|
PRIVACY POLICY Last Updated: 23-SEP-2026 · Version: 20.0 |
![]() |
Please review this policy in conjunction with our Master Subscription Agreement.
This Privacy Policy describes how ZenQMS collects, uses and discloses "Customer Data" and Other Information as defined herein (collectively, “Information ”), some of which could include information that identifies you personally, and what choices you have with respect to the Information that we collect.
When we refer to “ ZenQMS ” in this Privacy Policy, we mean ZenQMS LLC. Depending on which ZenQMS property you are using, and on what information is involved, ZenQMS acts either as a controller or as a processor of that information. Which role applies is set out in the “Which Parts Of This Policy Apply To You” section immediately below and in the “Identifying The Data Controller And Processor” section. When we refer to “Customers” we mean our customers who use our Software and Professional Services (defined below) that are directly in control of the Customer Data, including any personally identifiable Information they enter into ZenQMS’ environments.
1 APPLICABILITY OF THIS POLICY.
1.1 This Privacy Policy applies to ZenQMS’ software for managing quality activities, including all associated ZenQMS environments and the sign-in pages for those environments (collectively, the “Software”); www.zenqms.com and other ZenQMS marketing and informational websites (collectively, the “Websites”); and other interactions you may have with ZenQMS, such as customer support requests, the ZenQMS Support Portal at support.zenqms.com, and ZenQMS events (collectively, “Professional Services”, which for the purposes of this Privacy Policy is read more broadly than the defined term in the Master Subscription Agreement). This Privacy Policy explains our privacy practices; it is not a contract and it does not itself create or require consent. The legal bases on which we process Personal Data are set out in the “Legal Bases For Processing” section.
1.2 This Privacy Policy does not apply to any third-party applications or software that integrate with the Software through the ZenQMS API (“Third-Party Services ”), or any other third-party products, services or businesses. In addition, a separate agreement governs delivery, access and use of the Software and Professional Services (the “Master Subscription Agreement ” or "Terms of Service"), including the processing of any messages, files or other content submitted through Software accounts (collectively, “ Customer Data ”). The organization (e.g., your employer or another entity or person) that entered into the Master Subscription Agreement (“ Customer ”) controls their instance of the Software (their “ Customer Account ”) and any associated Customer Data. If you have any questions about specific Customer settings and privacy practices, please contact the Customer.
1.3 Protected health information (PHI) submitted to Software that a Customer has designated as HIPAA Eligible Software is governed by an executed ZenQMS Business Associate Addendum. Nothing in this Privacy Policy modifies that addendum, and where both apply to the same data the more protective obligation controls. ZenQMS’s obligations to notify a Customer of a security incident or data breach are set out in Section 5 of EXHIBIT I to the Master Subscription Agreement, in the Data Processing Addendum and, where applicable, in the Business Associate Addendum.
2 WHICH PARTS OF THIS POLICY APPLY TO YOU.
2.1 This Privacy Policy covers two different environments, and ZenQMS’ role is not the same in each. The ZenQMS Support Portal at support.zenqms.com sits across both and is addressed separately below. The sections on cookies, legal bases, controller and processor roles, and your rights are split accordingly. Every other section of this Privacy Policy applies to both environments.
2.2 Our Websites (for example www.zenqms.com). If you visit our marketing or informational websites, ZenQMS is the controller of the information we collect about you. We collect that information for our own purposes — to operate and measure the sites, respond to enquiries, and market our products. We rely on your consent for non-essential cookies and marketing email, and on our legitimate interests for site security, analytics and business operations. Requests about this information come to ZenQMS directly.
2.3 The Software (for example app.zenqms.com and its sign-in pages). If you use the ZenQMS application, you do so because an organization — normally your employer — has licensed it and provisioned you as an Authorized User. That organization is the Customer, and the Customer is the controller of the Customer Data in its account. ZenQMS processes Customer Data as a processor, on the Customer’s instructions and under the Master Subscription Agreement and any executed Data Processing Addendum. ZenQMS is the controller of a narrower set of Other Information that it needs in order to run the service — account and billing details, log and device data, and security records. Requests about Customer Data are directed to the Customer; requests about that narrower set of Other Information come to ZenQMS.
