Privacy Policy
1. About this Policy
This Policy describes what data the Qualone service (the "Service") processes, for what purposes, and how it is protected. The Service is built for organisations: access is by invitation, and data is processed on behalf of the organisation that has adopted the Service (the "Organisation").
With respect to working data, the Organisation acts as the data controller and determines the purposes of processing; the party providing the Service (the "Operator") processes data on the Organisation's behalf to the extent necessary to operate the Service.
2. Data we process
- Account data: email address, display name, assigned role. When signing in with Google, the Google account identifier is additionally processed to the extent required for authentication.
- Organisation working data(from its CRM and user activity): deal records and pipeline stages, managers' deal comments, performance indicators (scores, response times, process violations), workspace settings (targets, funnel mapping, notification recipients).
- Technical data: session information (authentication cookies) and service logs required for operation, diagnostics, and security.
The Service does not request and is not intended to process special categories of personal data (health, biometrics, etc.) or payment card data.
3. Sources of data
Working data flows from the Organisation's CRM via the configured integration and is entered by the Organisation's users in the workspace. Account data is provided when access is created by the Organisation/integrator and by the user themselves.
4. Purposes and legal bases
- providing manager-quality analytics to the Organisation's users — performance of the agreement with the Organisation;
- authentication, access control, and protection against unauthorised access — legitimate interest in securing the Service;
- sending service notifications and reports via channels configured by the Organisation (e.g. Telegram, email) — performance of the agreement;
- failure diagnostics and maintaining availability — legitimate interest.
5. Automated (AI) processing
To compute quality indicators, the Service uses artificial-intelligence technology: the text of managers' comments is automatically evaluated against quality criteria, and the resulting assessments feed scores and rankings. These outputs are informational and supportive, intended for the Organisation's management as a signal for review; they do not produce automated decisions with legal effect concerning employees — interpretation and decisions remain with the Organisation.
6. Cookies
The Service uses strictly necessary cookies only — for sign-in and session maintenance. No advertising or third-party analytics cookies are used.
7. Sharing and sub-processors
The Operator does not sell data and does not share it with third parties for their own purposes. Infrastructure providers acting on the Operator's instructions and bound by confidentiality obligations are engaged to run the Service:
- web application hosting (cloud platform);
- managed database and authentication service (data centres located in the EU);
- an AI model provider — for automated evaluation of comment texts;
- notification channel operators (e.g. Telegram) — to the extent of the messages sent.
Data may also be disclosed where required by applicable law or a lawful request of a competent authority.
8. International transfers
The Service's infrastructure may be located in different jurisdictions (in particular, the database is hosted in the EU). When engaging providers, the Operator selects solutions offering an adequate level of protection and contractual confidentiality safeguards.
9. Retention
Data is retained for as long as the Service is provided to the Organisation. Upon termination, the Organisation's working data is deleted or anonymised within a reasonable period, unless longer retention is required by applicable law. Technical logs are kept for a limited period necessary for security and diagnostics.
10. Security
- each Organisation's data is logically isolated at the architecture level (multi-tenancy);
- user access is role-based; access is by invitation, with no public registration;
- data in transit is protected with encryption (HTTPS/TLS);
- the Operator's personnel access data only to the extent necessary to support the Service.
11. Data subject rights
Depending on applicable law, data subjects may request access to their data, its rectification, erasure, or restriction of processing, and may object to processing. As working data is processed on the Organisation's behalf, such requests should be submitted via the Organisation (its workspace administrator); the Operator assists in fulfilling them.
12. Changes to this Policy
This Policy may be updated; the current version with its date is always available on this page. Organisations are notified of material changes by reasonably accessible means.
13. Contact
Questions about data processing should be directed via your Organisation's administrator or the contacts specified in the agreement with the Organisation. See also the Terms of Service.