Privacy Policy

How we use your personal data and what cookies we use.

Version 1.0 · effective 20 August 2026

About This Privacy Policy

This Privacy Policy explains how HQAlign Ltd (“We”, “Us”, “Our”) collects, uses, shares, and protects personal data when you use the HQAlign Platform at HQAlign.com (including the Service). It also explains your rights under UK data protection law and how to exercise them.

This Privacy Policy was last updated on 20th August 2026.

This Privacy Policy should be read alongside Our Terms and Conditions. This Privacy Policy governs how We process personal data; the Terms and Conditions govern your use of the Platform more generally. Where the two documents address different subject matter, both apply. In the unlikely event of any conflict between this Privacy Policy and the Terms and Conditions on a data protection matter, this Privacy Policy prevails on that data protection matter only; on all other matters the Terms and Conditions prevail.

Defined terms used in this Privacy Policy (including “Customer”, “Customer Data”, “Service”, “Platform”) have the meanings given to them in Our Terms and Conditions.

1. Who We Are (The Data Controller)

1.1 The data controller for the personal data described in this Privacy Policy is HQAlign Ltd, a company registered in England and Wales under company number 15815964. Our registered address is 71-75 Shelton Street, Covent Garden, London, UK.

1.2 We are registered with the UK Information Commissioner’s Office (ICO) under registration number ZB803884.

1.3 We have not appointed a Data Protection Officer, as We are not required to do so under UK GDPR. For any privacy enquiry, please contact Us using the details in the “How To Contact Us” section below.

1.4 We were previously known as KanbanGenie Limited, and the Platform was previously offered under the name TaskVal at taskval.com. The change of company name was registered at Companies House on 5th May 2026, and the Platform was rebranded from “TaskVal” to “HQAlign” at the same time. This is a change of name only. The data controller is the same legal entity, with the same company number, registered address, and ICO registration as before, and the personal data We held under the previous names continues to be processed under the same lawful bases, retention periods, and safeguards described in this Privacy Policy. Any reference in any prior privacy notice, consent record, or communication to “KanbanGenie Limited” or “TaskVal” shall be read as a reference to HQAlign Ltd. Your rights as a Data Subject (set out below) are unaffected by the name change.

2. When We Are A Controller And When We Are A Processor

2.1 We act as a controller for personal data We collect about: visitors to the marketing pages of the Platform; individuals who register an account or use the Service; individuals who contact Us via Our contact forms or email; individuals who consent to receive marketing communications from Us; and individuals at businesses We approach about the Service, whose business contact details We have obtained from publicly available professional sources or who have given them to Us directly. This Privacy Policy describes what We do with that personal data. If you fall into the last category and are not yet a customer, Our Prospect Privacy Notice sets out in detail what We hold about you, where We got it, and how to ask Us to stop.

2.2 Where Customer (a business, organisation, or other entity) uses the Service, the personal data Customer uploads or submits about its own employees, contractors, or other individuals as Customer Data is processed by Us as a processor on Customer’s instructions. Customer is the controller of that personal data and is responsible for providing its own privacy notice to those individuals. Our processing of Customer Data on Customer’s behalf is governed by Our Terms and Conditions and the Data Processing Agreement at https://hqalign.com/legal/dpa; this Privacy Policy does not describe that processing.

If you are using the Service as an employee, contractor, or agent of an organisation that holds an account with Us, that organisation is the controller of your data within the Service, and you should refer to that organisation’s privacy notice for information about how it processes your data. Your personal commitments in connection with your use of the Service are set out in Our Acceptable Use Policy at https://hqalign.com/legal/aup.

3. The Personal Data We Collect

3.1 When you visit the marketing pages of the Platform, We collect:

  • Technical data: IP address, browser type and version, device type, operating system, time zone, and language settings;
  • Usage data: pages visited, links clicked, the page that referred you to the Platform, and the date and time of your visit;
  • Cookie and similar technology data (see clause 9 below).

