Privacy Policy
This policy explains what personal information QSolve collects, why we collect it, and what you can do about it. It covers our website and the QSolve platform. Where we process customer ledger data on behalf of a customer, our role and obligations are set out in the Data Processing Addendum.
Contents
01Two different roles
QSolve handles personal information in two distinct capacities, and different rules apply to each.
| Capacity | What it covers | Governed by |
|---|---|---|
| Controller | Information about visitors to this site, people who request a demo, and the administrators and users we correspond with about accounts and support. | This policy |
| Processor | Ledger, sub-ledger, banking, and operational data a customer loads into the platform, including any personal information it contains, such as tenant or vendor contact details and preparer or reviewer identities. | The customer's instructions and our DPA |
When we act as processor we do not decide what data is loaded, why, or how long it is kept. Those decisions belong to the customer, and requests about that data should go to them.
02Information we collect
Information you give us
- Demo requests. Name, work email, company, and the ledger or ERP you use.
- Correspondence. What you send us by email or in support conversations, including attachments.
- Account information. For platform users, name, work email, role, and permission assignments.
Information collected automatically
- Usage and device data. IP address, browser and device type, pages viewed, referring page, and timestamps.
- Cookies. As described in section 4. Analytics cookies are set only after you accept.
- Platform audit logs. Actions taken in the platform, with the acting user and a timestamp. These exist so the record is auditable and cannot be edited or deleted by us or by you.
Information from other sources
- Publicly available business information used to understand an inbound request, such as company size or sector.
- Data a customer's integrations send us on the customer's instruction.
We do not collect special category data, government identifiers, or payment card numbers through this website. Subscription billing is handled through invoicing via Stripe.
03Why we use it
| Purpose | Information used | Legal basis |
|---|---|---|
| Respond to a demo request and arrange a walkthrough | Demo request fields, correspondence | Legitimate interests; steps toward a contract |
| Provide, support, and secure the platform | Account information, usage data, audit logs | Performance of a contract |
| Understand how the site is used and improve it | Usage data, analytics cookies | Consent |
| Send product and company updates to business contacts | Name, work email | Consent, or legitimate interests where permitted |
| Detect and investigate abuse, fraud, or security incidents | Usage data, audit logs | Legitimate interests; legal obligation |
| Meet legal, accounting, and audit obligations | Records as required | Legal obligation |
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
04Cookies and analytics
Cookies strictly necessary for the site to function are set without consent. Analytics cookies are set only after you choose "Accept analytics" in the banner. Declining leaves the site fully usable; you can change your choice at any time by clearing site data for www.qsolve.app.
| Cookie or service | Purpose | Set when | Retention |
|---|---|---|---|
| qsolve-consent (local storage) | Remembers your cookie choice | Always | Until cleared |
| HubSpot hubspotutk, __hstc, __hssc, __hssrc | Analytics; attributes a demo request to the visit it came from | After you accept | Up to 13 months |
HubSpot is our CRM and marketing platform. Their handling of this data is described in HubSpot's own privacy documentation.
05Who we share it with
We share personal information only where necessary, and only with parties bound to protect it:
- Service providers who host, secure, or support the platform and our business, acting on our instructions under written terms.
- Professional advisers such as auditors, accountants, and lawyers, where they need it to advise us.
- Authorities where we are legally required to disclose, or to establish or defend legal claims. Where we are permitted to notify the affected customer, we will.
- A successor in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
Subprocessors
| Provider | Function | Location |
|---|---|---|
| HubSpot | CRM, demo requests, website analytics | United States |
| Microsoft Azure | Platform hosting and storage | US East |
| Microsoft 365 | Business email and notifications | US East |
The current subprocessor list for platform data is maintained in the Data Processing Addendum, and customers are notified before a new subprocessor begins processing.
06International transfers
We operate from the United States and host platform data in US data centers. If you are outside that jurisdiction, your information will be transferred there.
QSolve currently serves customers in the United States and processes all data there. If your organization is subject to EU, UK, or Swiss data protection law and requires a specific transfer mechanism, contact us at info@qsolve.app before submitting data so we can put the appropriate terms in place.
07How long we keep it
| Category | Retention |
|---|---|
| Demo requests that do not become customers | 24 months from last contact |
| Customer account and contact records | Subscription term plus 24 months |
| Platform Customer Data | Per the customer's instruction; deleted or de-identified within 30 days of termination unless law requires otherwise |
| Audit logs and evidence records | 7 years, or the customer's configured retention period if longer |
| Website analytics | 13 months |
| Billing and tax records | As required by law, typically 7 years |
Audit logs are intentionally immutable. Where a deletion request conflicts with the integrity of an audit record a customer is required to keep, we will tell you and explain the basis.
08How we protect it
- Encryption in transit (TLS 1.2 or above) and at rest.
- Role-based access control and single sign-on, with least-privilege access for our own personnel.
- Segregation of duties enforced for people and for automated processing.
- Immutable, timestamped audit logging of platform activity.
- Background checks and confidentiality obligations for personnel with access to customer environments.
- Vulnerability management, logging, and incident response procedures. A SOC 2 Type II report is expected in Q1 2027 and will be available under NDA on completion.
No system is perfectly secure. If a breach affects your personal information, we will notify you and any relevant regulator as required by law, and without undue delay.
09Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict processing, to withdraw consent, and not to be discriminated against for exercising these rights.
To exercise a right, email info@qsolve.app. We will verify your identity, respond within 30 days or the period the law requires, and tell you if we need longer. There is no charge unless a request is excessive or repetitive.
If your request concerns data a customer loaded into the platform, we will refer you to that customer, who decides how that data is handled. EEA and UK residents may also complain to their local supervisory authority.
10California residents
Under the CCPA as amended, we disclose that in the past twelve months we collected the categories of information described in section 2 (identifiers, commercial information, and internet activity), for the purposes in section 3, from the sources in section 2. We have not sold personal information and have not shared it for cross-context behavioral advertising.
You may request to know, delete, or correct your personal information, and may limit use of sensitive personal information (we do not collect any in the ordinary course). Submit requests to info@qsolve.app. You may use an authorized agent with written proof of authority. We do not use or disclose personal information for purposes incompatible with those disclosed here.
11Automated processing
The platform uses automated processing to match transactions, reconcile balances, detect anomalies, and draft variance explanations. This processing operates on customer financial data within controls the customer configures, and every output is presented for human review before it is relied upon.
We do not use automated decision-making that produces legal effects for individuals, and we do not use one customer's data to train models serving other customers.
12Children
QSolve is a business product. We do not direct it at children and do not knowingly collect information from anyone under 18. If you believe a child has provided us information, contact info@qsolve.app and we will delete it.
13Changes to this policy
We will post any updated policy here with a new "last updated" date. For material changes affecting how we use information about you, we will give notice by email or in the platform before the change takes effect. Prior versions are available on request.
Contact us
Privacy questions and rights requests: info@qsolve.app
Security matters: info@qsolve.app
QSolve Inc. · 8 The Green, STE R, Dover, DE 19901, USA
