Privacy Policy

Last updated: July 19, 2026

1. Introduction

andba solutions FlexCo ("we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you use QuickPrio (the "Service", including this website and the QuickPrio application) in accordance with the EU General Data Protection Regulation (GDPR) and Austrian data protection laws.

We are the data controller responsible for your personal data. Our contact person for data protection matters is Andreas Baumühlner.

2. Personal Data We Collect

2.1 Account Information

  • Email address: Used for authentication and account management
  • Password: Stored in encrypted form for account security

2.2 Task Management Data

  • Task titles: The names you give to your tasks
  • Task descriptions: Detailed information about your tasks
  • Tag names: Categories and labels you create
  • Impact and effort ratings: Priority ratings you assign
  • Completion status: Whether tasks are completed or archived
  • Due dates: Deadlines you set for tasks
  • Creation timestamps: When tasks and tags were created

2.3 Analytics Data

If you consent to analytics, we collect:

  • Usage patterns: Which features you use and how often
  • Session data: Duration and frequency of your visits
  • Device information: Browser type, operating system, screen size
  • Interaction events: Clicks, navigation, feature usage

Important: We do NOT collect the content of your tasks, descriptions, or tag names in analytics. We only track aggregate usage patterns.

2.4 Technical Data

  • IP address: Temporarily processed for security and service provision
  • Session tokens: For maintaining your logged-in state

3. How We Use Your Data

3.1 Service Provision (Legal Basis: Contract Performance)

  • Creating and managing your account
  • Storing and synchronizing your tasks and tags
  • Providing task management features
  • Enabling access across multiple devices

3.2 Authentication (Legal Basis: Contract Performance)

  • Verifying your identity when you log in
  • Maintaining your session security
  • Preventing unauthorized access

3.3 Analytics and Improvement (Legal Basis: Consent)

  • Understanding how users interact with the Service
  • Identifying and fixing bugs
  • Improving user experience
  • Developing new features

You can withdraw your consent for analytics at any time through your account settings.

3.4 Essential Cookies (Legal Basis: Legitimate Interest)

  • Maintaining your logged-in state
  • Ensuring service functionality
  • Providing security features

4. Legal Basis for Processing

Under GDPR Article 6, we process your personal data based on the following legal grounds:

  • Contract Performance (Article 6(1)(b)): Processing your account data, tasks, and tags is necessary to provide the Service you signed up for
  • Consent (Article 6(1)(a)): Analytics and session recording require your explicit consent, which you can withdraw at any time
  • Legitimate Interest (Article 6(1)(f)): Essential cookies are necessary for the Service to function properly and for security purposes

5. Third-Party Data Processors

We use the following third-party services to provide and improve our Service. These processors are GDPR-compliant and process data on our behalf:

5.1 Supabase (Database and Authentication)

  • Purpose: Database hosting, user authentication, data storage
  • Data processed: All account and task management data
  • Location: EU region (GDPR-compliant)
  • Privacy policy: https://supabase.com/privacy

5.2 PostHog (Analytics and Session Recording)

  • Purpose: Product analytics, session recording, user behavior analysis
  • Data processed: Usage patterns, session data, device information (only if you consent)
  • Location: EU region (GDPR-compliant)
  • Privacy policy: https://posthog.com/privacy
  • Note: All input fields are automatically masked in session recordings

5.3 Vercel (Hosting)

  • Purpose: Application hosting and content delivery
  • Data processed: Technical data (IP addresses, request logs)
  • Location: Global CDN with EU presence
  • Privacy policy: https://vercel.com/legal/privacy-policy

We do not sell, rent, or share your personal data with any other third parties for their marketing purposes.

6. Cookies and Tracking

We use cookies and similar technologies to provide and improve our Service. For detailed information about the cookies we use, please see our Cookie Policy.

6.1 Essential Cookies

These cookies are strictly necessary for the Service to function:

  • Supabase authentication token: Stored in localStorage with key "quickprio-auth", maintains your logged-in state until you log out

6.2 Analytics Cookies (Requires Consent)

These cookies help us understand how you use the Service:

  • PostHog cookies: Track usage patterns and session data, duration per PostHog's policy

You can manage your cookie preferences through the cookie banner or in your account settings.

7. Data Retention

We retain your personal data only for as long as necessary to provide the Service and comply with legal obligations:

  • Account and task data: Retained until you delete your account
  • Analytics data: Retained according to PostHog's retention policy (typically 90 days for session recordings, longer for aggregate analytics)
  • Upon account deletion: All your personal data is immediately and permanently deleted from our systems

We do not retain any personal data after account deletion, except where required by law (e.g., for tax or accounting purposes).

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

8.1 Right of Access (Article 15)

You have the right to access all personal data we hold about you. You can view your data through the Service interface or request a copy by contacting us.

8.2 Right to Rectification (Article 16)

You can update and correct your personal data at any time through your account settings or by editing your tasks and tags.

8.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You can delete your account and all associated data at any time through the "Delete Account" button in your account settings. This action is immediate and irreversible.

8.4 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, machine-readable format (JSON). Contact us at quickprio@gmail.com to request a data export.

8.5 Right to Object (Article 21)

You can object to processing based on legitimate interests. For analytics processing, you can withdraw consent at any time through your account settings.

8.6 Right to Withdraw Consent (Article 7(3))

You can withdraw your consent for analytics and session recording at any time through:

  • Account settings → Analytics opt-out toggle
  • Cookie preferences → Disable analytics cookies

Withdrawing consent does not affect the lawfulness of processing before withdrawal.

8.7 Right to Lodge a Complaint

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Wien, Austria
Website: https://www.dsb.gv.at

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption: All data is encrypted in transit (HTTPS/TLS) and at rest
  • Access control: Row Level Security (RLS) ensures you can only access your own data
  • Authentication: Secure password hashing and session management
  • Infrastructure: GDPR-compliant hosting in EU regions
  • Regular updates: Security patches and updates applied promptly

However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

10. Data Breach Notification

In accordance with GDPR Article 33, we have procedures in place to handle data breaches:

  • We will report any data breach to the Austrian Data Protection Authority within 72 hours of becoming aware of it
  • If the breach poses a high risk to your rights and freedoms, we will notify you without undue delay
  • We will provide information about the nature of the breach, likely consequences, and measures taken

If you suspect a data breach, please contact us immediately at quickprio@gmail.com.

11. International Data Transfers

We primarily process data within the European Economic Area (EEA). Our third-party processors (Supabase, PostHog) use EU regions for data storage and processing.

If data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:

  • EU Standard Contractual Clauses
  • Adequacy decisions by the European Commission
  • Other legally approved transfer mechanisms

12. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us, and we will delete it immediately.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by sending an email to your registered email address or displaying a prominent notice on the Service.

The "Last updated" date at the top of this policy indicates when it was last revised. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.

14. Contact Information

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

andba solutions FlexCo
Scheunengasse 2-4/2/2, 3430 Tulln, Austria
Email: quickprio@gmail.com
Contact person for data protection: Andreas Baumühlner