3.2 When you register an account or use the Service, We collect:

  • Identity data: your full name;
  • Contact data: your email address;
  • Authentication data: a securely hashed version of your password (We never store your password in plain text), invite code (where one is required to register), session identifiers, and login timestamps;
  • Profile data: any optional account or profile details you provide;
  • Usage data: actions you take within the Service, features you use, and the time and frequency of use;
  • Technical data: IP address, browser type, device type, and information needed for security, fraud prevention, and Service operation.

3.3 When you contact Us (by email, contact form, or in-product support), We collect the content of your message together with any contact details you provide.

3.4 When you set your email preferences, We record the choice you made and the email address it applies to, together with when it was recorded, by what means, whether one of Our staff recorded it on your behalf, and, where you made the change yourself, the IP address it came from. Where the choice is a consent, that record is Our evidence of it; where it is an unsubscribe, it is what allows Us to keep honouring it. Clause 10.8 sets out how long each is kept.

3.5 Whether you have to provide personal data. Providing the identity, contact, and authentication data described in clause 3.2 is a contractual requirement: We need it to create your account, to authenticate you, and to provide the Service under Our Terms and Conditions. If you do not provide it, We cannot create an account for you or provide the Service. Providing optional profile details is not required, and choosing not to provide them does not affect your access to the Service. Where We rely on your consent (for example, for marketing communications), providing that consent is entirely voluntary and you may withdraw it at any time.

3.6 We do not knowingly collect special category personal data (such as data revealing race, ethnicity, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person’s sex life or sexual orientation), and the Service is not designed to receive such data. You must not upload special category data into the Service. If you wish to do so, you must first obtain Our prior written consent and a written confirmation that the Service has been configured to handle the data lawfully (see also clause 3.4 of Our Data Processing Agreement).

4. How We Collect Your Personal Data

4.1 Directly from you: when you register an account, fill in a form on the Platform, contact Us, or interact with the Service.

4.2 Automatically: through cookies, server logs, and similar technologies as you use the Platform.

4.3 From third parties: in limited circumstances, We may receive personal data from invite-code referrers, from infrastructure providers (e.g. abuse reports, fraud-prevention signals), or from publicly available sources.

5. Why We Use Your Personal Data and Our Legal Basis

5.1 We process personal data only where We have a lawful basis under Article 6 of the UK GDPR. The table below sets out the purposes of processing and the corresponding legal basis.

  • To provide the Service to you (creating and operating your account, authenticating you, and delivering the features you use): legal basis is performance of a contract with you, or steps taken at your request prior to entering into a contract.
  • To operate, secure, and improve the Platform (including monitoring, troubleshooting, security, fraud prevention, abuse detection, and analysing aggregated usage trends): legal basis is Our legitimate interests in running and improving Our business safely, balanced against your rights and freedoms.
  • To communicate with you about the Service (operational notices such as security alerts, changes to terms, billing, and support replies): legal basis is performance of a contract with you and Our legitimate interests in communicating with users of the Service.
  • To send marketing communications (for example, news about new features or offers): legal basis is your consent. You may withdraw consent at any time using the unsubscribe link in any marketing email or by contacting Us.
  • To comply with legal and regulatory obligations (such as accounting, tax, and responding to lawful requests from authorities): legal basis is compliance with a legal obligation.
  • To establish, exercise, or defend legal claims: legal basis is Our legitimate interests in protecting Our rights and property.

5.2 We do not currently use your personal data for automated decision-making that produces legal or similarly significant effects on you, and We do not currently engage in profiling of that kind. If We introduce such processing in the future, We will update this Privacy Policy and ensure compliance with Article 22 UK GDPR before doing so.

6. Sharing Your Personal Data

6.1 We share personal data only with the categories of recipient listed below, and only to the extent necessary for the purposes described in clause 5.

