imbaQRL

Privacy

Privacy Policy

Explains how personal data is processed in the imbaQRL service and for which purposes Google user data is used.

Last updated: July 6, 2026

This English text is a convenience translation. The legally binding version of this Privacy Policy is the Turkish version; in case of any discrepancy, the Turkish version prevails.

1. Overview

imbaQRL is a service for educational institutions that works with Google Workspace accounts and allows students to sign in to ChromeOS devices with a QR card. This privacy policy explains which personal data is processed when using the service, the purposes for which that data is used and your rights.

imbaQRL processes student and institution data only to provide the service, maintain security and carry out administrative actions requested by institution administrators.

2. Data categories processed

The following categories of data may be processed within the service:

  • Basic account information such as first name, last name, email address and profile photo.
  • Institution, school, role and authorization information.
  • Class, group or organizational unit information for students or users.
  • QR card creation, renewal, revocation and sign-in attempt records.
  • Operational logs kept for security, debugging and audit purposes.

3. Google user data

When you sign in with Google, imbaQRL uses only the basic profile information required to sign you in and identify the user. This may include name, email address, profile photo and sign-in verification information.

imbaQRL does not access Gmail, Drive, Calendar or similar personal Google service content through user OAuth consent. Student and institution directory information is processed based on organizational authorization separately granted by the institution administrator in Google Admin Console.

4. Purposes for using data

Personal data may be used for the following purposes:

  • Providing secure sign-in with a Google Workspace account.
  • Verifying institution and user permissions.
  • Generating, managing and revoking student QR sign-in cards.
  • Operating the ChromeOS QR sign-in flow.
  • Maintaining service security, record integrity and abuse prevention controls.
  • Responding to support requests and improving service quality.

Google user data is not used for advertising, resale, independent marketing profiling or purposes outside the service.

5. Limited use of Google API data

imbaQRL's use and transfer to other apps of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

imbaQRL uses Google user data only to provide the service functions described here; it does not use this data for advertising, does not sell it to third parties, and human access is limited to cases involving explicit user permission, security/debugging necessity or legal requirements.

6. Data sharing

imbaQRL does not sell or share personal data with third parties for marketing purposes. Data may be processed only by trusted infrastructure and service providers required for the operation of the service, under contractual and technical safeguards.

Unless there is a legal obligation, an authorized authority request or an explicit instruction from the institution administrator, data is not disclosed outside the service purpose.

7. Retention and deletion

Data is retained while the institution uses the imbaQRL service or for a reasonable period required by legal, operational and security needs. Institution administrators may revoke QR cards, resynchronize user data or request data deletion as part of service closure.

For account, access or data deletion requests, you can contact us at support@imbaqrl.com.

8. Security

imbaQRL aims to protect data through authorization controls, session protections, role-based access, audit logs and abuse-prevention measures. Institution administrators are responsible for correctly configuring their own Google Workspace and ChromeOS settings.

9. Your rights

Under applicable legislation, you may have rights to access, correct or delete your personal data, object to processing activities or request information about data processing. Requests relating to student accounts are generally managed through the relevant educational institution.

10. Policy changes

This policy may be updated from time to time. For material changes, the last-updated date is changed and institution administrators are informed where necessary.

11. Contact

For questions about this privacy policy or data processing practices, you can write to support@imbaqrl.com.

imbaQRL uses Google user data only for the limited purposes required to operate the service and does not sell this data for marketing purposes.
Back to home