Privacy Policy

Last Updated: December 22, 2025

This Privacy Policy describes how QraOne (https://qraone.com/) (“QraOne”, “we”, “us”, or “our”) collects, uses, discloses, and protects information when you access or use QraOne, our cloud-based electronic Quality Management System (eQMS), related websites, applications, and services (collectively, the “Services”).

By using QraOne, you acknowledge that you have read and understood this Privacy Policy.

1. Scope of This Policy

This Privacy Policy applies to:

  • Visitors to our websites
  • Users of QraOne (including trial, paid, and enterprise users)
  • Customers, prospects, and business partners
  • Individuals whose personal data is processed through QraOne as part of customer use

This Policy does not apply to data processed solely on behalf of customers under a Data Processing Agreement (DPA).

2. Information We Collect

2.1 Information You Provide Directly

We may collect information you voluntarily provide, including:

  • Contact Information: name, business email, phone number
  • Account Information: username, password, role, permissions
  • Organization Information: company name, address, industry, regulatory scope
  • Billing & Transaction Data: invoicing details, payment status (payment processing handled by third-party providers)
  • Support & Communications: tickets, emails, meeting notes, feedback

2.2 Information Collected Automatically

When you use the Services, we may automatically collect:

  • IP address, browser type, device identifiers
  • Operating system and usage logs
  • Feature usage, access times, audit trails
  • Cookies and similar tracking technologies

This data is used primarily for security, performance, and analytics.

2.3 Customer Content

QraOne allows customers to upload and manage regulated content, including:

  • Quality documents (SOPs, policies, records)
  • Design control files
  • Risk management files
  • Training records
  • Regulatory submissions and evidence

Customer Content remains the property of the customer.

QraOne processes such data strictly as a data processor.

3. How We Use Information

We use information to:

  • Provide, operate, and maintain QraOne
  • Authenticate users and manage accounts
  • Deliver support and onboarding services
  • Improve functionality, performance, and security
  • Comply with legal and regulatory obligations
  • Communicate service updates and important notices

We do not sell personal data.

4. Legal Bases for Processing (GDPR)

Where applicable, we process personal data based on:

  • Contractual necessity - to deliver the Services
  • Legitimate interests - security, fraud prevention, service improvement
  • Legal obligations - regulatory and compliance requirements
  • Consent - where explicitly obtained

5. Cookies and Tracking Technologies

We use cookies to:

  • Enable core platform functionality
  • Maintain user sessions
  • Monitor performance and usage trends

You can manage cookies through your browser settings. Disabling cookies may limit certain features.

6. Data Sharing and Disclosure

We may share information with:

  • Service Providers: cloud hosting, analytics, security, payment processors
  • Professional Advisors: auditors, legal counsel
  • Authorities: where required by law or regulation
  • Corporate Transactions: mergers, acquisitions, or restructuring

All vendors are contractually bound to confidentiality and data protection obligations.

6.1 AI Services and Data Processing

QraOne offers optional AI-enabled features. When users choose to use these AI Services, data or content submitted through such features may be shared with and processed by third-party AI service providers, including large language model (LLM) providers, solely to deliver the requested AI functionality.

QraOne does not use such data for independent AI model training unless explicitly stated and contractually agreed.

If users do not use the AI Services, their data is not shared with any third-party AI or LLM providers.

7. International Data Transfers

Data may be transferred and processed outside your country of residence, including the EU, UK, UAE, and other jurisdictions.

We rely on:

  • Standard Contractual Clauses (SCCs)
  • Appropriate technical and organizational safeguards

8. Data Security

We implement industry-standard technical and organizational measures, including:

  • Access controls and role-based permissions
  • Encryption in transit and at rest (where applicable)
  • Audit logging and monitoring
  • Secure hosting environments

No system is 100% secure; however, we continuously improve our security posture.

9. Data Retention

We retain personal data only as long as necessary to:

  • Provide the Services
  • Meet contractual and legal obligations
  • Resolve disputes and enforce agreements

Customer Content retention is governed by customer contracts and instructions.

10. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access your personal data
  • Rectify inaccurate data
  • Request deletion
  • Restrict or object to processing
  • Data portability

Requests may be submitted to:
info@compliancemedqra.net
support@qraone.com

11. Children’s Privacy

QraOne is intended for business users only and is not directed to children under 16.

12. Changes to This Policy

We may update this Privacy Policy periodically. Updates will be posted with a revised effective date.

13. Contact Information