Privacy Policy
This policy explains, in direct language, when the operator of QSigma360 acts as a controller and when it processes data for your organization, what we collect, why, how long we retain it, and how you can exercise your rights.
- Effective
- 6 August 2026
- Last updated
- 6 August 2026
- Version
- 1.0
No sale of data
We do not sell personal information or share it for cross-context behavioral advertising.
Governed AI
We do not train our general models on Customer Content without explicit written opt-in.
Limited collection and retention
We collect what the purpose requires and delete or de-identify it when the legal or contractual need ends.
This policy applies to the public website, platform, and related services. A Data Processing Agreement, Order Form, or feature-specific notice may supplement it, and broader protection applies where required by law.
1. Scope and who is responsible
The “Service” includes the QSigma360 public site, cloud workspaces, forms, support, enabled AI features, and integrations we operate. It does not cover third-party sites governed by their own notices.
For website, account, billing, security, and business-contact data, the legal party named in the collection notice or Order Form is the controller. For workspace content entered by a customer organization or its users, the operator normally acts as processor on the organization’s instructions and the organization acts as controller. If this policy conflicts with a Data Processing Agreement for Customer Content, the DPA controls.
2. Data we collect and its sources
Customer Content may include sensitive personal data or information about employees, customers, or suppliers when the organization chooses to enter it. The organization must establish a lawful basis, provide appropriate notice, minimize that data, and restrict access by need-to-know.
| Category | Examples | Source |
|---|---|---|
| Identity and account | Name, email, phone, title, language, identifiers, verification state, and permissions | You or your organization administrator |
| Organization and contract | Organization, sector, sites, contacts, subscription scope, and commercial correspondence | The customer or its representatives |
| Customer Content | Quality and food-safety records, complaints, NCR/CAPA, audits, suppliers, documents, attachments, signatures, and approvals | Users and authorized integrations |
| Usage and security | IP address, browser/device, sign-in times, event logs, authentication attempts, access, downloads, and changes | Automatically from Service use |
| Communications and support | Demo requests, messages, feedback, tickets, and call content if recording is disclosed | You and our correspondence |
| AI feature data | Prompts, authorized context, submitted files, outputs, feedback, and safety telemetry | The user and enabled feature |
| Cookies and local storage | Session and verification tokens, interface preferences, and local recovery drafts | Your browser |
3. Purposes and legal bases
When relying on legitimate interests, we balance the purpose, necessity, expected impact, and individual rights, and apply minimization and safeguards. You may object where the law permits.
| Purpose | Typical data | Legal basis, as applicable |
|---|---|---|
| Create accounts and operate workspaces | Account, organization, content, and settings | Contract performance or requested pre-contract steps |
| Protect, prevent abuse, and audit | Technical/security logs and access events | Legitimate interests, contract, and legal obligation |
| Support and request management | Contact data and request content | Contract or legitimate interests |
| Service communications | Email, phone, and account status | Contract or legal obligation |
| Optional marketing | Contact details and preferences | Consent where required, or legitimate interests with an easy opt-out |
| AI features | Prompt, context, and output | Contract and organization instructions; explicit consent where law requires |
| Compliance and legal claims | Relevant logs, contracts, and correspondence | Legal obligation or establishment, exercise, and defense of claims |
| Product reliability | Aggregated/de-identified usage and feedback | Legitimate interests; not general-model training on Customer Content without explicit opt-in |
4. Customer Content and sensitive data
- The organization and its licensors retain their rights in Customer Content; we use it only to provide, secure, support, and follow documented instructions for the Service.
- Do not enter passwords, verification codes, complete payment-card data, or secrets the workflow does not need.
- Do not upload health, biometric, criminal, child, or highly sensitive data unless necessary, contractually authorized, lawful, and protected by additional controls.
- Organization administrators may see account/activity data and may export content, restrict access, or delete it under organization policy and law.
5. AI and automated decisions
Enabled features may send the minimum necessary prompt, context, and files to an approved model provider acting as subprocessor. We enforce permission scope and suitable logging; processing locations may vary by customer configuration and provider.
Outputs are probabilistic suggestions and may be wrong. QSigma360 does not autonomously make final employment, credit, insurance, healthcare, food-safety, compliance, or approval decisions for a user. An authorized person must review evidence and outputs before any consequential decision.
7. Hosting and international transfers
Data may be processed in the customer’s country or other regions where providers operate. The Order Form or DPA identifies an agreed hosting region, if any. Cross-border technical access does not change data ownership.
