Enterprise DDR5 memory & ultra-fast NVMe storage for high-performance hosting.

See plans

Privacy Policy

How QeinTech collects, processes, stores, and protects the personal data you entrust to our infrastructure. Built to be transparent, auditable, and respectful of your rights.

// 01

Scope & Applicability

This Privacy Policy (“Policy”) applies to Qein Technologies Inc. and all subsidiaries, and describes the personal data we collect when you visit qeintech.com, sign in to our dashboard, deploy services, contact our support team, or otherwise interact with us (“Services”). It also describes the rights you have over that data and how you can exercise them.

For customers who use QeinTech solely as infrastructure to host their own end users, QeinTech acts as a data processor and the customer is the data controller. In that role, we process personal data only on the documented instructions of the customer and in accordance with our Data Processing Addendum (DPA).

// 02

Information We Collect

We collect the minimum information necessary to deliver and improve our services. The categories below describe every class of personal data we process:

  • Account data: name, email address, username, password (hashed), avatar URL, language preference, and timezone.
  • Billing data: cardholder name, billing address, VAT/GST number, and tax residency. Card numbers are tokenized by our payment processor and never touch our servers.
  • Technical data: IP address, browser fingerprint, operating system, screen resolution, referring URL, and user agent.
  • Usage data: pages viewed, dashboard actions, API calls, error stacks, and feature engagement metrics.
  • Support data: ticket contents, chat transcripts, call recordings (where legally permitted), and attachments you choose to share.
  • Customer Content: any files, databases, container images, environment variables, or workloads you deploy on our infrastructure.
// 03

Billing Data Processing

Payments are processed exclusively by PCI-DSS Level 1 certified providers — currently Stripe and PayPal — under separate data processing agreements. QeinTech does not store full payment card numbers, CVV codes, or expiration dates on our systems.

  • We receive a tokenized card reference (e.g. pm_xxx), brand, last four digits, and funding type.
  • Billing addresses and tax identifiers are stored encrypted at rest using AES-256-GCM.
  • Invoices are retained for the legally mandated period (typically 7–10 years depending on jurisdiction).
  • Subscription lifecycle events (renewals, cancellations, refunds) are logged for accounting and dispute resolution.
  • We never sell, rent, or trade billing information with third parties for marketing purposes.
// 04

Logs & Technical Files

Operating a global hosting platform requires capturing technical telemetry. We retain the following log classes for the periods indicated:

  • Network logs: source/destination IPs, ports, protocols, byte counts, and packet flags — retained for 30 days.
  • Authentication logs: sign-in attempts, MFA challenges, session IDs, and geographic origin — retained for 90 days.
  • Application logs: dashboard actions, API requests, error stacks — retained for 60 days in hot storage, then archived for 12 months.
  • Audit logs: administrative actions (role changes, billing events, permission grants) — retained for 24 months.
  • Abuse signals: spam, malware, and DDoS indicators shared with upstream providers and threat-intelligence feeds.
// 05

Cookies & Tracking

We use a minimal cookie footprint. We do not deploy advertising cookies or cross-site tracking tags.

  • Strictly necessary: session authentication, CSRF protection, load-balancer affinity. Cannot be disabled.
  • Functional: language, theme, and dashboard layout preferences. Optional.
  • Analytics: self-hosted Plausible Analytics on a cookieless basis — no personal identifiers, no cross-site profiling.
  • Performance: synthetic monitoring of dashboard latency and error rates. Optional.

You can clear cookies and adjust preferences from the cookie banner or your browser settings at any time without affecting your ability to use core services.

// 06

Security Measures

We treat security as a continuous, multi-layered practice — not a checkbox. The controls below are applied across all production systems:

  • TLS 1.3 for all data in transit; AES-256-GCM for data at rest; per-tenant encryption keys where technically feasible.
  • Hardware-bound MFA (FIDO2/WebAuthn) for all staff with production access; mandatory session logging.
  • Just-in-time privilege elevation with peer review for sensitive operations (e.g., database exports, key rotations).
  • 24/7 SOC monitoring backed by automated anomaly detection, intrusion detection, and adaptive DDoS mitigation.
  • Independent penetration tests at least annually; results summarized in our SOC 2 Type II report.
  • Encrypted, immutable backups stored across geographically separated regions with quarterly restore drills.
// 07

Third-Party Processors

We engage a small number of carefully vetted sub-processors. The current list is published at qeintech.com/legal/subprocessors and updated at least 30 days before any change takes effect.

