Privacy policy
Effective Date: July 22, 2026
Friendefi Inc. ("Friendefi", "Qarrot", "we", "our", or "us") respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use Qarrot, including:
- the Qarrot website located at www.qarrot.com;
- the Qarrot web application;
- the Qarrot mobile applications;
- integrations with third-party services;
- optional AI-powered features such as Qoach; and
- any related products and services that reference this Privacy Policy (collectively, the "Service").
This Privacy Policy applies to personal information collected through the Service, whether you are:
- an employee or end user of one of our customers;
- an administrator managing your organization's Qarrot account;
- a visitor to our website;
- or another individual who interacts with us.
This Privacy Policy does not apply to third-party websites, applications, products, or services that may be linked to from Qarrot. Those services are governed by their own privacy policies.
By accessing or using the Service, you acknowledge that your personal information will be collected, used, disclosed, and protected as described in this Privacy Policy.
Our Role
In most cases, your employer or organization has subscribed to Qarrot on your behalf.
When your organization provides your information to us to administer your Qarrot account, your organization generally acts as the controller (or equivalent legal role under applicable privacy legislation) of your personal information, while Friendefi acts as a service provider or processor on your organization's behalf.
For information relating to your organization's own privacy practices, please contact your employer or organization directly.
Privacy Principles
We are committed to handling personal information responsibly and in accordance with applicable privacy laws.
Our privacy practices are guided by the following principles:
- We collect only the personal information reasonably necessary to provide and improve the Service.
- We use personal information only for legitimate business purposes described in this Privacy Policy or as otherwise authorized by you or your organization.
- We do not sell personal information.
- We maintain administrative, technical, and physical safeguards designed to protect personal information.
- We strive to be transparent about our data practices and provide individuals with appropriate rights regarding their personal information.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our products or services;
- new features or technologies;
- changes in applicable laws or regulations; or
- improvements to our privacy practices.
When we make material changes, we will update the Effective Date shown above and provide notice through the Service, by email, or by other appropriate means where required by applicable law.
We encourage you to review this Privacy Policy periodically.
Continued use of the Service after an updated Privacy Policy becomes effective constitutes acceptance of the revised policy, unless applicable law requires additional consent.
2. Information We Collect
To provide and improve the Service, we collect personal information directly from you, from your organization, automatically through your use of the Service, and from third-party integrations that you or your organization authorize.
The categories of personal information we collect depend on how Qarrot is used by your organization and the features that are enabled.
Information Provided by Your Organization
When your organization creates or manages your Qarrot account, it may provide us with information such as:
- your name;
- business email address;
- employee or user identifier;
- job title;
- department, division, team, or location;
- manager or reporting relationships;
- employment start date or work anniversary;
- birthday (if your organization chooses to recognize birthdays);
- language preferences;
- profile photograph (if provided); and
- other information your organization chooses to synchronize with Qarrot.
Your organization is responsible for ensuring that it has the appropriate legal authority to provide this information to us.
Information You Provide
When using the Service, you may voluntarily provide information including:
- profile information;
- recognition messages;
- comments and replies;
- award nominations;
- campaign submissions;
- survey or feedback responses;
- reward selections and redemption preferences;
- support requests;
- communications with our customer support team; and
- any other information you choose to submit through the Service.
Because recognition messages are intended to recognize colleagues, they may contain information about other individuals. Users are responsible for ensuring that the content they submit complies with their organization's policies and applicable laws.
Recognition and Rewards Activity
As part of operating the Service, we collect information relating to employee recognition activities, including:
- recognitions sent and received;
- badges awarded;
- points awarded or redeemed;
- milestone recognitions;
- campaign participation;
- nominations;
- reward redemptions;
- social feed interactions, including likes and comments; and
- other activity generated through the Service.
This information enables organizations to administer employee recognition programs and measure participation and engagement.
Account and Authentication Information
Depending on how your organization configures Qarrot, we may collect information relating to authentication and account management, including:
- username;
- encrypted passwords (where applicable);
- Single Sign-On (SSO) identifiers;
- authentication tokens;
- security settings;
- login history;
- password reset requests; and
- account preferences.
Where your organization uses Single Sign-On, authentication is performed through your organization's identity provider, and we receive only the information necessary to authenticate your account.
Payment and Billing Information
If you purchase Qarrot directly or administer a paid subscription, we may collect billing information including:
- billing contact information;
- business address;
- company name;
- payment status;
- invoices; and
- subscription details.
