← Home page

QA Board Privacy Policy

Version of 31 August 2026

This is an informational English translation. The legally binding version is the Polish original, available under the language switch in the header. In the event of any discrepancy, the Polish wording prevails. Questions: kontakt@qualityisland.pl.

1. General information

1. This Privacy Policy sets out the rules for the processing of personal data in connection with the use of the QA Board online platform, available at https://qaboard.pl/ and at other addresses, domains or subdomains indicated by the Controller.

2. The QA Board platform serves in particular to present the profiles of specialists in QA, software testing, test automation, cybersecurity, digital accessibility, DevOps, quality analysis, quality management and related areas of IT, and to allow business clients to register their interest in cooperation, recruitment, the outsourcing of a specialist or a team, or a service delivered by Quality Island.

3. The Privacy Policy applies to visitors to the platform, people contacting Quality Island through forms, representatives of clients and business partners, specialists, candidates, people representing contractors, recipients of marketing communication and other people whose data is processed in connection with QA Board.

4. This document should be read together with the QA Board Terms of Service and other documents made available by Quality Island, where they apply to a given person or process. The rules on cookies and similar technologies are set out in section 17 of this Policy and in the consent banner available on the platform.

2. Data controller

1. The controller of personal data is Quality Island Sp. z o.o., with its registered office at ul. Grzybowska 87, 00-844 Warsaw, Poland, Tax ID (NIP): 5273002880, entered in the register of entrepreneurs of the National Court Register (KRS) under number 0000972652, REGON: 522066058.

2. The Controller can be contacted:

by email: kontakt@qualityisland.pl

in writing: Quality Island Sp. z o.o., ul. Grzybowska 87, 00-844 Warsaw, Poland

on personal data protection matters: kontakt@qualityisland.pl, with the words "dane osobowe" (personal data) in the subject line

If the Controller has appointed a Data Protection Officer, their contact details are given above or in a separate notice on the platform. If no Data Protection Officer has been appointed, contact on personal data matters is made through the address indicated for privacy matters.

3. Core principles of data processing

1. The Controller processes personal data lawfully, fairly and in a manner that is transparent to the data subject.

2. The Controller processes data solely for specified, explicit and legitimate purposes.

3. The Controller limits the scope of data to what is necessary for the given purpose.

4. The Controller takes steps to keep data accurate and up to date.

5. The Controller stores data no longer than is necessary to achieve the purpose of the processing, unless a longer period follows from the law, from a justified need to defend against claims, or from the consent of the data subject.

6. The Controller applies technical and organisational measures intended to protect data against unauthorised access, loss, destruction, alteration, disclosure or unauthorised use.

4. Categories of people whose data we process

The Controller may process the data of the following categories of people:

visitors to the QA Board platform,

people using contact forms, CTA buttons, recruitment forms, enquiry forms or other means of contact,

representatives of clients interested in working with QA & Testing specialists,

representatives of business partners, contractors, suppliers and subcontractors,

specialists, candidates, consultants and experts whose profiles may be presented or analysed within QA Board,

people taking part in calls, meetings, negotiations, recruitment processes, tender processes or projects,

people who have signed up for marketing communication, the newsletter, sales contact or similar activities,

people reporting infringements, complaints, questions, personal data requests, security incidents or other matters.

5. What data we may process

Depending on the relationship with a given person, the purpose of the contact and the functions of the platform, the Controller may process the following categories of data:

identification data, such as first name, surname, company, job title, role in the organisation,

contact data, such as email address, telephone number, postal address, professional profile details,

company data, such as company name, Tax ID (NIP), registered address, industry, size of the organisation, website, details of the people representing the company,

data concerning an enquiry, such as project description, recruitment needs, technology requirements, budget, preferred type of contract, working mode, location, start date of the cooperation, security requirements, language requirements,

data concerning a specialist or candidate, such as professional experience, role, seniority, technologies, tools, certificates, languages, project domains, preferred working mode, availability, financial expectations, type of cooperation, portfolio, CV, professional links, history of cooperation, recruitment notes, results of interviews or competence tests,

communication data, such as the content of messages, correspondence history, meeting notes, information provided by telephone, through a form, by email, via a messenger, a calendar or other channels of contact,

technical and usage data, such as IP address, device identifiers, cookie identifiers, browser data, device type, operating system, language settings, date and time of the visit, activity on the platform, security logs, error information, analytics data,

marketing data, such as the source of the contact, the history of consents, communication preferences, responses to communication, message opens, clicks, interest in services,

billing and contractual data, if an agreement is concluded, such as invoicing details, details of contact persons, order details, payment details, settlement history, project information,

data necessary to pursue or defend against claims, such as the history of arrangements, documents, correspondence, logs, confirmations, information about breaches of the Terms of Service, information about unauthorised activity.

6. Data that should not be sent to us

1. Users should not send the Controller excessive data or data that is not needed to handle an enquiry, a recruitment process, cooperation or another purpose of the contact.

2. In particular, no special categories of data should be sent, such as data concerning health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, or data concerning sex life or sexual orientation, unless this has been expressly agreed with the Controller and is necessary and lawful.