  • Stripe Inc. — payment processing, fraud signals.
  • Cloudflare Inc. — DNS, DDoS mitigation, edge caching.
  • Amazon Web Services — underlying compute, storage, and networking for some regions.
  • Resend Inc. — transactional email delivery.
  • Linear & Zendesk — support ticketing and incident response workflows.

Each sub-processor is bound by a written data processing agreement that mirrors the obligations we accept under this Policy.

// 08

GDPR & CCPA Compliance

For data subjects in the European Economic Area (EEA), the United Kingdom, and Switzerland, QeinTech processes personal data on the lawful bases of (i) performance of a contract, (ii) compliance with legal obligations, (iii) legitimate interests that are not overridden by your rights, and (iv) consent, where required (e.g., for non-essential cookies).

California residents have additional rights under the California Consumer Privacy Act (CCPA / CPRA), including the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of any sale or sharing — although QeinTech does not sell personal data.

EU/UK representative: Qein Technologies B.V., Keizersgracht 391A, 1016 EJ Amsterdam, Netherlands. UK representative: Qein Technologies UK Ltd., 30 St Mary Axe, London EC3A 8BF, United Kingdom.

// 09

Your Controls & Rights

Regardless of your location, you may exercise the following rights at any time:

  • Access: request a copy of the personal data we hold about you.
  • Correction: update or amend inaccurate data via the dashboard or by emailing privacy@qeintech.com.
  • Deletion: request permanent erasure, subject to legal retention obligations.
  • Portability: receive your data in a structured, machine-readable format (JSON or CSV).
  • Restriction: ask us to suspend processing while a complaint is investigated.
  • Objection: opt out of processing based on legitimate interests, including profiling.
  • Withdraw consent: where consent is the lawful basis, without retroactive effect.
  • Lodge a complaint: with your local supervisory authority.
// 10

Retention Timelines

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, plus the minimum period required by law. The default retention windows are:

  • Account data: the life of the account plus 30 days after deletion to allow reactivation.
  • Billing & invoicing records: 7 years (US/UK), 10 years (Germany), per local tax law.
  • Network & authentication logs: 30–90 days as detailed in the Logs section.
  • Support tickets: 36 months from last interaction.
  • Customer Content: deleted within 30 days of service termination; backups purged within 90 days.
  • Marketing consents: until withdrawn or after 24 months of inactivity.
// 11

International Data Transfers

QeinTech is headquartered in the United States with regional operations in the EU and APAC. When personal data is transferred across borders, we rely on the following legal mechanisms to ensure continued protection:

  • European Commission Standard Contractual Clauses (SCCs) for transfers out of the EEA.
  • The UK International Data Transfer Addendum where applicable.
  • EU–US Data Privacy Framework participation for certified sub-processors.
  • Data residency options on enterprise tiers for customers requiring in-region processing.
  • Encryption-in-transit and at-rest with keys held in the destination region to prevent unauthorized access.
// 12

Children's Privacy

Our services are not directed to children under the age of 13 (or older where defined by local law, including 16 in the EEA and UK under GDPR). We do not knowingly collect personal data from children.

If we become aware that we have inadvertently collected personal data from a child without verified parental consent, we will delete the data within 30 days. Parents or guardians who believe their child has provided us with personal data may contact privacy@qeintech.com to request deletion.

// 13

Contact & DPO

Our Data Protection Officer oversees compliance with this Policy and applicable privacy law. You can reach the DPO and our privacy team through any of the channels below:

  • Email: privacy@qeintech.com (typical response within 5 business days).
  • Postal mail: Qein Technologies, Inc. — Attn: Data Protection Officer, Jaipur, Rajasthan, India.
  • EU representative: Qein Technologies B.V., Keizersgracht 391A, 1016 EJ Amsterdam, Netherlands.
  • In-dashboard: Settings → Privacy → Submit a Request.

We will acknowledge your request within 72 hours and complete substantive responses within 30 days, or sooner where required by local law. If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority.