Last updated: October 1, 2026
This Privacy Policy describes how Qevik (hereinafter "Qevik", "we", "us") collects, processes and protects the personal data of users of the Qevik platform, accessible via the website and associated NFC/QR products (key rings, NFC cards).
The Qevik service allows users to associate a unique identifier with their personal or professional belongings. If someone finds a lost item, they can scan that identifier or enter the System ID on our website. Where the identifier belongs to an individual, the finder sees exactly the information that person has chosen to publish, and nothing beyond it; which information that is, they decide at any time in their visibility settings. Where they publish none, the finder receives no personal data and, when the code is scanned, we notify the owner ourselves by email about the find. Where the identifier belongs to a company, we display its public company profile: company name, legal form, address, website, telephone and fax number, the contact person designated by the company, with that person's name, telephone number and email address, and, where an engraved key on the item identifies an employee, the information that employee has published themselves, without their precise address. The company's details do not depend on any visibility setting and the company decides which of them it provides; the employee's details follow their own settings.
We process personal data in strict compliance with Regulation (EU) 2016/679 (GDPR / DSGVO), the German Federal Data Protection Act (BDSG) in its applicable version, and the Telecommunications and Telemedia Data Protection Act (TTDSG).
This policy applies to all categories of platform users: individuals, business accounts, agents (relay points), administrators, and anonymous finders.
Data protection contact: support@qevik.com
If you have any questions about the processing of your personal data, you may contact us at the address above or by email at support@qevik.com.
We collect only the data strictly necessary for the purposes described in this policy. The following categories of data are processed:
Transactions are processed exclusively through Stripe, Inc. Qevik does not collect, store or at any time access payment card data (card number, expiry date, security code). Stripe acts as a data processor within the meaning of Art. 28 GDPR.
We determine only the user's country, never their precise location. The country is established in the following order: the country you select yourself on the website, your own choice always taking precedence over any estimate, failing which an estimate made by our hosting provider from your IP address, failing which the country of the address held in your account, failing which the region indicated by your browser's language preferences (Accept-Language header). If none of these is available, Germany applies as the default market. This country is used solely to display the applicable language, catalogue, currency and VAT rate. No precise geolocation data (GPS coordinates) is collected or stored, and your IP address is not transmitted to any third-party geolocation service.
Every processing activity rests on a legal basis under Art. 6 GDPR. The main processing purposes and their legal bases are as follows:
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
We never sell, rent or transfer your personal data to third parties for commercial purposes. This section names two different sets of recipients: first the processors listed below, which act solely on our instructions and with which we have concluded a Data Processing Agreement (DPA) compliant with Art. 28 GDPR, and second lost property offices and partner agencies, which are independent controllers for their own processing and are not processors. First the processors:
In the context of the retrieval service, the finder's details from a public report (section 3.6) are transmitted to the owner of the identified item so that the owner can reach the finder. This sharing is inherent to the service purpose and is based on Art. 6(1)(b) GDPR.
When an item carrying a Qevik identifier is handed in to a lost property office or a partner agency, we use that identifier to determine the owner and we notify the owner ourselves by email: that message contains the name of the organisation, its full postal address, together with the name, email address and telephone number of the agent who registered the item, and, where the organisation has provided them, its opening hours. The organisation itself does not automatically receive your contact details. Your settings include a separate switch reserved for lost property offices, which is off on every newly created account: when it is on, an office holding one of your items may look up your email address and your telephone number without asking you first, including where you have not published those details. When it is off, the office actually holding the item has to send you a request. That request names exactly one detail, your email address or your telephone number, and may include a freely worded reason. You receive it by email and you decide, from your account, whether to grant or decline it. A granted authorisation covers one detail, one organisation and one item. It has no fixed term: it lasts as long as that organisation holds the item and ends when the item is returned. You can withdraw it at any time, with immediate effect. Partner agencies that are not lost property offices see only the information you have published, and this switch does not apply to them. For business accounts, the company name, the description and the designated public contact are disclosed without further condition as company information, and a separate switch belonging to the company, also off by default, additionally discloses the name of the employee who holds the item.
Three of our processors are headquartered in the United States (Stripe, Cloudflare, Vercel). These transfers to a third country are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR, constituting appropriate safeguards.
We do not carry out any other transfers of data to third countries outside this contractual framework. You may obtain a copy of the safeguards in place by contacting us at support@qevik.com.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration or destruction, in accordance with Art. 32 GDPR:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we commit to notifying the competent supervisory authority within 72 hours (Art. 33 GDPR) and informing you directly if the risk is high (Art. 34 GDPR).
Qevik uses only technically necessary cookies for the operation of the service. We do not use any advertising, behavioural tracking or third-party analytics cookies (no Google Analytics, no social media pixels).
Purely technical and preference cookies do not require prior consent under § 25(2) TTDSG. For more information, please consult our Cookie Policy accessible from the website footer.
In accordance with Articles 15 to 21 GDPR and the provisions of the BDSG, you have the following rights with respect to your personal data:
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority: DIE LANDESBEAUFTRAGTE FÜR DATENSCHUTZ UND INFORMATIONSFREIHEIT NORDRHEIN-WESTFALEN.
You may also contact the supervisory authority of your habitual residence or place of work. We encourage you, however, to contact us first so that we may address your concern directly.
To exercise your rights or for any questions regarding this policy:
Email: support@qevik.com
We commit to responding to any request within one month of receipt (Art. 12(3) GDPR). This period may be extended by a further two months for complex or numerous requests, after notification.
We reserve the right to amend this policy at any time to comply with legal developments or changes to our service. In the event of a material change, we will notify you by email or through a prominent notice on the platform at least 30 days before the change takes effect. The current version is always available on this page.
Version 1.0.1
In force from October 1, 2026 to October 1, 2026
Previous versionsWhen a person reports, using a Qevik identifier, that they have found an item, we collect the details they enter in the report form: first name (required), last name (optional), country where the item was found (required), email address (optional) and telephone number (optional). Making the report is itself voluntary. These details are used solely to notify the owner and to let the owner get in touch with the finder; we do not use them for any other purpose and we do not retain them. No Qevik account is needed for this.
Where the item is instead handed in to a lost property office or a partner agency, the agent on site records the case, and the following details about the finder are then stored: first name, last name, email address and telephone number, together with whether their identity was verified and whether they claim the item for themselves. The contact details make it possible to reach them. The two findings serve a different purpose: the organisation needs them to preserve the rights the law grants the finder, namely the finder's reward and the possible acquisition of ownership once the statutory period has run. Retention periods are set out in section 5.
We retain the version of the Terms and Conditions accepted, the version of this Privacy Policy accepted, and the timestamp of acceptance. This data is necessary to demonstrate the lawfulness of our processing activities (Art. 5(2) GDPR, accountability principle).
The legal basis for the notification we send to the owner is Art. 6(1)(b) GDPR (performance of the return service). The legal basis for a lost property office accessing your email address and your telephone number is your consent under Art. 6(1)(a) GDPR, whether it comes from the switch or from an authorisation you have granted, and you may withdraw it at any time under Art. 7(3) GDPR. For disclosing the company name, the description and the designated public contact of a business account, and, where the company switch is on, the name of the employee holding the item, we rely on Art. 6(1)(f) GDPR (legitimate interest in returning the item); the company informs its staff of this processing under Art. 13 and 14 GDPR, and you may object to it under Art. 21 GDPR. The lost property office is an independent controller for its further processing of the data it receives and is not a processor within the meaning of Art. 28 GDPR: it processes that data to carry out its statutory return duties. Every request, every authorisation, every refusal and every withdrawal is logged (Art. 5(2) GDPR).