  • Sub-processors and infrastructure providers: cloud hosting and computing providers, database providers, email delivery providers, customer-support tooling, monitoring and error-reporting providers, and (where used) analytics providers. These providers process personal data on Our behalf under written contracts requiring them to keep the data confidential and secure, and to use it only for the purposes We instruct.
  • Payment processing: We use Stripe to take subscription payments. Where you subscribe, the contact and billing identifiers you provide, together with transaction records, are shared with Stripe so that it can process the payment. Stripe processes some of that data on Our behalf as a processor, and also acts as an independent controller in its own right for its own purposes, including fraud prevention, anti-money-laundering, and meeting its own legal and regulatory obligations. Where Stripe acts as an independent controller, its own privacy notice governs that processing. Stripe processes personal data outside the United Kingdom, subject to the safeguards described in clause 7. We do not receive or store your full card details.
  • Professional advisers: lawyers, accountants, auditors, and insurers, where reasonably necessary.
  • Authorities: law enforcement, regulators, courts, and other public authorities, where We are required to disclose by law or where We reasonably believe disclosure is necessary to protect Our rights or the rights, property, or safety of others.
  • Successors: in the event of a merger, acquisition, restructuring, insolvency, or sale of all or part of Our business or assets, the recipient or prospective recipient, subject to appropriate confidentiality protections (including, where the data is shared with a prospective recipient before completion of the transaction, an undertaking that the data will be used only to evaluate or complete the transaction, will not be retained if the transaction does not complete, and will be subject to confidentiality terms no less protective than those in this Privacy Policy).

6.2 A current list of material sub-processors used in the provision of the Service is set out in Annex 3 of Our Data Processing Agreement at https://hqalign.com/legal/dpa.

6.3 We do not sell your personal data to anyone, and We do not share your personal data with third parties for their own marketing purposes.

7. International Transfers

7.1 The Service is hosted in the United Kingdom. The personal data You provide to Us when registering an account or using the Service is stored and primarily processed within the United Kingdom.

7.2 Some of Our sub-processors may process certain personal data outside the United Kingdom. In particular, when We activate the Google Analytics service described in clause 9, certain technical and usage data described in clause 3.1 will be transferred to and processed by Google (whose European entity is Google Ireland Limited, with onward transfers to Google LLC in the United States).

7.3 Where personal data is transferred to a country outside the United Kingdom that the UK Government has not designated as providing an adequate level of data protection, We rely on appropriate safeguards as required by Article 46 of the UK GDPR, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, the UK extension to the EU-US Data Privacy Framework (where applicable to the recipient), or another lawful transfer mechanism.

7.4 You may request further information about the safeguards in place for any specific international transfer by contacting Us.

8. How Long We Keep Your Personal Data

8.1 We keep personal data only for as long as is necessary for the purposes for which it was collected, plus any period required to comply with legal, regulatory, accounting, or reporting obligations, or to resolve disputes and enforce Our agreements.

8.2 Indicative retention periods:

  • Account data: while your account is active, plus up to 60 days after account closure to allow for accidental-deletion recovery and operational wind-down. Two records described elsewhere in this Privacy Policy deliberately outlive this period - the suppression record in clause 10.5 and an unsubscribe record under clause 10.8 - in each case because the record exists to keep a request of yours honoured after the account has gone. This 60-day period is aligned with the deletion timeline for Customer Personal Data in clause 12.4 of Our Data Processing Agreement, so that data covered by both this Privacy Policy and the DPA is deleted on a consistent schedule. Some account-related records may be retained for longer where required by law (for example, accounting records for six years under UK tax law). Encrypted backups may persist beyond active production deletion in accordance with Our backup policy and clause 12.5 of the DPA.
  • Authentication and session data: rotated regularly during active use; expired sessions are purged within 30 days of expiry.
  • Server logs and security logs: typically up to 12 months, except where We need to retain a specific log entry for longer to investigate or defend against an incident.
  • Support correspondence: typically up to 24 months after the matter is closed.
  • Marketing consent and contact records: a record of consent is kept while that consent stands, and is deleted when you close your account. Where you have objected to sales or marketing contact, see the separate entry for suppression records below - those are kept indefinitely, because that is what gives effect to the objection.
  • Email preference and unsubscribe records: a record that you have UNSUBSCRIBED from an email list is kept indefinitely, including after your account closes, because it is what stops mail resuming to somebody who asked Us to stop - see clause 10.8. A record that you are SUBSCRIBED is deleted when your account closes, because it evidences a permission that no longer has any subject. Where an unsubscribe record is retained past account closure, the IP address is removed from it.
  • Business development contact records: where We have obtained business contact details as described in clause 10.3, We delete them automatically within one month of obtaining them unless We have told the individual We hold them; thereafter We delete them automatically after a period of inactivity of approximately twelve months in the business conversation with that individual or their organisation, or within about a month of Our deciding not to pursue that conversation, or immediately on request. Where the organisation holds an account with Us and later closes it, those records are deleted at that point instead. This applies whether or not the organisation is a customer: becoming a customer does not extend the period. Our Prospect Privacy Notice sets this out in full.
  • Suppression records: retained indefinitely, to give effect to an objection under clause 10.4. This is a deliberate exception to the principle of deleting data that is no longer required: the record exists precisely so that We do not contact somebody who has told Us not to, and deleting it would remove that protection.
  • Financial and tax records: six years after the end of the relevant accounting period, in line with UK statutory requirements.

