Legal

Privacy Policy

Last updated: March 27, 2026

Qyvo P.S.A. ("Qonera," "we," "us," or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services, platform, or website (the "Services"). Please read this policy carefully. By using the Services, you consent to the practices described here.

1. Data We Collect

Account Data: When you create an account, we collect your name, email address, password (hashed), and organisation name.

Usage Data: We automatically collect information about how you interact with the Services, including IP address, browser type, device identifiers, pages visited, questions submitted, and timestamps.

Content Data: Documents, files, and data you upload to the Services for processing ("Customer Content"). We process this data strictly to provide the Services and do not use it to train AI models without your explicit consent.

Payment Data: Payment information is processed by our third-party payment processor. We do not store full card numbers or banking information.

Communications Data: If you contact us by email or through the Services, we retain those communications.

2. How We Use Your Data

  • To provide, operate, and improve the Services
  • To process your questions and generate reviewed outputs
  • To authenticate your account and manage subscriptions
  • To send transactional and service communications
  • To comply with legal obligations
  • To detect and prevent fraud, abuse, or security incidents
  • To conduct analytics and product research (aggregated and anonymised)

3. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we rely on the following legal bases for processing your personal data:

  • Contract performance — to fulfil our contractual obligations to you
  • Legitimate interests — to operate and improve our Services, prevent fraud, and ensure security
  • Legal obligation — to comply with applicable laws
  • Consent — where you have given explicit consent (e.g., marketing communications)

4. Cookies and Tracking

We use cookies and similar tracking technologies to operate and improve the Services. Types of cookies we use:

  • Strictly necessary cookies: Required for the Services to function. Cannot be disabled.
  • Analytics cookies: Help us understand how users interact with the Services. Disabled by default.
  • Preference cookies: Remember your settings and preferences.

You can manage your cookie preferences at any time via our Cookie Preferences page.

5. Third-Party Sharing

We do not sell your personal data. We may share your data with:

  • Service providers who process data on our behalf (sub-processors), subject to appropriate data protection agreements
  • AI model providers, solely to process your questions and documents for the purpose of generating outputs within the Services
  • Law enforcement or regulatory authorities where required by law
  • A successor entity in the event of a merger, acquisition, or asset sale, subject to notice to you

A full list of sub-processors is available on our Sub-processors page.

6. International Data Transfers

Qonera is based in the United States. If you are located in the EEA, UK, or Switzerland, your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission to lawfully transfer personal data from the EEA to the United States. Enterprise customers may request our DPA with SCCs attached.

7. Your Rights (GDPR and equivalent laws)

If you are located in the EEA, UK, or another jurisdiction with equivalent data protection laws, you have the following rights:

  • Right to access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your personal data, subject to legal obligations
  • Right to restriction — request that we restrict processing of your data
  • Right to portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — where processing is based on consent
  • Right to lodge a complaint — with your local data protection authority

To exercise any of these rights, contact security@qonera.ai.

8. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Services. We retain Customer Content for the duration of your subscription plus 30 days following termination, after which it is deleted. We may retain certain records for longer where required by law or for legitimate business purposes such as fraud prevention.

9. Security

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include encryption in transit (TLS) and at rest, access controls, and regular security assessments. However, no method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact security@qonera.ai immediately.

10. Children's Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact security@qonera.ai. We will take steps to delete such information promptly.

11. Contact Us

For questions, concerns, or to exercise your rights, contact our Data Protection contact at:

Qyvo P.S.A.
NIP (VAT): 5851509019
KRS: 0001195545
Poland
security@qonera.ai