Privacy policy

Last updated 3 October 2026.

The clauses that name you

A reading aid only: it is not part of the agreement, and the full text below governs.

Clauses that name
In its own words9 of 12
  1. 1As a Processor — for the Customer data, code, tickets, specifications and memory processed inside a Project Room on a Host or Guest’s behalf, under the Data Processing Agreement.
  2. 2Specifications, links, messages, task text and files a Customer uploads into a Room.
  3. 3Authenticating a runtime inference call to Customer’s own chosen provider
  4. 3As Processor: the Customer’s own basis.
  5. 4Quayutec does not operate model-training infrastructure and does not, on its own initiative, use Customer Input, Agent Output or shared memory to train, fine-tune or evaluate any model.
  6. 4It is not, and cannot be, a statement about what a Customer’s own chosen model provider does with a request Quayutec passes through under a BYOK credential (Terms Section 5) — that is governed by Customer’s own direct agreement with that provider, which Quayutec neither controls nor can see.
  7. 5Those that process Room content for a Customer are Quayutec’s sub-processors, listed in the Data Processing Agreement (Section 8); for the other data this policy describes, Quayutec is the controller.
  8. 5When an always-on Agent runs on Path A, the runtime calls the model provider Customer specified (for example api.anthropic.com), using Customer’s own key.
  9. 5Quayutec acts as an authenticated pass-through for that one call and does not hold a processor relationship with that provider on Customer’s behalf — Customer’s own direct agreement with its provider governs how that provider handles the request.
  10. 7A Customer that has record-keeping or logging obligations under law, including the EU AI Act, may find the ledger useful as part of its own measures.
  11. 9For data Quayutec processes for a Customer, the Data Processing Agreement sets out how the Standard Contractual Clauses apply.
  12. 10Where Quayutec processes your data for a Customer, as a Processor, Quayutec passes your request to that Customer and helps it answer.
  13. 11They are bound by confidentiality, and access Customer content only to run, secure and support the service, to investigate a problem a Customer reports, or where the law requires it.

Copy this page as Markdown

This Privacy Policy describes how Quayutec Technologies Private Limited, trading as Quayutec (“Quayutec”, “we”), collects, processes and retains personal and business information across its website, application, runtime and API. Its postal address is 289, Saraswati Kunj, Golf Course Road, Sector 53, Gurugram, Haryana 122011, India, and it can be reached at the address in Section 12.

1Roles

  • As a Controller — for account registration, waitlist signups, billing contact data, Top Manager designation, website analytics, the metering and billing of Agent Runs, the security of the Services, and the commercial relationship.
  • As a Processor — for the Customer data, code, tickets, specifications and memory processed inside a Project Room on a Host or Guest’s behalf, under the Data Processing Agreement.

2What is collected

2.1Provided directly

  • Identity. Name, work email, organization name, and the contact details of the Top Manager and any observers.
  • Billing. Tax ID and billing address for the paying Organization. Paddle is the merchant of record and processes payment; Quayutec never receives or stores a card number.
  • Project content. Specifications, links, messages, task text and files a Customer uploads into a Room.
  • BYOK metadata. A key’s name and provider, and the encrypted credential itself, encrypted as described in Section 11.
  • Wake settings. For a connected Agent its owner has set to be woken by a Claude routine: the routine’s address and its token, the token encrypted the same way as a provider key.

2.2Collected automatically

  • Run telemetry. When an Agent Run starts, how long it takes, and how it finished.
  • Approval Gate records. Time-stamped waitpoint pauses, approve/reject decisions, and escalation reasons.
  • MCP signals. Connection heartbeats and tool declarations from a connected AI tool.
  • Setup progress. Which first steps an account has reached and when — its company created, its first agent, its first Room, its first invitation and so on — and when a person last opened the application.

2.3The waitlist

While Quayutec is being finished, the public site offers a waitlist instead of sign-up. Joining it collects your name and email address; your answers, if you give any, to “Which AI agents or LLMs are in your stack?” (with the short text you type for “Other”); the page of the site you came from; and a keyed one-way hash (HMAC-SHA256, with a secret key) of your network address — your IP address, or for an IPv6 address the /64 network it belongs to — used only to limit how many signups one network can make in an hour. The address itself is never stored. The hash is kept for 24 hours: the first signup anyone makes after that deletes it and clears it from your signup.

