Skip to main content
Qubicweb logo

Trust & Safety

Privacy Notice

This notice explains how Qubicbox, including Qubicweb and E-Fraud Watch, collects, uses, stores, and protects personal data under the NDPR and GDPR frameworks.

Last updated: 29 January 2026

Who we are

  • Qubicbox Technologies Limited (“Qubicbox”, “we”, “our”) operates Qubicweb, Qlutterbox, Qubictry, the Trust Badge, and E-Fraud Watch. Qubicbox is the data controller for these services unless we expressly act as a processor for enterprise partners.
  • Operational headquarters sit in Lagos, Nigeria, with TrustOps and engineering teams distributed across the EU/EEA.

Information we collect

  • Identity & verification: names, pronouns, government-issued IDs, guild certificates, selfie/video captures when needed to issue badges.
  • Contact details: email, phone, messaging handles, notification preferences, and optional waitlist details.
  • Incident & listing context: narratives, artefacts, inspection logs, fraud evidence, TrustOps annotations, and marketplace inventory metadata.
  • Payments & protected payment metadata: payout accounts, transaction references, invoice numbers, and commission statements flowing through Qlutterbox or Qubictry.
  • Technical telemetry: device fingerprints, IP addresses, session identifiers, MFA events, moderation audit logs, rate-limiting fingerprints.
  • Trust graph signals: E-Fraud reports, badge status, referrals, leaderboard rank, DSAR tickets, and transparency acknowledgements.

Purposes & lawful bases

  • Contract: fulfilling verification, publishing stories, processing protected payment, inspections, payouts, disputes, and restitution workflows you request.
  • Legal obligation: NDPR/NDPA, GDPR, AML/CFT, financial services, consumer protection, and tax compliance.
  • Legitimate interest: preventing fraud, securing the platform, measuring product usage with privacy-preserving telemetry, and improving moderation accuracy. Legitimate interest assessments are reviewed annually.
  • Consent: optional marketing updates, saved searches, referrals, biometric capture where explicit consent is mandated. Consent can be withdrawn anytime without affecting prior lawful processing.

Retention

  • Verification dossiers, TrustOps case files, and protected payment records: active relationship plus 5 years to support appeals and regulatory audits.
  • Fraud reports and anonymised advisories: retained indefinitely after personal identifiers are removed for public-interest archiving.
  • Evidence uploads: 24 months unless legal holds apply, then securely deleted from primary and backup storage.
  • Audit logs and access records: minimum 36 months for accountability and forensic investigations.
  • Marketing preferences: until withdrawn; requests honoured within 72 hours.

International transfers

  • Primary hosting lives in the European Union (Vercel EU, AWS eu-west-1) with mirrored workloads in Nigeria and South Africa for latency and redundancy. Transfers rely on Standard Contractual Clauses, NDPR adequacy requirements, encryption, and scoped access.

How we secure data

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) across every store.
  • Mandatory MFA for TrustOps, Curators, payout actors, and admin tooling.
  • Honeypots, adaptive rate limiting, and Cloudflare Turnstile on public forms.
  • Evidence sanitisation (EXIF stripping, malware scanning) before analysts review uploads.
  • Quarterly access reviews, vendor diligence, and rehearsed incident response playbooks with 72-hour regulator notifications when required.

Sharing & processors

  • Cloud & infrastructure: Vercel, AWS, Cloudflare, Supabase, Resend, Upstash, Render (region-scoped).
  • Payments & protected payment: Paystack, Flutterwave, regulated payout partners supporting Qlutterbox/Qubictry commerce.
  • Communications: Resend, WhatsApp Business Platform, Twilio Verify for MFA.
  • Partner ecosystems: Qlutterbox, Qubictry, and the Trust Badge service when necessary to fulfil referrals, protected payment, or badge updates.
  • Law enforcement or regulators: only when legally compelled or vital to prevent imminent harm. Every disclosure is logged in immutable TrustOps audit trails.
  • We never sell personal data or permit uncontrolled sub-processing.

Your rights

  • Access, rectification, deletion, restriction, portability, and objection to processing based on legitimate interests.
  • Withdrawal of consent without affecting prior lawful processing.
  • Right to complain to the Nigeria Data Protection Commission (NDPC) or your local EU/EEA supervisory authority.
  • Right to obtain information about automated decision-making; we do not run solely automated decisions with legal effects.

Exercising rights

  • Submit a request via dpo@qubicbox.com with the subject “Data Subject Request” and include the email/phone tied to your account.
  • We acknowledge within one working day and fulfil within 30 days (extendable by 15 days for complex cases).
  • Postal address: Qubicbox Data Protection Office, 12B Adeola Odeku Street, Victoria Island, Lagos, Nigeria.

Product-specific notes

  • Qubicweb & E-Fraud Watch: community submissions are reviewed and anonymised before publication. Reporters can remain anonymous; personal contact remains private.
  • Qlutterbox & Qubictry: protected payment payouts and guild membership require verified identity and payout details to meet NDPR and financial regulations.
  • Trust Badge: biometric and document verification data is encrypted, access-logged, and deleted once verification expires unless retention is mandated by law.

Updates

  • We review this notice quarterly or whenever regulations, processors, or product scope changes. Updated versions appear here with a new revision date.
  • Latest revision: 29 January 2026.