2.4 The Support Portal (support.zenqms.com). The Support Portal is ZenQMS product documentation and support content. It forms part of the Professional Services and is neither part of the Software nor one of the Websites. Some content is available to read without signing in; the remainder, and the ability to raise a support ticket, is available to Authorized Users authenticated through the Software. Where you raise a support ticket — through the Support Portal or by email — the content of that ticket may include Customer Data, and ZenQMS processes it as a processor on the Customer’s instructions under the Master Subscription Agreement and any executed Data Processing Addendum, in the same way as Customer Data in the Software. ZenQMS is the controller of the narrower record of the support interaction itself, such as who raised a ticket and when. The Support Portal uses only necessary cookies; no analytics or marketing cookies are set there and no consent banner is presented.
2.5 Cookies in the Software and on the Support Portal are limited to what is necessary to deliver the application you have asked for. Cookies on the Websites include analytics and marketing cookies and are consent-gated. See the “Cookie Information” section.
3 INFORMATION WE COLLECT & RECEIVE.
ZenQMS may collect and receive Customer Data and other information and data (“Other Information”) in a variety of ways:
3.1 Customer Data . Authorized Users granted access to a Customer Account by a Customer routinely submit Customer Data to ZenQMS when using the Software.
3.2 Other Information includes, but is not limited to:
A.Customer Account and Account Information. To create or update a Customer Account, Authorized Users or other authorized individuals acting on behalf of Customer supply ZenQMS with an email address, phone number, password, domain and/or similar account details. In addition, Customers provide ZenQMS (or its payment processors) with billing details such as credit card information, banking information and/or a billing address.
B.Usage Information.
Software Metadata: When an Authorized User interacts with the Software, metadata is generated that provides additional context about the way Authorized Users work. For example, ZenQMS logs the features, content and links you interact with.
Log data: As with most websites and technology services delivered over the Internet, our servers automatically collect information when you access or use our Websites or Software and record it in log files. This log data may include the Internet Protocol (IP) address, the address of the web page visited before using the Website or Software, browser type and settings, the date and time the Software was used, information about browser configuration and plugins, language preferences and cookie data.
Device information: ZenQMS collects information about devices accessing the Software, including type of device, what operating system is used, device settings, application IDs, unique device identifiers and crash data. Whether we collect some or all of this Other Information often depends on the type of device used and its software and settings.
Location information: We receive information from you, the Customer and other third parties that helps us approximate your location. We may, for example, use a business address submitted by your employer, or an IP address received from your browser or device to determine approximate location. ZenQMS may also collect location information from devices in accordance with the consent process provided by your device.
C.Cookie Information. A cookie is a small data file that a website places on your device. We use both session-based cookies, which expire when you close your browser, and persistent cookies. Because our two environments use cookies differently, we describe them separately below.
In the Software (app.zenqms.com and related environments) and on the Support Portal (support.zenqms.com), we use only cookies that are necessary to deliver the application you have requested — recording your current session, supporting security features such as multi-factor authentication, and remembering interface state such as which tabs you had open. We do not use cookies in the Software for advertising, and we do not use Software cookie data to build marketing profiles. Because these cookies are strictly necessary, no consent banner is presented in the Software or on the Support Portal.
On our Websites (including www.zenqms.com), we use necessary cookies together with analytics, functional and marketing cookies, including cookies set by third parties such as Google Analytics and HubSpot. These help us understand how the sites are used, remember your preferences, and measure our marketing. Where consent is required, we set non-essential cookies only after you have given it through the consent banner presented on the Websites, and you can change or withdraw your choices at any time using the cookie preferences link in the Website footer.
Most browsers also let you block or delete cookies through your browser settings. Blocking cookies that are necessary to the Software will prevent the application from working correctly. We recommend clearing cookies and cache periodically as a matter of good practice.
D.Additional Information Provided to ZenQMS. We receive Other Information when submitted to our Websites or if you participate in a focus group, contest, activity or event, apply for a job, request support, interact with our social media accounts or otherwise communicate with ZenQMS.
E.System Data. Data based on information, activities and actions recorded in or by the Software that has been anonymized and aggregated such that it does not contain any Personal Data or reveal any Customer Confidential Information.
3.3Generally, no one is under a statutory or contractual obligation to provide any Customer Data or Other Information. However, certain Information is collected automatically and, if some Information, such as Customer Account setup details, are not provided, ZenQMS may be unable to provide the Software.