3. No data concerning criminal convictions or offences, login credentials, passwords, API keys, production data of end clients, trade secrets, financial data of third parties or other sensitive data should be sent, unless the Controller expressly asks for it and indicates a secure means of transfer.

4. If a user provides the data of third parties, the user should have an appropriate legal basis for providing it and should have fulfilled the required information obligations towards those people.

7. Purposes and legal bases of processing

7.1. Operating the platform and keeping it running

1. Data may be processed in order to make the platform available, to provide its basic functions, to maintain sessions, to display content, to handle forms, to save preferences, to keep the platform stable and to resolve technical problems.

2. The legal basis for the processing is the legitimate interest of the Controller in running and maintaining the platform, ensuring its functionality and enabling users to use QA Board.

7.2. Handling enquiries and contact

1. Data may be processed in order to reply to a message, to handle a contact form, telephone or email contact, to prepare information about a service, to arrange a call, to clarify a matter or to continue the communication.

2. The legal basis for the processing is the legitimate interest of the Controller in handling enquiries and communication and, where the contact is aimed at concluding an agreement, also the taking of steps prior to entering into that agreement.

7.3. Selecting specialists and handling recruitment or outsourcing enquiries

1. Data may be processed in order to analyse the client's needs, to match a specialist or a team, to present a profile, to confirm availability, to hold conversations, to prepare an offer, to present recommendations and to run a recruitment, outsourcing or project process.

2. The legal basis for the processing is the legitimate interest of the Controller in running its business, serving clients and specialists, preparing offers and carrying out recruitment and outsourcing processes.

7.4. Presenting specialist profiles on QA Board

1. The data of specialists may be processed in order to create, update, publish, present, hide, filter or analyse a specialist's profile on the QA Board platform.

2. The legal basis for the processing is the specialist’s consent (Article 6(1)(a) GDPR). The performance of an agreement is a basis only as regards the technical operation of the specialist’s account on the platform. Withdrawing consent means that the profile stops being presented.

7.5. Recruiting specialists and building a candidate database

1. The data of candidates and specialists may be processed in order to run recruitment, to assess competences, to make contact, to arrange interviews, to run tests, to verify experience, to archive applications, to propose projects and to build a database of QA & Testing specialists.

2. The legal basis for the processing is the taking of steps prior to entering into an agreement, the performance of an agreement, a legal obligation or consent.

7.6. Quality Island's own marketing

1. Data may be processed in order to market Quality Island's own services.

2. The legal basis for the processing may be the legitimate interest of the Controller and, to the extent required by law, also consent to marketing communication.

3. A person may object to direct marketing or withdraw consent at any time.

7.7. Analytics, development and optimisation of the platform

1. Data may be processed in order to analyse how the platform is used, to measure the effectiveness of content, to study interest in profiles, to improve functionality, to optimise UX, to detect errors and to produce statistics, reports and business analyses.

2. The legal basis for the processing is the legitimate interest of the Controller and, for tools that require it, the user's consent.

7.8. Security, prevention of abuse and protection of the platform

1. Data may be processed in order to protect the platform and to detect abuse, to prevent scraping, automated data harvesting, circumvention of security measures, attacks, attempts at unauthorised access, breaches of the Terms of Service and other activity that threatens Quality Island.

2. The legal basis for the processing is the legitimate interest of the Controller in protecting the platform, the data, the infrastructure, its trade secrets and its rights.

7.9. Performance of agreements and settlements

1. If an agreement is concluded, data may be processed in order to conclude, perform, amend, terminate and settle that agreement.

2. The legal basis for the processing is the performance of an agreement or the taking of steps prior to entering into it and, as regards accounting documents, a legal obligation.

7.10. Pursuing claims and defending against claims

1. Data may be processed in order to establish, pursue or defend against claims.

2. The legal basis for the processing is the legitimate interest of the Controller in protecting its rights and legal interests.

7.11. Compliance with legal obligations

1. Data may be processed in order to fulfil obligations arising from the law.

2. The legal basis for the processing is a legal obligation to which the Controller is subject.

8. Is providing data mandatory

1. Providing data is voluntary, but it may be necessary in order to use certain functions of the platform, to obtain a reply, to send an enquiry, to take part in a recruitment process, to receive an offer, to conclude an agreement or to carry out cooperation.

2. Failure to provide the required data may make it impossible for the Controller to handle an enquiry, present an offer, make contact, match a specialist, run a recruitment process or perform an agreement.

3. Where data is required by law, providing it may be mandatory.

9. Sources of data

1. Data may come directly from the person it concerns.

2. Data may come from a client, a partner, a contractor, a specialist, a referrer or another third party.

3. Data may come from publicly available sources.

4. Technical data may be collected automatically while the platform is being used.

10. Recipients of data

1. Personal data may be disclosed to entities that support the Controller in running the platform and its business.

2. The recipients of data may in particular be: hosting and IT providers, providers of CRM and recruitment tools, providers of email and messaging services, providers of analytics and marketing tools, providers of accounting and legal services, banks and payment operators, clients interested in cooperation, specialists and candidates, public authorities, and entities affiliated with Quality Island.

