- Is Qualflare GDPR compliant?
- Qualflare is built to align with the GDPR. Qualflare OÜ is established in Tallinn, Estonia, inside the EU, and customer data is stored in the European Union — application servers and the primary database run in Google Cloud europe-central2 (Warsaw, Poland). A full Data Processing Addendum including the 2021 Standard Contractual Clauses is published at qualflare.com/dpa rather than offered on request. Note that there is no blanket certification that makes a company GDPR compliant: the certification mechanisms in Articles 42 and 43 cover specific, defined processing operations, and Qualflare holds none of them.
- Is Qualflare a data controller or a data processor?
- Both, depending on the data. For the test results, logs and attachments you upload into your workspace, you are the controller and Qualflare is the processor, acting only on your documented instructions. For your own account and billing data, Qualflare is the controller.
- Where does Qualflare store customer data?
- Inside the European Union. Application servers and the primary PostgreSQL database run in Google Cloud europe-central2 (Warsaw, Poland), with object storage and edge services on Cloudflare using EU-region routing. In the ordinary course of operating the Services, customer data is not stored outside the EEA. Where data does leave the EEA via a sub-processor, Qualflare relies on the EU-US Data Privacy Framework, Standard Contractual Clauses with a transfer impact assessment, or an adequacy decision.
- Does Qualflare offer a Data Processing Agreement (DPA)?
- Yes, and it is published in full at qualflare.com/dpa — it does not need to be requested or negotiated. It includes the European Commission 2021 Standard Contractual Clauses (Modules 2 and 3), a description of the processing, the technical and organisational measures, and the named sub-processor list.
- Does Qualflare train AI models on customer data?
- No. The Data Processing Addendum contains an explicit commitment that Qualflare does not use customer data to train, fine-tune or evaluate foundation models, and that its AI sub-processors are contractually bound not to either. Data sent through Qualflare AI features is processed by Google via the Gemini API under enterprise terms that exclude API inputs and outputs from improving Google models.
- Does Qualflare hold SOC 2 or ISO 27001 certification?
- No. Qualflare does not currently hold a SOC 2 Type II or ISO 27001 certification, and says so plainly in both its Privacy Notice and its DPA. Qualflare intends to pursue independent third-party attestation as the company grows and will make any resulting report available under confidentiality. The technical and organisational measures that are in place are documented in Annex 2 of the DPA. Physical data-centre security is provided by Google Cloud and Cloudflare, which do operate ISO 27001-certified facilities.
- How quickly does Qualflare report a personal data breach?
- Qualflare notifies affected customers without undue delay and in any event within 72 hours of becoming aware of a breach affecting their data. Where a breach is likely to result in a risk to individuals, Qualflare notifies the Estonian Data Protection Inspectorate (AKI) within 72 hours under Article 33, and notifies individuals directly where the risk is high under Article 34.
- How do I exercise my GDPR rights with Qualflare?
- Email [email protected]. Qualflare supports access, rectification, erasure, restriction, portability, objection, the right not to be subject to a solely automated decision, and withdrawal of consent. A verified data export is delivered within 30 days. You may also lodge a complaint with your supervisory authority.
Questions about any of the above, or to exercise a right: [email protected] or the contact form. This page summarises our GDPR posture for convenience; the Privacy Notice and DPA are the documents that bind us.