1. IntroductionThis Privacy Policy describes how TrackerQMS collects, uses, discloses, stores, protects, and otherwise processes information in connection with our websites, hosted applications, software services, support services, communications, APIs, integrations, and related offerings. TrackerQMS is intended for use by organizations that manage regulated quality operations, supplier controls, controlled documents, quality events, compliance evidence, electronic approvals, audit trail activity, and other business records.
By accessing or using TrackerQMS, submitting information to us, communicating with us, or using our services on behalf of an organization, you acknowledge that information may be processed as described in this Privacy Policy. If you use TrackerQMS on behalf of an organization, references to “you” or “customer” may refer to both the individual user and the organization that controls the applicable account.
2. Information We CollectTrackerQMS may collect information that customers, users, prospective customers, administrators, and authorized representatives provide directly to us. This may include names, business email addresses, phone numbers, job titles, company names, billing information, account registration details, authentication information, support requests, procurement information, implementation information, security questionnaire responses, and other information submitted through forms, communications, contracts, or platform workflows.
TrackerQMS may also collect information generated through use of the platform, including user activity, login history, audit trail events, workflow activity, document activity, supplier records, quality records, electronic signature events, configuration settings, metadata, attachments, search activity, feature usage, API activity, integration activity, support interactions, device information, browser information, IP addresses, session identifiers, log data, and diagnostic information. Some of this information may be necessary to provide the service, maintain auditability, investigate security events, support customer operations, or comply with contractual and legal obligations.
3. Customer ContentCustomers may upload, enter, generate, transmit, store, or process content through TrackerQMS, including supplier information, controlled documents, document metadata, quality records, CAPA records, nonconformance records, complaint records, audit records, training records, calibration records, compliance evidence, workflow decisions, approvals, electronic signatures, attachments, comments, and other operational records. This information is referred to in this Privacy Policy as Customer Content.
Customers retain ownership of Customer Content. TrackerQMS processes Customer Content for the purpose of providing, securing, supporting, maintaining, and improving the services, and as otherwise permitted by agreement or applicable law. Customers are responsible for determining whether Customer Content is appropriate for submission to TrackerQMS, whether additional contractual safeguards are required, and whether the platform is suitable for the customer’s intended regulatory, privacy, security, retention, or compliance use case.
4. How We Use InformationTrackerQMS may use information to provide the services, authenticate users, administer customer accounts, configure subscriptions, process transactions, operate quality workflows, maintain audit trails, deliver alerts and notifications, provide support, respond to inquiries, troubleshoot issues, monitor system performance, improve product functionality, enforce agreements, protect the security and integrity of the services, comply with legal obligations, and communicate with customers about service, security, operational, billing, or administrative matters.
We may also use information to analyze usage trends, understand customer needs, improve product design, develop new features, maintain business records, conduct internal reporting, prevent fraud or abuse, detect unauthorized activity, investigate incidents, and support regulatory, procurement, or security review processes requested by customers. Where required by applicable law, TrackerQMS will rely on an appropriate legal basis for processing personal information.
5. Legal Bases for ProcessingWhere applicable privacy laws require a legal basis for processing personal information, TrackerQMS may process information based on performance of a contract, legitimate business interests, compliance with legal obligations, protection of rights and security, consent, or other lawful grounds. Our legitimate interests may include providing secure business software, supporting customers, improving services, preventing misuse, maintaining auditability, communicating with customers, and operating our business.
When TrackerQMS processes personal information on behalf of a customer as a processor or service provider, the customer is responsible for establishing the lawful basis for processing and providing any required notices or consents to its users, employees, suppliers, contractors, or other individuals whose information may be submitted to the platform.
6. Disclosure of InformationTrackerQMS may disclose information to service providers, subprocessors, contractors, professional advisors, affiliates, and other parties that assist us in operating, securing, supporting, billing, improving, or delivering the services. These parties may provide hosting, infrastructure, authentication, analytics, payment processing, communications, customer support, monitoring, logging, backup, implementation, security, legal, accounting, or other business services.
TrackerQMS may also disclose information when required by law, legal process, governmental request, court order, regulatory inquiry, or to protect the rights, safety, property, or security of TrackerQMS, customers, users, or others. In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, information may be disclosed or transferred as permitted by law and applicable agreements.
7. SecurityTrackerQMS maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, disclosure, or destruction. These safeguards may include encryption, authentication controls, access controls, secure hosting practices, audit logging, monitoring, vulnerability management, backup processes, employee access limitations, incident response procedures, and other security practices appropriate to the nature of the services.