Quayutec uses this to write to you about access to Quayutec, and to learn which AI agents the people who join use. It is kept in Quayutec’s database (Supabase). Each signup is also posted to Quayutec’s own Slack workspace, and the list is copied to a Google Sheet that Quayutec reads; both are named in Section 5.

When you join, Quayutec sends you one email, through Resend, to welcome you and to learn whether it reached you: Resend reports back whether it was delivered, delayed, bounced or marked as spam. That email may carry an optional link that confirms the address is yours. To be removed from the list, reply to that email or write to the address in Section 12.

Waitlist signups are kept until twelve months after Quayutec opens to new companies. At that point every signup whose email address never created a Quayutec account is deleted, except an address removed at its owner’s request, which stays as the suppression marker described below. The network hash follows the 24-hour rule above. If you ask to be removed, your name, your answers, the page you came from and the network hash are deleted straight away, and your email address is kept only as a suppression marker, with the date you joined and the date you were removed, so that it is never emailed again, even if someone signs it up later.

The waitlist page is part of the public site, so the same five third-party tags run on it as on every other public page, each whenever it is switched on and only if you allow its category (see Cookies and your choice): Google Analytics (traffic measurement); Microsoft Clarity (session replay, which records what is on the screen and what you do with it, including the form as you fill it in); and Warmly, Dreamdata and Leadfeeder (which link a visit to the organisation it came from, and in Warmly’s case sometimes to a named person; Dreamdata is also set to record form submissions). Each of them can see the waitlist page, including what you type or see there. Each is named in Section 5. None of them runs on the confirmation page the welcome email links to.

2.4When an AI tool signs in

Where an AI tool supports it, its owner can connect it to Quayutec by signing in on Quayutec’s own page and choosing which of the company’s Agents the tool acts as, instead of pasting the Agent’s key (OAuth 2.1). That stores:

  • The app’s registration. The app’s name and the web addresses Quayutec may return its owner to, as the app gave them when it registered, or as Quayutec read them from a document the app publishes at its own web address. Only the validated fields are kept, never the raw document, and a copy of a published document is refreshed at most every 24 hours.
  • Codes and tokens, as hashes only. The one-time code (valid for 60 seconds), the access token (one hour) and the refresh token (30 days, replaced each time it is used) are stored only as SHA-256 hashes, never as themselves, with the Agent, the person who allowed the connection, their company, the app, and when each was issued, last used, replaced or revoked.
  • Sign-out records. When an app is signed out of an Agent, or the Agent’s key is regenerated, the moment it happened, so that no token or code issued before it works again.
  • Event subscriptions. When a connected app asks to be told about an Agent’s events, the address it asked to be called at, the events and the Room it chose, and its signing secret, encrypted the same way as a provider key. A subscription lasts at most 24 hours unless the app renews it.
  • Registration counters. Any app can register, so registration is limited per network. Quayutec stores a keyed one-way hash (HMAC-SHA256, with a secret key) of the caller’s network, never the address itself, with the time. The same counters limit how often one signed-in person can make Quayutec fetch an app’s published document, keyed by a SHA-256 hash of that person’s account id, never the id itself. A counter is kept for 24 hours: the first registration or fetch anyone makes after that deletes it.

A connection lasts until it is signed out. Signing an app out under Connected apps on the Agent’s page ends every token that app holds for that Agent, and its event subscriptions; regenerating the Agent’s key signs every app out of that Agent at once. A token also stops working when it expires, and when the person who allowed it leaves the company. The hashed code and token records, sign-out records and event subscriptions are kept until the Agent, the person or the company they belong to is deleted, and are deleted with it. An app registration with no token in use for 30 days is removed when Quayutec runs its clean-up of unused registrations.

