Qualense Privacy Policy
July 22, 2026 · Qualense LLC, a California limited liability company
This Privacy Policy explains how Qualense LLC ("Qualense," "we," "us," or "our") handles personal information through the Qualense websites, applications, subscriptions, onboarding, and related services (collectively, the "Services"). It does not apply to personal information that a customer processes outside the Services.
1. Our role
For account administration, sales, website inquiries, billing, security, and operation of our business, Qualense generally determines why and how personal information is used and acts as a controller or business.
For personal information contained in Customer Content, Qualense generally processes the information on the customer's documented instructions and acts as a processor or service provider. The customer is responsible for its notices, legal basis, permissions, and instructions. The Data Processing Addendum governs if it applies and conflicts with this Policy.
2. Information we collect
Depending on how a person uses the Services, we may collect:
- Account and identity data: name, email address, organization, workspace membership, role, invitation status, authentication identifiers, and session information.
- Customer and engagement data: client or engagement names, owner, external reference, assessment scope, and related configuration.
- Customer Content: uploaded evidence files; file names, types, sizes, hashes, and storage references; extracted text and document metadata; evidence excerpts; mappings and citations; review decisions and comments; assessment results; gaps; plans of action and milestones; reports; and exported deliverables.
- Technical, audit, and security data: IP address, request and correlation identifiers, timestamps, authentication and authorization events, audit events, browser or device information, service health data, and diagnostic logs.
- AI-processing metadata: model and operation identifiers, token or usage counts, estimated cost, processing status, and provider responses needed to operate or troubleshoot the feature.
- Sales and support data: name, work email, company, role, team information, inquiry, legacy sales-application record, support messages, meeting information, and communications.
- Billing data: subscription, invoice, transaction, and customer identifiers. If a payment processor is used, payment-card details are handled by that processor rather than intentionally stored by Qualense.
Do not submit CUI, classified information, credentials or secrets, payment-card data, regulated health data, or other prohibited data described in the CUI Handling and Prohibited-Data Notice.
3. How we use information
We use information to:
- provide, secure, maintain, and troubleshoot the Services;
- authenticate users and enforce workspace permissions;
- receive and process evidence, support human review, calculate assessments, and produce requested deliverables;
- provide support, respond to inquiries, administer onboarding and subscriptions, and communicate about the Services;
- monitor reliability, prevent abuse, investigate security events, and maintain audit records;
- administer subscriptions, invoices, and contracts;
- comply with law and enforce our agreements; and
- improve the Services using operational and feedback data, subject to our agreements and the AI disclosure.
Qualense does not make a final compliance, certification, contracting, or legal decision for a customer. AI-generated and system-generated material must be reviewed by an authorized person.
4. AI and external processing
Some production processing is designed to send content to external providers:
- Anthropic may receive supported document content or extracted excerpts for assisted processing, semantic mapping, and verification. Images and scanned/image-only PDFs are currently stopped before external AI processing.
- Voyage AI may receive extracted text chunks to create embeddings.
- AWS is the intended production hosting, database, storage, identity, email, and logging provider when the production environment is deployed.
- Stripe may process billing information if paid billing is enabled.
The exact providers, purposes, unresolved safeguards, and current release gates appear in the AI Data Handling and Subprocessor Disclosure. Qualense will not represent that all providers are prohibited from training on Customer Content until the applicable contractual or account-level settings have been verified. Customer Content must not be used for model training by Qualense unless the customer gives separate, explicit written permission.
5. How we disclose information
We may disclose information:
- to subprocessors and service providers that perform contracted services for us;
- to the customer's authorized workspace users and administrators;
- to professional advisers subject to confidentiality duties;
- in a corporate transaction, subject to appropriate confidentiality protections;
- to comply with law, legal process, or a valid government request; or
- to protect rights, safety, security, and the integrity of the Services.
We do not sell personal information for money, use it for cross-context behavioral advertising, or share it with third parties for targeted advertising. This statement must be updated before Qualense introduces any analytics or advertising practice that changes it.
6. Legal bases
Where a legal basis is required, we process personal information as needed to perform a contract, comply with legal obligations, protect legitimate interests such as operating and securing the Services, or based on consent where consent is the appropriate basis. Customers determine the legal basis for personal information they place in Customer Content.
7. Retention and deletion
We retain information only as long as reasonably needed for the purposes described in this Policy, our agreements, security and audit needs, dispute resolution, and legal obligations. The current implementation does not enforce a complete customer-data retention schedule. Deleting an individual evidence item removes all versions of that evidence object through the configured storage adapter and redacts its content-bearing application records while retaining minimized identifiers needed for audit continuity. Client deletion, account/workspace purge, generated exports, backups, and provider-held data require separate processes and are not proven erased by an interface action. Designed S3 storage expires noncurrent versions after 30 days and access logs after 90 days, but those settings remain subject to deployed verification. Accordingly, no fixed end-to-end deletion promise should be published until the complete deletion workflow is implemented and tested.
The approved target retention schedule and current implementation limitations are in the Data Retention, Deletion, and Offboarding Policy. External AI providers may retain inputs or outputs under their own agreements. For example, Anthropic's standard commercial API retention is generally up to 30 days unless a different arrangement or exception applies. Qualense uses business accounts for Anthropic and Voyage AI, but the executed terms and selected settings must be retained and verified before publishing a provider-specific retention or no-training promise.
8. Security
We use administrative, technical, and organizational safeguards appropriate to the Services and describe implemented, planned, and unverified controls separately in the Security Controls and Data Protection Statement. No system is completely secure, and the Services are not currently represented as FedRAMP authorized, FIPS validated, SOC 2 certified, CMMC certified, or as implementing every NIST SP 800-171 requirement.
9. International processing
Qualense's intended AWS production region is us-east-1, subject to deployment verification. Qualense and its providers may process information in the United States and other locations permitted by the applicable agreement. No data-residency commitment applies unless stated in an Order Form. Where required, the DPA will provide an appropriate transfer mechanism.
10. Privacy choices and rights
Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. These rights may be limited by law, security, another person's rights, and our role as a processor.
Submit a request to deeppractise@gmail.com. If the information is in a customer's workspace, contact that customer first; we will assist the customer as required by the applicable agreement and law. We may verify identity and authority before acting.
Users can manage certain account information through the Services. A workspace control can disable AI-assisted semantic mapping. That control must not be described as disabling every external AI operation until all supported processing paths and deployed provider behavior are verified.
11. Children
The Services are for business users age 18 or older and are not directed to children. Do not submit children's personal information.
12. Changes
We may update this Policy. We will post the updated version with a revised effective date and provide additional notice when required by law or contract.
13. Contact
Qualense LLC Privacy: deeppractise@gmail.com Support: deeppractise@gmail.com