3. The Controller concludes appropriate data processing agreements with processors where this is required.

11. Transfers of data outside the EEA

1. The Controller may use tools from providers located outside the European Economic Area.

2. Where data is transferred outside the EEA, the Controller applies the mechanisms required by law (a European Commission adequacy decision, standard contractual clauses, additional safeguards).

3. A person may obtain information about the safeguards applied by contacting the Controller.

12. Retention period

1. Data is stored for the period necessary to achieve the purpose and then for the period required by law or needed for protection against claims.

2. Enquiry data: for the time it takes to handle the enquiry and then for up to 3 years from the end of the contact.

3. Contractual data: for the term of the agreement and the limitation period for claims.

4. Accounting data: for 5 years in accordance with tax law.

5. Candidate data: for the duration of the process and, for the purposes of future recruitment, for up to 24 months from the last contact.

6. Technical logs: up to 12 months.

7. Once the period has elapsed, the data is deleted, anonymised or restricted.

13. Rights of data subjects

1. A person has the right to: access their data, obtain a copy of the data, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent, and to lodge a complaint with the supervisory authority.

2. Withdrawing consent does not affect the lawfulness of processing carried out before it was withdrawn.

3. Requests can be sent to: kontakt@qualityisland.pl, with the words "dane osobowe" (personal data) in the subject line

4. The Controller may ask for additional information in order to confirm identity.

5. The Controller replies within one month of receiving the request and, in complex cases, may extend that period by a further two months, informing the person who made the request.

14. Right to object

1. A person may object to processing based on the legitimate interest of the Controller on grounds relating to their particular situation.

2. In the case of direct marketing, an objection is effective without giving any reason.

15. Complaint to the supervisory authority

1. A person has the right to lodge a complaint with the supervisory authority if they consider that the processing infringes data protection law.

2. In Poland the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

16. Automated decision-making and profiling

1. The Controller may use tools that support analysis, the filtering of profiles and the matching of a specialist to a project.

2. Final decisions require human involvement.

3. The Controller does not take decisions in relation to data subjects that are based solely on automated processing and that produce legal effects or similarly significantly affect those people.

17. Cookies and similar technologies

1. The platform may use cookies, local storage, session storage, pixels, tags and similar technologies.

2. Essential cookies may be used on the basis of a legitimate interest.

3. Analytics and marketing cookies require consent where consent is required by law.

4. Users can manage cookie settings in their browser or in the consent banner.

18. External tools

The platform may use external tools. Using them may involve the processing of data by their providers in accordance with those providers' own documentation.

19. Data security

1. The Controller applies technical and organisational measures appropriate to the risks.

2. Those measures may include access control, encryption, backups, security monitoring and incident response procedures.

3. Only authorised people have access to the data.

20. Confidentiality of specialist profiles

1. Data on QA Board may constitute confidential information or a trade secret.

2. Users are not entitled to copy, download or use that data for any purpose other than assessing possible cooperation.

21. Children's data

1. The platform is not intended for children or for people under 16 years of age.

2. The Controller does not intend to knowingly collect children's data.

22. Social media and external links

1. The platform may contain links to external websites.

2. The Controller is not responsible for how third parties process data.

23. Changes to the Privacy Policy

1. The Controller may amend the Privacy Policy if the law, the functions of the platform or the scope of the processing change.

2. The current version is published on the platform.

3. This Privacy Policy is published in Polish and in an English translation. The binding version is the Polish one. In the event of any discrepancy between the language versions, the Polish wording prevails.

24. Contact details for privacy matters

Quality Island Sp. z o.o.

ul. Grzybowska 87

00-844 Warsaw, Poland

Tax ID (NIP): 5273002880

kontakt@qualityisland.pl

25. Consent wordings

25.1. Mandatory acceptance of the Privacy Policy

"I confirm that I have read the QA Board Privacy Policy and that I understand the rules under which Quality Island Sp. z o.o. processes my personal data."

25.2. Consent to marketing contact by email

"I consent to receiving marketing and commercial information from Quality Island Sp. z o.o. by electronic means at the email address I have provided. I may withdraw this consent at any time."

25.3. Consent to contact by telephone

"I consent to being contacted by telephone by Quality Island Sp. z o.o. for marketing and commercial purposes at the number I have provided. I may withdraw this consent at any time."

25.4. Specialist's consent to the presentation of their profile

"I consent to Quality Island Sp. z o.o. processing my personal data in order to create, publish, present and update my specialist profile on the QA Board platform."

25.5. Specialist's consent to future projects

"I consent to Quality Island Sp. z o.o. processing my personal data in order to contact me about future projects, recruitment, B2B cooperation, outsourcing or other professional opportunities."

25.6. Notice below the "Start recruiting" form

"The controller of personal data is Quality Island Sp. z o.o. The data will be processed in order to handle the enquiry, make contact, analyse needs, present information about cooperation and, where applicable, prepare an offer. Details are set out in the QA Board Privacy Policy."

Questions about this document: kontakt@qualityisland.pl

Quality Island Sp. z o.o., ul. Grzybowska 87, 00-844 Warsaw, Poland. Tax ID (NIP) 5273002880, KRS 0000972652.