4 HOW WE USE INFORMATION.
Customer Data will be used by ZenQMS in accordance with the Master Subscription Agreement and as required by applicable law. ZenQMS is a processor of Customer Data and Customer is the controller. Customer may, for example, use the Software to grant and remove access to a Customer Account, assign roles and configure settings, access, modify, export, share and remove Customer Data and otherwise apply its policies to the Software. ZenQMS uses Other Information in furtherance of our legitimate interests in operating our Software, Websites, Professional Services and business. More specifically, ZenQMS uses Other Information:
4.1To Provide, Update, Maintain And Protect Our Software, Websites And Business. This includes use of Other Information to support delivery of the Software and Professional Services under a Master Subscription Agreement, prevent or address service errors, security or technical issues, analyze and monitor usage, trends and other activities or at an Authorized User’s request.
4.2 As Required By Applicable Law, Legal Process Or Regulation.
4.3 To Communicate With You By Responding To Your Requests, Comments And Questions. If you contact us, we may use your Other Information to respond.
4.4 To Develop And Provide Search, Learning And Productivity Tools And Additional Features. ZenQMS tries to make the Software as useful as possible for specific Customer Accounts and Authorized Users. For example, we may look for OS/Browser information relative to common errors to identify possible issues.
4.5 To Send Emails And Other Communications.
A. Communications regarding the Software and Professional Services. We may send you service, technical and other administrative emails, messages and other types of communication. We may also contact you to inform you about changes in our Software and Professional Services, our Software and Professional Services offerings, and important Software and Professional Services-related notices, such as security and fraud notices. These communications are considered part of the Software and Professional Services and you may not opt out of them.
B. Marketing Messages. In addition, we sometimes send emails about new product features or other news about ZenQMS. These are marketing messages so you can control whether you receive them.
4.6 For Billing, Account Management And Other Administrative Matters. ZenQMS may use Other Information to contact you for invoicing, account management and similar administrative reasons, and to keep track of billing and payments.
4.7 To Investigate And Help Prevent Security Issues And Abuse. ZenQMS may use Other Information to monitor, detect and anticipate potential security issues and incidents, and to take appropriate protective and/or remedial measures.
4.8 With Your Consent. We use Information about you where you have given us consent to do so for a specific purpose not listed above. For example, we may publish testimonials or featured customer stories to promote the Services, with your permission.
4.9 Legal Bases For Processing (EEA, UK and Swiss Individuals). If you are an individual in the European Economic Area (EEA), the United Kingdom or Switzerland, we collect and process Personal Data about you only where we have a legal basis for doing so under the EU GDPR, the UK GDPR or the Swiss Federal Act on Data Protection, as applicable. Which basis applies depends on the environment. For the Software, we rely principally on the necessity of processing to perform the Master Subscription Agreement with the Customer, and on our legitimate interests in the security, integrity and support of the service. For the Websites, we rely on your consent for non-essential cookies and marketing communications, and on our legitimate interests for site operation, security and measurement. In both environments we also process Personal Data where required to comply with a legal obligation. Specifically, we collect and use Personal Data about you where:
A.We need it to provide you the Software and Professional Services, including to operate the Software, provide customer support and to protect the safety and security of the Software;
B.It satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote the Software and Professional Services and to protect our legal rights and interests;
C.You give us consent to do so for a specific purpose;
D.We need to process your Information to comply with a legal obligation or regulatory requirements (e.g. 21 CFR Part 11);
E.If you have consented to our use of Information about you for a specific purpose, you have the right to withdraw that consent at any time, though this will not affect any processing that has already taken place. Where we rely on a legitimate interest, you have the right to object to that use, though in some cases this may mean no longer being able to use the Software. Your other rights, including access, rectification, erasure, restriction of processing and data portability, are set out in the “Your Rights” section.
4.10 If Information is aggregated or de-identified so it is no longer reasonably associated with an identified or identifiable natural person, ZenQMS may use it for any lawful purpose. To the extent Information is associated with an identified or identifiable natural person and is protected as personal data under applicable data protection law, it is referred to in this Privacy Policy as “Personal Data”.
