QSigma360
Privacy and data protection

Privacy Policy

This policy explains, in direct language, when the operator of QSigma360 acts as a controller and when it processes data for your organization, what we collect, why, how long we retain it, and how you can exercise your rights.

Effective
6 August 2026
Last updated
6 August 2026
Version
1.0

No sale of data

We do not sell personal information or share it for cross-context behavioral advertising.

Governed AI

We do not train our general models on Customer Content without explicit written opt-in.

Limited collection and retention

We collect what the purpose requires and delete or de-identify it when the legal or contractual need ends.

This policy applies to the public website, platform, and related services. A Data Processing Agreement, Order Form, or feature-specific notice may supplement it, and broader protection applies where required by law.

1. Scope and who is responsible

The “Service” includes the QSigma360 public site, cloud workspaces, forms, support, enabled AI features, and integrations we operate. It does not cover third-party sites governed by their own notices.

For website, account, billing, security, and business-contact data, the legal party named in the collection notice or Order Form is the controller. For workspace content entered by a customer organization or its users, the operator normally acts as processor on the organization’s instructions and the organization acts as controller. If this policy conflicts with a Data Processing Agreement for Customer Content, the DPA controls.

The statement that the brand is owned by Code Lines does not alone assign controller or processor status. The legal party and address must be identified in the Order Form or collection notice before live commercial processing begins.

2. Data we collect and its sources

Customer Content may include sensitive personal data or information about employees, customers, or suppliers when the organization chooses to enter it. The organization must establish a lawful basis, provide appropriate notice, minimize that data, and restrict access by need-to-know.

CategoryExamplesSource
Identity and accountName, email, phone, title, language, identifiers, verification state, and permissionsYou or your organization administrator
Organization and contractOrganization, sector, sites, contacts, subscription scope, and commercial correspondenceThe customer or its representatives
Customer ContentQuality and food-safety records, complaints, NCR/CAPA, audits, suppliers, documents, attachments, signatures, and approvalsUsers and authorized integrations
Usage and securityIP address, browser/device, sign-in times, event logs, authentication attempts, access, downloads, and changesAutomatically from Service use
Communications and supportDemo requests, messages, feedback, tickets, and call content if recording is disclosedYou and our correspondence
AI feature dataPrompts, authorized context, submitted files, outputs, feedback, and safety telemetryThe user and enabled feature
Cookies and local storageSession and verification tokens, interface preferences, and local recovery draftsYour browser

3. Purposes and legal bases

When relying on legitimate interests, we balance the purpose, necessity, expected impact, and individual rights, and apply minimization and safeguards. You may object where the law permits.

PurposeTypical dataLegal basis, as applicable
Create accounts and operate workspacesAccount, organization, content, and settingsContract performance or requested pre-contract steps
Protect, prevent abuse, and auditTechnical/security logs and access eventsLegitimate interests, contract, and legal obligation
Support and request managementContact data and request contentContract or legitimate interests
Service communicationsEmail, phone, and account statusContract or legal obligation
Optional marketingContact details and preferencesConsent where required, or legitimate interests with an easy opt-out
AI featuresPrompt, context, and outputContract and organization instructions; explicit consent where law requires
Compliance and legal claimsRelevant logs, contracts, and correspondenceLegal obligation or establishment, exercise, and defense of claims
Product reliabilityAggregated/de-identified usage and feedbackLegitimate interests; not general-model training on Customer Content without explicit opt-in

4. Customer Content and sensitive data

  • The organization and its licensors retain their rights in Customer Content; we use it only to provide, secure, support, and follow documented instructions for the Service.
  • Do not enter passwords, verification codes, complete payment-card data, or secrets the workflow does not need.
  • Do not upload health, biometric, criminal, child, or highly sensitive data unless necessary, contractually authorized, lawful, and protected by additional controls.
  • Organization administrators may see account/activity data and may export content, restrict access, or delete it under organization policy and law.

5. AI and automated decisions

Enabled features may send the minimum necessary prompt, context, and files to an approved model provider acting as subprocessor. We enforce permission scope and suitable logging; processing locations may vary by customer configuration and provider.

Outputs are probabilistic suggestions and may be wrong. QSigma360 does not autonomously make final employment, credit, insurance, healthcare, food-safety, compliance, or approval decisions for a user. An authorized person must review evidence and outputs before any consequential decision.

We do not use Customer Content or prompts to train a QSigma360 general model without explicit, written, revocable opt-in. A model provider may process data under the organization’s contracted service terms and DPA.

6. Disclosures and subprocessors

We do not sell personal information. We may disclose the minimum necessary data to these categories under appropriate contractual and security commitments:

  • hosting, database, storage, backup, and content-delivery providers;
  • email, SMS, verification, and support providers;
  • AI model providers when the customer enables the feature;
  • confidential advisers, auditors, insurers, and professional providers;
  • an acquirer or legal successor in a corporate transaction, with notice and continued protection;
  • authorities or others where legally required or necessary to protect rights and safety, while challenging excessive demands where possible;
  • parties the customer selects or authorizes for integration or distribution.
We do not share personal information for cross-context behavioral advertising and do not offer a discount or different treatment in exchange for permission to sell data.