Payment card information is processed by our third-party payment providers. Qarrot does not store complete payment card numbers on its own systems.
Technical and Usage Information
When you use the Service, we automatically collect certain technical information, including:
- IP address;
- browser type and version;
- operating system;
- device type;
- mobile device identifiers (where applicable);
- pages or screens visited;
- actions performed within the Service;
- referring websites;
- date and time of access;
- session duration;
- diagnostic information;
- application performance information; and
- other technical information necessary to operate, secure, and improve the Service.
This information helps us maintain system security, troubleshoot issues, improve usability, and understand how the Service is being used.
Cookies and Similar Technologies
We use cookies and similar technologies to:
- authenticate users;
- maintain secure sessions;
- remember preferences;
- improve website functionality;
- understand website usage;
- analyze performance; and
- enhance the user experience.
Some cookies are necessary for the operation of the Service and cannot be disabled. Others may be optional depending on your browser settings and applicable law.
Additional information about cookies is provided later in this Privacy Policy.
Information from Third-Party Integrations
If your organization enables integrations with third-party services, we may receive information necessary to provide those integrations.
Depending on the integration, this information may include:
- user identifiers;
- organizational structure;
- employee profile information;
- messaging platform identifiers;
- authentication information;
- directory information; or
- other information expressly authorized by your organization.
We collect only the information reasonably necessary to provide the requested integration.
AI-Powered Features
If your organization enables Qarrot's optional AI-powered features, and you choose to use them, we may temporarily process information that you submit to generate AI-assisted responses or suggestions.
For example, Qoach analyzes draft recognition messages in order to provide writing suggestions and feedback.
Additional information regarding our AI-powered features, including how recognition messages are processed, is provided in the AI-Powered Features section of this Privacy Policy.
Information We Do Not Intentionally Collect
Unless specifically required for a feature offered by the Service, we do not intentionally collect:
- Social Insurance Numbers or Social Security Numbers;
- driver's licence numbers;
- passport information;
- financial account numbers;
- credit history;
- health information;
- biometric information;
- precise geolocation data;
- racial or ethnic origin;
- religious beliefs;
- political opinions; or
- other categories of sensitive personal information.
We ask that users and organizations avoid including sensitive personal information in recognition messages, comments, or other user-generated content unless there is a legitimate business need to do so.
Data Minimization
We strive to collect only the personal information that is reasonably necessary to provide, secure, maintain, and improve the Service.
Where practical, organizations may configure which employee attributes are synchronized with Qarrot, allowing them to limit the amount of personal information shared with us.
3. How We Use Personal Information
Friendefi uses personal information only for legitimate business purposes related to providing, maintaining, securing, and improving the Service. The specific ways in which we use personal information depend on how Qarrot is configured by your organization and how you use the Service.
To Provide the Service
We use personal information to:
- create and manage user accounts;
- authenticate users and administer access to the Service;
- enable employee recognition and rewards programs;
- display recognition activity, badges, campaigns, milestones, and social feeds;
- process reward redemptions;
- administer organizational recognition budgets;
- deliver notifications and reminders;
- synchronize employee information with authorized third-party systems;
- provide customer support; and
- perform other activities necessary to operate the Service.
To Administer Customer Accounts
We use personal information to:
- establish and manage customer subscriptions;
- process invoices and payments;
- administer licensing;
- communicate with account administrators;
- respond to customer inquiries;
- provide onboarding and implementation services; and
- fulfill our contractual obligations.
To Improve and Develop the Service
We continually improve Qarrot based on customer feedback and product usage.
We may use personal information and aggregated or de-identified information to:
- improve existing features;
- develop new functionality;
- evaluate feature adoption;
- troubleshoot issues;
- identify usability improvements;
- measure product performance;
- improve accessibility; and
- enhance the overall user experience.
Where practical, we use aggregated or de-identified information for analytics and product improvement.
AI-Powered Features
If your organization enables Qarrot's optional AI-powered features and you choose to use them, we process the information you submit to generate AI-assisted suggestions.
For example, Qoach analyzes draft recognition messages and provides writing suggestions intended to help users:
- write more specific recognition;
- explain the impact of an employee's contribution;
- align recognition with organizational values;
- personalize recognition messages; and
- communicate in a genuine and authentic tone.
Information processed through Qoach is used solely to provide the requested writing assistance and to operate the AI-powered feature.