5 ARTIFICIAL INTELLIGENCE FEATURES.
5.1 Where a Customer has enabled ZenQMS AI Features, an Authorized User may submit Customer Data and other content to an AI Feature (an “AI Input”) and the AI Feature returns generated content (an “AI Output”). As between ZenQMS and the Customer, AI Input and AI Output are Customer Data, and the Customer retains all right, title and interest in them. ZenQMS processes them as a processor on the Customer’s instructions, on the same terms as all other Customer Data.
5.2 ZenQMS does not use Customer Data, AI Input or AI Output to train, fine-tune or improve any generally available artificial-intelligence or machine-learning model.
5.3 AI Features are delivered in part through third-party model providers, which act as sub-processors. They are identified in the sub-processor list referred to in the “International Transfers” section, and they are contractually prohibited from using Customer Data, AI Input or AI Output to train their own models.
5.4 AI Output is a draft. AI Features are decision-support tools and no AI Feature applies an electronic signature. ZenQMS does not use AI Features to make any decision about an individual that produces legal effects concerning that individual or similarly significantly affects them, and does not carry out automated decision-making of that kind within the meaning of Article 22 of the GDPR.
5.5 Use of an AI Feature is recorded in the audit trail for the applicable record, including which AI Feature was used, the Authorized User who invoked it, and the date and time. The Customer determines what may be submitted to an AI Feature; further terms, including restrictions on submitting personal data of patients or clinical trial subjects and protected health information, are set out in Section 18 of the Master Subscription Agreement and in the ZenQMS Acceptable Use Policy.
6 HOW WE SHARE AND DISCLOSE INFORMATION
This section describes how ZenQMS may share and disclose Information with third parties (subject to any contractual duty of confidentiality between ZenQMS and the Customer). Customers determine their own policies and practices for the sharing and disclosure of Information, and ZenQMS does not control how they or any other third parties choose to share or disclose Information
6.1 Customer’s Instructions. ZenQMS will solely share and disclose Customer Data in accordance with a Customer’s instructions, including any applicable terms in the Master Subscription Agreement and Customer’s use of Software functionality, and in compliance with applicable law and legal process.
6.2 Displaying the Software. When an Authorized User submits Other Information, it may be displayed to other Authorized Users in the same Customer Account. For example, an Authorized User’s email address may be displayed with their Customer Account profile.
6.3 Collaborating with Others. The Software provides different ways for Authorized Users to collaborate. Other Information, such as an Authorized User’s profile Information, may be shared internally among other Authorized Users within a Customer Account, subject to the policies and practices of the other Customer Account(s).
6.4 Customer Access. Owners, administrators, Authorized Users and other Customer representatives and personnel may be able to access and modify Other Information.
6.5 Third Party Service Providers and Partners. We may engage third party companies or individuals as service providers or business partners to process Other Information and support our business (“Third Party Services”). Third Party Services include, for example, virtual computing and storage services (e.g. Amazon Web Services). Regulatory compliance with policies (e.g. GDPR, HIPAA) may be reviewed during a Quality Risk Assessment of these service providers or business partners.
6.6 Third Party Services Connected through API. Customer may enable or permit Authorized Users to enable Third Party Services to access information in ZenQMS through its API. When enabled, ZenQMS may share Other Information with Third Party Service providers. Third Party Services are not owned or controlled by ZenQMS and third parties that have been granted access to Other Information may have their own policies and practices for its collection and use. Please check the privacy settings and notices of such Third Party Service providers or contact the provider for any questions.
6.7 During a Change to ZenQMS’ Business. If ZenQMS engages in a merger, acquisition, bankruptcy, dissolution, reorganization, sale of some or all of ZenQMS' assets or stock, financing, public offering of securities, acquisition of all or a portion of our business, a similar transaction or proceeding, or steps in contemplation of such activities (e.g., due diligence), some or all Other Information may be shared or transferred, subject to standard confidentiality arrangements and/or business associate agreements.
6.8 To Comply with Laws. If we receive a request for information, we may disclose Other Information if we reasonably believe disclosure is in accordance with or required by any applicable law, regulation or legal process. In certain situations, we may also be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
6.9 To Enforce our Rights, Prevent Fraud, and for Safety. ZenQMS may disclose Information to protect and defend the rights, property or safety of ZenQMS or third parties, including enforcing contracts or policies, or in connection with investigating and preventing fraud or security issues.