8.3 Where retention periods are not fixed by law, We periodically review the personal data We hold and delete or anonymise data that is no longer required.

9. Cookies And Similar Technologies

9.1 Cookies are small text files that are placed on your device when you visit a website. We use cookies and similar technologies (such as local storage) within the Platform for the purposes described below.

9.2 Strictly necessary cookies and storage are required for the Platform to function. These are set without consent because the Privacy and Electronic Communications Regulations 2003 (PECR) permit this. Examples include:

  • sid - a signed, HTTP-only session cookie used to authenticate logged-in users. Without this cookie, the Service cannot identify your session;
  • isAuthenticated - a small client-side flag used to adapt navigation and account-aware menus to whether you are signed in. It does not contain any authentication credential or token;
  • Local storage entries used for dark-mode preference and other essential UI state.

9.3 Analytics, performance, and other non-essential cookies: We will not set any non-essential cookies or similar technologies on your device without your prior consent, and you may withdraw consent at any time.

9.4 Google Analytics (planned): We intend to use Google Analytics, a web analytics service provided by Google Ireland Limited (or its successor in the European Economic Area / United Kingdom), to understand how visitors use the Platform in aggregate. When activated, Google Analytics will set cookies on your device (typically named _ga and ga<identifier>) and will collect technical and usage data including IP address (which Google may truncate), pages viewed, time spent, referring page, device and browser characteristics, and a randomly generated identifier. This information is used solely to produce aggregated, statistical reports about use of the Platform. We will not enable Google Analytics until We have implemented an appropriate consent mechanism, and Google Analytics will be set only where you have given consent. When activated, Google acts as Our sub-processor under the Google Ads Data Processing Terms (or the equivalent terms in force at the relevant time), and personal data may be transferred to the United States subject to the safeguards described in clause 7. You will be able to withdraw your consent at any time and to opt out of Google Analytics across all participating sites by installing Google’s opt-out browser add-on, available from https://tools.google.com/dlpage/gaoptout. As at the “last updated” date of this Privacy Policy, Google Analytics is not active on the Platform. This Privacy Policy will continue to describe Google Analytics accurately if and when activation occurs.

9.5 Most browsers allow you to refuse or delete cookies through their settings. If you block strictly necessary cookies, parts of the Platform may not function correctly.

10. Marketing Communications

10.1 We will not send you marketing emails without your prior express consent. Where you have given consent, you may opt out at any time by clicking the unsubscribe link in any marketing email or by contacting Us.

10.2 Operational and service-related communications (such as security alerts, important notices about your account, billing communications, and changes to Our Terms and Conditions or this Privacy Policy) are not marketing communications and will continue to be sent while your account is active. These are necessary for the operation of the Service.

10.3 Business development contact. Separately from clause 10.1, We may contact individuals at businesses about the Service where We have obtained their business contact details from publicly available professional sources or where those details were given to Us directly. We do that on the basis of Our legitimate interests in business development under Article 6(1)(f) of the UK GDPR, not on the basis of consent. Anyone contacted in this way is told so at the time, and Our Prospect Privacy Notice sets out what We hold, where it came from, how long We keep it, and how to object.

