Qualia Enterprise ("Qualia," "we," "us," or "our") provides Recipient Intelligence infrastructure for AI — including the Qualia application, the Recipient Intelligence API, and the Microsoft Outlook Add-In. Our customers include enterprise sales teams, customer success organizations, AI builders, and institutions across multiple industries.
We are committed to responsible data handling across all the industries and jurisdictions we serve. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our website and related services (the "Services"), and how we address applicable regulatory frameworks including SOC 2, GDPR, CCPA, HIPAA, and FERPA.
1. Scope of This Policy
This Privacy Policy applies when:
- You use Qualia as an individual or as part of a team or organization
- You register for or use the Recipient Intelligence API as a developer
- You install and use the Microsoft Outlook Add-In
- You access Qualia through an institutional or enterprise account
- You visit our website
Where Qualia is deployed under a Data Processing Agreement (DPA) or Business Associate Agreement (BAA), the terms of that agreement govern in addition to this policy.
2. Information We Collect
A. Account & Registration Information
When you create an account or register for API access, we may collect:
- Name
- Email address
- Organization name or affiliation
- Login credentials
- Billing information (processed by our payment provider)
For developer accounts, API keys are generated and stored in hashed form; the plaintext key is shown only at creation.
B. Recipient Intelligence API Data
When you make requests to the API, we process:
- Request content — context you submit (recipient identifiers, message drafts, or relationship signals)
- Response content — the recipient intelligence output returned to your application
- Usage logs — API key identifier, endpoint called, timestamp, credit consumption, and response status
- Account metadata — credit balance, rate limit counters, and plan information
Request and response content is processed solely to provide the requested output. We do not use it to train public AI models or for advertising.
C. Microsoft Outlook Add-In Data
The Add-In requests the Mail.Read permission to read mailbox context for the active email and generate communication suggestions. This data is transmitted over an encrypted connection, processed only for the requested suggestion, and not stored beyond the time required to return a response (unless explicitly saved within the Add-In). The Add-In does not read emails unless you activate it on a specific message and does not access your full mailbox, contacts, or calendar.
D. Technical & Usage Information
We may collect IP address, device and browser type, usage logs, feature interaction data, security and diagnostic logs, and API request metadata.
E. Information About Non-Users
Email content and API requests may include information about individuals who do not use Qualia directly (such as email recipients). We process such information only to provide the requested service and do not use it for marketing or secondary purposes.
3. How We Use Information
We use personal information to:
- Provide and operate the Services
- Generate AI-assisted drafts and recipient intelligence outputs
- Manage developer accounts, API keys, and usage quotas
- Improve system reliability, performance, and safety
- Maintain security and prevent abuse
- Communicate with users about their accounts and the Services
- Comply with legal obligations
We do not sell personal information. We do not use personal information for advertising.
4. AI Processing & Model Use
Qualia uses third-party AI language models accessed via secure API. Submitted content is transmitted securely, processed solely to generate the requested output, and is not used for advertising or to train public AI models. AI-generated outputs are suggestions — Qualia does not send communications automatically on your behalf.
5. How We Share Information
We share information only as necessary to operate the Services.
A. Service Providers (Subprocessors)
We may share data with trusted providers including cloud infrastructure providers, AI model API providers, authentication and identity providers, payment processors, and communication and support tools. These providers are contractually required to maintain confidentiality and appropriate security safeguards.
B. Legal Requirements
We may disclose information if required by law, regulation, or valid legal process.
C. Business Transfers
If Qualia undergoes a merger or acquisition, personal data may be transferred as part of that transaction, subject to applicable law.
6. Data Retention
- Account information — retained while your account is active and for a reasonable period after closure to fulfill legal obligations
- API request/response content — not retained beyond the time needed to return the response, unless retained for audit or abuse-prevention purposes (maximum 90 days)
- API usage logs — retained for up to 12 months to support billing, debugging, and account management
- Outlook Add-In message content — not stored beyond the time required to return a suggestion, unless explicitly saved
- Enterprise/institutional data — deleted within 30 days of contract termination unless legally required to retain it
You may request deletion of your data at any time (see Section 11).
