Privacy & Data Policy
QUAISS Data Security & Compliance
At QUAISS, we understand that data security is paramount in the construction industry. When bridging the gap from AI to construction, we ensure that your commercial and operational data is handled with the highest level of security, confidentiality, and regulatory compliance.
1. Data Privacy and AI Training
Your data will never be used to train foundational AI models. QUAISS utilises enterprise-grade commercial APIs that operate under strict terms explicitly prohibiting the use of customer data for model training. Your inputs and the generated outputs remain entirely private and exclusive to your organisation.
2. Data Retention and Storage
We adhere to strict data minimisation policies. Data processed through our workflows is retained only for as long as necessary to complete the specific task, typically measured in days, not months. For clients with the most stringent requirements, we can implement Zero Data Retention (ZDR) protocols, where data is processed in real-time and immediately discarded without being logged. All data storage utilises secure, enterprise-grade cloud infrastructure with appropriate safeguards for international transfers.
3. Confidentiality and NDAs
QUAISS and our infrastructure providers act as secure, contracted sub-processors. When your documents are processed, it occurs within a secure, isolated cloud environment (a Zero Trust sandbox). All data is encrypted both in transit and at rest. Because the data is encrypted, isolated, and legally protected from unauthorised use, utilising our services is legally equivalent to using secure enterprise cloud storage.
4. Regulatory Compliance and Certifications
The infrastructure powering QUAISS meets the highest enterprise security standards. Our technology partners maintain comprehensive compliance certifications, including SOC 2 Type I and Type II, ISO 27001 (Information Security Management), and ISO 27701 (Privacy Information Management). These certifications demonstrate that independent auditors have verified the strict security controls protecting your data.
5. UK GDPR and Personal Data
QUAISS is fully committed to UK GDPR compliance, acting as a Data Processor on your behalf. We process data strictly according to your documented instructions. Our short retention cycles, isolated processing environments, and strict Data Processing Agreements (DPAs) with our sub-processors ensure that the chain of UK GDPR compliance remains unbroken and that data subject rights can be easily upheld.
QUAISS — Registered in England & Wales. For data enquiries contact: [email protected]