Quillaris Privacy Policy.
Last updated September 27, 2026 · Effective September 27, 2026
Quillaris LLC (“Quillaris,” “we,” “our,” or “us”) respects privacy and is committed to explaining how we collect, use, disclose, retain, and protect personal information. This Privacy Policy applies to our websites, hosted software platform, products, demos, support, communications, and related offerings, collectively the Services.
This Policy describes Quillaris’s general privacy practices. An executed master subscription agreement, order, data processing addendum, or other written agreement may contain additional protections for Customer Data. If such an agreement conflicts with this Policy regarding Customer Data, the executed agreement controls.
Scope of this Policy
This Policy applies to personal information Quillaris processes through the Services, including information about website visitors, prospective and current customers, account administrators, authorized users, support contacts, and other individuals whose information is provided to Quillaris.
This Policy does not govern the independent privacy practices of a Customer, a Customer-selected integration, or another third party. Links to third-party sites and services are provided for convenience, and their own privacy notices apply to their processing.
Our Roles
Quillaris determines the purposes and means of processing information collected for its own business operations, including website, subscription, billing, sales, account administration, support, communications, analytics, and security information. Depending on applicable law, Quillaris may be described as a controller or business for that information.
For data submitted to the Services by or on behalf of a Customer, Customer Data, Quillaris generally acts as the Customer’s service provider or processor and processes Customer Data under the Customer’s instructions and the applicable agreement. Individuals seeking to exercise rights concerning Customer Data should ordinarily contact the Customer that submitted or controls that data. Quillaris will assist Customers as required by applicable law and the applicable Data Processing Addendum.
Information We Collect
The information we collect depends on how a person or Customer interacts with the Services. During the preceding twelve months, Quillaris may have collected the following categories.
| Category and examples | Sources | Purposes |
|---|---|---|
| Identifiers and professional information Names, business contact details, company, title, account identifiers, mailing addresses | Directly from individuals, Customers, authorized users, identity providers, integrations | Accounts, authentication, service delivery, support, communications, security, contract administration |
| Account and authentication information Login identifiers, authentication records, permissions, and account settings | Individuals, Customers, identity providers, and Service activity | Provisioning, authentication, access control, security, and troubleshooting |
| Commercial and subscription information Orders, subscription tier, transaction and billing records | Customers, account administrators, and payment providers | Orders, billing, accounting, customer service, fraud prevention, and legal compliance |
| Internet and network activity IP address, browser, device and operating-system information, pages viewed, timestamps, referrals, sessions, feature usage, and clickstream events | Collected automatically through the Services, cookies, logs, and analytics tools | Operation, security, diagnostics, product analytics, capacity planning, and improvement using deidentified or aggregated data |
| Communications and support information Emails, requests, feedback, demo information, recordings if notice is provided, and support content | Directly from individuals, Customers, and support systems | Responding to requests, support, training support personnel, service improvement, security, and dispute resolution |
| Customer Data Manuscripts, contracts, rights records, submissions, royalty and commission records, attachments, notes, agency records, and related content | Customers, authorized users, Customer-authorized integrations, and source systems | Providing, securing, maintaining, and supporting the Services under Customer instructions |
| Sensitive Customer Data Social Security numbers, taxpayer identification numbers, and bank-account, routing, or ACH information submitted for agency, tax, or payment administration | Customers, authorized users, and Customer-authorized source systems | Customer-directed agency, tax, payment, accounting, security, and compliance functions |
| Location information Approximate location inferred from an IP address and ordinary static mailing addresses | Network activity and information submitted by Customers or users | Security, fraud prevention, localization, communications, and Customer-directed recordkeeping |
Information We Do Not Intentionally Collect
The Services are not designed to collect biometric identifiers used for identification, protected health information, consumer health data, genetic information, or precise geolocation used for live tracking. An ordinary static mailing address is not treated as precise geolocation for this purpose. Customers must not submit those categories unless Quillaris has expressly authorized the processing in a written agreement or addendum.
Subscription payments may be processed by a designated payment provider. Quillaris does not intend to receive or store complete payment-card numbers in the hosted platform, and Customers must not place complete payment-card information in Customer Data outside a Quillaris-designated payment workflow.
