Privacy Policy

Last updated

Template — not yet reviewed by counsel. This Privacy Policy is a plain-English draft prepared by the Quordo product team to describe our intended data practices. It is a starting point, not legal advice, and it must be reviewed and adapted by a qualified lawyer (and aligned with our final sub-processor list and the regulations that apply to our customers, including GDPR and CCPA/CPRA) before Quordo relies on it at go-live.

Quordo is a control plane for an organization's AI estate. Our customers are businesses, and most personal data we handle is business-account data — the names and work emails of the people who use Quordo for their employer. We collect the minimum needed to run the service, we do not sell personal data, and we act as a processor for the AI usage and agent-activity data our customers connect. Privacy questions: [email protected].

Who we are and our role

Quordo ("we", "us", "our") operates the service at https://quordo.com. We are the data controller for the account and marketing data described below. For the AI usage records, cost data, mission context, and agent-activity traces that a customer connects to Quordo, the customer organization is the controller and we act as their data processor under their instructions and our agreement. If a registered company entity is published on the site, we will update this section with the company name, number, and registered address.

Who this policy covers

This policy covers three groups: (1) workspace users — the employees or contractors of a customer organization who sign in to Quordo; (2) prospects and contacts — people who request a demo, sign up for the waitlist, or email us; and (3) website visitors. It does not attempt to govern our customers' own relationships with their end users — each customer is responsible for its own privacy notices.

What we collect and why

We collect four categories of personal data. (1) Account data: name, work email, password (stored as a one-way hash by Supabase Auth), organization, role, and team assignment. Lawful basis: performance of our contract with the customer. (2) Estate data processed on the customer's behalf: AI provider usage events (provider, model, token/cost figures, timestamps, the team a connection is attributed to), mission context, handoffs, and the agent-activity trace. This may incidentally include personal data the customer chooses to put into mission context; the customer controls what they send. Lawful basis: processing on documented instructions of the customer (controller). (3) Billing data: company billing details and a tokenised payment reference from Stripe. Lawful basis: contract and legal obligation (tax). (4) Usage telemetry: a pseudonymous identifier, browser type, approximate region from IP, pages visited, and error reports. Lawful basis: our legitimate interest in a secure, reliable service, subject to cookie consent where required.

Provider credentials

When a customer connects an AI provider, they supply API credentials. We encrypt these at rest and never return them to the browser after they are saved. They are used only to read usage and cost data for the connected estate. We do not use them for any other purpose, and we do not send a customer's provider credentials to any other customer or to third parties beyond the originating provider.

What we do not do

We do not sell personal data. We do not share personal data with advertising networks, data brokers, or for cross-context behavioural advertising. We do not use the content of a customer's mission context, traces, or usage data to train our own or anyone else's general-purpose models. We do not combine one customer's estate data with another's.

Sub-processors

We use a small, defined set of sub-processors, each bound by a data processing agreement and (for international transfers) the relevant Standard Contractual Clauses. The current list is: Supabase (database, authentication, and storage, with row-level isolation per organization); Stripe (subscription billing — we never store full card numbers); and the AI providers a customer connects (OpenAI, Anthropic, Azure OpenAI, Amazon Bedrock, Google Vertex), which receive only the requests needed to read usage and cost data using the customer's own credentials. Where we use product-analytics or error-monitoring tools, they load only with consent. The complete, current list — with the purpose, data handled, and region for each — is published on our Sub-processors page; we give notice of material changes as our agreements require.

International transfers

We prefer hosting in a region close to our customers and choose EU-hosted tenants of our processors where available. Some processors may transfer data to the United States or other countries. Where that happens we rely on Standard Contractual Clauses (and the UK Addendum where applicable) and on each processor's safeguards. A list of current transfer mechanisms is available on request.

How long we keep data

We keep account data for as long as the customer's workspace is active and for a limited wind-down period after termination so the customer can export or reactivate, after which it is deleted or anonymised in line with the customer agreement. Estate data (usage, cost, missions, traces) is retained per the customer's configuration and our agreement; the audit log and append-only trace are retained as a security and accountability record. Billing records are retained as required by tax law. Customers can request earlier deletion subject to our legal retention duties.

Security

We encrypt data in transit (TLS) and at rest, encrypt provider credentials and never return them to the UI, isolate each organization's data with row-level security, and keep an append-only audit log of mutations. Quordo is not SOC 2 certified today — SOC 2 is on our roadmap and we are building toward it; we will not claim a certification we do not hold. See the Security page for the current posture and how to report a vulnerability.

Cookies and local storage

We use strictly necessary cookies to keep you signed in and protect the service, and (only with consent where required) optional analytics and error-monitoring cookies. You can review and change your choice from the Cookie Policy page.

Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to processing based on legitimate interests. Workspace users should usually exercise these rights through their organization (the controller); we will assist our customers in responding. For account or marketing data we control directly, email [email protected] from your account address and we will respond within the time the applicable law requires. California residents have rights under the CCPA/CPRA, including the right to know and to delete, and the right not to be discriminated against for exercising them; we do not sell or share personal data as those terms are defined.

How to complain

If you're unhappy with how we've handled personal data, contact [email protected] and we'll try to put it right. You also have the right to complain to your local data protection authority — for example, the UK Information Commissioner's Office (https://ico.org.uk/make-a-complaint/) or the relevant EU supervisory authority.

Changes to this policy

We'll update this policy when our processors change, when the law changes, or when we add features that affect privacy. We'll notify the customer account of significant changes and update the "last updated" date at the top. Prior versions are available on request.