7 DATA RETENTION & DELETION.
7.1 ZenQMS retains Customer Data in accordance with a Customer’s instructions, including any applicable terms in the Master Subscription Agreement and Customer’s use of Software functionality, and as required by applicable law and regulation. Depending on the Software and Professional Services plan, Customer may be able to customize its retention settings and apply those customized settings at the Customer Account level, Site level or other level. In some instances, Customer may also apply different settings to messages, files or other types of Customer Data. The deletion of Customer Data and other use of the Software and Professional Services by Customer may result in the deletion and/or de-identification of certain associated Other Information. ZenQMS retains Other Information for no longer than is necessary for the purposes described in this Privacy Policy, applying the following criteria: account and billing records are retained for the duration of the Customer relationship and then for the period required by tax, accounting and limitation-of-actions law; log, device and security records are retained for the period set out in ZenQMS’ retention polciy per SOP 101; marketing contact records are retained until you unsubscribe or ask us to delete them, and are reviewed periodically; and records ZenQMS is required to keep in order to demonstrate regulatory compliance (for example under 21 CFR Part 11) are retained for the applicable regulatory retention period. ZenQMS may also retain Other Information for the period needed to pursue legitimate business interests, conduct audits, resolve disputes and enforce our agreements.
7.2 ZenQMS Authorized Users should direct requests for deletion, correction and/or amendment of Information to the Customer in accordance with the “Your Rights” section in this Privacy Policy. As per Section 3 of the Data Processing Addendum, ZenQMS notifies a Customer if any data subject request has been made to it directly from one of the Customer’s users. On termination, Customer Data is returned or deleted in accordance with Section 7 of the Data Processing Addendum and Section 4 of EXHIBIT I to the Master Subscription Agreement, which set the timetable for deletion, the outer deletion deadline for data held in backups, and the Customer-instructed retention of audit trail data required under 21 CFR Part 11 and EU Annex 11.
7.3 Data deletion, correction and/or amendment requests regarding Other Information should be made to ZenQMS via email to help@zenqms.com or legal@zenqms.com. ZenQMS responds to such requests within a reasonable timeframe. ZenQMS may ask you and/or Customer to verify your identity, or the data subject’s identity, if different, the reason for the request, and what information is requested to be deleted, corrected and/or amended. Where the request concerns Other Information held in a Customer Account and the Customer is the controller of that information, ZenQMS will refer the request to the Customer and notify you that it has done so; where ZenQMS is the controller, ZenQMS decides the request itself and does not require the Customer’s approval. We will delete, correct and/or amend your Information following the request unless doing so would conflict with ZenQMS’ ability to comply with (and demonstrate compliance with) legal obligations and regulatory requirements. ZenQMS sends a confirmation to the requester or Customer that Information was deleted, corrected or amended. If Information was not deleted, corrected or amended for the reasons listed above, ZenQMS notifies the requester or Customer with the reasoning for the denial.
8 SECURITY.
8.1 ZenQMS takes security of Information very seriously. ZenQMS applies, maintains and monitors physical, technical and administrative safeguards, in accordance with industry standards and as set out in ZenQMS’ System and Data Security SOP, to protect Information from loss, misuse and unauthorized access or disclosure. These measures consider the sensitivity of the Information we collect, process and store, and the current state of technology, and include (but not limited to) encryption of Customer Data in transit and at rest, mandatory multi-factor authentication for ZenQMS personnel, role-based logical access controls, continuous vulnerability scanning, and continuous security monitoring. ZenQMS maintains ISO conformance and certification, undergoes an annual independent third-party SOC 2 Type 2 audit covering all five Trust Services Criteria, undergoes an annual independent third-party GxP/GAMP audit, and commissions an annual independent third-party penetration test. Materials describing ZenQMS’ security standards, certifications and audit reports are available in the ZenQMS Auditor Share.
8.2 Given the nature of communications and information processing technology, ZenQMS cannot guarantee that Information, during transmission through the Internet or while stored on our systems or otherwise in our care, will always be safe from intrusion by others.
8.3 It is the Customer’s responsibility to apply the physical, technical and administrative controls that are within the Customer’s control rather than ZenQMS’, including configuring account permissions and managing its own users’ credentials, and to take reasonable steps to prevent incidents originating in the Customer’s own organization.