10.4 Our suppression record. If you ask Us not to contact you again for sales or marketing purposes, We will stop, and We will delete Our record of you as an individual - your name, job title, contact details, where We obtained them, and the record of the notice We sent you. Our record of the ORGANISATION and of the business conversation itself is not deleted: it is a record about that business rather than about you, although it may mention you by name. We will also retain a minimal record on an internal suppression list - what is needed to recognise you if We encounter your details again, which may be an email address, a telephone number, a link to your professional profile, or more than one of these, together with when you objected, how the objection reached Us, and who recorded it. We do this so that We can honour your objection: without such a record, your details could be collected again from a public source at a later date and you could be contacted again in error. That record is used solely to prevent contact, is never used to contact you, and is not shared with any third party. Our lawful basis for retaining it is Our legitimate interest, and yours, in ensuring that your objection is respected.

10.5 We keep the suppression record indefinitely and We will not delete it on request. That is not a refusal to honour a deletion request: the record exists because you objected, and removing it would remove the only thing preventing you from being found and contacted all over again. Keeping it is how the objection is given effect. It holds the minimum needed to recognise you and nothing in it is used for any other purpose. In the unusual case where We hold nothing capable of recognising you again, We will still delete your record and note the objection, but We should be clear that nothing would then prevent your details being collected afresh from a public source in future.

10.6 An objection under clauses 10.3 or 10.4 stops sales and marketing contact only. It does not prevent Us from replying to an enquiry you make, or from sending the operational and service-related communications described in clause 10.2 if you hold an account with Us.

10.7 Optional emails about your own workspace. Separately from clauses 10.1 and 10.2, We may send account holders periodic emails summarising their own use of the Service - for example a digest of outstanding notifications, upcoming deadlines, tasks assigned to them, and how their teams are progressing. These are not marketing communications: they contain no promotional content and relate solely to the Customer Data and activity already within your own workspace. They are also not among the communications described in clause 10.2, because they are not necessary for the operation of the Service. Our lawful basis is Our legitimate interests, and yours, in your making effective use of a service you already hold an account for, under Article 6(1)(f) of the UK GDPR; We do not rely on consent for them, and We do not ask for consent We would not honour. They may be switched on by default. Every such email carries a link to switch it off, they may also be switched off at any time in your account settings, and switching them off takes effect for all future emails of that kind. Doing so has no effect on the essential communications described in clause 10.2, which continue while your account is active.

10.8 Our record of your email preferences. Where you unsubscribe from any email described in clauses 10.1 or 10.7, We keep a record that you did so - the email address concerned, which emails it relates to, when it was recorded, by what means, and, where you made the change yourself, the internet protocol (IP) address it came from. Where you have instead given consent, the same record is Our evidence of that consent, as We are required to keep under Article 7(1) of the UK GDPR. A record that you have unsubscribed is kept indefinitely, including after you close your account, and this is a deliberate exception to the retention periods in clause 8. The reason is the same as for the suppression record in clause 10.5: the record exists because you asked Us to stop, so deleting it would remove the only thing preventing the same address being added again - by a later registration, or by any future import - and mail resuming to somebody who had said no. It is used solely to prevent sending, is never used to contact you, and is not shared with any third party. A record that you have subscribed is not kept once you close your account: it evidences a permission that no longer has any subject, so We delete it. Where a record is retained after your account closes, We remove the IP address from it, since that was evidence of a relationship that has ended and is not needed to honour your choice.

10.9 A consequence worth stating plainly: if you unsubscribe, later close your account, and then register again with the same email address, you will still be unsubscribed. You may turn any of them back on at any time in your account settings.

