Legal
Privacy & cookie policy
How Qevatrix collects, uses, shares and protects personal data — for visitors to this website, for customers, and for the people whose records our customers manage in the platform.
Who we are
Qevatrix provides quality, regulatory, clinical and evidence software for medical device manufacturers. For data you enter into a Qevatrix application, your company is the controller and Qevatrix is the processor acting on your documented instructions. For our own website, marketing and billing, Qevatrix is the controller.
What we collect
Account details (name, work email, role), workspace content you create, billing details (company name, address, VAT identifier — card data is handled by our payment processor and never reaches our servers), support correspondence, and technical logs such as IP address, browser type and timestamps used for security and troubleshooting.
Why we process it
To provide and secure the service under our contract with you (Art. 6(1)(b)), to meet our own legal and accounting obligations (Art. 6(1)(c)), and for the legitimate interests of keeping the platform secure and improving it (Art. 6(1)(f)). Marketing emails are sent only with your consent (Art. 6(1)(a)) and every message carries a one-click unsubscribe.
Health data
Clinical applications may process health data. Direct identifiers are removed at import wherever the study design allows, and subjects are handled by code. Where identifiable data is necessary, your organisation relies on an Article 9 condition — normally explicit participant consent, scientific research, or the medical devices public-health condition — and must hold the corresponding ethics approval.
How long we keep it
Workspace content is retained for the life of the subscription and then deleted 30 days after termination, with backups rolling off within a further 30 days. Regulated quality, vigilance and clinical records are retained for the period you configure in the retention register. Billing records are kept for 10 years to meet statutory accounting duties. Website enquiries are deleted 24 months after the last interaction.
Security
Data is encrypted in transit (TLS 1.2+) and at rest. Every row is scoped to a single workspace with row-level security, privileged operations run through audited server functions, and every create, change, signature and export is written to an append-only audit trail. Automated security scans run nightly and findings are triaged in a documented register.
International transfers
EU and UK workspaces are hosted in EU regions by default. Where a subprocessor operates outside the EEA, transfers rely on the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by a transfer impact assessment.
Your rights
You may request access, rectification, erasure, restriction, portability, or object to processing, and withdraw consent at any time. We answer within one month. If we cannot erase a record because medical device law requires us to keep it, we will tell you which obligation applies. You may also complain to your supervisory authority.
Contact
Privacy questions, data subject requests and DPA copies: use the contact form and mark your message “Privacy”. Requests from our customers' study participants should go to the sponsoring organisation, which is the controller for that data.