> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Qumo Deploy collects, uses, and safeguards personal data under GDPR, CCPA/CPRA, and APPI.

# Privacy Policy

**Last updated: September 2026**

Qumo Deploy ("the Service") is operated by **Foalk, Inc.** ("the Company", "we", "us", or "our"). This Privacy Policy explains our practices regarding the collection, storage, and processing of personal data across the Qumo Deploy web console (`console.qumo-deploy.com`), REST APIs (`api.qumo.dev`), documentation site (`docs.qumo-deploy.com`), and corporate presence (`qumo-deploy.com`).

***

## 1. Personal Data We Collect

Depending on your interactions with the Service, we process the following categories of information:

| Category                   | Information Collected                                                                                                                     | Purpose                                                                            |
| :------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------------------------- |
| **Account Profile**        | User UUID, full name, email address, avatar URL, and GitHub login handle.                                                                 | Identity verification, session authentication, and invitation routing.             |
| **Authentication & OIDC**  | OAuth provider identifiers (Google, GitHub), device flow verification codes, and encrypted tokens.                                        | Secure authentication and delegated authorization.                                 |
| **Session & Network Logs** | Client IP address, user-agent string, session expiry timestamps, and request path metadata.                                               | Security telemetry, abuse prevention, brute-force mitigation, and CSRF protection. |
| **Audit Logs**             | Immutable, append-only records of control plane administrative operations (e.g. project provisioning, API key issuance, bot role grants). | Tenant governance, security review, and enterprise compliance reporting.           |
| **Billing & Transactions** | Customer ID, payment method tokens (processed via Stripe), billing email address, subscription plan, and bandwidth metering events.       | Invoicing, subscription billing enforcement, and usage quota monitoring.           |

***

## 2. Lawful Basis for Processing (GDPR Article 6)

For individuals located in the European Economic Area (EEA) and the United Kingdom, we process personal data under the following legal bases:

* **Contractual Necessity (Art. 6(1)(b))**: Necessary to provision your workspace, authenticate sessions, issue short-lived relay credentials, and deliver the core Qumo Deploy orchestration service requested under our Terms of Service.
* **Legitimate Interests (Art. 6(1)(f))**: Necessary to monitor system health, enforce rate limits, maintain tamper-evident audit logs, and secure the global edge network against attacks.
* **Legal Obligation (Art. 6(1)(c))**: Necessary for tax compliance, corporate bookkeeping, and lawful government requests.
* **Consent (Art. 6(1)(a))**: Used exclusively for non-essential cookies and analytics preferences, which may be granted or withdrawn at any time.

***

## 3. Third-Party Sub-Processors

We engage trusted infrastructure and software service providers to deliver the Service. Each sub-processor is bound by data protection agreements meeting the requirements of GDPR Article 28:

| Sub-Processor                 | Service Provided                                                    | Location      |
| :---------------------------- | :------------------------------------------------------------------ | :------------ |
| **Amazon Web Services (AWS)** | Cloud infrastructure hosting, compute nodes, and private relay VPCs | US, Japan, EU |
| **Cloudflare, Inc.**          | Cloudflare R2 object storage, DNS routing, and edge DDoS protection | Global        |
| **Cockroach Labs, Inc.**      | CockroachDB Serverless distributed relational database              | United States |
| **Stripe, Inc.**              | Payment card processing, subscription billing, and tax invoicing    | United States |
| **GitHub, Inc.**              | OAuth 2.0 OIDC login authentication and repository sync             | United States |

<Note>
  We **do not** sell, rent, or trade your personal information. We do not engage in cross-context behavioral advertising and do not use customer telemetry to train public machine-learning models.
</Note>

***

## 4. Your Rights

Under applicable privacy regulations (including GDPR, UK GDPR, and the Japanese APPI), you have the right to:

* **Access**: Request confirmation and copies of your personal data held by us.
* **Rectification**: Request correction of incomplete or inaccurate data.
* **Erasure ("Right to be Forgotten")**: Request deletion of your personal account (`DELETE /admin/v1/users/me`), subject to legal retention constraints.
* **Data Portability**: Export your personal data in structured, machine-readable JSON format (`GET /admin/v1/users/me/export`).
* **Object & Restrict**: Object to processing based on legitimate interests or request restrictions during ongoing disputes.

***

## 5. California Consumer Privacy Rights (CCPA / CPRA)

If you are a California resident:

* **Notice of Collection**: We collect the identifiers, commercial transaction details, and internet activity described in Section 1 solely for business operational purposes.
* **No Sale or Sharing**: We do not sell or share personal information as defined under the California Consumer Privacy Act.
* **Minors**: We do not knowingly collect personal data from individuals under 16 years of age.
* **Exercising Rights**: California residents may submit verifiable privacy requests by emailing `privacy@qumo-deploy.com`. You will not face discrimination or altered service tiers for exercising your legal privacy rights.

***

## 6. Cookies and Storage

* **Essential Cookies**: Necessary for session state (`qumo_session`), CSRF tokens (`qumo_csrf`), and authentication flow continuity. These cannot be disabled.
* **Preferences**: Local browser storage (`~/.qumo/config.json` for CLI, `localStorage` for console project preferences).
* **Telemetry**: Opt-in analytics cookies are active only upon explicit acceptance via our Cookie Consent banner.

***

## 7. Contact Us

For data protection inquiries, Data Subject Access Requests (DSAR), or compliance verification:

* **Email**: `privacy@qumo-deploy.com`
* **Postal Address**: Foalk, Inc., Compliance & Legal Affairs, Tokyo, Japan