7. Hosting and international transfers

Data may be processed in the customer’s country or other regions where providers operate. The Order Form or DPA identifies an agreed hosting region, if any. Cross-border technical access does not change data ownership.

Where law requires a transfer safeguard, we use a recognized mechanism such as standard contractual clauses, an adequacy decision, or applicable local transfer rules, with risk assessment and supplementary measures where needed. Customers may request subprocessor and processing-location information.

8. Retention and deletion

We may retain specific data longer for a dispute, preservation order, or legal duty and restrict it to that purpose. At the end of retention, we securely delete it or irreversibly de-identify it using reasonable measures.

DataBaseline periodNotes
Sign-in sessionUp to 7 daysEnds earlier on logout or revocation
Pending login challengeUp to 10 minutesDeleted or invalid after use/expiry
Demo verification sessionUp to 30 minutesUsed only to complete verification
Customer ContentSubscription term plus the contractual export/deletion windowCustomer copies or statutory retention may apply
Security and audit logsBased on security risk, contract, and legal requirementsMay be retained longer to protect integrity or prove actions
Non-customer sales/support requestsUp to 24 months after last interactionUnless deletion is requested or claims require retention
Financial and contract recordsPeriod required by lawDepends on the contracting party’s jurisdiction
BackupsLimited, rolling cyclesIsolated; restored only for continuity and overwritten on schedule

9. Security and incident response

No electronic service is 100% secure. Customers must manage users, devices, permissions, exports, and link sharing, and promptly report suspected misuse.

  • logical tenant separation and role/context-based authorization;
  • signed sessions and HttpOnly, SameSite, and production Secure attributes for sensitive cookies;
  • email/phone verification where required, restricted administrative access, and least privilege;
  • logging for access and sensitive changes, plus file/output integrity controls where supported;
  • in-transit encryption and risk-appropriate storage, backup, testing, patching, and vulnerability management;
  • incident response, assessment, and customer/regulator/individual notice within legally required periods.

10. Your rights and how to exercise them

Depending on your location and our role, rights may include notice, access and a copy, correction, deletion/destruction, restriction, portability, objection, withdrawal of consent without retroactive effect, non-discrimination, opt-out of sale/sharing or certain automated decisions, and complaint to a regulator.

Email ceo@qsigma360.com. We will acknowledge the request, identify the applicable legal party, and respond within the statutory period. We may request proportionate information to verify identity or authority. For data in an organization workspace, we may refer the request to the organization or assist it as processor. An authorized agent may submit a request where law permits.

  • Unsubscribe from marketing using the message link; necessary service messages may continue.
  • We honor Global Privacy Control where applicable, although we do not sell data or share it for behavioral advertising.
  • If a request is denied, we explain why and provide appeal or complaint options where required.

11. Regional legal disclosures

Egypt

Where Egypt’s Law No. 151 of 2020 applies, we follow lawfulness, transparency, purpose limitation, and minimization principles; enable applicable rights; and implement licensing/permit, transfer, and notification requirements when effective for the relevant party.

Saudi Arabia

Where the Saudi PDPL and regulations apply, the collection notice states the basis, purpose, data, collection method, disclosure, geographic scope, retention, destruction, rights, and complaint channel, and applicable transfer controls are used.

EEA and United Kingdom

Where the GDPR or UK GDPR applies, we identify a legal basis, execute processor terms, use transfer safeguards, and enable applicable rights. You may complain to your local data-protection authority.

California

Where the CCPA as amended applies, consumers may know, access, delete, correct, opt out of sale/sharing, limit certain sensitive-information use, and receive non-discriminatory treatment. We do not sell personal information or share it for cross-context behavioral advertising and do not knowingly sell or share data of anyone under 16.

12. Children, changes, and notices

The Service is for organizations and professionals, not children, and we do not knowingly solicit data from anyone under 18 through the public site. If we learn of unauthorized collection, we take appropriate deletion and customer-notification steps.

We may update this policy when the Service or law changes. We show the revision date and provide notice or obtain renewed consent for material changes where required. We do not retroactively reduce contractual rights without a lawful basis or required agreement.

Contact us about privacy

To exercise a data right or report a privacy concern, email us and identify your country and relevant workspace. Do not send a password, verification code, or identity document unless we request it through a secure channel.

QSigma360 is a brand owned by Code Lines, not a separate legal entity. The applicable Order Form, agreement, or collection notice identifies the service operator/contracting party and its legal role. Brand ownership alone does not automatically make Code Lines the service operator or data controller.

Start with a tailored demo built around your organization’s needs.