How We Use Information
We may use personal information to:
- provide, configure, maintain, secure, and support the Services;
- authenticate users and administer accounts and permissions;
- process subscriptions, invoices, and payments;
- respond to support, sales, demo, and other communications;
- monitor performance, diagnose errors, maintain availability, and prevent abuse;
- detect, investigate, and prevent fraud, security incidents, and unlawful activity;
- send service, security, billing, and administrative communications;
- send marketing communications where permitted, subject to the right to opt out;
- create and use deidentified Usage Data and Aggregated Data for analytics and Service improvement;
- comply with law, enforce agreements, establish or defend legal claims, and protect rights and safety; and
- complete a corporate transaction subject to appropriate confidentiality and privacy protections.
Customer Data and Deidentified Data
Quillaris processes Customer Data only to provide, secure, maintain, and support the Services, comply with applicable law, perform the applicable agreement, and carry out Customer instructions. Customer Data remains controlled by the Customer subject to the applicable agreement.
Quillaris may use Usage Data and Aggregated Data to operate, secure, analyze, and improve the Services only where the information has been deidentified so that it cannot reasonably identify a Customer or individual. Quillaris will take reasonable measures to prevent reidentification, will not attempt to reidentify that information, and will require recipients to observe equivalent restrictions where required by law.
Artificial Intelligence Processing
When a Customer uses an artificial-intelligence-enabled feature, Customer Data may be transmitted to and processed through Amazon Bedrock solely for model inference and related processing necessary to provide that feature. AI processing of Customer Data is routed through Amazon Bedrock and is not transmitted to a separate third-party AI service provider.
Quillaris configures and uses Amazon Bedrock so that Customer prompts, inputs, and outputs are not used by AWS or an underlying model provider to train, fine-tune, or improve a base or foundation model and are not disclosed to or made accessible by an underlying model provider. Quillaris will not use Customer Data to train, fine-tune, evaluate, benchmark, develop, or improve an artificial-intelligence or machine-learning model without the Customer’s affirmative written opt-in.
As of the Effective Date, Amazon Bedrock is the only third-party artificial-intelligence service authorized to process Customer Data. Quillaris will provide prior notice before transmitting Customer Data to an additional or replacement artificial-intelligence provider, consistent with the applicable Data Processing Addendum.
Quillaris does not use automated decisionmaking technology to make significant decisions about an individual’s eligibility for employment, housing, education, credit, insurance, health care, or essential goods or services. If that practice changes, Quillaris will provide any notice and choices required by applicable law before the new processing begins.
Cookies Analytics and Tracking
Quillaris uses cookies, logs, and similar technologies to operate and understand the Services. Cookies may fall into the following categories.
Necessary Cookies
Necessary cookies support authentication, session management, security, fraud prevention, load balancing, and other functions required to provide the Services. These cookies cannot ordinarily be disabled through our preference tool because the Services may not operate correctly without them.
Functional Cookies
Functional cookies remember settings and preferences and support optional Service features. Disabling them may reduce functionality.
Analytics Cookies
Analytics technologies help us understand website and Service performance, pages visited, session duration, interactions, browser information, and approximate location inferred from an IP address. We use this information for traffic analysis, troubleshooting, capacity planning, and improvement. Where required by law, nonessential analytics technologies are disabled unless consent is provided.
Our cookie preference tool allows visitors to accept or reject nonessential cookies and modify their preferences. Browser settings may provide additional controls. As of the Effective Date, Quillaris does not use third-party advertising cookies to serve cross-context behavioral advertising.
Because there is no uniform industry standard for traditional browser Do Not Track signals, the Services do not currently respond to those signals. Quillaris recognizes and processes legally required opt-out preference signals, including Global Privacy Control, as required by applicable law. Because Quillaris does not sell personal information or share it for cross-context behavioral advertising, such a signal may not change disclosures necessary to provide the Services.
How We Disclose Information
Quillaris may disclose personal information only as reasonably necessary for the purposes described in this Policy, including to:
- hosting, infrastructure, storage, monitoring, authentication, security, support, communications, analytics, and other service providers processing information on our behalf;
- payment providers that process Quillaris subscription payments;
- Customer-authorized accounting platforms, identity providers, and other integrations;
- professional advisers, auditors, insurers, and financial institutions subject to appropriate duties of confidentiality;
- law-enforcement agencies, regulators, courts, or other parties when required by law or reasonably necessary to protect rights, safety, and security; and
- a buyer, investor, lender, or successor in connection with a proposed or completed merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
Quillaris requires service providers and subprocessors to protect personal information and process it only for contracted purposes. A Customer’s use of a Customer-selected integration is also governed by that provider’s privacy practices and the Customer’s instructions.