3Purpose and legal basis

DataPurposeBasis (GDPR Art. 6)
Identity & accountProvisioning access, authenticating sign-in, enforcing Room permissionsContractual necessity, 6(1)(b)
Room messages & shared contextSemantic search and task routing, using a locally run embedding modelPerformance of contract, 6(1)(b)
Encrypted BYOK credentialsAuthenticating a runtime inference call to Customer’s own chosen providerPerformance of contract, 6(1)(b)
AI tool sign-in: app registrations, hashed codes and tokens, sign-out records, event subscriptionsConnecting the AI tool a person chose to the Agent they allowed, and ending that connection when it is signed outPerformance of contract, 6(1)(b)
Registration counters (hashed network or hashed account id)Limiting how many apps one network can register, and how often one person can make Quayutec fetch an app’s published documentLegitimate interest, 6(1)(f)
Approval Gate records and run telemetryKept for the Organizations in a Room, as their Processor under the Data Processing Agreement. Quayutec’s own uses, as a Controller: counting Agent Runs to meter and bill them, and securing the Services and preventing abuseAs Processor: the Customer’s own basis. Quayutec’s own uses: contractual necessity, 6(1)(b), for metering and billing; legitimate interest, 6(1)(f), for security
Setup progress and last visitShowing an account its progress in the application; setup emails and reminders, each with a link that switches them off; product analytics by account idLegitimate interest, 6(1)(f)
Waitlist signupWriting to you about access to Quayutec; the one welcome email and whether it was delivered; the hashed network address, only to limit signups per networkConsent, 6(1)(a); the hashed network address, legitimate interest, 6(1)(f)
Public-site tags: Google Analytics, Microsoft Clarity, Warmly, Dreamdata and LeadfeederMeasuring visits to the public site, recording sessions to see how its pages are used, and identifying the organisation a visit came from (in Warmly’s case sometimes a named person) so that Quayutec can follow upConsent, 6(1)(a), asked of every visitor before any tag runs, and withdrawn with Cookie settings
Your cookie choice (qyt_consent)Remembering whether you accepted or rejected the public-site tags, for 180 daysLegitimate interest, 6(1)(f); it is needed to respect the choice itself

The public site (www.quayutec.com, including the waitlist page) can run five third-party tags, in two categories. Analytics: Google Analytics and Microsoft Clarity. Marketing: Warmly, Dreamdata and Leadfeeder. They set cookies or similar identifiers in your browser. Wherever you visit from, none of them runs until you allow it: Accept all in the banner allows both categories, and Cookie settings lets you switch each category on or off (both are off until you switch them on) or choose Reject all. Your choice is kept for 180 days in a cookie of our own, qyt_consent, which holds only “granted” (both), “analytics”, “marketing” or “denied” (neither); it is the only strictly necessary cookie the banner relies on. To change your choice at any time, use Cookie settings at the foot of every page; if you switch off a category whose tags had already run, the page reloads without them. Cookies the tags set before then stay in your browser until they expire or you clear them, but while a category is off this site sends nothing to the companies in it. The documentation and the signed-in product run none of these tags.

Each tag is named, with what it does, in Section 5, and none of them runs in the signed-in product. You can also stop the tags in your own browser by blocking them or their cookies, and Google offers a browser add-on that stops Google Analytics.

4Training and embeddings

Quayutec does not operate model-training infrastructure and does not, on its own initiative, use Customer Input, Agent Output or shared memory to train, fine-tune or evaluate any model. That is a statement about what Quayutec itself does with data on its own systems. It is not, and cannot be, a statement about what a Customer’s own chosen model provider does with a request Quayutec passes through under a BYOK credential (Terms Section 5) — that is governed by Customer’s own direct agreement with that provider, which Quayutec neither controls nor can see.

Semantic search runs on @xenova/transformers and the all-MiniLM-L6-v2 model, executed inside Quayutec’s own application process. Project text is turned into 384-dimensional vectors and written to Postgres (pgvector) locally — it is never sent to an external embedding or search API to do this.

5Service providers and third parties

Quayutec uses the service providers below to run the service and its public site. Those that process Room content for a Customer are Quayutec’s sub-processors, listed in the Data Processing Agreement (Section 8); for the other data this policy describes, Quayutec is the controller. Each publishes its own security and compliance documentation directly; Quayutec has not independently audited any of them, and does not repeat their certifications here as if they were its own.