Additional information regarding Qoach is provided in the AI-Powered Features section of this Privacy Policy.
To Communicate With You
We may use personal information to communicate with you regarding:
- your account;
- product updates;
- new features;
- service announcements;
- security notifications;
- support requests;
- billing matters;
- scheduled maintenance;
- changes to our policies; and
- other communications relating to your use of the Service.
Where permitted by law, we may also send marketing communications to administrators or other contacts who have expressed interest in Qarrot. Recipients may unsubscribe from marketing communications at any time using the instructions included in those communications or by contacting us.
Service-related communications that are necessary to administer the Service are not considered marketing communications.
To Maintain Security
We use personal information to:
- authenticate users;
- detect unauthorized access;
- monitor for fraud or abuse;
- investigate suspicious activity;
- prevent security incidents;
- maintain system integrity;
- enforce our Terms and Conditions; and
- protect the rights, property, and safety of Friendefi, our customers, and users.
To Comply With Legal Obligations
We may use personal information to:
- comply with applicable laws and regulations;
- respond to lawful requests from governmental authorities;
- comply with court orders or legal process;
- establish, exercise, or defend legal claims;
- enforce our contractual rights; and
- satisfy recordkeeping, accounting, tax, or audit obligations.
Use of Aggregated and De-Identified Information
We may aggregate or de-identify information so that it can no longer reasonably identify an individual.
Aggregated or de-identified information may be used to:
- analyze usage trends;
- measure feature adoption;
- improve product performance;
- develop new products and services;
- prepare statistical reports; and
- conduct internal research and business analysis.
Because this information no longer identifies an individual, it is not considered personal information under this Privacy Policy.
What We Do Not Do
To help our customers understand our privacy practices, we believe it is equally important to explain how we do not use personal information.
Unless required by law or expressly authorized by you or your organization, Friendefi does not:
- sell personal information to third parties;
- rent or license personal information to advertisers or data brokers;
- use recognition messages to create public profiles of individuals;
- use personal information for unrelated advertising purposes;
- make employment decisions on behalf of customers; or
- use AI-powered recognition messages to train public artificial intelligence models.
Our Legal Bases for Processing
Where applicable privacy laws require us to identify the legal basis for processing personal information (including under the General Data Protection Regulation ("GDPR")), we process personal information on one or more of the following legal bases:
- performance of a contract with our customer;
- compliance with legal obligations;
- our legitimate interests in operating, securing, and improving the Service, provided those interests are not overridden by the rights and freedoms of individuals; or
- consent, where required by applicable law.
Where processing is based on consent, individuals may withdraw that consent at any time, subject to legal or contractual limitations.
4. AI-Powered Features (Qoach)
Qarrot offers optional artificial intelligence ("AI") features designed to assist users in creating more meaningful employee recognition. These features are intended to enhance the user experience by providing writing suggestions and feedback while allowing users to retain complete control over the content they choose to submit.
At the time of this Privacy Policy, Qarrot's AI-powered writing assistant is known as Qoach.
How Qoach Works
Qoach analyzes the text of draft recognition messages as they are being written and provides real-time writing suggestions to help users communicate recognition more effectively.
For example, Qoach may evaluate whether a recognition message:
- clearly describes the employee's actions;
- explains the impact of those actions;
- reflects the organization's values;
- feels personal and meaningful; and
- communicates in a genuine and authentic tone.
Qoach is intended solely as a writing assistant. It does not write recognition messages on behalf of users, nor does it require users to accept its suggestions before submitting a recognition.
Information Processed by Qoach
When a user chooses to use Qoach, Friendefi temporarily processes:
- the draft recognition message;
- the recognition criteria selected by the user (where applicable);
- the organization's configured values (where applicable); and
- limited contextual information necessary to generate relevant writing suggestions.
This information is processed solely for the purpose of providing AI-generated writing assistance.
AI Technology Provider
Qoach is powered by OpenAI language models deployed through Microsoft Foundry (Azure AI).
Recognition messages submitted to Qoach are processed within Friendefi's managed cloud environment using Microsoft's enterprise AI infrastructure. Recognition messages are not submitted to the public ChatGPT service.
We select AI service providers that maintain appropriate technical, organizational, and contractual safeguards for processing customer information.
Model Training
Recognition messages processed through Qoach are not used by Friendefi or OpenAI to train public artificial intelligence models.
Friendefi does not use customer recognition messages to build generalized AI models or to improve publicly available AI systems.