No Sale or Targeted Advertising
Quillaris does not sell personal information and does not share personal information for cross-context behavioral advertising or process personal information for targeted advertising. During the preceding twelve months, Quillaris has not sold or shared personal information as those terms are defined by the California Consumer Privacy Act. Quillaris does not knowingly sell or share personal information concerning individuals under sixteen years of age.
Retention and Deletion
Quillaris retains personal information only for as long as reasonably necessary for the purposes described in this Policy. We consider the following criteria when setting retention periods.
| Information | Retention criteria |
|---|---|
| Customer Data | The subscription term plus the contractual export and deletion period. The standard Terms allow export requests during the term and for ninety days after termination or expiration. Active-system deletion occurs within sixty days after that period, and backups are deleted through ordinary overwrite cycles within one hundred twenty days, unless law requires retention. |
| Account contact and professional information | The duration of the account or business relationship and a reasonable period afterward for support, relationship management, security, legal claims, and compliance. |
| Subscription billing and transaction records | The period required for billing, tax, accounting, audit, anti-fraud, dispute, and legal obligations. |
| Support and communications | The period needed to resolve the request, maintain an appropriate support history, improve support quality, address security issues, and establish or defend legal claims. |
| Security logs and technical data | The shortest period reasonably necessary for security monitoring, diagnostics, fraud prevention, availability, audit, and incident investigation. |
| Analytics and deidentified information | Analytics data is retained according to configured tool settings and operational need. Deidentified and aggregated information may be retained where it no longer reasonably identifies a Customer or individual and remains subject to non-reidentification commitments. |
| Marketing information | Until the recipient opts out or the information is no longer needed, with limited suppression records retained to honor the opt-out. |
Deletion from backups may be delayed until the applicable backup is overwritten through the ordinary cycle. Information retained for legal, security, backup, or dispute purposes remains protected and unavailable for ordinary use.
Security
Quillaris maintains commercially reasonable administrative, organizational, and technical safeguards designed to protect personal information. These safeguards include encryption in transit and at rest, tenant separation, access controls based on least privilege, authentication controls, logging and monitoring, network protections, backups, recovery procedures, and personnel confidentiality obligations.
Customer Data and confidential financial, contractual, royalty, and agency information remain protected for as long as Quillaris retains or has access to them. No security program eliminates all risk. If Quillaris becomes aware of a security incident requiring notice, it will provide notice as required by applicable law and the applicable agreement or Data Processing Addendum.
Privacy Rights and Requests
Depending on applicable law and Quillaris’s role, an individual may have the right to request access to personal information, receive a portable copy, correct inaccurate information, request deletion, withdraw consent, opt out of certain processing, limit certain uses of sensitive personal information, and appeal a decision concerning a privacy request. Individuals also may have the right not to receive discriminatory treatment for exercising privacy rights.
To submit a request concerning information controlled by Quillaris, email [email protected] with the subject line Privacy Request and describe the requested action. Quillaris may ask for information reasonably necessary to verify the request and protect against fraudulent or unauthorized disclosure. Verification information will be used only for the verification process.
An authorized agent may submit a request where permitted by law. Quillaris may require proof of the agent’s authority and may ask the individual to verify identity or directly confirm authorization. If Quillaris denies a request, the response will explain the reason and, where applicable, how to appeal. An appeal may be submitted to [email protected] with the subject line Privacy Appeal.
Requests concerning Customer Data should generally be directed to the Customer that controls the relevant account or records. Quillaris will assist the Customer in responding as required by applicable law and the applicable Data Processing Addendum.
Marketing emails include an unsubscribe method. Opting out of marketing does not prevent Quillaris from sending transactional, service, billing, legal, or security communications.
California Privacy Notice
This section applies to California residents to the extent the California Consumer Privacy Act, as amended, the CCPA, applies to Quillaris and the relevant processing. It supplements the other sections of this Policy.
