not store personal details. Joining a QandR session is anonymous. The data stored in the database cannot be connected to persons.
No, participants do not need to register an account. They participate completely anonymously.
Yes. Answers cannot be traced back to individual participants unless you explicitly ask identifying questions.
QandR uses Secure Sockets Layer (SSL), which means that a secure layer is placed between a server and an internet browser to protect the data. All traffic, both from the phones of participants to the server and from the server to the presentation screen, runs via https with an SSL certificate so that the traffic is encrypted and cannot be intercepted.
Every facilitator creates a password when starting his QandR account, which is stored securely using end-to-end encryption. These passwords are not visible to the developer Noterik either.
When an organisation needs it, two factor authentication (2FA) can be offered on QandR facilitator accounts. The 2FA is not part of the standard account, please contact Rutger Rozendal on 020 2401145 or via rutger@qandr.eu.
For the storage of data, we use a server centre located on European territory. Read more about this on this page. Among other things, this page states that compliance with EU regulations applies to the transfer of data. The GDPR, which is the European version of the AVG, and also other EU privacy regulations are thus applicable to the hosting and storage facilities of QandR.
The QandR developer Noterik has an FG (data protection officer) who oversees customer and user privacy compliance in accordance with the AVG, who is also registered with the AP (Authority for the Protection of Personal Data). In this way, in addition to the restrictions already built into the service, we offer our customers additional reliability and ensure that internally everything is always in order.
Facilitators of public meetings have a responsibility to follow the GDPR guidelines within QandR session. The QandR modules may not be used to retrieve personally identifiable information. For example, a Wordcloud may not be used to retrieve the first or last names or other personal information of participants. And according to the GDPR guidelines, no selfies may be uploaded to the Moodboard either.
When a QandR session of a public meeting does contain personal data of participants, we advise facilitators to delete the archive of that session. In the dashboard and [the editor] functions are available for this.
To conduct QandR sessions as a moderator, you need a QandR account. With it, you can start all your sessions and view their results afterwards. These are the visuals that visually represent the collective responses of your participants - not the individual responses of identifiable individuals. Your QandR account is a secure account that can only be accessed by you. A QandR account requires only a few pieces of information from you, such as email, name, and name of your organization that you enter once when you register your account. QandR only uses your data to run the service and will never share it with others.
Please review our privacy policy for more technical details on how we handle the collection, storage and disclosure of personal data from facilitators, participants and other stakeholders.