Privacy Policy
This Privacy Policy explains what information QIOKO, LLC (“QIOKO”, “we”, “us”) collects about users of the QIOKO platform, how we use it, who we share it with, and the rights you have over your data.
1. Who we are
QIOKO, LLC is a U.S. limited liability company registered at 6740 Pershing Ave, Scottsdale, 85254, United States. For the purposes of this Policy, QIOKO is the data controller of the personal data processed through the platform at qioko.com (the “Service”).
You can reach us about privacy at support@qioko.com.
2. What data we collect
Account data
- Email address, hashed password, display name and public account ID.
- Account creation time, last login time, IP addresses of logins, user-agent strings.
- Multi-factor settings (TOTP device fingerprint) when enabled.
Identity & financial verification
- Full legal name, country, date of birth, government ID images (passport / national ID / driver license) and selfie, if you choose to complete identity verification.
- Proof of address or financial source documents if financial verification is requested for a specific action.
- Verification status and reviewer notes. Sensitive verification files are stored encrypted at rest.
Deployment and compute data
- Node configurations you create, GPU tier, region, uptime, hourly output estimates and accrued earnings.
- Referral relationships and referral earnings.
- Upgrade purchases and their status (including VIP / Private Server).
Wallet and payments
- Crypto deposit addresses issued to you, deposit and withdrawal transaction hashes, amounts and confirmation metadata.
- Internal ledger entries (credits, debits, corrections) tied to your account.
Support, appeals and logs
- Support messages and appeal submissions, including any files you attach.
- Technical logs of API calls made on your behalf (endpoint, status code, response time, IP, user-agent) for security and debugging.
Cookies and similar technologies
We use strictly necessary cookies / localStorage entries to keep you logged in, to carry security tokens, and to remember UI preferences. We do not use third-party advertising trackers.
3. How we use data
- Provide the Service — create your account, run nodes, calculate earnings, process deposits and withdrawals, deliver support.
- Security & fraud prevention — detect suspicious logins, prevent account takeover, investigate abuse, enforce suspensions and appeals.
- Compliance — meet AML/KYC obligations where applicable, respond to lawful requests, keep required financial records.
- Product improvement — aggregate, non-identifying usage statistics to improve features.
- Communications — send transactional messages (login alerts, appeal status, withdrawal confirmations). We only send marketing email if you explicitly opt in.
4. Legal bases (GDPR/EEA, UK)
If you are located in the EEA or the UK, we rely on the following legal bases under the GDPR: performance of a contract (running your account and the Service), compliance with a legal obligation (KYC/AML, tax, fraud reporting), our legitimate interests (security, product analytics, anti-abuse), and, where required, your consent (e.g. optional cookies, marketing).
5. Sharing
We do not sell personal data. We share data only with:
- Infrastructure providers that host the Service (cloud compute, managed PostgreSQL, DDoS/edge providers), under written data processing terms.
- Payments and on-chain partners strictly to execute deposits/withdrawals you initiate.
- KYC providers if we delegate identity verification to a regulated partner; they receive only the files you submit for verification.
- Law enforcement or regulators, only when we receive a valid legal request and, where permitted, after notifying you.
- Successors in a merger, acquisition or restructuring, with the same obligations.
6. International transfers
QIOKO operates edge regions in the US, EU, APAC and Taipei. Data may be transferred across borders for operational reasons. Where transfers leave the EEA/UK, we rely on Standard Contractual Clauses or an equivalent lawful mechanism.
7. Retention
- Account data — while the account exists plus up to 12 months after deletion, for dispute handling.
- KYC / verification files — for the period required by applicable AML rules (typically up to 5 years after the relationship ends).
- Wallet / financial records — as required by law (typically 5–7 years).
- Support and appeal logs — 24 months by default, longer where needed for safety.
- Technical/security logs — typically 90–365 days.
8. Your rights
Subject to the laws of your jurisdiction, you may have the right to access, correct, export, or delete personal data we hold about you, to object to processing, to restrict processing, and to withdraw consent where we rely on it. To exercise these rights, write to support@qioko.com from the email on your account. If you believe we mishandle your data you can complain to your local supervisory authority.
Some data we are legally required to keep (e.g. AML/financial) and cannot delete on request until the retention period expires.
9. Security
- Passwords hashed with a modern KDF; verification files encrypted at rest.
- TLS in transit; strict security headers; rate limiting and IP throttling on auth endpoints.
- Separation of duties between application, admin, and payments services.
- Audit log on admin actions affecting balance, suspension, verification status, and appeals.
10. Children
The Service is not directed to children under 18 and we do not knowingly collect data from them. If you believe a child has given us personal data, write to support@qioko.com and we will delete it.
11. Changes to this Policy
We will update this Policy when the Service or applicable law changes. Material changes will be announced in-app or by email at least 7 days before they take effect. The “Effective date” above reflects the current version.
12. Contact
QIOKO, LLC · 6740 Pershing Ave, Scottsdale, 85254, United States · support@qioko.com.