If Friendefi ever intends to use customer content for AI model training in the future, we will update this Privacy Policy and obtain any required permissions or consents under applicable law before doing so.
Customer and User Control
Qoach is designed to give organizations and individual users control over how AI-powered features are used.
Specifically:
- Organizations may choose whether AI-powered features are available to their users.
- Organizations may disable Qoach at any time.
- Where enabled by an organization, individual users may disable AI-powered features within their own account settings.
- Users may choose whether or not to use Qoach when composing recognition messages.
Friendefi does not require customers to enable AI-powered features in order to use Qarrot.
User Responsibility
Qoach provides suggestions only.
Users remain solely responsible for reviewing, editing, and approving the content of every recognition message they submit.
AI-generated suggestions may occasionally be inaccurate, incomplete, inappropriate, or fail to reflect the circumstances of a particular recognition.
Users should exercise their own judgment before accepting or incorporating any AI-generated suggestions.
No Automated Decision-Making
Qoach does not:
- evaluate employee performance;
- determine eligibility for rewards;
- rank employees;
- recommend promotions, compensation, or disciplinary actions;
- make hiring or termination decisions; or
- make automated decisions that produce legal or similarly significant effects on individuals.
Qoach is a writing assistance tool only.
All employment-related decisions remain the sole responsibility of the customer organization.
Human Access to Recognition Messages
Friendefi personnel do not routinely review recognition messages solely for the purpose of operating Qoach.
Authorized employees may access customer information, including recognition messages, only where reasonably necessary for purposes such as:
- providing customer support;
- investigating reported issues;
- responding to security incidents;
- maintaining the Service;
- complying with legal obligations; or
- performing other activities permitted under applicable agreements and this Privacy Policy.
Access to customer information is restricted to personnel with a legitimate business need and is subject to appropriate access controls.
Improving AI-Powered Features
Friendefi may analyze aggregated, anonymized, or de-identified information relating to the use and performance of AI-powered features to:
- improve the quality of AI suggestions;
- evaluate feature effectiveness;
- identify usability improvements;
- measure adoption;
- monitor system performance; and
- develop future product enhancements.
Where this analysis is performed using aggregated or de-identified information, it is conducted in a manner that does not reasonably identify individual users.
Future AI Features
Friendefi may introduce additional AI-powered capabilities from time to time.
Those capabilities will be governed by this Privacy Policy unless otherwise stated. If a future AI feature materially changes how personal information is collected, processed, or disclosed, we will update this Privacy Policy and provide any notices required by applicable law before the change takes effect.
5. Sharing and Disclosure of Personal Information
Friendefi does not sell or rent personal information. We disclose personal information only as described in this Privacy Policy or as otherwise authorized by our customers or required by law.
The circumstances in which we may share personal information are described below.
With Your Organization
If you access Qarrot through your employer or another organization, information relating to your use of the Service may be visible to authorized administrators within that organization.
Depending on how your organization has configured Qarrot, administrators may have access to information including:
- employee profile information;
- recognition messages;
- badges awarded;
- points awarded and redeemed;
- campaign participation;
- reward redemption history;
- reports and analytics;
- user activity relating to the organization's recognition program; and
- other information necessary to administer the organization's Qarrot account.
Friendefi shares this information with your organization because it is necessary to provide the Service under our agreement with that organization.
With Service Providers
We engage carefully selected third-party service providers to assist us in operating and delivering the Service.
Depending on the services provided, these providers may process personal information on our behalf.
Examples include providers of:
- cloud hosting;
- data storage;
- authentication and identity management;
- artificial intelligence infrastructure;
- customer support software;
- payment processing;
- analytics;
- email delivery;
- monitoring and logging;
- application security;
- backup and disaster recovery; and
- other operational services.
These providers are contractually required to:
- process personal information only on our instructions;
- protect personal information using appropriate security safeguards;
- maintain confidentiality;
- comply with applicable privacy laws; and
- refrain from using personal information for their own marketing purposes.
We share only the information reasonably necessary for them to perform the services we have requested.
AI Service Providers
When users choose to use Qoach or other AI-powered features, the information necessary to generate AI-assisted suggestions is processed through our AI infrastructure providers.
As described in the AI-Powered Features section of this Privacy Policy:
- recognition messages are processed using OpenAI language models deployed through Microsoft Foundry (Azure AI);
- recognition messages are not submitted to the public ChatGPT service; and
- recognition messages are not used to train public AI models.
