Legal document

Privacy Policy

This first-layer summary explains who controls your data, why we use it, and how to exercise your rights. The detailed sections below provide the fuller notice.

Effective date
September 12, 2026
Version
2026-09-12

1. Controller and contact

The controller is Valendra Tech S.L., NIF B22798409, Calle Larga 43, 11402 Jerez de la Frontera, Cádiz, Spain. For privacy questions or rights requests, contact support@valendra.tech.

We process personal data to provide QDivZero infrastructure and deployment services, keep accounts and systems secure, process payments and legal obligations, answer support requests, improve the service where permitted, and send optional communications only where you have the required choice or legal basis.

2. Data we process

  • Account and authentication data, such as email address, password credentials, verification records, sessions, and security events.
  • Organization, billing, fiscal-profile, payment, invoice, and credit-ledger data.
  • Infrastructure, API, security, audit, device, IP address, user-agent, availability, and diagnostic data.
  • Prompts, files, model inputs, outputs, and logs only to the extent that the deployed service or a configured provider actually stores or processes them.
  • Support messages and other information you choose to provide to us.

Do not send information to a deployed model unless you have the right to do so and have assessed the risks. The retention and processing of prompts, files, inputs, outputs, and logs can depend on the deployment, runtime, and provider configuration; this policy does not promise that those materials are never retained, shared, or used for training.

Log retention and Responses API persistence are optional and can be disabled globally. The Responses API uses store: true by default, but it only works when global persistence is enabled. When global persistence is enabled, stored responses are kept for technical purposes, such as allowing a response_id to be used in subsequent API requests; you can intentionally disable persistence if you do not want this behavior.

3. Purposes, legal bases, and retention

  • Account provision and authentication: performance of the contract; kept while the account is active and then for the periods needed for security, claims, and legal duties.
  • Billing, payments, invoices, credits, and fiscal records: performance of the contract and legal obligations; retained for the applicable accounting, tax, payment, and limitation periods.
  • Security, fraud prevention, API, and audit records: legitimate interests and legal obligations; retained for a period proportionate to security and claim-management needs.
  • Support: performance of the contract or legitimate interests; retained while needed to resolve the request and manage related claims.
  • Service improvement: legitimate interests or consent where required; retained only for the criteria and period appropriate to the specific data and purpose.
  • Optional communications: consent or another applicable legal basis; retained until you withdraw the choice or the communication relationship ends.

When a fixed period is not possible, we use the criteria above and delete, anonymize, or restrict data when it is no longer needed, subject to backups, disputes, legal holds, and mandatory retention. Prompt, file, input, output, and log retention has no single repository-backed period: it depends on the selected deployment, runtime, provider, and configuration, so the applicable current production configuration and provider retention terms must be checked before use.

4. Recipients and providers

We share data only as needed for the purposes described here, with service providers acting under appropriate instructions and safeguards. Depending on the selected product and deployment, these can include Stripe for payment, tax, and invoice services; configurable GPU infrastructure providers such as RunPod or Vast.ai; Hugging Face as a model source; Cloudflare Turnstile for CAPTCHA where enabled; and PostHog for analytics and session recording only after you expressly enable analytics. We may also share data when required by law, a valid authority, or to protect rights and safety.

The actual provider, region, and processing path depend on the selected product, deployment, and configuration. Production provider assignments, locations, transfer mechanisms, and provider retention settings are not fully verifiable from this repository at all times, so the applicable current production configuration and provider information must be checked before relying on this notice. This notice does not assert that a provider never retains or trains on service data.

5. International transfers

If data is transferred outside the European Economic Area, we use an adequacy decision or another lawful safeguard such as Standard Contractual Clauses, together with supplementary measures where appropriate. Contact us for information about the safeguard applicable to a specific processing activity.

6. Your rights

You can request access, rectification, erasure, restriction, portability, or objection, and you can withdraw consent where processing relies on consent. Send a request to support@valendra.tech with enough information for us to verify and handle it. You also have the right to complain to the Spanish Data Protection Agency (AEPD).

7. Cookies and separate choices

QDivZero uses essential cookies and storage needed for account security and operation. Non-essential analytics or marketing tracking is kept separate and is controlled through the existing cookie-consent mechanism. You can review your cookie choices using the cookie-preference control when it is available.