Privacy Policy
Privacy Policy
Last Updated: April 2026
Effective Date: April 2026
RhythmQ Inc.
1. Introduction
RhythmQ Inc. (“RhythmQ,” “we,” “us,” or “our”) operates the RQ Platform and website located at rhythmq.com and rqawards.com (collectively, the “Service”). We are committed to protecting personal data and processing it transparently, lawfully, and securely.
This Privacy Policy explains:
- what personal data we collect and how we use it;
- our role as a data processor or controller depending on context;
- the legal bases on which we rely;
- how we transfer data internationally;
- the rights available to individuals under the GDPR, the Brazilian LGPD, and applicable U.S. privacy laws; and
- how to exercise those rights.
Please read this policy carefully. If you have any questions, contact us using the details in Section 11.
2. Scope and Applicability
This Privacy Policy applies to:
- visitors and users of the rhythmq.com and rqawards.com websites;
- individuals who contact us directly (e.g., via forms, email, or telephone);
- prospective and existing business clients and their representatives; and
- end-users whose personal data is processed through the RQ Platform on behalf of our business clients.
Where RhythmQ acts as a data processor on behalf of a business client (see Section 3), the applicable privacy notice for end-users is that published by the relevant business client as data controller. This policy supplements — and does not replace — any such notice.
3. Our Role: Controller vs. Processor
Privacy law distinguishes between “data controllers” (who determine the purposes and means of processing) and “data processors” (who process data on controllers’ instructions). RhythmQ acts in both capacities, depending on context:
3.1 RhythmQ as Data Processor — Core Platform Service
In this capacity:
- RhythmQ processes personal data solely on the documented instructions of the business client;
- we do not use end-user personal data for our own purposes without explicit authorisation;
- we implement appropriate technical and organisational security measures;
- we assist business clients in responding to data subject rights requests;
- we engage sub-processors only with the client’s prior written consent (general or specific, as agreed); and
- we conclude a Data Processing Agreement (DPA) with each business client as required by Article 28 GDPR and equivalent provisions under applicable law.
If you are an end-user filling out a form on a 3rd party website, powered by our Services, your primary point of contact for privacy matters is the Controller, meaning the organization operating that website.
Controllers may configure the forms to require any given number of Data Points, according to their needs (which may include Sensitive Personal Data). RhythmQ acting as a Processor has no control or even notion of which dataset each Controller is using on their respective forms.
3.2 RhythmQ as Data Controller — Own Activities
RhythmQ acts as an independent Data Controller when processing personal data for its own purposes, including:
- operating and improving the rhythmq.com website;
- marketing and promotional communications (where consent or legitimate interest applies);
- managing relationships with prospective and existing business clients;
- recruitment and employment activities; and
- complying with legal obligations.
The remainder of this Privacy Policy addresses our controller activities in detail.
4. Personal Data We Collect as a Controller
Depending on how you interact with us, we may collect the following categories of personal data:
4.1 Identity and Contact Data
- Full name
- Corporate Email address
- Corporate Telephone number
- Job title and employer organisation
4.2 Technical and Usage Data
- IP address
- Browser type and version
- Cookie identifiers
4.3 Communications Data
- Content of messages, enquiries, or support requests sent to us
- Records of communications for quality and compliance purposes
4.4 Commercial and Contractual Data
- Company information and procurement details
- Billing and invoicing information (excluding payment card data, which is handled by our payment processors)
- Contractual records
4.5 Special Categories of Data
We do not undertake the Processing of special categories of personal data/ Sensitive Personal Data as a Controller (e.g., health data, racial or ethnic origin, religious beliefs) through our website, marketing activities or other activities. If such data is provided inadvertently directly to us, it will be deleted promptly.
5. Purposes of Processing
We use personal data, as a Controller and exclusively under a B2bv perspective for the following purposes:
- Providing and operating the Service, including Corporate Client user support;
- Managing and fulfilling contractual obligations with business clients;
- Sending service-related communications (e.g., account notifications, updates);
- Sending marketing and promotional materials, where you have opted in or we have a legitimate interest;
- Analysing website usage to improve functionality and user experience;
- Preventing and detecting fraud, abuse, or security incidents;
- Complying with legal and regulatory obligations; and
- Pursuing or defending legal claims.
6. Sharing and Disclosure of Personal Data
We do not sell personal data. We may share personal data with:
6.1 Service Providers (Sub-Processors)
We engage trusted third-party service providers who process data on our behalf under binding data processing agreements. Categories include: cloud hosting, analytics, email delivery, customer relationship management, payment processing, and security services.
