Privacy Policy
Last Updated: December 22, 2025
This Privacy Policy describes how QraOne (https://qraone.com/) (“QraOne”, “we”, “us”, or “our”) collects, uses, discloses, and protects information when you access or use QraOne, our cloud-based electronic Quality Management System (eQMS), related websites, applications, and services (collectively, the “Services”).
By using QraOne, you acknowledge that you have read and understood this Privacy Policy.
1. Scope of This Policy
This Privacy Policy applies to:
- Visitors to our websites
- Users of QraOne (including trial, paid, and enterprise users)
- Customers, prospects, and business partners
- Individuals whose personal data is processed through QraOne as part of customer use
This Policy does not apply to data processed solely on behalf of customers under a Data Processing Agreement (DPA).
2. Information We Collect
2.1 Information You Provide Directly
We may collect information you voluntarily provide, including:
- Contact Information: name, business email, phone number
- Account Information: username, password, role, permissions
- Organization Information: company name, address, industry, regulatory scope
- Billing & Transaction Data: invoicing details, payment status (payment processing handled by third-party providers)
- Support & Communications: tickets, emails, meeting notes, feedback
2.2 Information Collected Automatically
When you use the Services, we may automatically collect:
- IP address, browser type, device identifiers
- Operating system and usage logs
- Feature usage, access times, audit trails
- Cookies and similar tracking technologies
This data is used primarily for security, performance, and analytics.
2.3 Customer Content
QraOne allows customers to upload and manage regulated content, including:
- Quality documents (SOPs, policies, records)
- Design control files
- Risk management files
- Training records
- Regulatory submissions and evidence
Customer Content remains the property of the customer.
QraOne processes such data strictly as a data processor.
3. How We Use Information
We use information to:
- Provide, operate, and maintain QraOne
- Authenticate users and manage accounts
- Deliver support and onboarding services
- Improve functionality, performance, and security
- Comply with legal and regulatory obligations
- Communicate service updates and important notices
We do not sell personal data.
4. Legal Bases for Processing (GDPR)
Where applicable, we process personal data based on:
- Contractual necessity - to deliver the Services
- Legitimate interests - security, fraud prevention, service improvement
- Legal obligations - regulatory and compliance requirements
- Consent - where explicitly obtained
5. Cookies and Tracking Technologies
We use cookies to:
- Enable core platform functionality
- Maintain user sessions
- Monitor performance and usage trends
You can manage cookies through your browser settings. Disabling cookies may limit certain features.
6. Data Sharing and Disclosure
We may share information with:
- Service Providers: cloud hosting, analytics, security, payment processors
- Professional Advisors: auditors, legal counsel
- Authorities: where required by law or regulation
- Corporate Transactions: mergers, acquisitions, or restructuring
All vendors are contractually bound to confidentiality and data protection obligations.
6.1 AI Services and Data Processing
QraOne offers optional AI-enabled features. When users choose to use these AI Services, data or content submitted through such features may be shared with and processed by third-party AI service providers, including large language model (LLM) providers, solely to deliver the requested AI functionality.
QraOne does not use such data for independent AI model training unless explicitly stated and contractually agreed.
If users do not use the AI Services, their data is not shared with any third-party AI or LLM providers.
7. International Data Transfers
Data may be transferred and processed outside your country of residence, including the EU, UK, UAE, and other jurisdictions.
We rely on:
- Standard Contractual Clauses (SCCs)
- Appropriate technical and organizational safeguards
8. Data Security
We implement industry-standard technical and organizational measures, including:
- Access controls and role-based permissions
- Encryption in transit and at rest (where applicable)
- Audit logging and monitoring
- Secure hosting environments
No system is 100% secure; however, we continuously improve our security posture.
9. Data Retention
We retain personal data only as long as necessary to:
- Provide the Services
- Meet contractual and legal obligations
- Resolve disputes and enforce agreements
Customer Content retention is governed by customer contracts and instructions.
10. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your personal data
- Rectify inaccurate data
- Request deletion
- Restrict or object to processing
- Data portability
Requests may be submitted to:
info@compliancemedqra.net
support@qraone.com
11. Children’s Privacy
QraOne is intended for business users only and is not directed to children under 16.
12. Changes to This Policy
We may update this Privacy Policy periodically. Updates will be posted with a revised effective date.