Data protection notice

Privacy Policy

How QSentia handles personal data across accounts, customer workspaces, billing, support, recruitment, APIs, and security operations.

Effective / 19 June 2026Version / 2.1Owner / QSentia LLC

This policy describes QSentia LLC's current public website and platform-data practices. It will be updated when new processors, checkout payment flows, broker-connection workflows, or launch jurisdictions are added.

Section 1

Scope and role

This policy applies to QSentia websites, authenticated dashboards, customer workspaces, APIs, support interactions, recruitment workflows, and related digital services operated by QSentia LLC.

QSentia LLC is the controller or business for personal data collected through the public website and customer-facing service unless a signed customer agreement states otherwise. Separate contracts, data-processing terms, or institutional onboarding documents may supplement this policy.

Privacy requests are handled through inquiries@qsentia.com and the contact form. QSentia verifies the requester before disclosing, changing, deleting, or exporting account-related data.

Section 2

Personal data we collect

We collect data that is reasonably necessary to provide, secure, improve, and administer the platform.

  • Account and identity data, including name, email address, organization, authentication provider, account identifiers, and session information.
  • Commercial and billing data, including plan, invoice, billing contact, tax-status, and payment-status information. The current public site does not collect full payment-card numbers, and QSentia does not store full payment-card numbers on its own servers.
  • Technical data, including IP address, browser and device information, request logs, security events, cookie choices, API usage, and approximate location derived from network data.
  • Customer configuration data, including model entitlements, broker-connection status, automation settings, risk controls, support tickets, and audit events. QSentia does not collect broker passwords through public website forms. Broker connection tokens or credentials are handled only through an approved account-connection workflow when that workflow is enabled for a customer.
  • Financial-profile and account-connection data, including investor type, expected allocation, strategy interest, account-readiness state, broker connection state, and model-access entitlements submitted for diligence, onboarding, or customer support.
  • Information submitted through contact, recruitment, lead, grievance, and support workflows.
Section 3

Purposes and lawful processing

QSentia processes personal data for specified purposes communicated at or before collection. Depending on the context and applicable law, processing may be based on consent, performance of a contract, compliance with law, security and fraud prevention, or another permitted legitimate use.

  • Create and administer accounts, sessions, permissions, and customer workspaces.
  • Deliver research, model-access, API, billing, support, recruitment, and onboarding services.
  • Protect users and systems, investigate abuse, maintain audit trails, and respond to incidents.
  • Communicate service notices and respond to requests, grievances, and contractual obligations.
  • Improve reliability and usability using aggregated or consented analytics where enabled.
Section 4

Cookies and similar technologies

Necessary cookies and browser storage support authentication, security, fraud prevention, consent records, and essential site operation. Optional preference, analytics, or marketing categories remain disabled unless the user selects them through the consent manager.

Users can change optional choices at any time through the Cookie settings control in the footer. Additional details, including category and retention information, are available in the Cookie Policy.

Section 5

Processors, service providers, and disclosure

QSentia uses service providers for authentication, cloud hosting, code hosting, communications, monitoring, market data, and support. Providers receive only the information reasonably required for their role and are bound by confidentiality, security, and data-protection obligations.

Personal data may also be disclosed when required by law, to protect legal rights or platform security, in connection with a corporate transaction subject to safeguards, or with the individual's direction or consent.

  • Hosting and deployment: Vercel-managed infrastructure for the public web application.
  • Authentication and database services: Supabase where authentication, sessions, and customer data stores are configured.
  • Code hosting and source telemetry: GitHub repositories and logs where QSentia or model-source integrations are configured.
  • Identity providers: Google and GitHub OAuth when a user chooses those sign-in methods.
  • Payments: no public checkout payment processor is active on this website version. The payment processor will be named before paid checkout is enabled.
Section 6

Retention and deletion

QSentia retains personal data for the period needed for the stated purpose, contractual obligations, security, dispute resolution, legal compliance, and the retention schedule below. When the purpose ends and no lawful retention need remains, QSentia deletes, anonymizes, or places the data beyond active use.

  • Consent records: retained for up to 12 months after the latest consent choice, or longer where needed to demonstrate the user's choices.
  • Account and session records: retained while the account is active and for a reasonable period after closure for security, support, and audit needs.
  • Security and audit logs: retained for incident investigation, abuse prevention, and compliance review.
  • Billing, tax, and contractual records: retained for the applicable tax, accounting, dispute, and contract limitation periods.
  • Recruitment records: retained for the active hiring process and a reasonable follow-up period unless a longer retention period is required or consented to.
  • Backups: deleted or overwritten through controlled lifecycle processes.
Section 7

Your choices and privacy rights

Subject to applicable law and verification, individuals may request information about processing, access to personal data, correction of inaccurate data, deletion where retention is no longer required, portability, restriction or objection where available, withdrawal of consent, and opt-out choices required by applicable US state privacy laws.

Withdrawing consent does not affect processing already completed before withdrawal and may prevent QSentia from providing features that depend on that data. Requests may be submitted through the official contact channel and will be handled after proportionate identity verification.

Section 8

Children and sensitive personal data

QSentia is intended for adults and professional users. The platform is not directed to children. QSentia does not knowingly collect children’s personal data through its authenticated products. If such data is identified, QSentia will take reasonable steps to restrict processing and delete it unless a lawful basis requires otherwise.

Section 9

Security and personal-data breach response

QSentia applies administrative, technical, and organizational safeguards proportionate to the nature and risk of processing. Measures may include access control, encryption in transit, credential separation, secure development, logging, supplier review, backups, vulnerability management, and incident response.

If a personal-data breach occurs, QSentia will assess impact, contain and remediate the event, preserve appropriate records, and provide notifications to affected individuals and authorities when required by applicable law.

Section 10

International processing and transfers

Cloud, authentication, code-hosting, market-data, and support providers process data in regions configured by QSentia and its service providers. QSentia uses contractual, technical, and organizational safeguards for cross-border processing. Where GDPR transfer rules apply, QSentia relies on appropriate contractual safeguards such as standard contractual clauses or equivalent lawful mechanisms.

Section 11

Privacy requests, complaints, and contact

Submit privacy requests or complaints to inquiries@qsentia.com with the subject "Privacy Request," or use the contact form. Include enough information to identify the relevant account and request, but do not send passwords, private keys, full payment-card numbers, or broker credentials.

If a complaint is not resolved through QSentia's process, an individual may have the right to approach a competent data-protection authority, state attorney general, privacy regulator, or other regulator under applicable law.

Section 12

Changes to this policy

QSentia may update this policy when services, laws, suppliers, or processing activities change. Material changes will be communicated through an appropriate channel, and renewed consent will be requested when required.

Official references