6.2 Business Clients (Controllers)
In our processor capacity, we share processed data with the relevant business client (as controller) in accordance with the applicable DPA.
6.3 Legal and Regulatory Authorities
We may disclose personal data when required by law, court order, or binding regulatory demand, including to law enforcement or governmental authorities. Where legally permissible, we will notify affected parties.
7. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to provide core functionality, analyse traffic, and (where you have consented) deliver personalised content.
Categories of cookies we use:
- Strictly necessary: essential for the website to function. These cannot be disabled.
- Analytics/performance: help us understand how visitors interact with our site (e.g., Google Analytics). Set only with your consent in the EU/EEA.
- Functional: remember your preferences (e.g., language settings).
- Marketing: used to deliver targeted advertisements. Set only with your consent.
You can manage your cookie preferences through our consent banner or your browser settings. Refusing certain cookies may affect the functionality of our website. For full details, see our Cookie Policy.
8. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration, or disclosure. Measures include:
- Encryption of data in transit (TLS) and at rest;
- Access controls and role-based permissions;
- Regular security assessments and vulnerability testing;
- Incident response and breach notification procedures; and
- Staff training on data protection and information security.
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but will notify affected individuals and regulators of any breach in accordance with applicable law (within 72 hours to the relevant supervisory authority under the GDPR; within the timeframes required under applicable U.S. laws).
9. Your Rights under Personal Data Protection legislation
Depending on your location and the applicable law, you may have the following rights. Where RhythmQ acts as a processor (Section 3.1), you should direct your request to the relevant data controller (your employer or the organisation that deployed RhythmQ). Where RhythmQ acts as a controller (Section 3.2), you may exercise your rights directly with us.
| Right | Applicable Law(s) | Description |
|---|---|---|
| Right to be informed | GDPR | Right to receive clear, concise information about how your data is processed (fulfilled by this policy). |
| Right to restriction of processing | GDPR | Right to request that we limit processing of your data in certain circumstances (e.g., while accuracy is contested). |
| Right to object | GDPR • LGPD | Right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds. |
| Right not to be subject to automated decisions | GDPR • LGPD | Right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects. |
| Right of access | GDPR • LGPD • CCPA/CPRA • VCDPA • CPA • CTDPA | Right to obtain confirmation of whether we process your personal data, access to that data, and a copy in a commonly used format. |
| Right to rectification / correction | GDPR • LGPD • CCPA/CPRA • VCDPA • CPA • CTDPA | Right to have inaccurate or incomplete personal data corrected or updated. |
| Right to erasure / deletion | GDPR • LGPD • CCPA/CPRA • VCDPA • CPA • CTDPA | Right to request deletion of your personal data, subject to certain exceptions (e.g., legal obligations, freedom of expression). |
| Right to data portability | GDPR • LGPD • CCPA/CPRA (limited) | Right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller. |
| Right to opt out of sale / sharing | CCPA/CPRA • VCDPA • CPA • CTDPA | U.S.-specific right to opt out of the sale of your personal information or its sharing for cross-context behavioural advertising. RhythmQ does not sell personal data. |
| Right to opt out of targeted advertising | CCPA/CPRA • VCDPA • CPA • CTDPA | U.S.-specific right to opt out of the use of your personal data for targeted advertising based on cross-site tracking. |
| Right to limit use of sensitive data | CCPA/CPRA | California-specific right to direct us to limit the use and disclosure of sensitive personal information to what is necessary to provide the services. |
| Right to non-discrimination | CCPA/CPRA • VCDPA • CPA • CTDPA | U.S.-specific right not to receive discriminatory treatment (e.g., denial of goods or services) for exercising your privacy rights. |
| Right to appeal | VCDPA • CPA • CTDPA | U.S.-specific right (Virginia, Colorado, Connecticut, and similar states) to appeal a decision we make in response to your rights request within a reasonable time. |
| Right to revoke consent | GDPR • LGPD • CCPA/CPRA | Right to withdraw consent at any time where processing is consent-based, without affecting the lawfulness of prior processing. |
| Right to lodge a complaint | GDPR • LGPD • Various U.S. state laws | Right to lodge a complaint with the competent supervisory authority: the relevant EU/EEA Data Protection Authority, the UK ICO, the Brazilian ANPD, or the relevant U.S. state Attorney General. |
10. Children’s Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately and we will take steps to delete such data promptly.
11. Contact Us
For any questions, concerns, or rights requests relating to this Privacy Policy, please contact us:
RhythmQ Inc.
Privacy Enquiries
Email: dpo@rhythmq.com




