We collect what we need to run the service and bill you for it. We do not sell your data, we do not use it to train models, and we do not run an advertising business. You can export or delete it.
This summary is for orientation. The sections below are the terms that apply.Controller and processor
For your account and billing information, we are the data controller.
For the data you put into the service — your customers, employees, projects and documents — you are the controller and we are the processor. We act on your instructions and do not decide what you collect or why.
What we collect
Account data. Names, work email addresses, phone numbers and role, for the people you give access to.
Billing data. Company details, tax identifiers and payment records. Card details are handled by our payment processor, not stored by us.
Usage data. Log records of actions taken in the product, used for security, troubleshooting and audit trails.
Customer data. Whatever you choose to store in the modules you switch on. We do not inspect it except where you ask us to for support.
Why we process it
To provide the service you have subscribed to, to bill you, to support you when you ask, to keep the service secure, and to meet our legal obligations.
We do not process your data for advertising, profiling or resale. We do not use it as training data for machine learning models.
Who we share it with
Sub-processors that help us run the service — hosting, email delivery, payment processing and error monitoring. Each is bound by contract to equivalent obligations. A current list is available on request.
Authorities, where we are legally required to. Where we are permitted to tell you about such a request, we will.
A successor, if the business is acquired. You would be told before your data moved.
Where it is stored, and for how long
Data is stored in encrypted regional data centres. Enterprise customers may choose a residency region.
Active account data is retained for as long as the account is open. After termination we retain it for thirty days so you can export it, then delete it from live systems. Backups age out within a further ninety days.
Some records — invoices, for example — are kept longer where tax or accounting law requires it.
Security
Encryption in transit and at rest, role-based access control, audit logging, encrypted daily backups and least-privilege access for our own staff.
Access to customer data by our team is restricted, logged, and only for support or incident response.
If a breach affects your data, we will notify you without undue delay and tell you what we know, what we are doing, and what you should do.
Your rights
Depending on where you are, you may have rights to access, correct, export, restrict or delete personal data, and to object to certain processing.
Where we are the processor, requests from your employees or customers should come to you as the controller. We will help you respond.
To exercise a right over data we control, contact privacy@qubi360.com. We respond within thirty days.
Cookies
We use strictly necessary cookies for authentication and security, and a small number of analytics cookies to understand how the marketing site is used.
We do not use advertising or cross-site tracking cookies. Analytics can be declined without affecting your use of the site.
Children
The service is a business product and is not directed at children. We do not knowingly collect personal data from anyone under sixteen.
Changes to this policy
We will post changes here and update the date at the top. For material changes affecting how we use personal data, we will give notice before they take effect.
Contact
Privacy questions and requests go to privacy@qubi360.com, or by post to Qubalytic, Malviya Nagar, Jaipur 302017, Rajasthan, India.