Questa
  • Product
  • How it works
  • The app
  • Pricing
  • FAQ
Sign inBook a demo
Legal

Privacy Policy

Last updated: January 1, 2026

This Privacy Policy explains how Questa collects, uses, shares and protects your personal data when you use our platform — website, web backoffice and iOS / Android mobile apps. It complies with the EU General Data Protection Regulation (GDPR), Portuguese law nº 58/2019, and the requirements of the App Store and Google Play.

1. Who we are and how to contact us

Questa (NIF: 240600070) ("Questa", "we") is the data controller for your personal data when you use the questa.pt website or the generic Questa app.

Important — Multi-tenant model: When you use Questa in the context of an event hosted by a customer organization, that organization is the data controller for your event participation data, and Questa acts as the processor under a data processing agreement (DPA). For questions about your participation data in a specific event, please contact that organization first.

Questa contacts:

  • General email: info@questa.pt
  • Data Protection Officer (DPO): info@questa.pt
  • Address: Porto, Portugal

2. Data we collect

We collect the following categories of personal data:

  • Account data: name, email address, password (hashed), profile picture (optional), preferred language
  • Optional contact data: phone, institution, role, social media links
  • Event data: events you participate in, completed challenges, score, networking connections, posts in the event feed
  • Communication data: emails we send you (event import, password recovery, notifications)
  • Device technical data: device type, operating system, app version, anonymized installation identifier, language
  • Usage data: pages visited in the backoffice, actions performed (creating challenges, submitting answers), access dates and times
  • Location data (optional, with consent): only for "QR check-in" challenges and only with explicit device-level permission
  • Payment data: processed directly by Stripe; Questa only keeps a customer identifier and invoice history (never card numbers)

We do not collect sensitive data (racial or ethnic origin, political opinions, religious beliefs, health, sexual orientation) unless you voluntarily share it in free-text fields.

3. How we use your data

We process your personal data for the following purposes:

  • Operate the Platform and deliver the agreed service (contract performance — Art. 6(1)(b) GDPR)
  • Manage your account, authentication and security
  • Let you participate in events and interact with other participants (based on your privacy settings)
  • Send operational communications (password recovery, event notifications, service updates)
  • Process payments via Stripe (contract performance)
  • Improve the Platform via aggregated, anonymous analytics (legitimate interest — Art. 6(1)(f))
  • Comply with legal obligations (invoicing, tax retention — Art. 6(1)(c))
  • Detect and prevent fraud, abuse and security violations (legitimate interest)

4. Legal basis for processing (GDPR)

The legal basis for processing your data depends on the context:

  • Contract performance — when we create your account and provide the service
  • Consent — for optional data (profile picture, phone, location for QR check-ins) and marketing communications
  • Legitimate interest — for security, fraud prevention and service improvement
  • Legal obligation — for tax retention and responses to lawful requests from authorities

You can withdraw your consent at any time in your account settings. Withdrawal does not affect the lawfulness of prior processing.

5. Sharing with third parties

We do not sell your personal data. We share data strictly with the following third parties, under data-processing agreements:

  • Event-hosting organization — receives your participation data to run the event (name, email, score, connections; other fields only if authorized in your privacy settings)
  • Cloud hosting provider (EU) — data storage and Platform execution
  • Stripe (Ireland/USA) — payment processing; subject to Stripe's own privacy policies
  • Transactional email provider (EU) — delivery of operational emails
  • Google Play and Apple App Store — for distribution of the app (under their own policies)
  • Google Ireland Ltd. (Google Analytics) — usage statistics for the questa.pt website, only if you accept analytics cookies
  • Public authorities — when legally required (court order, tax authority)

We maintain an up-to-date list of sub-processors available upon request at info@questa.pt.

6. International data transfers

Most data is stored and processed in the European Union (Frankfurt, Germany). When some sub-processors operate outside the EU (e.g. Stripe in the US), transfers are subject to Standard Contractual Clauses approved by the European Commission and/or equivalent mechanisms (Data Privacy Framework, BCRs).

