Legal
Privacy policy
Last updated: 26 July 2026
QFormance (“QFormance”, “we”, “us”) provides a cloud-based quality-management system (the “Service”). This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to our website and the Service.
Who controls your data
QFormance is a business-to-business product. When your organization subscribes, that organization is the controller of the records it stores in the Service, and QFormance acts as its processor — we handle that data on the organization’s instructions to provide the Service. For our own website and account administration, QFormance is the controller. If you use QFormance through your employer, their internal privacy notice may also apply.
Information we collect
- Account information. Name, email address, organization, role, and the sign-in credentials or factors you set up (password, passkeys, authenticator apps, and linked single-sign-on accounts).
- Content you put into the Service. The quality-management records your organization creates — documents, non-conformances, audits, risks, meetings, training records, suppliers, and the files you upload. We process this on your organization’s behalf.
- Usage and device data. Log data such as IP address, browser type, pages viewed, and timestamps, used to operate, secure, and improve the Service.
- Cookies and similar technologies. Strictly-necessary cookies for sign-in and security, and limited analytics to understand product usage. We do not use advertising cookies.
- Payment information. Handled by our payment processor. We store billing metadata (plan, invoices) but not full card numbers.
Google and Microsoft user data
If you choose to sign in with Google or Microsoft, or to connect a Google Workspace or Microsoft 365 account, we access only the data needed for that feature:
- Sign-in (SSO). Your basic profile — name and email address — to identify your account. We do not receive your Google or Microsoft password.
- Calendar & meeting integration (optional). Read access to your calendar events and meeting details/transcripts, used solely to import meetings and draft minutes inside the Service at your request.
Limited Use commitment
QFormance’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve features you have requested; we do not sell it, use it for advertising, or allow humans to read it except with your consent, for security, or as required by law. The same principles apply to Microsoft data.
You can disconnect an integration at any time from your profile, and revoke access directly in your Google account permissions or Microsoft account.
How we use information
- To provide, maintain, and secure the Service and your account.
- To authenticate you, including multi-factor authentication.
- To power features you use, such as AI-assisted drafting and meeting import.
- To process payments and manage subscriptions.
- To communicate with you about the Service, support, and security matters.
- To detect, prevent, and investigate abuse, fraud, and security incidents.
- To meet legal, regulatory, and audit obligations.
How we share information
We do not sell your personal information. We share it only with service providers who process it on our behalf under contract, and only as needed to run the Service:
- Cloud hosting and database — to host the application and store your data.
- Payment processing — to handle subscriptions and invoices.
- AI providers — when you use an AI feature, the specific content needed for that request is sent to the AI provider to generate the result; it is not used to train their models under our agreements.
- Google / Microsoft — only for the sign-in and integration features you enable.
- Email delivery — to send transactional and security emails.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger or acquisition (subject to this policy).
Data retention
We keep your data for as long as your organization’s account is active. After a subscription is cancelled, your data follows the lifecycle described in our refund policy — a 30-day read-only window, then permanent deletion. Some records may be retained longer where required for legal, tax, or audit purposes. You can request an export of your data before deletion.
Security
We protect data with encryption in transit and at rest, strict tenant isolation so one organization cannot access another’s data, access controls, audit logging, and support for strong authentication including passkeys, hardware security keys, and multi-factor authentication. No system is perfectly secure, but we work continuously to safeguard your information and will notify you of a breach affecting your data as required by law.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Because your organization controls the records in the Service, please direct requests about that content to your organization’s administrator; we will assist them. For account-level requests, contact us using the details below. We do not use your data for automated decisions with legal effects, and we do not knowingly collect data from children.
International transfers
We and our service providers may process data in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards such as standard contractual clauses.
Changes to this policy
We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you. Continued use of the Service after an update means you accept the revised policy.
Contact us
Questions about this policy or your data? Email privacy@qformance.io. We’ll respond within a reasonable timeframe.
See also our refund policy .