8.4 If a Customer terminates its use of the Software, or its subscription is terminated by ZenQMS, Customer Data is returned or deleted in accordance with Section 7 of the Data Processing Addendum and Section 4 of EXHIBIT I to the Master Subscription Agreement.
9 AGE LIMITATIONS.
9.1 To the extent permitted by applicable law, ZenQMS does not permit use of our Software and Websites by anyone younger than 16 years old. If you believe that anyone younger than 16 has provided us with their Personal Data, please contact us and we will take steps to delete it.
10 PRIVACY CONTACT.
10.1 Questions about this Privacy Policy, or about how ZenQMS handles Personal Data, should be directed to the ZenQMS Privacy Contact at legal@zenqms.com, or by post to ZenQMS LLC, Attn: Privacy, 40 Coulter Ave, Suite 265, Ardmore, PA 19003, USA. ZenQMS acts as a processor for the great majority of the Personal Data it handles; our representatives for the EEA, the United Kingdom and Switzerland are identified in the “Complaints” section.
11 IDENTIFYING THE DATA CONTROLLER AND PROCESSOR.
11.1 Data protection law in certain jurisdictions differentiates between the “controller” and “processor” of information. For Customer Data, and for Other Information that ZenQMS processes on a Customer’s behalf in order to deliver the Software to that Customer, the Customer is the controller and ZenQMS is the processor, as provided in Section 2 of the Data Processing Addendum. ZenQMS is the controller only of (a) information collected through the Websites, and (b) the limited categories of Other Information that ZenQMS determines the purposes of for its own account — billing and payment records, ZenQMS’ own security and audit logs, aggregated or de-identified System Data, and marketing contact records. Where ZenQMS is the controller, ZenQMS answers requests about that information directly; where ZenQMS is the processor, requests are directed to the Customer.
12 YOUR RIGHTS.
12.1 This section describes your rights. Which of them you exercise against ZenQMS, and which against the Customer, depends on who is the controller — see the two sections named above. Where ZenQMS is the processor, ZenQMS will pass your request to the Customer and support the Customer in answering it.
12.2 Access and correction in the Software. Authorized Users can view and edit their own Personal Data from the application’s personal settings pages, can ask their organization’s ZenQMS administrator to make the change, and/or can email help@zenqms.com. Because the Software is a regulated records system, certain data cannot be deleted where doing so would defeat an audit trail the Customer is required to keep.
12.3 Minimum data required. The Software requires a minimum of Personal Data to function — a user ID (normally an email address) and first and last name. Access to that data within ZenQMS is limited to personnel who require it for their role; it is also processed by the sub-processors identified in the sub-processor list referred to in the “International Transfers” section. If you do not wish your Personal Data to be processed in the Software, you should raise that with the organization that provisioned your account, since it is that organization — not ZenQMS — that decides whether you are given access.
12.4 Rights of EEA, UK and Swiss individuals. Where ZenQMS’ processing of your Personal Data is subject to the EU GDPR, the UK GDPR or the Swiss Federal Act on Data Protection, you have the right to request access to your Personal Data; to have inaccurate Personal Data rectified; to have your Personal Data erased; to have processing restricted; to receive your Personal Data in a portable format and have it transmitted to another controller where the processing is based on consent or contract and carried out by automated means; to object to processing based on our legitimate interests; to object at any time to processing for direct marketing purposes; to withdraw any consent you have given; and not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. As described in the “Artificial Intelligence Features” section, ZenQMS does not carry out automated decision-making of that kind. The legal bases on which we rely are set out in the “Legal Bases For Processing” section — they are not limited to legitimate interests.
12.5 Sensitive data. To the extent that ZenQMS' processing of your Personal Data is subject to the General Data Protection Regulation, you have the right to opt-out from sensitive data collection. Because certain of that data is required for the Software to function, exercising this choice will fully restrict access to the application.
12.6 Complaints. You have the right to lodge a complaint with a supervisory authority about the collection and use of your Personal Data. See the “Complaints” section of this Privacy Policy for details, including how to reach our EEA, UK and Swiss representatives.
12.7 Exercising your rights. You have the right to obtain confirmation of whether we hold Personal Data relating to you in the United States and, on request, to be given access to it and to have it corrected, amended or deleted. Requests may be made directly to legal@zenqms.com, or through our representative for your region as identified in the “Complaints” section. We respond within a reasonable time, as stated in the “Data Retention & Deletion” section, and will tell you if we need longer and why.