Where law requires a transfer safeguard, we use a recognized mechanism such as standard contractual clauses, an adequacy decision, or applicable local transfer rules, with risk assessment and supplementary measures where needed. Customers may request subprocessor and processing-location information.
8. Retention and deletion
We may retain specific data longer for a dispute, preservation order, or legal duty and restrict it to that purpose. At the end of retention, we securely delete it or irreversibly de-identify it using reasonable measures.
| Data | Baseline period | Notes |
|---|---|---|
| Sign-in session | Up to 7 days | Ends earlier on logout or revocation |
| Pending login challenge | Up to 10 minutes | Deleted or invalid after use/expiry |
| Demo verification session | Up to 30 minutes | Used only to complete verification |
| Customer Content | Subscription term plus the contractual export/deletion window | Customer copies or statutory retention may apply |
| Security and audit logs | Based on security risk, contract, and legal requirements | May be retained longer to protect integrity or prove actions |
| Non-customer sales/support requests | Up to 24 months after last interaction | Unless deletion is requested or claims require retention |
| Financial and contract records | Period required by law | Depends on the contracting party’s jurisdiction |
| Backups | Limited, rolling cycles | Isolated; restored only for continuity and overwritten on schedule |
9. Security and incident response
No electronic service is 100% secure. Customers must manage users, devices, permissions, exports, and link sharing, and promptly report suspected misuse.
- logical tenant separation and role/context-based authorization;
- signed sessions and HttpOnly, SameSite, and production Secure attributes for sensitive cookies;
- email/phone verification where required, restricted administrative access, and least privilege;
- logging for access and sensitive changes, plus file/output integrity controls where supported;
- in-transit encryption and risk-appropriate storage, backup, testing, patching, and vulnerability management;
- incident response, assessment, and customer/regulator/individual notice within legally required periods.
10. Your rights and how to exercise them
Depending on your location and our role, rights may include notice, access and a copy, correction, deletion/destruction, restriction, portability, objection, withdrawal of consent without retroactive effect, non-discrimination, opt-out of sale/sharing or certain automated decisions, and complaint to a regulator.
Email ceo@qsigma360.com. We will acknowledge the request, identify the applicable legal party, and respond within the statutory period. We may request proportionate information to verify identity or authority. For data in an organization workspace, we may refer the request to the organization or assist it as processor. An authorized agent may submit a request where law permits.
- Unsubscribe from marketing using the message link; necessary service messages may continue.
- We honor Global Privacy Control where applicable, although we do not sell data or share it for behavioral advertising.
- If a request is denied, we explain why and provide appeal or complaint options where required.
11. Regional legal disclosures
Egypt
Where Egypt’s Law No. 151 of 2020 applies, we follow lawfulness, transparency, purpose limitation, and minimization principles; enable applicable rights; and implement licensing/permit, transfer, and notification requirements when effective for the relevant party.
Saudi Arabia
Where the Saudi PDPL and regulations apply, the collection notice states the basis, purpose, data, collection method, disclosure, geographic scope, retention, destruction, rights, and complaint channel, and applicable transfer controls are used.
EEA and United Kingdom
Where the GDPR or UK GDPR applies, we identify a legal basis, execute processor terms, use transfer safeguards, and enable applicable rights. You may complain to your local data-protection authority.
California
Where the CCPA as amended applies, consumers may know, access, delete, correct, opt out of sale/sharing, limit certain sensitive-information use, and receive non-discriminatory treatment. We do not sell personal information or share it for cross-context behavioral advertising and do not knowingly sell or share data of anyone under 16.
12. Children, changes, and notices
The Service is for organizations and professionals, not children, and we do not knowingly solicit data from anyone under 18 through the public site. If we learn of unauthorized collection, we take appropriate deletion and customer-notification steps.
We may update this policy when the Service or law changes. We show the revision date and provide notice or obtain renewed consent for material changes where required. We do not retroactively reduce contractual rights without a lawful basis or required agreement.
Contact us about privacy
To exercise a data right or report a privacy concern, email us and identify your country and relevant workspace. Do not send a password, verification code, or identity document unless we request it through a secure channel.
QSigma360 is a brand owned by Code Lines, not a separate legal entity. The applicable Order Form, agreement, or collection notice identifies the service operator/contracting party and its legal role. Brand ownership alone does not automatically make Code Lines the service operator or data controller.