Legal

Privacy Policy

This policy explains what information Quirna collects when you use the API, the Console, the mobile app, the Slack app and this website, why we collect it, who helps us process it, and how long we keep it. Words like “Service”, “Organization” and “Approval Request” mean what they mean in our Terms of Service.

1. Two roles

2. What we collect

Account and sign-in

Approvals and the audit record

Mobile app

Slack

Systems and API keys

Website and waitlist

Technical data

3. How we use it

We do not sell personal data, use it for advertising, or use your Organization’s content to train machine learning models.

4. Who processes it for us

We share data only with the providers needed to run the Service:

Webhook callbacks go to the URLs your Organization configures; what happens to the data there is up to that Organization. We may also disclose data when the law requires it, or to protect the Service and its users.

5. International transfers

The Service is hosted in the United States and some providers operate in other countries. By using the Service, your data will be processed outside the country where you live.

6. How long we keep it

7. Your choices and rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, or to object to or restrict how we use it. Write to [email protected] and we will respond within 30 days.

For data inside an Organization, we will usually involve its admins, since they control it. Deletion requests are limited by section 6: we can remove your account, but not rewrite decisions already in an Organization’s record. You can also complain to your local data protection authority.

8. Security

Traffic is encrypted in transit. Codes, session tokens and API keys are stored as hashes. Decisions are signed so changes can be detected. Access to production is limited to the people who operate the Service. No system is perfectly secure; if a breach affects your data, we will tell you as the law requires.

9. Children

The Service is for work use and is not directed at anyone under 18.

10. Changes

We will update the date at the top when this policy changes, and tell admins by email or in the Console before material changes take effect.

11. Contact

Privacy questions and requests: [email protected].