13 INTERNATIONAL TRANSFERS.
13.1 ZenQMS hosts the Software on infrastructure located in the United States, so your information may be transferred to, stored in, or processed in the United States. Where the data protection laws of the United States differ from those of your own country, ZenQMS relies on the transfer mechanisms described below and in the “Data Privacy Framework (DPF) Programs” section, and applies the technical and organizational measures described in the Data Processing Addendum — including encryption in transit and at rest and a documented process for handling government or law enforcement requests for data. Individuals in the EEA, the United Kingdom and Switzerland also have access to the independent redress mechanisms described in the “Complaints” section.
13.2 In addition, we engage Third Party Service providers that process Personal Data on our behalf in order to provide the Software and Professional Services, and their servers may be located outside your country of residence, including in the United States. A current list of these sub-processors, identifying each one’s role and the country in which it processes data, is available on request from legal@zenqms.com and, for Customers, in the ZenQMS Auditor Share. ZenQMS gives Customers notice before adding or replacing a sub-processor, and Customers may object as provided in Section 4 of the Data Processing Addendum. We take steps to ensure that our sub-processors offer appropriate safeguards to protect Personal Data they process on our behalf, and contractually obligate them to process that data in compliance with applicable data protection laws. ZenQMS remains liable for the acts and omissions of its sub-processors to the same extent it would be liable if it performed the processing itself, as provided in Section 4 of the Data Processing Addendum.
13.3 ZenQMS contractually commits to transfer and process all of its Customers’ EU, UK and Swiss data in compliance with the Standard Contractual Clauses (“SCCs”) and, as applicable, the UK International Data Transfer Addendum and the Swiss Addendum, which are valid data export mechanisms and which apply as part of the Data Processing Addendum (DPA) to the Master Subscription Agreement.
13.4 In addition to incorporating SCCs, our DPA also specifies our commitments to security, confidentiality of processing, limitations on international transfers of Personal Data, cooperation with data subject rights, notice of security incidents, and more. Customers who wish to sign a DPA with ZenQMS may request it by contacting us at legal@zenqms.com .
14 DATA PRIVACY FRAMEWORK (DPF) PROGRAMS
14.1 ZenQMS may transfer your Personal Data to countries other than the one in which you live. To safeguard transfers of Personal Data originating from the European Union, the UK, or Switzerland to other countries not deemed adequate under applicable data protection law, ZenQMS participates in the EU-U.S. Data Privacy Framework (DPF) program and has accordingly self-certified as part of the U.S. Department of Commerce Data Privacy Framework Program. ZenQMS has certified to the U.S. Department of Commerce that it adheres to (1) the EU-U.S. DPF Principles with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF, (2) the Swiss-U.S. DPF Principles with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF, and (3) the UK Extension to the EU-U.S. Data Privacy Framework with regard to the processing of personal data from the UK (collectively, the “DPF Principles”). To learn more about the Data Privacy Framework program, please visit https://www.dataprivacyframework.gov/. To view ZenQMS’s certification, please visit the Data Privacy Framework List at https://www.dataprivacyframework.gov/list and search for “ZenQMS”.
14.2 ZenQMS is subject to the regulatory and enforcement powers of the U.S. Federal Trade Commission with respect to Personal Data received or transferred pursuant to the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework and the UK Extension. EU, UK and Swiss individuals have the right to obtain confirmation of whether ZenQMS holds Personal Data relating to them in the United States. On request, ZenQMS will provide access to that Personal Data, and individuals may also correct, amend or delete it. To request access or correction of Personal Data transferred to the United States under the DPF Principles, individuals should contact ZenQMS at legal@zenqms.com or their regional representative as identified in the “Complaints” section. If requested to remove data, ZenQMS will respond per “Data Retention & Deletion” section.
14.3 ZenQMS provides an individual opt-out choice for sensitive Personal Data, which fully restricts access to the application if selected. In certain situations, ZenQMS may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
14.4 ZenQMS is accountable for Personal Data that it receives in the United States under the EU-U.S. Data Privacy Framework, UK extension, and Swiss-U.S. Data Privacy Framework and subsequently transfers to a third party. ZenQMS remains responsible and liable under the DPF Principles if third-party agents that it engages to process the Personal Data on its behalf do so in a manner inconsistent with the DPF Principles, unless ZenQMS proves that it is not responsible for the event giving rise to the damage.
