Privacy Policy
What Qua collects, why we collect it, who it reaches, how long we keep it, and how to get it back or get rid of it. Written to satisfy the GDPR and UK GDPR, the California CCPA/CPRA and the other US state privacy laws, and India's Digital Personal Data Protection Act.
1. Who we are and what this policy covers
Qua ("Qua", "we", "us") provides an enterprise AI workspace that routes work across multiple AI models, records a cost and outcome receipt for every session, and gives administrators governance controls over how those models are used. This Privacy Policy explains how we handle personal data on the qua.dev website and in the Qua application.
Two different roles. For visitors to our website, people who sign up directly, and our own account records, Qua is the controller (in India, the Data Fiduciary) of that personal data. For content that a customer organization's users put into the workspace — prompts, uploaded documents, sessions, artifacts — Qua acts as a processor (Data Processor) on the instructions of that organization, which is the controller. Where an organization's own privacy notice conflicts with this one in respect of workspace content, theirs governs the purposes of processing and ours governs how we operate as processor. Our processor commitments are set out in the Data Processing Agreement.
2. Personal data we collect
Data you give us
- Account data — name, email address, authentication identifiers, the organization and department you belong to, your role, and login timestamps. If you sign in with Google, we receive your name, email address and profile image from Google; we do not receive your Google password.
- Workspace content — prompts and conversation messages, documents and files you upload as knowledge sources, notes, saved memory entries, generated artifacts, and the acceptance and outcome ratings you record on a session.
- Organization configuration — policies, budgets, model approvals, connector settings, invitations and access requests.
- Communications — messages you send to our support, sales or privacy addresses.
Data generated by using the service
- Session and receipt metadata — which resolution tier answered, which model was used, token counts, latency, measured cost, estimated cost avoided, task class, and the derived value band.
- Audit and security logs — administrative actions, policy decisions, moderation events, IP address, browser and device information, and error diagnostics.
- Embeddings and indexes — vector representations of your knowledge sources and of verified cached answers, used for retrieval.
We do not sell personal data and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, and we have not done so in the preceding twelve months. We do not use customer workspace content to train our own or any third party's models.
3. How and why we use personal data
| Purpose | Data used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Providing the workspace — resolving prompts through the answer waterfall, retrieval over your sources, generating artifacts | Account data, workspace content, embeddings | Performance of a contract; for enterprise users, our customer's legitimate interests as controller |
| Receipts, ledger and analytics — measuring cost, deflection and outcome value at user, department and organization level | Session metadata (never prompt content in admin analytics) | Legitimate interests in measuring and governing AI spend |
| Security, abuse prevention and moderation | Logs, IP address, device data, flagged content | Legitimate interests; legal obligation |
| Billing and plan management | Account data, usage counts | Performance of a contract |
| Service communications and support | Account data, correspondence | Performance of a contract; legitimate interests |
| Marketing emails and product updates | Name, email | Consent (opt-in), withdrawable at any time |
| Improving reliability and quality of the service | Aggregated and de-identified metrics | Legitimate interests |
Where we rely on legitimate interests we have carried out a balancing assessment; you can request a summary of it at privacy@qua.dev.
4. AI model processing and automated decisions
When a prompt cannot be answered from your own saved knowledge or your organization's verified cache, Qua sends the prompt — together with any source excerpts selected for that turn — to the model chosen for the turn. The provider that receives it is named on the receipt for that session and listed on our subprocessor page.
- Private or unselected sources are never sent to an external provider without an explicit confirmation step in the interface.
- Model providers act as our subprocessors and are contractually prohibited from training on inputs submitted through their APIs.
- Answers resolved at the zero-cost tiers (Personal Knowledge and Enterprise Search) are produced inside our perimeter and are not sent to any model provider.
- Qua does not make decisions producing legal or similarly significant effects about you through solely automated means. Routing, scoring and moderation are operational and reviewable, and every routing decision is recorded with its reason.
6. International transfers
Qua operates across the United States, the European Economic Area, the United Kingdom and India, and our processors are located in several countries. The primary application database is hosted in Australia (AWS ap-southeast-2); model inference, retrieval and speech providers are primarily in the United States.
