Privacy Policy
Last updated: October 8, 2026
This Privacy Policy explains how QubForge, tehnološke rešitve, d.o.o. ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the WhatsNextAction platform ("Service"). We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Slovenian Personal Data Protection Act (ZVOP-2), and other applicable data protection laws.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
QubForge, tehnološke rešitve, d.o.o. Jakopičeva ulica 9, 2000 Maribor, Slovenia
For all privacy-related inquiries, please contact us at: info@whatsnextaction.com
2. Personal Data We Collect
2.1 Account Data
When you register for the Service, we collect:
- Email address - used as your account identifier and for account-related communications (password resets, security notifications)
- Password - stored only in hashed form; we never have access to your plain-text password
- Google account identifier - if you choose to sign in with Google, we receive a verified identifier and your email address from Google to create or link your account. We do not receive your Google password, and we do not request access to your Gmail, Google Calendar, Google Drive, or other Google services.
2.2 User-Generated Content
When you use the Service, you create and store content including:
- Inbox items (stuff), actions, and projects
- Descriptions, comments, and tags
- File attachments (stored in the Reference file manager)
- Recurring action templates
- Calendar entries and scheduling data
You control what content you create. We process this content solely to provide the Service to you.
2.3 Inbound Email Content (Email-to-Inbox)
If you use the Email-to-Inbox feature (available on the Pro and Team plans), you can generate a unique email address that forwards messages into your inbox as items. When you or others send mail to that address, we process the message content to create an item in your inbox, including:
- The sender's email address
- The subject line and message body
- Any attachments included with the message
This may include personal data about third parties (the people who send mail to your address). We process it solely to create the corresponding item in your inbox. You can pause capture or reset (invalidate) your inbox address at any time from your settings.
2.4 Collaboration Data (Team plan)
If you use collaboration features on the Team plan, certain data becomes visible to the other WhatsNextAction users you choose to work with:
- Connections - when you invite another person to connect, we store the invitee's email address and send them an invitation. Invitations may be sent to people who do not yet have a WhatsNextAction account.
- Delegation - when you delegate an action to a connection, the action's title, description, and related details are shared with that person as an item in their inbox, and completion updates are shared back with you.
- Shared projects - when you share a project, the members you choose can see the project's actions (titles, descriptions, attachments), assignments, completion status, and comments. Your personal tags remain private to you and are never shown to other members.
We share this data only with the specific users you choose, and only to provide the collaboration features you have enabled.
2.5 Billing and Payment Data
If you subscribe to a paid plan, we collect and store:
- Billing details - the full name, address, and country you enter at checkout (the country determines the VAT rate)
- Payment records - date, amount, plan, status, payment method type and, for cards, the card brand and last 4 digits, and refunds of each payment, together with the invoices and credit notes we issue to you
- Location evidence for VAT - the country of your card's issuer, where available (received from our payment provider) and, for your first payment, the country derived from your IP address. EU VAT law requires us to keep evidence of the customer's location.
- ToS acceptance record - the version of the Terms of Service you accepted at checkout, the time, your IP address and browser (user agent)
We never receive your full card number, bank account details or other payment credentials; these are entered on our payment provider's page. For card payments we receive only the card brand and last 4 digits, which appear on your invoice.
2.6 Technical and Session Data
We automatically collect certain technical data when you use the Service:
- IP address - recorded per login session
- Device information - browser and device string (e.g., "Chrome on Windows"), used to identify sessions in your account settings
- Session timestamps - login time and last activity time per session
- Authentication tokens - stored in your browser's localStorage for session management
2.7 Preference Data
Your application settings are stored to provide a personalized experience:
- Calendar preferences (week start day, time format, business hours)
- Display preferences (view modes, item positioning, theme)
- Tag presets and context filters
- Notification preferences (email notification toggles)
- Dismissed tips and hints
2.8 Data We Do Not Collect
- We do not use analytics or tracking tools
- We do not use advertising cookies or pixels
- We do not collect location data beyond your IP address and the country-level evidence described in Section 2.5
- We do not collect biometric data
3. Legal Basis for Processing
We process your personal data under the following legal bases (Article 6 GDPR):
| Data Category | Legal Basis | Purpose |
|---|---|---|
| Account data (email, password) | Contract performance (Art. 6(1)(b)) | Necessary to create and maintain your account and provide the Service |
| User-generated content | Contract performance (Art. 6(1)(b)) | Necessary to deliver the core functionality of the Service |
| Inbound email content (Email-to-Inbox) | Contract performance (Art. 6(1)(b)) | Necessary to capture forwarded messages into your inbox |
| Collaboration data (Team plan) | Contract performance (Art. 6(1)(b)) | Necessary to provide delegation and shared-project features you enable |
| Payment data | Contract performance (Art. 6(1)(b)) | Necessary to process subscriptions and payments |
| Invoices, payment records, and VAT location evidence | Legal obligation (Art. 6(1)(c)) | Required by tax and accounting law (invoicing, VAT, and fiscal verification of invoices) |
| ToS acceptance record | Legitimate interest (Art. 6(1)(f)) | Proof of the contract terms you accepted at checkout |
| Technical/session data | Legitimate interest (Art. 6(1)(f)) | Security, fraud prevention, and service reliability |
| Preference data | Contract performance (Art. 6(1)(b)) | Necessary to provide personalized service features |
Where we rely on legitimate interest, we have conducted a balancing test and determined that our interests do not override your fundamental rights. You have the right to object to processing based on legitimate interest (see Section 8).
