Last updated: March 2026
When you make a request to the Qivam API, we log the following data per request:
GET /v1/mosques/nearby200, 404Content-Length header if presentX-Forwarded-For header set by AWS API GatewayNo mosque search coordinates are persisted. No end-user personal data is stored. We do not set cookies or use browser fingerprinting.
Legal basis: Legitimate interest (GDPR Article 6(1)(f)). We process this data to operate, secure, and rate-limit the platform — for example, to detect abuse, diagnose errors, and understand traffic patterns. IP address and user-agent are personal data under GDPR. Our API key holders are developers and businesses (B2B), not end consumers.
Request logs are stored in AWS CloudWatch (eu-west-1) and are retained for 30 days, after which they are automatically deleted.
You can disable request logging for your API key at any time. Send a request with your key in the header:
POST https://api.qivam.com/v1/analytics/opt-out
X-API-Key: your_api_keyTo re-enable logging:
POST https://api.qivam.com/v1/analytics/opt-in
X-API-Key: your_api_keyThis satisfies the Article 21 right to object to processing based on legitimate interest.
All data is processed within AWS eu-west-1 (Ireland). No third-party analytics services are used. Your data is never sold or shared with third parties.
For GDPR requests (access, erasure, portability) or any privacy questions, email team@qivam.com.