7. Data Security
We implement administrative, technical, and organizational safeguards including:
- Encryption in transit (TLS 1.2 or higher)
- Encryption at rest
- Role-based access controls
- Multi-factor authentication for administrative access
- Logging of administrative actions
- Incident response procedures
- API key hashing — plaintext keys are never stored
8. SOC 2
Qualia is actively pursuing SOC 2 Type II certification. Our security program is designed around the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. We maintain policies and controls aligned with these criteria, including access management, change management, vendor risk management, and continuous monitoring. Enterprise customers may request information about our SOC 2 readiness program under a confidentiality agreement.
9. GDPR — European Users
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or applicable local law applies to our processing of your personal data.
Legal basis for processing. We process personal data under the following legal bases: (a) performance of a contract, when processing is necessary to provide the Services you have requested; (b) legitimate interests, for security, fraud prevention, and service improvement; and (c) compliance with legal obligations.
Data subject rights. EEA and UK residents have the right to access, rectify, erase, restrict, or port their personal data, and to object to certain processing. To exercise these rights, contact us at adya@qualiaai.co.
Data transfers. Where we transfer personal data outside the EEA, we implement appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.
Data Processing Agreements. Enterprise customers requiring a DPA under GDPR Article 28 may request one by contacting us.
10. CCPA — California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may apply to our collection and use of your personal information.
Categories of personal information collected. We collect identifiers (name, email, IP address), commercial information (billing records), internet or network activity (usage logs), and professional or employment-related information (organization affiliation). We do not sell or share personal information as defined under the CCPA.
Your rights. California residents may request to know what personal information we collect, request deletion, request correction of inaccurate information, and opt out of sale or sharing (though we do not engage in either). We will not discriminate against you for exercising your rights.
To submit a CCPA request, contact us at adya@qualiaai.co.
11. HIPAA — Healthcare Customers
Where Qualia provides services to a Covered Entity or Business Associate under the Health Insurance Portability and Accountability Act (HIPAA), we act as a Business Associate and will execute a Business Associate Agreement (BAA) with the customer prior to processing any Protected Health Information (PHI).
Under a BAA, Qualia will:
- Use and disclose PHI only as permitted by the BAA and required by law
- Implement appropriate safeguards to protect the confidentiality, integrity, and availability of electronic PHI (ePHI)
- Report to the Covered Entity any use or disclosure of PHI not provided for by the BAA, including breaches as required under HITECH
- Ensure that subcontractors who access PHI agree to the same restrictions
- Return or destroy PHI upon termination of the BAA where feasible
Healthcare customers should contact adya@qualiaai.co to request a BAA before transmitting any PHI to Qualia systems.
12. FERPA — Educational Institutions
When providing services to educational institutions under a Data Processing Agreement (DPA), Qualia acts as a "School Official" under the Family Educational Rights and Privacy Act (FERPA). In those circumstances, we:
- Process student education records only for legitimate educational interests as defined by the institution
- Do not re-disclose student information without authorization
- Implement administrative, technical, and physical safeguards appropriate to the sensitivity of the data
- Delete student data upon request or contract termination
Schools retain control of student education records. FERPA obligations apply only where Qualia services are provided to an institution under a DPA. Developers and individual users outside institutional accounts are not subject to FERPA protections.
13. Your Rights & Choices
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or port your personal information, and to object to certain processing. If you use Qualia through an institutional account, your institution may also exercise rights on your behalf.
To make a privacy request, contact us at adya@qualiaai.co or via our Contact Us page.
14. Children's Privacy
Qualia's platform and API are designed for use by adults, businesses, institutions, and developers. We do not knowingly collect personal information directly from children under 13. Where Qualia is used by an educational institution under a DPA, student data is processed only under that institution's authorization and for legitimate educational purposes, consistent with Section 12 (FERPA) above.
15. International Data Transfers
Qualia may process data in the United States. Where required by applicable law (including GDPR), we implement appropriate safeguards for cross-border data transfers, such as Standard Contractual Clauses or other mechanisms recognized under applicable data protection law.
16. Changes to This Policy
We may update this Privacy Policy periodically. If material changes are made, we will provide notice through the Services or by email. Continued use of the Services after the effective date of an updated policy constitutes acceptance of the changes.