No method of transmission, storage, hosting, or processing is completely secure. Customers are responsible for maintaining appropriate administrative controls within their own accounts, including user provisioning, role assignments, permission configuration, password practices, device security, internal policies, and timely removal of access for users who no longer require platform access.
8. Data RetentionTrackerQMS may retain information for as long as necessary to provide the services, support customer accounts, comply with legal obligations, resolve disputes, enforce agreements, maintain security, preserve auditability, complete backups, satisfy operational requirements, and support business records. Retention periods may depend on the type of information, customer configuration, subscription status, contractual terms, legal obligations, backup cycles, and the nature of the applicable records.
Customers may have the ability to export, delete, archive, or configure certain records within the platform depending on their subscription, permissions, and enabled functionality. Deletion or termination requests may not immediately remove information from backups, logs, archives, or records that must be retained for legal, security, operational, or compliance reasons.
9. Cookies and Similar TechnologiesTrackerQMS websites and services may use cookies, local storage, pixels, session identifiers, analytics tools, and similar technologies to operate the website, authenticate users, maintain sessions, remember preferences, measure usage, analyze performance, improve functionality, support security, and understand how customers and visitors interact with our services.
Users may configure browser settings to block or limit certain cookies. Some features may not function properly if cookies or similar technologies are disabled, particularly features related to authentication, account security, session management, preferences, and protected areas of the platform.
10. Artificial Intelligence FeaturesTrackerQMS may provide artificial intelligence or automation-assisted features that help users search, summarize, classify, draft, analyze, or interpret information within the platform. Customer use of AI-enabled functionality may involve processing Customer Content, prompts, outputs, usage metadata, and related context necessary to provide the requested functionality.
Customers are responsible for reviewing AI-assisted outputs before relying on them for quality, regulatory, compliance, legal, technical, or operational decisions. AI-assisted features are intended to support human decision-making and do not replace customer responsibility for approvals, validation, regulatory interpretation, compliance obligations, or quality system decisions.
11. International TransfersInformation may be processed, stored, or accessed in jurisdictions other than the location where a user or customer is located. These jurisdictions may have data protection laws that differ from those in the user’s jurisdiction. Where required, TrackerQMS may implement contractual, technical, or organizational safeguards intended to support lawful international transfers.
Customers are responsible for determining whether their use of TrackerQMS involves cross-border transfers of personal information, regulated records, supplier information, or other data subject to jurisdiction-specific requirements.
12. Privacy RightsDepending on applicable law, individuals may have rights to request access to personal information, correction of inaccurate information, deletion of information, restriction of processing, portability of information, objection to processing, withdrawal of consent, or information regarding disclosures. These rights may be subject to limitations, exceptions, verification requirements, contractual obligations, legal requirements, and the nature of the information involved.
Where TrackerQMS processes personal information on behalf of a customer, individuals should generally direct requests to the customer that controls the applicable account or data. TrackerQMS may assist customers in responding to requests as required by applicable agreement or law.
13. Regulated Information and Customer ResponsibilitiesTrackerQMS is designed to support regulated quality operations, but customers remain responsible for determining whether the platform is appropriate for their intended use and regulatory environment. Customers are responsible for validation, configuration, procedure definition, training, approval practices, record retention, regulatory interpretation, supplier controls, audit readiness, and compliance with applicable laws, standards, and internal policies.
Customers should not submit protected health information, export-controlled information, classified information, highly sensitive personal information, or other restricted data unless authorized to do so and unless appropriate contractual, technical, and compliance arrangements are in place.
14. Children’s PrivacyTrackerQMS is intended for business and organizational use. The services are not directed to children and are not intended for use by individuals under the age required by applicable law to consent to the processing of personal information. TrackerQMS does not knowingly collect personal information from children in violation of applicable law.
15. Changes to This Privacy PolicyTrackerQMS may update this Privacy Policy from time to time to reflect changes in law, regulation, technology, security practices, business operations, or platform functionality. When changes are made, the effective date may be updated and the revised Privacy Policy may be posted on our website or made available through the platform.
Continued use of TrackerQMS after an updated Privacy Policy becomes effective constitutes acknowledgment of the updated policy. Customers are encouraged to review this Privacy Policy periodically.
16. ContactQuestions regarding this Privacy Policy, privacy practices, data handling, security reviews, or related matters may be directed to TrackerQMS through the contact methods provided on the TrackerQMS website. Customers with enterprise agreements should follow any notice procedures specified in the applicable agreement.