This Privacy Policy describes how Pavel Ivanov, in the process of incorporating the company BCrypto (the "Controller"), processes the personal data of users of the Q-Audion application (the "Application") during its Beta Test phase, in compliance with the GDPR and Italian Legislative Decree 196/2003 as amended by Decree 101/2018.
1. Data controller
Pavel Ivanov, a natural person, Italian tax code VNVPVL76C22L219M, domiciled at Corso Orbassano 216, 10137 Torino (TO), Italia, reachable at bcrypto@gmail.com. Upon incorporation of BCrypto, the controller role will transfer to the incoming company. Given the current scale of processing, no DPO has been appointed under Art. 37 GDPR.
2. Categories of data, purposes and legal basis
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account identifiers | User ID, display name, profile picture (end-to-end encrypted) | Account creation and management | Contract |
| Phone number | If provided, stored only as a SHA-256 hash with pepper, never in plaintext | Discovery of contacts already on Q-Audion | Consent / Contract |
| Communication content | Messages, audio/video calls, attachments | Service delivery | Contract |
| Technical metadata | Sender/recipient, timestamps, delivery status, call type, connection IP | Routing, security | Contract / Legitimate interest |
| Presence data | Online/offline status, last seen | Presence feature | Contract |
| Push notification tokens | Firebase Cloud Messaging (Google) | Notification delivery | Contract |
| Diagnostic data | Firebase Crashlytics (Google): crashes, OS/device version | Bug detection | Legitimate interest |
| Voluntary reports | Bug reports, beta feedback | Service improvement | Consent |
| Device integrity | Google Play Integrity / Keystore | Fraud and tampering prevention | Legitimate interest |
Messages, calls and attachments are protected by end-to-end encryption: the Controller cannot access their plaintext content.
3. Processing methods and security measures
Processing uses IT tools with logic tied to the purposes above. Measures in place: end-to-end encryption of content; cryptographic hashing of phone numbers; encryption in transit (TLS); app and device integrity checks; minimisation of data access.
4. Recipients and data processors
- Server and hosting infrastructure providers for signalling, sync and call-connectivity relay;
- Google Ireland Limited, for Firebase Cloud Messaging, Firebase Crashlytics and Play Integrity;
- network infrastructure providers (STUN/TURN relay), which transiently process IP addresses and routing metadata without access to encrypted content.
If the User enables the optional Google Assistant integration for voice-initiated calls or messages, the voice component is processed by Google under its own privacy policy, as an independent controller for that part. The Controller only receives the name and/or number resolved by Google Assistant, used transiently.
Data is not disclosed to third parties for marketing or commercial profiling.
5. Transfers outside the EU
Some processors (notably Google) may process data outside the European Economic Area, based on an adequacy decision (including, where applicable, the EU-U.S. Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
6. Retention period
Account data is kept for the duration of use and deleted, typically within 30 days, after account deletion or the end of the Beta Test. Technical communication metadata is kept for the minimum time necessary, generally no more than 90 days. Diagnostic data follows the provider's terms (Crashlytics), generally no more than 90 days.
7. Data subject rights
Users have the right to access, rectify, erase, restrict and object to processing, to data portability, and to withdraw consent at any time, by writing to bcrypto@gmail.com. Users may also lodge a complaint with the Italian Data Protection Authority (Garante).
8. Minors
The Application, during Beta Test, is not intended for persons under 18. The Controller does not knowingly collect data from minors and will delete it if it becomes aware of any.
9. Nature of data provision
Providing the data required to create an account is necessary to use the Application. Phone number, push notifications and participation in bug reporting are optional.
10. Automated decision-making
The Controller does not carry out processing based solely on automated decision-making or profiling under Art. 22 GDPR.
11. Changes
The Controller may update this Policy, notifying Users via the Application or by publishing the updated version with its date.
12. Contact
For questions or to exercise your rights: bcrypto@gmail.com.