Legal

Privacy Policy

This Policy explains how QASA Solutions collects, uses, shares, retains, and protects personal information through the Sendvelo website, customer accounts, purchases, downloads, license services, and support.

Effective:
October 1, 2026
Last updated:
October 1, 2026

1. Scope and our role

QASA Solutions is responsible for the personal information described in this Policy. It applies to thesendvelo.com and QASA-operated account, commerce, release-download, licensing, and support services for Sendvelo Self-Hosted.

It does not generally apply to contacts, campaigns, message content, provider credentials, or behavioral events held inside a customer's self-hosted installation. The customer controls that environment and decides how such data is processed. If a customer gives us personal data for support or another service where we act on its instructions, our Data Processing Addendum may apply.

2. Information we collect

Information you provide

  • name, work email address, phone number, organization, and account profile;
  • support requests, contact-form messages, feedback, and related correspondence;
  • order details such as product, amount, currency, transaction identifiers, billing status, and customer name or email received from Paddle;
  • license and download records, including license identifier, order number, release version, download status, and entitlement dates; and
  • security information such as password hashes, multi-factor authentication secrets, recovery-code hashes, and account verification status.

We do not receive or store complete payment-card numbers through our checkout. Paddle processes payment details as merchant of record.

Information collected automatically

  • IP address, browser or device information, request path, timestamps, and security or error logs;
  • cookies, local storage, and similar technologies described in our Cookie Notice;
  • license key presented in transit, a cryptographic hash and masked hint of that key, installation identifier, configured production domain, application version, activation status, validation timestamps, and license-event metadata; and
  • release download and account activity needed to secure delivery, investigate abuse, and administer entitlements.

We do not use license validation to collect customer contact lists, campaign content, messages, or customer databases.

3. How we use information

  • create, authenticate, secure, and administer accounts;
  • process orders, issue licenses, deliver releases, and manage support and update entitlements;
  • activate, validate, transfer, deactivate, suspend, or revoke licenses and enforce installation limits;
  • provide support, respond to inquiries, and send service communications;
  • detect fraud, brute-force attempts, abuse, security incidents, and unauthorized redistribution;
  • debug, maintain, and improve our website and vendor-operated services;
  • comply with law, tax, accounting, sanctions, and valid legal requests; and
  • establish, exercise, or defend legal claims.

5. How we share information

We may share relevant information with:

  • Paddle for checkout, merchant-of-record, tax, fraud, refund, and payment administration;
  • infrastructure, storage, email, security, error-monitoring, bot-protection, and customer-support providers;
  • professional advisers, auditors, insurers, regulators, courts, or law enforcement where reasonably necessary;
  • a buyer or successor in a merger, financing, reorganization, or sale, subject to appropriate safeguards; and
  • other parties at your direction or with your consent.

Our current categories and conditional providers are listed in Third-Party Services and Subprocessors. We do not sell personal information for money and do not share it for cross-context behavioral advertising.

6. Customer-hosted data and optional integrations

Sendvelo Self-Hosted runs in infrastructure selected and controlled by the customer. QASA does not routinely host or have access to the customer's contacts, campaigns, message bodies, custom attributes, provider credentials, or analytics database.

Customers may configure third-party messaging, AI, media, monitoring, or hosting services. Data sent by a customer installation to those services is controlled by the customer and governed by its contracts with them. In particular, optional AI features can send prompts, email content, or journey definitions to OpenRouter and selected model providers when configured. Customers should not submit sensitive or unnecessary personal data to AI features.

7. International transfers

QASA operates from Ghana and providers may process information in Ghana, the United States, the European Economic Area, or other countries. Privacy protections may differ from those in your country. Where required, we use contractual safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may request information about applicable safeguards.

8. Retention

We retain personal information only for as long as reasonably needed for the purposes above, including the account or commercial relationship, license verification, software delivery, security, disputes, and legal, tax, and accounting obligations. Retention varies by record type and applicable law.

Closing an account deactivates access but does not itself erase every related record. We may retain transaction, entitlement, licensing, fraud-prevention, and legal records after closure. We delete or anonymize information when it is no longer needed, unless preservation is required or reasonably necessary for a legal claim.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, password hashing, token and API-key hashing, optional multi-factor authentication, signed license payloads, throttling, and transport encryption in production.

No system is completely secure. Customers are responsible for securing their self-hosted environment, databases, backups, secrets, networks, and integrations and for applying relevant updates.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, or complain to a regulator. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

Submit a request to support@thesendvelo.com. We may verify identity and authority before responding. If your request concerns data in a customer's self-hosted Sendvelo installation, contact that customer directly; QASA generally cannot access or fulfill requests against that environment.

You may appeal a denied request by replying with "Privacy Appeal" in the subject line. You may also complain to Ghana's Data Protection Commission or your local supervisory authority.

11. Children and sensitive information

Sendvelo is a business product and is not directed to children. We do not knowingly collect account information from anyone under 18. Customers must not use Sendvelo to unlawfully collect or message children or to process sensitive information without a lawful basis and appropriate safeguards.

12. Changes and contact

We may update this Policy to reflect changes in law, providers, or practices. We will post the revised version with a new "Last updated" date and provide additional notice when appropriate.

The data controller is QASA Solutions, 5th Mankralo Link, Mataheko, Accra, Ghana. Privacy questions and requests may be sent to support@thesendvelo.com.

Questions about this document?

Contact support@thesendvelo.com. QASA Solutions is located at 5th Mankralo Link, Mataheko, Accra, Ghana.