Categories Collected and Disclosed
During the preceding twelve months, Quillaris may have collected the categories described below. Quillaris may disclose these categories to service providers and contractors for the listed business purposes. Quillaris has not sold or shared these categories for cross-context behavioral advertising during that period.
| CCPA category and examples | Sources | Purposes and recipient categories |
|---|---|---|
| Identifiers Name, business contact information, IP address, account identifiers, mailing address | Customers, users, integrations, identity providers, and automatic collection | Service delivery, accounts, support, communications, security; disclosed to hosting, authentication, support, communications, and security providers |
| Customer records information Contact, signature, contract, tax, SSN or TIN, and bank-account or routing information when included in Customer Data | Customers, authorized users, source systems, and payment or accounting integrations | Customer-directed agency, tax, payment, contract, and accounting functions; disclosed to infrastructure and Customer-authorized providers |
| Commercial information Orders, subscription, billing, transaction, and service history | Customers, account administrators, and payment providers | Contract administration, billing, accounting, support, audit, fraud prevention, and compliance |
| Internet or electronic network activity Browser, device, IP address, pages, sessions, usage, clickstream, and logs | Automatic collection through the Services and analytics technologies | Operation, security, diagnostics, analytics, capacity planning, and improvement using deidentified or aggregated data |
| Approximate geolocation General location inferred from an IP address | Network activity | Security, fraud prevention, localization, and analytics |
| Professional information Company, job title, business contact details, and account role | Individuals, Customers, identity providers, and business communications | Account administration, service delivery, sales, support, communications, and contract management |
| Sensitive personal information Account credentials and Customer-submitted SSN, TIN, and bank-account, routing, or ACH information | Individuals, Customers, authorized users, source systems, and integrations | Authentication and Customer-directed tax, agency, payment, security, and compliance functions |
California Rights
Subject to applicable exceptions and verification, California residents may have the following rights:
- the right to know the categories and specific pieces of personal information Quillaris has collected, the sources, purposes, and categories of recipients;
- the right to request deletion of personal information;
- the right to correct inaccurate personal information;
- the right to opt out of the sale or sharing of personal information;
- the right to limit the use or disclosure of sensitive personal information where it is used beyond legally permitted purposes;
- where applicable, rights concerning covered automated decisionmaking technology; and
- the right not to be retaliated or discriminated against for exercising CCPA rights.
Quillaris does not sell or share personal information and uses sensitive personal information only for purposes reasonably necessary to provide and secure the Services, perform requested functions, prevent fraud, comply with law, and carry out other purposes permitted without a right to limit. Quillaris therefore does not currently provide Do Not Sell or Share or Limit the Use links. If those practices change, Quillaris will provide the required notices and opt-out mechanisms before the changed processing begins.
California residents may submit a request by emailing [email protected] with the subject line California Privacy Request. Quillaris will confirm receipt and respond within the time required by law, ordinarily within forty-five days, subject to permitted extensions. Quillaris may deny or limit a request where an exception applies and will explain the decision where required.
Quillaris does not offer financial incentives or price or service differences in exchange for the collection, sale, sharing, or retention of personal information.
Children and Minors
The Services are intended for business use and are not directed to children. Individuals under eighteen years of age may not create or use an Authorized User account. Quillaris does not knowingly collect personal information directly from children under thirteen through a child-directed website or service.
A Customer may submit Customer Data relating to a minor only if the Customer has the rights, permissions, and lawful basis required to do so. Quillaris processes that information as Customer Data under the Customer’s instructions. If a parent or guardian believes a child provided personal information directly to Quillaris without appropriate authorization, the parent or guardian may contact [email protected].
United States Processing and International Users
The Services are intended primarily for United States business customers. Personal information may be processed and stored in the United States, where privacy laws may differ from those in another jurisdiction. If Quillaris offers the Services in a jurisdiction requiring additional transfer safeguards or privacy disclosures, Quillaris will provide the applicable regional notice, contractual terms, or transfer mechanism.
Changes to this Policy
Quillaris may update this Policy to reflect changes in the Services, legal requirements, or privacy practices. The Last Updated date identifies the latest revision. If a change materially affects how personal information is collected, used, or disclosed, Quillaris will provide additional notice before the change becomes effective when required by law or the applicable agreement. Quillaris will obtain consent where applicable law requires consent for the changed processing.
Contact Us
Questions, concerns, and privacy requests may be directed to:
Quillaris LLC
Attn Privacy
[email protected]