AI service providers process information solely for the purpose of providing the requested AI functionality.
Third-Party Integrations
If your organization enables integrations with third-party services such as identity providers, messaging platforms, human resources information systems (HRIS), or other business applications, personal information may be exchanged between Qarrot and those services as necessary to support the requested integration.
The information exchanged depends on the specific integration and your organization's configuration.
Your use of third-party services is also governed by the privacy policies and terms of those providers.
Legal Requirements
We may disclose personal information where we believe disclosure is necessary or appropriate to:
- comply with applicable laws or regulations;
- comply with court orders, subpoenas, warrants, or other lawful legal processes;
- respond to requests from regulatory authorities;
- enforce our agreements;
- investigate suspected fraud or unlawful activity;
- protect the rights, property, or safety of Friendefi, our customers, our users, or others; or
- establish, exercise, or defend legal claims.
Where legally permitted, we will seek to limit such disclosures to the minimum information reasonably necessary.
Business Transactions
If Friendefi is involved in a merger, acquisition, financing, corporate reorganization, sale of assets, or similar business transaction, personal information may be transferred as part of that transaction.
Where required by applicable law, we will provide appropriate notice before personal information becomes subject to a materially different privacy policy.
Any successor organization receiving personal information will remain bound by applicable confidentiality obligations.
With Your Consent
We may disclose personal information to other parties where:
- you request or authorize us to do so;
- your organization instructs us to do so;
- you provide your consent; or
- disclosure is otherwise permitted or required under applicable law.
Aggregated and De-Identified Information
We may disclose aggregated, statistical, or de-identified information that cannot reasonably identify an individual.
Examples include information relating to:
- platform usage;
- feature adoption;
- recognition trends;
- engagement metrics;
- customer demographics;
- product performance; and
- industry benchmarking.
Such information does not identify individual users or organizations unless expressly agreed with the customer.
What We Never Sell
Friendefi does not sell personal information.
Specifically, we do not sell:
- employee profile information;
- recognition messages;
- reward history;
- administrator information;
- usage data associated with identifiable individuals; or
- AI prompts submitted through Qoach.
Nor do we permit third parties to purchase access to customer recognition data for advertising or marketing purposes.
International Processing
Because Friendefi serves customers in multiple jurisdictions, personal information may be processed by Friendefi or its service providers in Canada, the United States, or other jurisdictions in which we or our service providers operate.
Where personal information is transferred across borders, we take reasonable steps to ensure that appropriate contractual, technical, and organizational safeguards are in place consistent with applicable privacy laws.
Additional information regarding international data transfers is provided later in this Privacy Policy.
6. International Data Transfers, Security, and Data Retention
Protecting the confidentiality, integrity, and availability of customer information is fundamental to the design and operation of Qarrot. Friendefi maintains administrative, technical, and organizational safeguards designed to protect personal information throughout its lifecycle—from collection through secure deletion.
International Data Transfers
Friendefi is headquartered in Montreal, Quebec, Canada, and provides services to customers in multiple countries.
To operate the Service, personal information may be stored or processed in Canada, the United States, or other jurisdictions where Friendefi or its authorized service providers maintain facilities or provide services.
As a result, personal information may become subject to the laws of those jurisdictions, including lawful requests by courts, regulators, or governmental authorities.
Where personal information is transferred outside the jurisdiction in which it was originally collected, Friendefi implements appropriate safeguards designed to protect that information, which may include:
- contractual data protection obligations;
- confidentiality agreements;
- technical security controls;
- vendor due diligence;
- access restrictions; and
- other safeguards appropriate to the sensitivity of the information and applicable privacy laws.
Where required by applicable law, Friendefi will conduct privacy impact assessments or transfer assessments before implementing new international processing arrangements.
Security
Friendefi maintains a comprehensive information security program designed to protect personal information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Our security program is continually reviewed and updated as our products, technologies, and legal obligations evolve.
Depending on the nature of the information and the services being provided, our safeguards may include:
Administrative Safeguards
- employee confidentiality obligations;
- security awareness and privacy training;
- role-based access controls;
- documented security policies and procedures;
- vendor security reviews;
- change management practices;
- incident response procedures; and
- periodic review of security controls.