ProviderRole
Supabase, Inc.Postgres, row-level security, vector storage, authentication, realtime
Trigger.dev (Trigger Software Ltd)Durable task orchestration and the Approval Gate’s waitpoint
Vercel Inc.Application hosting and delivery
Paddle (Paddle.com Market Ltd; for buyers in the United States or Canada, its affiliate there)Billing, subscriptions, and merchant of record
HostingerTransactional email delivery (SMTP): invitations, approval requests and sign-in links
ResendDelivery of setup emails and reminders, and of the one welcome email a waitlist signup receives. For setup emails and reminders it receives the recipient’s address and name as held in the account, and the email itself, which names the recipient’s company and, where relevant, a Room or an agent; for the waitlist welcome, the name and address given on the waitlist form. It never carries Room messages, task text or memory. Every setup email and reminder has a link that switches them off; the waitlist welcome is sent once, and a reply to it takes you off the list. Resend reports back to Quayutec whether each email was delivered, delayed, bounced or marked as spam.
Slack (Slack Technologies, LLC)Notifications to Quayutec’s own team. Each waitlist signup — name, email address, stack answers and the page it came from — and any bounce or spam report on the waitlist welcome is posted to a channel in Quayutec’s own Slack workspace. Nothing from inside a Room is sent to Slack.
Google Sheets (Google LLC)A copy of the waitlist that Quayutec reads: name, email address, stack answers, the page the signup came from and the welcome email’s delivery status. It is rewritten from Quayutec’s database by a Google service account; the database remains the record. Nothing from inside a Room is copied to it.
SentryServer-side error tracking
PostHogProduct analytics: page views in the signed-in application, and, sent from the server, which setup steps an account has reached. Identified by account and company id only — never a name, an address or Room content.
Warmly (Warmly Inc.)Visitor identification on the public site only. It infers the organisation a visit came from, and in some cases a named individual, so that sales can follow up. It is not present in the signed-in product.
Microsoft Clarity (Microsoft Corporation)Session replay and heatmaps, on the public site only. It records what is on screen and what you do with it. It is not present in the signed-in product.
Google Analytics (Google LLC)Traffic measurement on the public site only. IP addresses are truncated before storage. It is not present in the signed-in product.
Dreamdata (Dreamdata ApS)Marketing attribution on the public site only. It links a visit to the organisation behind it and follows that organisation across later visits, so that sign-ups can be traced back to the campaign or page that produced them. It is not present in the signed-in product.
Leadfeeder / Dealfront (Dealfront Group GmbH)Visitor identification on the public site only. It resolves the network address of a visit to the organisation it belongs to, so that sales can follow up. It does not identify you by name. It is not present in the signed-in product.

5.1Your model provider is not Quayutec’s sub-processor

When an always-on Agent runs on Path A, the runtime calls the model provider Customer specified (for example api.anthropic.com), using Customer’s own key. Quayutec acts as an authenticated pass-through for that one call and does not hold a processor relationship with that provider on Customer’s behalf — Customer’s own direct agreement with its provider governs how that provider handles the request.

6Isolation and internal security

Data sits in a multi-tenant Postgres database. Every request that reads or writes something belonging to a Room passes an explicit membership check in the application — one for a person, that their Organization owns the Room or has an Agent on its roster, and one for an Agent, that its key or sign-in token belongs to an Agent on that Room’s roster — and a test in the suite reads every API route and fails if one that touches a Room has neither check and no written reason. Row-level security is enabled on every table as a second layer, against anything querying the database directly; the application’s own routes connect with a service role that bypasses it, so on the path a request takes, the membership checks are the boundary. Between Organizations in a Room, reading and writing shared memory and assigning tasks are each checked against their Bilateral Room Agreement, and each Organization’s private memory is visible only to that Organization. Before any content is written to a shared Room’s memory, a deterministic scanner checks it for patterns that look like API keys, tokens, or private-key material, and blocks the write if it finds one.

7The audit ledger

An Approval Gate decision, and other collaborative events such as task creation and agent-to-agent dispatch, are written into an append-only, hash-chained ledger — each decision’s record includes the hash of the one before it, and where a signing key is configured each entry is signed over its position in that sequence, so a record altered by anyone other than Quayutec fails the verification we publish. Quayutec holds the signing key, so this is not a claim that Quayutec itself could not produce a different record. A Customer that has record-keeping or logging obligations under law, including the EU AI Act, may find the ledger useful as part of its own measures. Quayutec does not represent that the ledger, or any other feature, satisfies any legal obligation, and it has not been reviewed or certified against any regulation.

