QSentia does not claim regulator approval, GDPR certification, SOC 2 certification, or full US state-law compliance by publication of this page. This page describes an implementation baseline that must be matched to actual operations and legally reviewed.
Governance and accountability
QSentia maintains a data-protection programme that identifies processing activities, assigns ownership, documents purposes, minimizes collection, manages suppliers, and supports privacy requests and incidents. The programme is reviewed as the company, product, customer base, and regulatory footprint change.
- Maintain a record of processing activities and data-flow inventory.
- Assign accountable owners for privacy, security, product, HR, support, and vendor processing.
- Perform privacy and security reviews before launching high-risk features, analytics, broker integrations, or API workflows.
- Keep evidence of notices, consent where used, privacy requests, complaints, incidents, and remediation.
Notice, lawful basis, and permitted uses
Privacy notices are written to be clear, accessible, and specific about the personal data collected, purpose, categories of recipients, rights, and contact route. Where GDPR applies, QSentia documents the lawful basis for each processing activity. When consent is used, it is specific, informed, unambiguous, and capable of withdrawal through a comparable route.
Privacy rights request process
QSentia acknowledges privacy rights requests, verifies identity proportionately, locates responsive systems, applies lawful exceptions, records the decision, and responds through a secure channel. Depending on the applicable jurisdiction, requests may concern access, correction, deletion, portability, objection, restriction, opt-out of sale or sharing, opt-out of certain profiling or targeted advertising, or withdrawal of consent.
Complaints and regulator escalation
Privacy complaints may be submitted through the contact form or inquiries@qsentia.com. QSentia assigns an owner, investigates relevant evidence, communicates the outcome, and provides regulator or appeal information where applicable law requires it.
Children and sensitive data
The service is designed for adults and professional users. QSentia does not intentionally collect children’s data through authenticated products, investor workflows, or customer dashboards. Sensitive personal information is collected only when necessary, disclosed in the relevant notice, protected with stronger controls, and limited to the documented purpose.
Processors, service providers, and vendors
Before entrusting personal data to a provider, QSentia assesses purpose, location, security, subprocessors, deletion, incident notification, audit rights, and contractual protections. GDPR data-processing terms, US service-provider restrictions, confidentiality duties, and security commitments are matched to the provider's role.
International transfers and data residency
QSentia documents where production systems, support tools, authentication providers, code repositories, analytics tools, and payment providers process personal data. For EU/EEA data, QSentia uses transfer mechanisms such as appropriate contractual safeguards where required. For US customers, state privacy notices and contractual commitments reflect the actual hosting and vendor footprint.
Personal-data breach management
QSentia maintains a documented workflow to detect, triage, contain, investigate, remediate, and learn from personal-data breaches. The workflow identifies who assesses notification duties under GDPR, US state breach laws, customer contracts, and applicable sector rules; preserves evidence; communicates with affected individuals and authorities; and tracks corrective actions.
Programme status and legal review
These controls are a readiness baseline, not a representation that every statutory obligation has been independently audited. QSentia validates entity details, controller or processor roles, state-law thresholds, financial-sector obligations, retention schedules, request-response timelines, processor contracts, cookie/analytics use, and cross-border transfer restrictions before expanding production processing.