For transfers of personal data out of the EEA or the UK we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) together with a transfer impact assessment, or on an adequacy decision where one exists.
Models processed outside the US and EU. Some open-weight models in the Open Models tier are served from mainland China or Singapore. Qua never routes to them automatically: a user must name the model explicitly, and an organization administrator can switch the tier off entirely. If your organization needs those providers excluded, disable the Open Models tier in the admin console.
7. Retention
| Category | Retention |
|---|---|
| Sessions, messages and artifacts | Retained for the life of the account, or until deleted by the user or an administrator; purged within 30 days of deletion |
| Knowledge sources and embeddings | Deleted with the source; the derived index entry is removed in the same operation |
| Verified cache entries | Time-limited by task class, re-verified on a set cadence, and retired on rework or administrator action |
| Account records | Deleted within 30 days of account closure, other than records we must keep |
| Audit, security and moderation logs | Up to 24 months, then deleted or de-identified |
| Billing and tax records | Up to 7 years, as required by law |
| Backups | Rolling encrypted backups expire within 35 days; deleted data does not return to the live system |
8. Your privacy rights
EEA and UK (GDPR / UK GDPR)
You have the right to access your personal data, to rectification, to erasure, to restriction of processing, to object to processing based on legitimate interests, to data portability, and to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority, or with the UK Information Commissioner's Office.
California (CCPA/CPRA) and other US states
California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of sale or sharing (we do neither); and to limit the use of sensitive personal information (we do not use personal information for purposes requiring that limit). We will not discriminate against you for exercising a right. Comparable rights, including the right to appeal a denied request, are available to residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws, and we honour them for all US residents regardless of state. We recognise the Global Privacy Control signal on qua.dev.
You may use an authorised agent; we will verify the agent's authority and your identity before acting.
India (Digital Personal Data Protection Act, 2023)
Data Principals in India may request access to a summary of their personal data and our processing, correction, completion, updating and erasure, may nominate another individual to exercise rights on their behalf in the event of death or incapacity, and may raise a grievance with our Grievance Officer at grievance@qua.dev before approaching the Data Protection Board of India. We respond to grievances within 30 days.
How to exercise a right
Email privacy@qua.dev from the address on your account, or use the deletion controls in the application. We acknowledge requests within 10 days and respond within 30 days (45 days in California, extendable once where permitted, with notice). There is no charge unless a request is manifestly unfounded or excessive.
If you use Qua through an employer, send requests about workspace content to that organization; we will refer such requests to them and assist them in responding.
9. Deleting your data
- Delete a session, artifact or knowledge source from the item's menu in the application. The record, its messages and its derived embeddings are removed immediately from the live system.
- Delete your account by asking an organization administrator to remove you, or by emailing privacy@qua.dev. Personal data is deleted within 30 days; aggregated, de-identified cost and outcome statistics that cannot be linked back to you may remain in organization reporting.
- Organization deletion. On termination, and at the customer's option, all workspace data is deleted or returned within 30 days, after which backups expire on the schedule above.
10. Security
We encrypt data in transit with TLS and at rest with AES-256. Access to customer data is governed by row-level security in the database, role-based access control in the application, and least-privilege administrative access with audit logging of every privileged action. Secrets are held in managed secret storage and never in source code. We maintain an incident response process and will notify affected customers without undue delay, and within 72 hours where the GDPR requires it. Report a vulnerability to security@qua.dev.
12. Children
Qua is a workplace product and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under 16 in the EEA/UK, and under 18 in India for purposes requiring verifiable parental consent). If you believe a child has provided us personal data, contact privacy@qua.dev and we will delete it.
13. Changes and contact
We will update this policy as the product and our processors change, and will post the new effective date here. Material changes are notified by email or in the application at least 14 days in advance. This policy was last updated on August 25, 2026.
Privacy enquiries: privacy@qua.dev · Data protection contact: dpo@qua.dev · Grievance Officer (India): grievance@qua.dev · Security: security@qua.dev · Legal: legal@qua.dev
See also the Terms of Service, the Data Processing Agreement and the subprocessor list.