QaiS
Privacy Policy Terms & Conditions Delete Account Accessibility

Privacy Policy

Effective September 22, 2026

1. Who we are and when this policy applies

HQE Systems Inc. ("HQE," "we," or "us") operates QaiS, QRM Workspaces, qais.app, and related web and mobile applications (the "Service"). This policy explains how HQE handles personal information in the Service and on our public sites.

For workspace content and personnel records submitted by an organization ("Customer Data"), the organization generally decides why and how the information is used, and HQE acts as its service provider or processor. For account registration, billing, security, support, sales, and our public sites, HQE may act as the business or controller. Users should also consult their organization's privacy notices.

2. Information we collect

  • Account and contact information: name, business email, username, phone number, profile image, job details, workspace, authentication identifiers, and support or sales communications.
  • Customer Data: messages, files, tasks, projects, leads, customer and vendor records, tickets, invoices, workforce records, calendar items, forms, and other content a user or integration submits.
  • Usage, device, and security information: IP address, browser and device type, operating system, timestamps, pages and features used, session and authentication events, diagnostics, audit events, approximate location derived from IP, and precise or attendance location when an enabled feature requests it.
  • Transaction information: plan, purchased seats, subscription and invoice status, and Stripe customer references. Payment processors receive payment-card details directly; HQE does not store full card numbers.
  • Connected-service information: data and tokens needed for integrations Customer enables, such as email, calendar, communications, cloud storage, or financial-account connections.
  • Domain registration information: when a workspace claims a domain name, the registrant, administrative, technical, and billing contact details supplied (name, organization, postal address, email address, and phone number), the domain name, registration, expiry, and renewal dates, DNS settings, lock and transfer status, and related order and subscription references.
  • AI inputs and outputs: prompts, selected workspace context, generated results, feedback, and operational metadata when a user invokes an AI feature.
  • Cookies and local storage: session, security, workspace routing, preferences, and similar information needed to operate the Service. We do not use third-party behavioral advertising cookies.

We receive information from users, Customer administrators, devices and browsers, enabled integrations, payment and infrastructure providers, and service logs. Customers choose much of the information placed in their workspace.

3. How we use information

  • Provide, personalize, maintain, and support the Service.
  • Create accounts, authenticate users, route workspaces, enforce permissions, and process subscriptions.
  • Deliver requested communications, integrations, AI results, and automation.
  • Protect users and the Service; prevent abuse, fraud, and security incidents; debug and monitor reliability.
  • Analyze and improve performance, usability, and features using Customer instructions and aggregated or de-identified information.
  • Respond to sales, support, privacy, and legal requests and enforce our agreements.
  • Comply with law and establish, exercise, or defend legal claims.

HQE does not use or license Customer Data to train general-purpose AI models unless Customer gives an explicit written or in-product opt-in. AI providers may process only the content needed to return the feature a user requests, subject to applicable provider and Customer settings. Information obtained through Google Workspace APIs is excluded from any such opt-in: HQE does not use it to develop, improve, or train generalized or non-personalized AI or machine-learning models, and does not transfer it to a third-party AI or machine-learning tool for that purpose (see Section 5a).

4. When we disclose information

We disclose personal information only as reasonably needed for the purposes above:

  • Customer and authorized users: workspace administrators and users according to Customer's configuration and permissions.
  • Service providers and subprocessors: hosting, databases, storage, security, communications, support, analytics, AI processing, and software operations.
  • Payments: Stripe and related financial institutions for subscriptions, invoices, fraud prevention, and payment support.
  • Customer-enabled integrations: a connected provider when a user or administrator enables and uses that integration. For example, Plaid may connect selected financial accounts; Slack or email/calendar providers may exchange selected workspace content.
  • Domain registrar, registries, and ICANN: when a workspace claims a domain name, Name.com, Inc. (the sponsoring registrar), the registry operator for the domain's extension, ICANN and its designated data-escrow agents, and dispute-resolution providers receive the registrant contact and registration data required to register, verify, renew, transfer, lock, secure, and maintain the domain and to comply with ICANN policies. Public WHOIS/RDDS records use privacy protection by default, so the registrant's contact details are not published; the underlying data may still be disclosed where law, a court order, a UDRP or URS proceeding, or a registry or ICANN policy requires it. name.com processes this data under its own privacy policy.
  • Professional and legal recipients: auditors, insurers, advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, or investigate abuse.
  • Business transfers: a buyer, investor, lender, or successor in a financing, merger, reorganization, or sale, subject to appropriate confidentiality and continued protection.

HQE does not sell or share personal information for cross-context behavioral advertising, does not rent personal information, and does not disclose it to third parties for their independent direct marketing. If this practice changes, we will update this policy and provide legally required choices before the change applies.

5. Financial-account connections

If Customer enables a financial connection through Plaid, bank credentials are entered directly with Plaid and are not provided to HQE. HQE may receive the selected account's name, type, masked number, balance, and transaction details to provide imports, categorization, and reconciliation. Disconnecting stops new retrieval; already imported business records remain under Customer's control and applicable retention. Plaid handles information under its End User Privacy Policy.

5a. Google account connections

"Sign in with Google" requests only the user's Google identity (name, email address, and profile picture) to create or match the user's account. Nothing else is requested at sign-in.

