QynQue Privacy Policy
Effective date: 30 September 2026 Last updated: 30 September 2026
DRAFT — NOT LEGAL ADVICE. Placeholders marked TO CONFIRM must be filled and the whole document reviewed by counsel, including a PDPA (Malaysia) notification/assessment check and disclosure review for every market you serve.
This Privacy Policy explains how the QynQue Platform (platform.qynque.com) and the QynQueOS services operated through it (the "Service") collect, use, share, and protect information about you, and the choices you have. The entity named in Section 10 is the data controller.
1. What we collect
1.1 Account data. When you register: your name (optional), email address, and password (stored only as a cryptographic hash). Email verification is required for full access.
1.2 Billing data. When you purchase: subscription tier, token packs, order history, usage totals, and the last digits of your payment method as returned by our payment processor. We do not see or store full card numbers, CVVs, or bank credentials — those go directly to Stripe.
1.3 Usage data. Model/token consumption per request (counts, model name, latency, success or failure), API key metadata (name, prefixes, creation and last-use times — keys themselves are stored hashed), and workspace or agent identifiers you create.
1.4 Content data. Prompts, documents, and agent instructions you submit, and the outputs generated for you. We read this data only to deliver the Service, troubleshoot when you report a problem, and as required by law.
1.5 Technical data. IP address, browser or app version, and request metadata, used for security, rate limiting, and basic operations.
2. Why we use it (purposes and bases)
- to provide, maintain, and secure the Service (contract);
- to bill you and issue invoices and receipts (contract, and legal obligation for tax records);
- to communicate account, billing, security, and material-change notices (contract / legitimate interests — these are not marketing);
- to detect and prevent abuse, fraud, and terms violations (legitimate interests);
- to comply with law, subpoenas, and regulatory requests (legal obligation);
- for product improvement and analytics, in aggregated or de-identified form where practicable (legitimate interests / consent where required).
We do not sell your personal data, and we do not train general AI models on Your Content without your opt-in consent.
3. Who processes data for us
| Recipient | Purpose | Location |
|---|---|---|
| Stripe Payments | payment processing, invoicing, refunds, Customer Portal | Stripe's global infrastructure (stripe.com/legal) |
| SendGrid / AWS SES | transactional email (verification, receipts) | provider regions [TO CONFIRM which is enabled] |
| AI inference providers you enable under your plan | processing prompts/context to generate outputs | per provider terms |
| Hosting providers | running the Service (servers, database, cache) | [TO CONFIRM datacenter country] |
These processors act on our instructions and are contractually required to protect the data. On-device and local model usage (e.g. the built-in engine in QynQueOS desktop) processes content on your own hardware.
4. Sharing
We share personal data only: with the processors in Section 3; with your consent; in a corporate transaction (merger, acquisition) with notice; to comply with legal process or imminent harm; and to enforce our Terms. Agents and QuePilots act on your instructions and may send data to destinations you configure — that is your processing via the Service, not ours.
5. Retention
- Account and billing records: for the life of your account, then up to seven (7) years where tax and company law requires (Malaysia: seven years for company records — TO CONFIRM with counsel).
- Usage logs: up to twenty-four (24) months, then aggregated.
- Content data (prompts, outputs): retained as needed to provide your agents' memory and history features; you can delete it in-app; deletion removes it from active systems within thirty (30) days, with backups aging out thereafter.
6. Security
Access is role-restricted and logged; credentials are hashed; tokens and keys are stored hashed; traffic is encrypted with TLS; database and cache run on private networks; payments are handled by PCI-DSS-compliant infrastructure via Stripe. No system is perfectly secure — report concerns to the contact below.
7. Your rights
Depending on your country (Malaysia's PDPA gives rights of access and correction; GDPR/UK/EU-style rights are honored as described where applicable), you may request: access to your personal data; correction; deletion; a portable export; withdrawal of consent; and objection to or restriction of processing. Use in-app controls where offered (profile, billing history, usage) or email [privacy@qynque.com — TO CONFIRM]. We respond within thirty (30) days and verify your identity first. You can complain to your local data protection authority (in Malaysia: the Personal Data Protection Commissioner, pdp.gov.my).
8. Children
The Service is not directed at children under 18 (the age of majority in Malaysia; older where your law requires). We do not knowingly collect their data; if we learn we have, we delete it.
9. International transfers
Our providers may process data outside your country. Where the law requires safeguards for transfers, we rely on the recipients' standard contractual or certification mechanisms (e.g. Stripe's and AWS's transfer frameworks) [TO CONFIRM per hosting setup].
10. Changes and contact
Material changes to this Policy are announced in-app or by email at least fourteen (14) days ahead. Operator: [registered legal entity name and address — TO CONFIRM]. Privacy contact: [privacy@qynque.com — TO CONFIRM]. Cookie practices are described separately in the Cookie Policy (which for this Service is short: we set no tracking cookies).