4. How We Use Your Data
We use your personal data exclusively for the following purposes:
- Providing the Service - storing and organizing your content, synchronizing across your sessions
- Authentication and security - verifying your identity, managing login sessions, detecting unauthorized access
- Account communications - sending password reset emails, email verification, login alerts, security notifications, subscription and payment notices, and service notices (such as changes to these terms, maintenance, and security matters)
- Product announcements - occasional emails about new features and product news (you can opt out in notification settings)
- Task notifications - sending optional email reminders such as tasks due today, daily next-action summaries, and project nudges (controllable via notification settings)
- Collaboration - enabling delegation and shared projects with the connections you choose (Team plan)
- Subscription management - processing payments, issuing invoices, managing plan tiers and feature access
- Service maintenance - identifying and resolving technical issues, ensuring platform stability
- Legal compliance - fulfilling our legal obligations under applicable law
We do not use your data for profiling, automated decision-making, targeted advertising, or any purpose beyond providing and maintaining the Service.
5. Data Sharing and Third Parties
We share your personal data only with the following categories of recipients, strictly as necessary to provide the Service:
5.1 Infrastructure Provider
- Google Cloud Platform (EU region - Prague, Czech Republic) - hosts our servers and databases within the European Economic Area
5.2 Email Delivery
- Zoho ZeptoMail (EU data centre) - delivers our emails (account, security, and notification emails)
- Zoho Mail (EU data centre) - receives messages sent to Email-to-Inbox addresses before they are added to your inbox
5.3 Sign-In with Google
- Google - if you choose to sign in with Google, Google authenticates you and provides us with a verified identifier and your email address to create or link your account. This is governed by Google's own privacy policy. We do not request access to any of your Google data beyond basic sign-in information.
5.4 Payment Processing
- Dinaro d.o.o. (formerly Paywiser d.o.o.), Bravničarjeva ulica 13, 1000 Ljubljana, Slovenia, an electronic money institution licensed by the Bank of Slovenia - processes subscription card payments. We share your email address, billing details, and the plan you purchase with Dinaro so it can process your payments; on its checkout page Dinaro also collects your card details (card number, expiry date, cardholder name) and IP address. Your full card details are never received or stored by us; we receive only the payment result, the country of your card's issuer, and the card brand and last 4 digits.
- As our processor: for the payment gateway (integration and technical operation of card acceptance) and the settlement of payments, Dinaro processes personal data on our behalf under a data processing agreement. Its sub-processor for the payment gateway software is SIA Spell (Riga, Latvia).
- As an independent controller: for card acquiring and payment processing under its licence, fraud monitoring and prevention, anti-money-laundering checks, and its other legal obligations, Dinaro decides how it processes the data itself. For this it works with financial partners such as partner banks (e.g. Shift4 Limited, Malta) and the card schemes (Visa, Mastercard). Dinaro's own processing is described in its privacy policy at dinaro.si/privacy-policy.
- Dinaro generally retains payment and transaction records for 10 years after the transaction, or longer where required by law. When you delete your account, we also delete your customer record at the payment platform, subject to these legal retention obligations.
- Stripe Payments Europe, Limited, 1 Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland - processes subscription payments when the checkout page shows Stripe as the payment provider. We share your email address, billing name, address and country, the plan you purchase, and our internal user identifier with Stripe so it can process your payments; on its checkout page Stripe also collects your payment details (such as card number or bank account details), IP address, and device data. Your full payment details are never received or stored by us; we receive only the payment result, the payment method type and, for cards, the country of the card's issuer and the card brand and last 4 digits.
- As our processor: for processing payments on our behalf, Stripe processes personal data under the data processing agreement that forms part of its Services Agreement.
- As an independent controller: for fraud monitoring and prevention, anti-money-laundering checks, and its other legal obligations, Stripe decides how it processes the data itself. Payment services are provided by Stripe Technology Europe, Limited, an electronic money institution authorised by the Central Bank of Ireland. Stripe's own processing is described in its privacy policy at stripe.com/privacy.
- Stripe retains payment and transaction records as required by its legal obligations. When you delete your account, we also delete your customer record at Stripe, subject to these legal retention obligations.
5.5 Tax Authority
- Financial Administration of the Republic of Slovenia (FURS) - where required by Slovenian law (ZDavPR), we send invoice data to FURS for fiscal verification of invoices. We also report VAT as required by law.
5.6 Avatar Service
- Gravatar (Automattic, Inc.) — We send a one-way SHA-256 hash of your lowercase email address to gravatar.com to retrieve your profile avatar image. No other personal data is shared with Gravatar. If no Gravatar account exists for your email, no image is returned and a local fallback (your initials) is displayed instead.
