1. Controller

The controller for data processing on this website is Qelivia, owner (Inhaber) Michael Bruders, Am Golfplatz 1, 52249 Eschweiler, Germany, email: kontakt@qelivia.de. Further details can be found in the Legal notice.

2. General information on data processing

We process personal data only to the extent necessary to provide a functioning website and our services. The legal bases are in particular Art. 6(1)(b) GDPR (contract/pre-contractual measures), Art. 6(1)(f) GDPR (legitimate interest) and Art. 6(1)(a) GDPR (consent).

3. Hosting

This website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Strato processes technical data arising when the website is accessed on our behalf. The basis for this is a contract for processing on behalf (Auftragsverarbeitung) pursuant to Art. 28 GDPR. We operate the client area described under section 8 on the same server.

4. Server log files

When the website is accessed, the provider automatically collects information in server log files: page accessed, date and time, volume of data transferred, referrer URL, browser type and version, operating system and the (generally shortened) IP address. Processing takes place on the basis of Art. 6(1)(f) GDPR for the secure and stable operation of the website. The data is deleted after a short period, unless it is required to investigate faults or misuse.

5. Cookies

We use no cookies for audience measurement, analytics, profiling or advertising, and we embed no third-party services requiring consent. A consent banner is therefore not necessary.

The cookies listed below are strictly necessary for the function you have requested. No consent is required for them pursuant to § 25(2)(2) TDDDG; the legal basis for the subsequent processing is Art. 6(1)(f) GDPR, based on our interest in a secure and functioning service.

No cookies are set when you visit this website. The same applies to the appointment booking at www.qelivia.de/termin. Cookies are only created if you open one of the following areas:

Test Runner sign-in page (www.qelivia.de/testrunner): tr_csrf — protects the sign-in form against being submitted from other websites (cross-site request forgery). Lifetime 1 hour, transmitted only via HTTPS, not readable by JavaScript (HttpOnly), SameSite=Lax. The cookie holds a random value and no information about you.

Test Runner instance (your-code.testrunner.qelivia.de): csrftoken (lifetime 24 hours, same purpose as above) and, after sign-in, a session cookie that keeps you signed in for the duration of the session. If you select a language, an additional cookie stores that choice. Details on this service under section 8.

Document area (cloud.qelivia.de): a session cookie and technical cookies of the Nextcloud software (among them oc_sessionPassphrase and two cookies containing nc_sameSiteCookie in their name), which serve session management and protection against cross-site request forgery.

You can delete or block cookies in your browser at any time. For the areas named above, this means that signing in is no longer possible; visiting this website is unaffected.

6. Fonts

The fonts used (Geist, Geist Mono) are served locally from our server. There is no connection to third-party servers (for example Google Fonts), and no personal data is transmitted to third parties in this context.

7. Appointment booking

To arrange initial calls, we operate our own application at www.qelivia.de/termin on our server in Germany. No third-party service is involved; the data does not leave our servers. No cookies are set in this process.

If you book an appointment, we process the details you enter (name and email address as mandatory information; company, telephone number and your enquiry on a voluntary basis, together with the selected appointment and the IP address to prevent automated entries) in order to arrange and hold the appointment with you. The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual measures at your request), and otherwise Art. 6(1)(f) GDPR based on our interest in orderly appointment scheduling. The details are deleted automatically no later than 90 days after the appointment, unless statutory retention periods apply. You can cancel the appointment at any time using the link in the confirmation email.

Until 13 August 2026 we used the Cal.com service for appointment booking, which was loaded only after express consent. This service has been removed in full; no data is transmitted to it any longer.

8. Client area: document area and Test Runner

8.1 Document area (cloud.qelivia.de)

For the exchange of project documents with our clients, we operate our own instance of the Nextcloud software at cloud.qelivia.de. It runs on our own server; no data is transmitted to the software manufacturer.

Who receives access. We set up accounts exclusively for named contacts at our clients. Registration by third parties is not possible.

Which data is processed. When setting up an account, we process name, email address and user name. During use, we process the content you upload or retrieve as well as technical log data (time of access, IP address, action performed), which serves the secure operation and the traceability of access. The legal basis is Art. 6(1)(b) GDPR (performance of the contract with your company) and Art. 6(1)(f) GDPR (security of our systems).

Security. Access is exclusively encrypted via HTTPS and exclusively through personal accounts created by us. Public share links are technically disabled. Administrative accounts are protected by two-factor authentication. Repeated failed log-in attempts result in an automatic block of the calling IP address. Log data is deleted after 30 days, unless it is required to investigate a fault or a case of misuse.

Retention period. We delete project documents 90 days after completion of the respective project. We give notice of the deletion 14 days in advance by email. We deactivate access accounts at the same time.