11. Your Rights Under UK Data Protection Law

11.1 Subject to certain conditions and exceptions under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:

  • Right of access: to obtain confirmation of whether We process personal data about you and a copy of that data;
  • Right to rectification: to have inaccurate or incomplete personal data corrected;
  • Right to erasure (the “right to be forgotten”): to have your personal data erased in certain circumstances;
  • Right to restriction of processing: to restrict Our processing of your personal data in certain circumstances;
  • Right to data portability: to receive personal data you have provided to Us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
  • Right to object: to object to processing carried out on the basis of Our legitimate interests, and (in all cases) to object to processing for direct marketing;
  • Right to withdraw consent: where We rely on consent to process your personal data, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal;
  • Rights in relation to automated decision-making: to not be subject to a decision based solely on automated processing that has a legal or similarly significant effect (We do not currently carry out such automated decision-making).

11.2 To exercise any of these rights, please contact Us using the details in the “How To Contact Us” section below. We will respond within one month, although We may extend this by a further two months for complex or numerous requests (in which case We will notify you).

11.3 We may need to verify your identity before responding to a request, particularly if it concerns access to or deletion of personal data.

11.4 In most cases there is no fee for exercising your rights. Where a request is manifestly unfounded or excessive, We may charge a reasonable fee or refuse to act on the request, and We will tell you why.

12. Complaining To Us About Our Use Of Your Personal Data

12.1 You have the right to complain to Us about how We have used your personal data. You may make a complaint using the contact form on the Platform at https://hqalign.com/contact, or by post to the address in the “How To Contact Us” section below. Please tell Us that you are making a data protection complaint, and give Us enough detail to identify what your complaint is about.

12.2 We will acknowledge your complaint without undue delay and in any event within thirty days of receiving it, and We will respond to it substantively without undue delay. Where a complaint is complex, or where We receive a number of complaints from you, it may take Us longer to respond; if that is the case, We will tell you and explain why.

12.3 We may need to verify your identity before dealing with your complaint, and We may ask you for further information where We need it in order to investigate.

13. Right To Complain To The ICO

If you are unhappy with how We have handled your personal data, We would prefer you to complain to Us first, as set out in clause 12, so We can try to resolve the issue. However, you have the right at any time to lodge a complaint with the UK Information Commissioner’s Office (the supervisory authority for data protection in the UK). You can find the ICO’s current contact details, including their helpline and postal address, on their website at https://ico.org.uk.

Lodging a complaint with the ICO does not affect your other legal rights or remedies, and you do not have to complain to Us first.

14. Children

The Service is intended for use by businesses, trades, professions, and other organisations (see clause 19 of Our Terms and Conditions). It is not directed at, and We do not knowingly collect personal data from, children under the age of 18. The 18-year threshold is conservative and consistent with Our business-use-only policy; it does not reflect a determination that 16- or 13-year thresholds (variously referenced in UK data protection law) are otherwise relevant to the Service. If you believe a child has provided Us with personal data, please contact Us so We can delete it.

15. Security

15.1 We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures include encryption in transit, access controls, role-based permissions, secure password hashing, audit logging, and ongoing security review.

15.2 No method of transmission over the internet or storage on a computer is completely secure. While We strive to protect personal data, We cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying Us promptly of any suspected unauthorised access to your account.

15.3 In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, We will notify the ICO within 72 hours where required by law, and We will notify affected individuals where required by law.

16. Links To Other Websites

The Platform may contain links to third-party websites and services. This Privacy Policy applies only to Our processing of personal data; We are not responsible for the privacy practices of third-party websites or services, and We recommend that you read their privacy notices before providing any personal data to them.

17. Changes To This Privacy Policy

17.1 We may update this Privacy Policy from time to time. The “last updated” date at the top of this Privacy Policy will reflect any change.

17.2 Where the changes are material, We will take reasonable steps to bring them to your attention (for example, by email or by an in-product notice) before the changes take effect. Continued use of the Platform after the effective date constitutes your acknowledgement of the updated Privacy Policy.

18. How To Contact Us

For any questions about this Privacy Policy, or to exercise any of your rights, please contact Us via the contact form on the Platform at https://hqalign.com/contact, or by post to HQAlign Ltd, 71-75 Shelton Street, Covent Garden, London, UK.

Copyright © 2026, HQAlign Ltd, All Rights Reserved
Made with ❤ by the team at HQAlign