5.7 Other WhatsNextAction Users (Team plan)
- If you use collaboration features, content you choose to delegate or share becomes visible to the specific connections you select, as described in Section 2.4. This sharing happens only at your direction and only with the users you choose.
5.8 What We Do Not Do
- We do not sell your personal data to any third party
- We do not share your data with advertisers or data brokers
- We do not use your content to train machine learning models
- We do not provide any third party with access to your content beyond what is described above
5.9 Legal Obligations
We may disclose your data if required to do so by law, court order, or a binding request from a competent authority.
6. International Data Transfers
We process your data within the European Economic Area (EEA). Our servers are hosted by Google Cloud Platform in Prague, Czech Republic, and our email providers operate from EU data centres.
The exception is card payment data. To process a card payment, it may be transferred to, processed, and stored outside Slovenia and the EEA by our payment provider Dinaro, its service providers (located mostly in the EEA and in Hong Kong), its partner banks, and the international card schemes (such as Visa and Mastercard), and may be disclosed where required by law. Such transfers take place where they are necessary to perform the payment you request (Art. 49(1)(b) GDPR) or under safeguards such as Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR), as described in Dinaro's privacy policy.
If you pay through Stripe, your payment data may also be transferred by Stripe to Stripe, LLC in the United States and to its sub-processors. Such transfers take place under the EU-US Data Privacy Framework (Art. 45 GDPR) and Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR), as described in Stripe's privacy policy.
If any data transfer outside the EEA becomes necessary in the future, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, and we will update this Privacy Policy accordingly.
7. Data Retention
| Data | Retention Period |
|---|---|
| Active account data and content | Retained for the duration of your account |
| Deleted items (trash) | Soft-deleted; permanently removed when you empty the trash |
| Account data after deletion | Permanently deleted within 30 days of account deletion request |
| Session data | Sessions expire after 14 days without activity; session records (IP address, device, login times) are deleted 30 days after the session expires |
| Backups | Retained for up to 30 days, then permanently deleted |
| Invoices, credit notes, and payment records (including VAT location evidence and the ToS acceptance record) | Retained for 10 years as required by Slovenian tax law, also after account deletion; permanently deleted after that period |
When you delete your account, we initiate permanent deletion of all your personal data and content, except invoices, credit notes, and payment records that we are legally required to retain (Art. 17(3)(b) GDPR). Backup copies are purged according to our backup retention schedule (up to 30 days).
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) - You can request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) - You can correct inaccurate data. Most data can be corrected directly in the Service (e.g., editing your content). For email changes, contact us.
- Right to erasure (Art. 17) - You can delete your account and all associated data. You can also delete individual items within the Service at any time.
- Right to restrict processing (Art. 18) - You can request that we limit processing of your data in certain circumstances.
- Right to data portability (Art. 20) - You can request an export of your data in a commonly used, machine-readable format. Contact us at info@whatsnextaction.com to request an export.
- Right to object (Art. 21) - You can object to processing based on legitimate interest. We will cease processing unless we have compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)) - Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
How to Exercise Your Rights
Contact us at info@whatsnextaction.com with your request. We will respond within one month as required by GDPR. If your request is complex, we may extend this by an additional two months, and we will inform you of any extension.
We may ask you to verify your identity before processing your request.
Right to Lodge a Complaint
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec):
Informacijski pooblaščenec Dunajska cesta 22, 1000 Ljubljana, Slovenia Website: www.ip-rs.si Email: gp.ip@ip-rs.si
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Passwords are stored using industry-standard one-way hashing
- All data transmission is encrypted using HTTPS/TLS
- Authentication is managed through JWT tokens with automatic expiration and refresh mechanisms
- Sessions can be individually managed and revoked through account settings
- Cross-tab logout ensures all browser sessions are terminated simultaneously
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but are committed to maintaining appropriate safeguards.
10. Cookies and Local Storage
WhatsNextAction does not use cookies for tracking or advertising purposes.
We use your browser's localStorage to store:
- Authentication tokens (required for you to stay logged in)
- User preferences (calendar settings, view modes, display options)
- Session state (dismissed tips, drag-and-drop hints)
These storage mechanisms are strictly necessary for the Service to function and fall under the exemption in Article 5(3) of the ePrivacy Directive (2002/58/EC). No consent is required for strictly necessary storage.
You can clear this data at any time through your browser settings. Doing so will log you out and reset your preferences.
11. Children's Privacy
The Service is not intended for children under the age of 15 (in accordance with Slovenian law implementing Article 8 GDPR). We do not knowingly collect personal data from children under 15.
If we become aware that we have collected personal data from a child under 15, we will take steps to delete that data promptly. If you believe a child under 15 has provided us with personal data, please contact us at info@whatsnextaction.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this document
- Notify registered users via email or an in-app notification
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, contact us at:
QubForge, tehnološke rešitve, d.o.o. Jakopičeva ulica 9, 2000 Maribor, Slovenia Email: info@whatsnextaction.com