7. Data retention

We keep your data for the time strictly necessary for the purposes described:

  • Active account data: while the account exists
  • Event participation data: up to 24 months after the end of the event (or as decided by the organization)
  • Invoices and tax data: 10 years (Portuguese legal obligation)
  • Technical and security logs: up to 12 months
  • Data after account deletion: anonymized or deleted within 30 days, except legally required retentions

8. Your rights

Under the GDPR you have the following rights:

  • Access — obtain a copy of the data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure ("right to be forgotten") — request deletion of your data
  • Restriction of processing — request limited use of your data in certain circumstances
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — at any time, without affecting prior processing
  • Complaint — lodge a complaint with the Portuguese Data Protection Authority (CNPD) at www.cnpd.pt

To exercise these rights, email info@questa.pt. We will respond within a maximum of 30 days.

9. Children's privacy

The Platform is not intended for children under 13. We do not knowingly collect personal data from children under 13. If a parent or guardian becomes aware that their minor child has provided us with personal data, they should contact info@questa.pt so we can delete that data.

For minors between 13 and 15, processing depends on verifiable parental consent, managed by the event-hosting organization.

10. Cookies and similar technologies

The questa.pt website uses strictly necessary cookies for operation and optional analytics cookies, the latter only with your consent. We do not use advertising cookies and we do not share data with ad networks.

Strictly necessary cookies (no consent required):

  • questa_cookie_consent — stores your cookie decision for 6 months, so we do not ask again on every visit.
  • questa_session and XSRF-TOKEN — session and CSRF protection in the management area. They expire when the session ends.

Analytics cookies (only after you accept):

  • _ga and _ga_* (Google Analytics 4) — distinguish visitors and sessions so we can measure traffic and most-viewed pages. Valid for up to 2 years. The IP address is anonymised and we do not collect data that directly identifies you.

If you decline, no Google script is loaded. You can change your mind at any time via "Cookie preferences" in the site footer — withdrawing consent is as easy as giving it, and it deletes any analytics cookies already set.

The mobile app uses anonymous device identifiers for operation (session, authentication). We do not use IDFA, GAID or cross-app tracking identifiers.

11. Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (HTTPS/TLS 1.2+)
  • Encryption at rest for sensitive data
  • Password hashing with modern algorithms (bcrypt/argon2)
  • Role-based access control (RBAC)
  • Audit logs of administrative actions
  • Regular backups and tested recovery procedures
  • Continuous security updates

In case of a personal-data breach that may result in a high risk to your rights and freedoms, we will notify the supervisory authority (CNPD) within 72 hours and, where appropriate, also the affected users.

12. Automated decisions

The Platform does not make fully automated decisions producing legal effects or similarly significantly affecting you without human intervention.

13. Changes to this Policy

We may update this Policy periodically. We will notify you by email or via the Platform when changes are material. The date of the last update is always indicated at the top of the document.

14. Contact

For any question about this Policy or your personal data:

  • Data Protection Officer: info@questa.pt
  • General email: info@questa.pt
  • Address: Porto, Portugal
  • Supervisory authority: Portuguese Data Protection Authority (CNPD) — www.cnpd.pt
Questa

The event gamification platform built for teams who care about engagement. Quests, leaderboards and live insights — all in one.

info@questa.pt+351 938 353 294
Product
FeaturesPricingThe appSign in
Solutions
ConferencesUniversitiesHackathonsTrade showsCorporate eventsAssociations
Company
Resources & guidesBook a demoFAQContact
Legal
Terms & ConditionsPrivacy PolicyCookie preferences
© 2026 Questa. All rights reserved.Built in Portugal with

We use cookies

We use essential cookies to make the site work and, with your permission, analytics cookies to understand how it is used. You can change your mind at any time. Read the Privacy Policy