15 COMPLAINTS.
15.1 In compliance with the DPF Principles, ZenQMS commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States.
A. European Union, UK and Swiss individuals with DPF inquiries or complaints should first contact ZenQMS at: Email: legal@zenqms.com · Phone: +1 267 670 8999 · Mail: 40 Coulter Ave, Suite 265, Ardmore, PA 19003, USA
B. ZenQMS Privacy Contact (DPO): Panos Boudouvas via legal@zenqms.com
C. ZenQMS EU Representative (GDPR Article 27): Alina Cobarzan via legal@zenqms.com
D. ZenQMS UK Representative (UK GDPR Article 27): DataRep Ltd.1 Email: datarequest@datarep.com , Mail: DataRep 07-111 Fleet Street, London, EC4A 2AB, United Kingdom
E. ZenQMS Swiss Representative (Switzerland Article 27): DataRep. Ltd. Email: datarequest@datarep.com , Mail: Leutchenbachstrasse 95, Zurich, 8050, Switzerland
15.2 ZenQMS has further committed to refer unresolved privacy complaints under the DPF Principles to an independent dispute resolution mechanism, BBB National Programs' Data Privacy Framework Services. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://bbbprograms.org/programs/all-programs/dpf for more information and to file a complaint. This service is provided free of charge to you.
15.3. If your complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms.
15.4 European Union, UK and Swiss individuals also have the right to lodge a complaint with a supervisory authority about the collection and use of their Personal Data. Contact details for the supervisory authorities of the EEA Member States are available from the European Data Protection Board at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. In the United Kingdom, the supervisory authority is the Information Commissioner’s Office, https://ico.org.uk/. In Switzerland, it is the Federal Data Protection and Information Commissioner, https://www.edoeb.admin.ch/.
16 UNITED STATES STATE PRIVACY LAWS.
16.1 A number of U.S. states have enacted comprehensive consumer privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”). Two distinct questions arise under these laws. First, whether ZenQMS is itself a “business” or “controller” subject to the law: that turns on thresholds such as annual revenue and the volume of consumer data processed, and as at the date of this Privacy Policy ZenQMS does not meet the applicable thresholds under the CCPA. ZenQMS reviews this position at least annually and will update this Privacy Policy if it changes. Second, whether ZenQMS acts as a “service provider” or “processor” when it handles Customer Data on a Customer’s behalf: it does. In that capacity ZenQMS processes personal information only on the Customer’s behalf and in accordance with the Master Subscription Agreement and any executed Data Processing Addendum; it does not sell or share personal information, does not retain, use or disclose it for any purpose other than performing the services, does not combine it with personal information from other sources except as permitted by law, and cooperates with the Customer in responding to consumer rights requests. If you are a consumer with a request about personal information held in a Customer’s ZenQMS account, please contact that organization; if you have a request about information ZenQMS holds as a business or controller — for example information collected through our Websites — please contact legal@zenqms.com.
17 CHANGES TO THIS PRIVACY POLICY.
17.1 ZenQMS may change this Privacy Policy from time to time. Laws, regulations and industry standards evolve, which may make those changes necessary, or we may make changes to our business. We will post the changes to this page and encourage you to review our Privacy Policy to stay informed. If we make changes that materially alter your privacy rights, ZenQMS will provide additional notice, such as via email or through the Software. If you disagree with the changes to this Privacy Policy, you should deactivate your Software account. Contact the Customer if you wish to request the removal of Personal Data under their control.
18 CONTACTING ZENQMS.
18.1 Please feel free to contact ZenQMS if you have any questions about this Privacy Policy or ZenQMS’ practices, or if you are seeking to exercise any of your rights. You may contact us at legal@zenqms.com for privacy matters, at help@zenqms.com for support matters, or at our mailing address below. Individuals in the EEA, the United Kingdom and Switzerland may also contact our regional representative as identified in the “Complaints” section.
18.2 ZenQMS LLC, 40 Coulter Ave, Suite 265, Ardmore, PA 19003, USA