Backups. For resilience, we create encrypted backups on a daily basis. These are held with Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in a data centre in Germany. The basis for this is a contract for processing on behalf (Auftragsverarbeitung) pursuant to Art. 28 GDPR; processing takes place exclusively within the EU or the EEA. The backups are encrypted before transfer and the key remains exclusively with us. For technical reasons, deleted content may still be present in encrypted form for the duration of the backup retention periods; these periods are twelve months at most.

Your rights. The rights described under section 12 apply. Please note that we process content which your employer has provided to us in the context of an engagement on your employer's behalf. Please address any requests in this regard to your employer.

8.2 Qelivia Test Runner

For test execution we provide our clients, on request, with their own Test Runner environment. Each client receives a completely separate instance with its own database at its own address in the form your-code.testrunner.qelivia.de. Access between the instances of different clients is technically impossible. The instances run on the same server in Germany as this website; no data is transmitted to the software manufacturer.

How you reach your environment. You receive the address of your instance together with your credentials and normally open it directly. If you no longer have the address at hand, you can find it again at www.qelivia.de/testrunner using your Qelivia access ID. There you enter only that access ID — no password. We resolve this ID to your instance on our server and forward you there. The actual sign-in with user name and password takes place on your instance. The entry page checks no passwords and stores none.

Which data is processed. When setting up an account, we process name, email address and user name. During use, we process the test content you enter (among other things test cases, test runs, results and comments, each recorded with the account that made the change) as well as technical log data (time of access, IP address, address requested). The legal basis is Art. 6(1)(b) GDPR (performance of the contract with your company) and Art. 6(1)(f) GDPR (security of our systems).

Security. Access is exclusively encrypted via HTTPS. Passwords are not stored in plain text but exclusively as a cryptographic hash. Repeated failed sign-in attempts result in an automatic block of the calling IP address. Access logs are deleted after 30 days.

Retention period. We delete test content according to the same periods as the other project documents, that is 90 days after completion of the respective project, with notice 14 days in advance. Where a Care mandate is ongoing there is no project completion; the content is then retained for the duration of the mandate.

Backups. The same information applies as under section 8.1.

Your rights. The rights described under section 12 apply. Here too: content processed on behalf of your employer means enquiries should be addressed to them.

9. Contacting us

If you contact us by email or by telephone, we process your details in order to deal with the enquiry on the basis of Art. 6(1)(b) or Art. 6(1)(f) GDPR. In the case of a telephone call, the usual connection data of your provider is generated; we do not record calls. The data is deleted as soon as it is no longer required and no statutory retention periods apply.

10. Data transfers in the context of our services

In the context of an engagement, we process the documents you provide exclusively for the purpose of delivering the commissioned service, in compliance with the GDPR and within the EU. In doing so, we use carefully selected service providers as processors (including hosting; see sections 3 and 8). Where we use AI-supported tools for preparation, this is done exclusively with anonymised data; personal or confidential raw data is not transmitted to AI services for this purpose. We use Anthropic (Claude, USA) as our AI service provider; the transfer of anonymised content takes place on the basis of EU standard contractual clauses. We agree scope and confidentiality in advance, as a rule by way of a separate non-disclosure agreement (NDA) and, where personal data is concerned, a data processing agreement (Auftragsverarbeitungsvertrag, AVV). On completion, copies that are no longer required are deleted.

11. Transparency on the use of AI

Qelivia uses AI-supported tools as an accelerator in preparatory work, exclusively with anonymised data. Every work result is reviewed and approved by a responsible specialist; the professional and editorial responsibility rests entirely with Qelivia.

12. Your rights

You have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.

13. Open-source software in use

Qelivia's services make use of free software. The following information serves to meet licence notice obligations and to be transparent towards our clients. It does not involve any processing of personal data; the processing carried out in the services named is described in sections 8 and 3.

Qelivia Test Runner. The Test Runner is based on Kiwi TCMS. The software is licensed under the GNU General Public License, version 2 (GPL-2.0); individual components are licensed under the GNU Affero General Public License, version 3 (AGPL-3.0). Source code: github.com/kiwitcms/Kiwi. Qelivia runs a modified version. The modifications cover the logo, favicon and page title, removal of the advertising banner, deactivation of the anonymous usage analytics, removal of the language menu and of the link to the vendor's change log, replacement of the help menu entries, replacement of the vendor notice on the sign-in page with our own text, an own stylesheet for the appearance of the interface, own typefaces and an own wordmark, and limiting the language selection to German and English. Copyright and licence notices in the source code remain unchanged.

Client area. The client area at cloud.qelivia.de is based on Nextcloud, licensed under the GNU Affero General Public License, version 3 (AGPL-3.0). Qelivia runs an unmodified version; adjustments are limited to configuration and presentation. Source code: github.com/nextcloud/server.

Licence texts: GPL-2.0 · AGPL-3.0. A list of the modified files, and the modified versions themselves, are available on request at kontakt@qelivia.de. The full notices including the trade mark statement are available under Open source notices.

14. Currency of this policy

This privacy policy is amended as required in order to comply with legal requirements and changes to our services.