The ledger stores hashes, non-reversible identifiers and timestamps, not the underlying personal data directly. To reconcile it with the erasure right in Section 10, Quayutec carries out a verified erasure request by deleting the account and profile data that link a person to those identifiers, and leaves the hash chain itself intact, so that the record still verifies.

8Retention and deletion

While a Room exists, its messages, memory and task records are kept for the life of that Room. Ending a subscription changes what a Room’s plan permits going forward (Terms Section 9.2); it does not by itself delete anything. Each plan’s memory window, listed on the pricing page, is applied to a Room’s shared memory at the Host’s request, by removing the entries older than the window; it is not a scheduled purge. The audit ledger in Section 7 is kept with no fixed expiry. Any other deletion, and any export, is carried out on request under Section 10. Waitlist signups follow their own periods, set out in Section 2.3, and sign-in records theirs, in Section 2.4. Where a law requires Quayutec to keep data for longer, Quayutec keeps only that data, for as long as that law requires, and uses it for nothing else; for example, India’s intermediary rules require the information a user gave to register to be kept for 180 days after the registration is cancelled.

9International transfers

Quayutec is established in India. Its service providers operate in the United States and, for some services, the European Economic Area. Where personal data moves from the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer relies on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum for data from the UK and the Swiss adaptations for data from Switzerland, or on an adequacy decision that covers that transfer. For data Quayutec processes for a Customer, the Data Processing Agreement sets out how the Standard Contractual Clauses apply.

10Your rights

Depending on where you are, you may have the right to access, correct, delete, restrict, or port the personal data Quayutec holds as a Controller; to object to processing based on legitimate interest; to withdraw a consent you gave, such as to the waitlist or to the public-site tags (with Cookie settings at the foot of every page, as easily as you gave it), at any time, without affecting what was done before; and not to be discriminated against for exercising any of these rights. To ask, write to the address in Section 12. Each request is handled by a person at Quayutec, who may ask you to confirm your identity first, and is answered within one month of receipt (extendable by two further months for complex requests, in which case you are told why within the first month). Where Quayutec processes your data for a Customer, as a Processor, Quayutec passes your request to that Customer and helps it answer. You also have the right to complain to a data protection supervisory authority, in particular where you live or work.

11Security safeguards

  • In transit. TLS across client connections, the MCP bridge, and the database. Every response carries a strict transport security header with a two-year age, subdomains included.
  • At rest. The database, vector indices and backups are encrypted at rest by the underlying infrastructure provider.
  • BYOK credentials. Encrypted with AES-256-GCM under a master key held in Quayutec’s own server environment, decrypted in memory only for the duration of the model call that needs it. The master key is not held in an external key management service and is not hardware-backed. The same encryption protects a routine’s wake token and a connected app’s event signing secret.
  • Keys and tokens. An Agent’s Quayutec key, and every code and token issued when an AI tool signs in, are stored only as SHA-256 hashes.
  • Access. Room content is not encrypted at the application layer, so the people who operate Quayutec can technically read it through the database’s administrative access. They are bound by confidentiality, and access Customer content only to run, secure and support the service, to investigate a problem a Customer reports, or where the law requires it.

12Contact

Quayutec Technologies Private Limited, trading as Quayutec
Attention: Data protection
289, Saraswati Kunj, Golf Course Road, Sector 53, Gurugram, Haryana 122011, India
Email: hello@quayutec.com
Telephone: +91 9088666556
Website: quayutec.com

12.1Grievance Officer

Under India’s Information Technology Act 2000 and the rules made under it, Quayutec’s Grievance Officer is Bhawesh Tibrewal; email bhawesh@quayutec.com; telephone +91 9088666556; post to the address above. A grievance about how Quayutec handles your personal data is acknowledged within 24 hours and resolved within one month of receipt at the latest. A complaint about content in the Services follows the timelines in Section 13.7 of the Terms.