Technical Safeguards
Our technical safeguards may include:
- encryption of data in transit using industry-standard protocols;
- encryption of sensitive data at rest where appropriate;
- strong authentication mechanisms;
- Single Sign-On (SSO) support;
- multi-factor authentication for administrative systems where appropriate;
- network security controls;
- application logging and monitoring;
- audit trails;
- vulnerability management;
- backup and disaster recovery processes;
- malware protection;
- infrastructure monitoring; and
- secure software development practices.
Physical Safeguards
Where Friendefi or its service providers maintain physical infrastructure, safeguards may include:
- secure data centres;
- controlled physical access;
- environmental protections;
- redundant infrastructure; and
- disaster recovery capabilities.
Access to Personal Information
Friendefi follows the principle of least privilege.
Access to personal information is limited to employees, contractors, and authorized service providers who require access in order to:
- provide customer support;
- maintain the Service;
- investigate technical or security issues;
- fulfill contractual obligations;
- comply with legal requirements; or
- perform other legitimate business functions.
Access permissions are reviewed periodically and adjusted as responsibilities change.
Security Incidents
Despite reasonable safeguards, no method of transmitting information over the Internet or storing electronic information can be guaranteed to be completely secure.
Accordingly, Friendefi cannot guarantee the absolute security of personal information.
If Friendefi becomes aware of a security incident involving personal information, we will investigate the incident promptly and provide any notifications required under applicable law.
Where appropriate, we will also take reasonable steps to mitigate the effects of the incident and reduce the likelihood of similar incidents occurring in the future.
Data Retention
Friendefi retains personal information only for as long as reasonably necessary to:
- provide the Service;
- fulfill our contractual obligations;
- comply with applicable laws;
- resolve disputes;
- enforce our agreements; or
- satisfy legitimate business purposes.
The length of time information is retained depends on the type of information and the purposes for which it was collected.
For example:
- User account information: Until the account is deleted or the customer relationship ends, subject to contractual or legal requirements
- Recognition history: To preserve the integrity and continuity of the organization's recognition program unless otherwise directed by the customer
- Rewards history: Financial reporting, auditing, and customer administration
- Technical logs: Security, troubleshooting, fraud prevention, and system monitoring
- Support communications: Customer support, quality assurance, and dispute resolution
Retention periods may be extended where required by law or reasonably necessary to protect Friendefi's legal rights.
Customer-Controlled Data
Organizations using Qarrot determine how long employee information remains active within their Qarrot environment.
When instructed by a customer and where contractually appropriate, Friendefi will delete or anonymize customer data in accordance with the applicable subscription agreement and our internal data retention practices.
Former employees may be deactivated or anonymized while preserving historical recognition activity where requested by the customer.
Secure Deletion
When personal information is no longer required, Friendefi takes reasonable steps to securely delete, anonymize, or otherwise render the information inaccessible, taking into account:
- legal retention obligations;
- contractual requirements;
- backup and disaster recovery processes; and
- legitimate business needs.
Because backup systems are designed for disaster recovery, copies of deleted information may remain in secure backup media for a limited period before being overwritten in the ordinary course of business.
Privacy by Design
Friendefi considers privacy and security throughout the design, development, and operation of Qarrot.
When introducing new features—including AI-powered capabilities—we seek to incorporate privacy and security considerations into the development process by:
- evaluating the types of information required;
- limiting unnecessary data collection;
- applying appropriate access controls;
- considering security risks during development;
- assessing privacy impacts where appropriate; and
- reviewing new technologies before deployment.
Our goal is to collect and process the minimum amount of personal information reasonably necessary to provide valuable functionality to our customers.
7. Your Privacy Rights
Friendefi believes individuals should have meaningful control over their personal information. Subject to applicable laws, contractual obligations, and our role as a service provider to our customers, you may have the rights described below.
Because many Qarrot accounts are provided through an employer or other organization, some requests relating to your personal information may need to be directed to your organization rather than Friendefi.
Access to Your Personal Information
You may request access to the personal information that Friendefi holds about you.
Where permitted by applicable law, you may request information regarding:
- the categories of personal information we maintain about you;
- the purposes for which your information is used;
- the categories of third parties with whom your information has been shared;
- the source of the information (where it was not collected directly from you); and
- other information required by applicable privacy laws.
Where we are processing your personal information solely on behalf of your employer or organization, we may direct your request to that organization, which is responsible for determining how your information is managed.
Correcting Your Information
We strive to keep personal information accurate, complete, and up to date.
Many profile details can be updated directly through your Qarrot account, subject to your organization's configuration.
