About QuantaForze
At QuantaForze Technologies Inc. ("QuantaForze", "we", "us", or "our"), we respect customers' need for privacy and data security. We offer our Sites, CLI engines (@quantaforze/cli), developer SDKs (@quantaforze/core), Autonomous Agent runtimes, Intelligence Layer APIs, and AxioVital Healthcare Operating Environments to developers, enterprise teams, and healthcare organizations either directly or via authorized partners.
Where we refer to our "Customers" in this Privacy Notice, we refer to individuals or entities that have entered into an agreement with us to use our Services (each, an "Agreement"). Each Customer's respective website users, developers, or patient care stakeholders are referred to as their "End Users."
Applicability of this Privacy Notice
This Privacy Notice covers our treatment of personal information that we gather when you access or use our Sites and Services. It does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage.
When providing Services on behalf of an enterprise Customer, QuantaForze acts primarily as a Data Processor or Service Provider, processing Customer Data strictly in accordance with Customer instructions and our executed Data Processing Addendums (DPAs).
Information We Collect
We collect information about you directly from you, from third parties, and automatically through your use of our Sites and Services.
That You Provide Directly
We collect information you provide directly to us when creating an account, subscribing to paid plans, or contacting support:
- Account Credentials: Full name, professional email address, organization name, password hash, and OAuth authentication tokens;
- Billing Details: Billing address, payment card details (processed securely via our PCI-DSS compliant payment processors), and tax IDs;
- Communications & Feedback: Support ticket logs, inquiry messages, feedback responses, and bug report submissions.
From Third Parties
If you choose to log in to our Services using a third-party single sign-on (SSO) service (such as GitHub, Google Workspace, or Enterprise SAML), we receive personal data from that provider, such as your public profile name, avatar URL, and verified email address.
From Customers
Enterprise Customers may invite team members to their QuantaForze workspace. In doing so, the Customer provides us with the invited member's email address and assigned role permissions.
Automatically Collected
When you interact with our Sites or run CLI developer engines, we automatically collect technical telemetry and usage metrics:
- System & Device Metrics: Operating system version (macOS, Windows, Linux kernel), CPU architecture, CLI version, and memory availability;
- Network Data: IP address, browser type, referring URLs, time zone settings, and request timestamps;
- Diagnostic Telemetry: Aggregated command execution duration, error stack traces (scrubbed of code variables), and API response latency.
How We Use Your Information
We process your personal information for the following legitimate business purposes:
- To operate, maintain, and deliver the core functionality of our Services;
- To manage Customer billing, subscriptions, and usage tier verification;
- To authenticate users and prevent unauthorized access or fraudulent activities;
- To detect, diagnose, and resolve technical bugs, stability degradation, and security vulnerabilities;
- To communicate essential service updates, security advisories, and system status notices;
- To comply with applicable legal obligations, tax filings, and regulatory requirements.
Zero-Retention & Local AI Model Execution
QuantaForze is built on a privacy-first, zero-trust engineering philosophy. For local model execution and zero-retention workloads:
- No Code Mining: We do not store, index, or use your proprietary source code, local repository files, or prompt queries to train public AI models;
- Ephemeral Memory Execution: Autonomous execution loops operate in transient, sandboxed runtime environments that are cleared immediately upon task completion;
- On-Premises & Hybrid Isolation: Enterprise clients can deploy QuantaForze execution kernels within their isolated VPCs or air-gapped infrastructure.
Sharing and Disclosure of Information
We do not sell, rent, or trade your personal information to third parties. We share your information only under the following limited circumstances:
- Third-Party Vendors & Infrastructure Providers: Hosting facilities, cloud infrastructure providers, payment processors, and transactional email services that process data under strict confidentiality contracts;
- Workspace Administrators: If your account is affiliated with a Customer workspace, your workspace owner can view your activity logs, role assignments, and usage metrics;
- Legal Requirements: If required to disclose information by subpoena, court order, or applicable government regulation, provided we promptly notify you unless legally prohibited;
- Business Transfers: In connection with an eventual merger, acquisition, or sale of company assets, where customer data is transferred as a business asset under binding privacy assurances.
Data Security and Retention
We deploy robust administrative, physical, and technical safeguards to protect your personal information against unauthorized access, loss, or destruction:
- Encryption: TLS 1.3 encryption in transit and AES-256-GCM encryption at rest for stored database records and access keys;
- Access Control: Strict role-based access control (RBAC), multi-factor authentication requirements, and audited administrative access logs;
- Data Retention: Account data is retained for the active subscription duration plus 30 days to facilitate account restoration, after which it is permanently purged from active storage.
Your Privacy Rights and Choices
Depending on your location (including the European Economic Area, UK, California, and other jurisdictions), you may possess specific rights regarding your personal information:
- Right of Access: Request a copy of the personal information we hold about you;
- Right to Rectification: Request correction of inaccurate or incomplete personal details;
- Right to Erasure (Right to be Forgotten): Request permanent deletion of your account and associated personal data;
- Data Portability: Request export of your account data in a structured, machine-readable format (JSON/CSV);
- Opt-Out of Communications: Unsubscribe from promotional updates by clicking the unsubscribe link in any marketing email.
AxioVital Healthcare Data Privacy & HIPAA
For healthcare organizations deploying AxioVital OS and hospital data pipelines:
- Protected Health Information (PHI): AxioVital complies with HIPAA and HITECH privacy standards when handling PHI;
- Business Associate Agreements (BAAs): We execute standard BAAs with covered entities prior to processing healthcare data streams;
- Clinical Isolation: Patient profiles and inter-hospital care continuity channels operate in encrypted, tenant-isolated healthcare partitions.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Notice or our data handling practices, please contact our privacy officer:
QuantaForze Technologies Inc.
Attn: Data Privacy & Security Officer
Email: security@quantaforze.com
General Support: support@quantaforze.com