Privacy Policy
We are committed to protecting your privacy. This policy explains exactly what data we collect, how we use it, and how you can control it.
Introduction
QualityOS ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use getqualityos.com.
This policy complies with:
- –India's Digital Personal Data Protection Act 2023 (DPDPA)
- –EU General Data Protection Regulation (GDPR)
- –California Consumer Privacy Act (CCPA)
Data We Collect
2a — Account Data (collected at registration)
- –Full name
- –Email address
- –Password (hashed, never stored in plain text)
- –Organisation / company name (optional)
2b — Usage Data (collected automatically)
- –Pages visited and features used
- –Analysis runs and scorecard history
- –API key usage and webhook activity
- –Browser type, device type, IP address
- –Session timestamps
2c — Content Data (uploaded by you)
- –Call transcripts and audio files
- –Support ticket content
- –Knowledge base documents (SOPs, policies)
- –Agent names and metadata
2d — Payment Data
- –Payment processing is handled entirely by Dodo Payments
- –We do not store credit card numbers or payment details
- –We receive only transaction confirmation and subscription status
How We Use Your Data
We use your data to:
- –Provide, operate, and improve the Service
- –Process AI analysis of your uploaded content
- –Generate QA scorecards and coaching reports
- –Send transactional emails (receipts, account notices)
- –Send product update emails (you can opt out anytime)
- –Detect and prevent abuse and fraud
- –Comply with legal obligations
We do not
- –Sell your personal data to third parties
- –Use your content to train AI models
- –Share your data with advertisers
- –Use your data for purposes beyond providing the Service
Data Storage and Security
- –All data stored in Supabase (Singapore region, SOC2 compliant)
- –Data encrypted in transit using TLS 1.3
- –Data encrypted at rest using AES-256
- –Authentication managed by Clerk (SOC2 compliant)
- –DDoS protection via Cloudflare
- –Access to production data limited to authorised personnel only
- –Regular security reviews conducted
Data Retention
- –Active account data: retained while account is active
- –Scorecard history: retained per your plan limits
- –Uploaded content (transcripts, KB docs): retained while active
- –After account deletion: all data deleted within 30 days
- –Payment records: retained 7 years for tax compliance
Your Rights
Under GDPR, DPDPA, and CCPA you have the right to:
- –Access: Request a copy of your personal data
- –Correction: Request correction of inaccurate data
- –Deletion: Request deletion of your data ("right to be forgotten")
- –Portability: Request your data in a machine-readable format
- –Objection: Object to certain processing of your data
- –Withdrawal: Withdraw consent at any time
To exercise these rights, email: bitan1basu@gmail.com
We will respond within 30 days.
Cookies
We use essential cookies only:
- –Authentication session cookies (Clerk)
- –Security cookies (Cloudflare)
We do not use advertising or tracking cookies. You can disable cookies in your browser settings.
Third-Party Data Processors
We share data with these processors solely to provide the Service. All processors are bound by data processing agreements.
| Processor | Purpose | Location | Privacy |
|---|---|---|---|
| Groq | AI inference | USA | groq.com/privacy |
| Supabase | Database | Singapore | supabase.com/privacy |
| Clerk | Authentication | USA | clerk.com/privacy |
| Dodo Payments | Payment processing | Global | dodopayments.com/privacy |
| Vercel | Frontend hosting | USA | vercel.com/legal/privacy |
| Cloudflare | Security / CDN | USA | cloudflare.com/privacypolicy |
| Railway | Backend hosting | USA | railway.app/legal/privacy |
International Data Transfers
QualityOS is operated from India. Your data may be processed in the United States and Singapore by our service providers. These transfers are protected by standard contractual clauses and the processors' compliance with applicable data protection laws.
Children's Privacy
QualityOS is not intended for users under 18 years of age. We do not knowingly collect data from minors.
Business Transfers
If QualityOS is acquired or merges with another company, your data may be transferred as part of that transaction. We will notify you via email before any such transfer occurs.
Changes to This Policy
We may update this Privacy Policy and will notify you via email or in-app notice at least 30 days before changes take effect. Continued use of the Service after changes constitutes acceptance.
Contact and Complaints
If you believe we have not handled your data correctly, you may lodge a complaint with:
- –India: Data Protection Board of India (once operational)
- –EU: Your local Data Protection Authority
- –UK: Information Commissioner's Office (ICO)
© 2026 QualityOS. All rights reserved.
Terms of Service →