If you believe information we maintain about you is inaccurate or incomplete, you may request that it be corrected.
In some cases, your organization may need to make these corrections through its HR system or directory service if that information is synchronized with Qarrot.
Deleting or Anonymizing Your Information
You may request that Friendefi delete or anonymize personal information associated with your account, subject to applicable legal, contractual, and operational requirements.
In many cases, organizations prefer that former employee records be anonymized rather than permanently deleted in order to preserve:
- recognition history;
- organizational reporting;
- campaign results;
- historical analytics; and
- reward accounting.
Where appropriate, Friendefi may anonymize personal information while retaining historical records that no longer identify an individual.
Certain information may be retained where required to:
- comply with legal obligations;
- resolve disputes;
- enforce agreements;
- maintain system integrity; or
- satisfy legitimate business or accounting requirements.
Withdrawing Consent
Where Friendefi relies on your consent to process personal information, you may withdraw that consent at any time, subject to legal or contractual limitations.
Withdrawal of consent does not affect the lawfulness of processing that occurred before the consent was withdrawn.
Please note that withdrawing consent for certain processing activities may limit your ability to use some features of the Service.
Marketing Communications
You may opt out of receiving marketing communications from Friendefi at any time by:
- clicking the unsubscribe link included in our marketing emails; or
- contacting us using the information provided at the end of this Privacy Policy.
Even if you opt out of marketing communications, we may continue to send important service-related communications, including:
- security notifications;
- billing notices;
- product updates affecting your account;
- changes to legal agreements; and
- other administrative communications necessary to provide the Service.
AI-Powered Features
Where your organization has enabled AI-powered features, you may choose whether to use those features.
If available within your organization's Qarrot environment, you may also disable AI-powered features within your personal account settings.
Disabling AI-powered features prevents Friendefi from processing new content through those features but does not affect recognition messages that have already been submitted.
Additional information regarding AI processing is provided in the AI-Powered Features section of this Privacy Policy.
Exercising Your Rights
To exercise your privacy rights, please contact us using the contact information provided at the end of this Privacy Policy.
To help protect your privacy, we may request information sufficient to verify your identity before responding to your request.
Where Friendefi acts solely as a service provider or processor on behalf of your employer or organization, we may refer your request to the appropriate organization for handling.
Rights Under Quebec Law 25
If you are located in Quebec, you may have additional rights under Quebec's Act respecting the protection of personal information in the private sector, including the right to:
- request access to your personal information;
- request correction of inaccurate personal information;
- request deletion or de-indexing of information where provided by law;
- withdraw consent where consent is the legal basis for processing;
- request information about the processing of your personal information; and
- submit a complaint to the Commission d'accès à l'information du Québec (CAI).
Friendefi will respond to requests in accordance with applicable legal requirements.
Rights Under the GDPR
If the General Data Protection Regulation ("GDPR") applies to the processing of your personal information, you may have additional rights, including the right to:
- access your personal information;
- rectify inaccurate information;
- request erasure of personal information;
- restrict certain processing;
- object to certain processing;
- receive your personal information in a portable format where applicable; and
- lodge a complaint with your local data protection authority.
These rights are subject to the limitations and exceptions provided by applicable law.
Response Times
Friendefi will respond to privacy requests within the timeframes required by applicable law.
If additional time is reasonably necessary due to the complexity of a request, we will notify you accordingly where required.
There is generally no charge for exercising your privacy rights.
However, where permitted by law, Friendefi may charge a reasonable administrative fee or decline requests that are manifestly unfounded, repetitive, or excessive.
Complaints
If you believe Friendefi has not handled your personal information appropriately, we encourage you to contact us first so that we can investigate and attempt to resolve your concerns.
If you remain dissatisfied, you may have the right to file a complaint with the applicable privacy regulator in your jurisdiction.
8. Cookies, Analytics, and Similar Technologies
Friendefi uses cookies and similar technologies to provide, secure, improve, and personalize the Service. This section explains how these technologies work and the choices available to users.
What Are Cookies?
Cookies are small text files placed on your computer, smartphone, tablet, or other device when you visit a website or use certain online services.
Cookies help websites recognize your device, remember preferences, maintain secure sessions, and improve the overall user experience.
In addition to cookies, we may use similar technologies such as local storage, session storage, software development kits (SDKs), web beacons, pixels, or comparable technologies where appropriate.
For simplicity, we refer to these collectively as "cookies" throughout this Privacy Policy.