Separately, a user or a workspace administrator may connect Gmail, Google Drive, Google Calendar, Google Contacts, or Google Meet from Settings → Integrations. Each connection asks for the Google permissions listed on Google's consent screen, and HQE receives only the data those permissions cover and uses it solely to provide the connected feature inside the Service:

  • Gmail: shows the user's mail inside the Service so a thread can be linked to the customer or project it belongs to; lets the user reply, compose, archive, label, mark read or unread, move to trash, and save drafts from the Service; and sends mail from the user's own address. The Service never permanently deletes a message. Mail is fetched from Google when the user opens it; short-lived caches used to render a thread are held only as long as needed to display it.
  • Google Calendar: lists the user's calendars and shows their events beside the Service's own events; creates, updates, and cancels Google events for the meetings a user schedules in the Service and syncs changes made in Google back to the matching Service event.
  • Google Drive: shows a title, type, and icon preview for a Drive link a user pastes; lets the user attach files from Drive, save documents generated in the Service to a Drive folder the user chooses, organize and share those files, and import a Google Meet recording or transcript the user selects.
  • Google Contacts: looks up the user's contacts when the user picks a recipient or attendee, and saves a contact back to Google Contacts when the user asks.
  • Google Meet: creates a Meet space for a meeting the user schedules and, after the meeting, shows the user the conference record, recording, and transcript of a Meet the user created.

Storage. HQE stores the OAuth tokens for each connection, encrypted at rest, in the user's workspace so the connection keeps working, together with the records a user deliberately creates from Google data (a file attached to a project, a calendar event synced into the Service, a contact saved into the workspace, a Meet transcript imported to a record). Those records are Customer Data and stay under Customer's control. HQE does not build a standing copy of a user's mailbox, Drive, or contacts.

Sharing. Google data is shown only to the user who connected the account and to the workspace members that user shares a record with, and is processed by the hosting and infrastructure providers that run the Service. HQE's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data is never used for advertising, never sold, and never read by humans at HQE except with the user's consent, for security or legal reasons, or in aggregated, anonymized form.

AI and machine learning. HQE does not use information obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized AI or machine-learning models, and does not transfer it to any third-party AI or machine-learning tool for that purpose. When a user asks an AI feature to act on Google data (for example, to summarize a thread the user opened), only the content needed for that request is processed to return the result, and it is not retained for model training.

Disconnecting and deletion. Disconnecting from Settings revokes and deletes HQE's access and refresh tokens for that Google account, and no new Google data is retrieved. A user can also revoke the Service from their Google Account permissions page. Already imported business records remain under Customer's control and applicable retention, and are removed under the account deletion process. Workspace administrators who connect a domain-wide service account control that access from their own Google Admin console.

6. Retention and deletion

We retain information while needed to provide the Service, fulfill Customer instructions, secure accounts, meet contractual and legal obligations, resolve disputes, and enforce agreements. Retention varies by information type, workspace settings, subscription status, and legal requirements. Security and audit records may be retained after account closure. Domain registration data is kept for the life of the domain and afterwards as needed for billing, disputes, and registrar obligations (ICANN requires the sponsoring registrar to retain registration data for two years after a registration ends). Backups are protected and removed on their normal rotation.

A user may initiate account deletion in the mobile app or use our web deletion instructions. Removing an individual account ends that user's access, but an organization may retain shared business records it controls, subject to law and its own instructions. Workspace owners should export needed data and cancel billing separately before closing a workspace.

7. Security

We use safeguards designed for the nature and sensitivity of the information, including encrypted network transport, authentication and session controls, tenant and role authorization, logging, restricted administrative access, and backup and recovery practices. No method of storage or transmission is completely secure, so we cannot guarantee absolute security. Please report suspected incidents to security@qais.app.

8. Privacy choices and rights

Depending on where you live and subject to exceptions, you may have rights to know or access personal information; obtain a portable copy; delete it; correct inaccurate information; limit certain uses of sensitive personal information; opt out of sale, sharing, or targeted advertising; and receive equal service without unlawful discrimination. We do not currently sell or share personal information as those terms are defined by California law.

Submit a request through your organization administrator, the deletion page, or privacy@qais.app. State the account email, workspace, request, and state or country. We may verify identity and authority, including an authorized agent's authority. If HQE processes the information only for an organization, we may direct the request to that organization. We will respond within the period required by applicable law and explain any denial or available appeal.

Because we do not sell or share personal information for behavioral advertising, we do not offer a separate sale/sharing opt-out link. We treat a recognized Global Privacy Control signal consistently with this stated practice.

9. International use and children

The Service is operated from the United States. Information may be processed in the United States and other locations where our providers operate, subject to contractual and legal safeguards where required. Enterprise customers needing specific data-location or transfer terms must address them in an order form or data-processing addendum.

The Service is for organizations and is not directed to children under 16. We do not knowingly collect personal information directly from children under 16. Contact us if you believe a child supplied information without appropriate authorization.

10. Changes

We may update this policy as the Service or law changes. We will post the new effective date and provide reasonable notice of material changes. We will not materially expand use of previously collected Customer Data without a lawful basis and appropriate notice or choice.

11. Contact

HQE Systems Inc.

27348 Via Industria, Temecula, CA 92590, United States

privacy@qais.app

© 2026 HQE Systems Inc. All rights reserved.

Privacy Policy Terms & Conditions Delete Account Accessibility