How We Use Cookies
We use cookies and similar technologies for several purposes, including:
Essential Cookies
These cookies are necessary for the operation of Qarrot.
They help us:
- authenticate users;
- maintain secure login sessions;
- protect against unauthorized access;
- remember security settings;
- maintain application functionality; and
- enable core features of the Service.
Because these cookies are necessary for the Service to function, they generally cannot be disabled without affecting the operation of Qarrot.
Functional Cookies
These cookies remember preferences that improve your experience, such as:
- preferred language;
- display preferences;
- recently used settings;
- accessibility preferences; and
- other customization choices.
Performance and Analytics Cookies
We use analytics technologies to better understand how our websites and applications are used.
Analytics information may include:
- pages viewed;
- features used;
- navigation patterns;
- session duration;
- browser type;
- device type;
- operating system;
- referral sources;
- general geographic region derived from IP address; and
- other information that helps us improve the Service.
Where practical, analytics information is aggregated or de-identified before analysis.
Security Cookies
Certain cookies are used to:
- detect fraudulent activity;
- identify suspicious login attempts;
- protect user accounts;
- monitor application integrity; and
- support incident investigation.
These cookies help maintain the security of the Service.
Analytics Providers
Friendefi may use third-party analytics providers to understand how users interact with the Service and our websites.
These providers may use cookies or similar technologies to collect information regarding:
- website usage;
- feature adoption;
- application performance;
- technical errors; and
- user interactions.
Information collected by analytics providers is used to improve the Service and is subject to the privacy policies of those providers.
Where required by applicable law, we obtain consent before enabling non-essential analytics technologies.
Advertising Cookies
Qarrot is a business software platform and is not supported by third-party advertising.
Friendefi does not permit third-party advertising networks to use Qarrot user data for behavioural advertising within the Service.
From time to time, our public marketing website may use limited marketing or analytics technologies to evaluate the effectiveness of advertising campaigns.
These technologies are used only in accordance with applicable privacy laws.
Browser Controls
Most web browsers allow you to:
- view cookies stored on your device;
- delete cookies;
- block cookies;
- receive notifications when cookies are placed; or
- configure cookie preferences.
Please note that disabling certain cookies may affect the functionality or availability of portions of the Service.
Do Not Track
Some web browsers transmit "Do Not Track" ("DNT") signals.
Because there is currently no universally accepted standard governing how websites should respond to DNT signals, Friendefi does not currently respond differently to such signals.
If industry standards change in the future, we may update our practices accordingly.
Cookie Preferences
Where required by applicable law, Friendefi will provide mechanisms for users to manage cookie preferences for non-essential cookies.
Your cookie preferences may be updated at any time using the tools made available through our website, where applicable.
9. Children's Privacy
Qarrot is designed for use by businesses and their workforce.
The Service is not intended for children or individuals under the age of 16.
Friendefi does not knowingly collect personal information directly from children.
If we become aware that we have unintentionally collected personal information from a child in violation of applicable law, we will take reasonable steps to delete that information as soon as practicable.
If you believe that a child has provided personal information through the Service, please contact us using the information provided at the end of this Privacy Policy.
10. Changes to this Privacy Policy
Friendefi may update this Privacy Policy from time to time to reflect:
- changes to the Service;
- new products or features;
- technological developments;
- changes in applicable laws or regulations; or
- improvements to our privacy practices.
When we make material changes, we will update the Effective Date shown at the beginning of this Privacy Policy.
Where required by applicable law, we will also provide notice through one or more of the following methods:
- email;
- notifications within the Service;
- announcements on our website; or
- other appropriate communication channels.
We encourage users and administrators to review this Privacy Policy periodically to remain informed about how Friendefi protects personal information.
Continued use of the Service following the effective date of an updated Privacy Policy constitutes acceptance of the revised Privacy Policy, unless additional consent is required by applicable law.
11. Contact Us
If you have questions about this Privacy Policy or our privacy practices, or if you wish to exercise your privacy rights, please contact us.
Privacy Officer
Friendefi Inc.
Montreal, Quebec, Canada
📧 privacy@qarrotperformance.com (recommended)
or
📧 help@qarrotperformance.com
📞 +1 (514) 397-0415
Website: https://www.qarrot.com
If you are contacting us regarding your personal information, please provide sufficient information for us to identify your account and understand your request.
We may request additional information to verify your identity before responding.
