Loading
Qivoranta is an AI-powered customer-service platform that helps businesses provide immediate assistance, automate routine interactions and deliver better customer experiences.
Information for business customers about Qivoranta processing personal data on their behalf.
This page explains Qivoranta's standard approach to processing personal data for business customers. It complements the Privacy Policy and the applicable customer agreement. Where required, the customer and Epixel Solution enter into a Data Processing Addendum ("DPA") that forms part of the contractual relationship.
When a business customer determines why and how personal data is processed through Qivoranta, that customer is normally the controller and Qivoranta/Epixel Solution acts as processor. Qivoranta remains a controller for personal data it processes for its own account administration, billing, security, sales, legal compliance and business operations.
When acting as processor, Qivoranta processes personal data only to provide, secure, maintain and support the Service and to perform functions configured or instructed by the customer. Processing can include hosting, storing, transmitting, retrieving, organizing, transforming, generating AI responses, supporting workflows, integrating authorized systems, troubleshooting and maintaining service security.
Processing generally continues for the duration of the customer's subscription or service agreement. After termination, Customer Data is returned or deleted in accordance with the applicable agreement, subject to normal backup cycles, legal obligations and any agreed export period.
Depending on the customer's use case, data subjects can include:
Depending on the customer configuration, Qivoranta can process:
Customers should not submit sensitive or special-category information unless the use case has been assessed, is lawful, is supported by the agreed Service, and the necessary safeguards have been implemented.
Qivoranta processes Customer Data in accordance with the customer's documented instructions, including the customer agreement, DPA, authorized product configuration, API calls, integration settings and support instructions. If an instruction would require processing that is unlawful, Qivoranta may inform the customer and suspend the affected processing to the extent necessary.
Personnel authorized to access Customer Data are subject to confidentiality obligations and are granted access only to the extent reasonably necessary for their responsibilities. Access is managed using role and permission controls appropriate to the Service.
Qivoranta applies technical and organizational measures appropriate to the nature of the Service and the risks of the processing. These measures include controls relating to user access, authentication, secure communications, system monitoring, vulnerability management, backup and recovery, incident response, confidentiality and operational security. Enterprise customers can request additional security information as part of procurement or contractual due diligence.
Qivoranta uses third-party service providers and subprocessors to support infrastructure, AI functionality, communications, security, monitoring, support and other technical functions necessary to deliver the Service. When a provider processes Customer Data on Qivoranta's behalf, it is subject to contractual data-protection and confidentiality obligations appropriate to the service it provides.
For business customers for whom Qivoranta acts as processor, the applicable named subprocessor schedule is provided through the relevant DPA, order documentation or procurement materials so that it reflects the providers and processing locations relevant to the customer's deployment. Where required by the applicable DPA, Qivoranta will provide notice of material changes to subprocessors.
Where Customer Data is transferred internationally and applicable law requires a transfer safeguard, Qivoranta uses an appropriate lawful mechanism, such as an adequacy decision, approved standard contractual clauses or another recognized transfer mechanism, together with supplementary measures where appropriate.
Qivoranta processes Customer Data to provide, secure and support the contracted Service. Customer Data is not used by Qivoranta for unrelated general-purpose model training unless the customer has expressly authorized that use in writing. Where an AI provider processes Customer Data as part of a configured service, the provider is handled under the applicable contractual and data-processing arrangements.
Taking into account the nature of the processing, Qivoranta will provide reasonable assistance to a customer in responding to requests from individuals exercising applicable data-protection rights where the relevant data is processed through the Service and the customer cannot reasonably complete the request without Qivoranta's assistance.
Qivoranta maintains an incident-response process. Where Qivoranta becomes aware of a confirmed personal data breach involving Customer Data for which it acts as processor, it will notify the affected customer without undue delay to the extent required by applicable law and the DPA and will provide available information reasonably necessary for the customer to assess its own obligations.
At the end of the service relationship, Qivoranta will return or delete Customer Data in accordance with the applicable agreement and DPA, subject to normal backup cycles and any legal requirement to retain specific information. Data retained solely because of a legal obligation or backup cycle remains protected and is not used for unrelated purposes.
Qivoranta will make reasonable information available to business customers to demonstrate compliance with agreed processor obligations. The scope, confidentiality, frequency and method of audits or compliance reviews are governed by the applicable DPA or enterprise agreement.
Some customer deployments may create higher data-protection risk because of the nature, scale or context of the processing or because they involve sensitive information, vulnerable individuals or significant automated decisions. The customer is responsible for determining whether a data-protection impact assessment or similar review is required, and Qivoranta will provide reasonable information about the Service to assist with that assessment.
Company for Information Technology and Services EPIXEL SOLUTION
DOOEL Skopje-Čair
Metodija Mitevski St. No. 3-2/8, Skopje-Čair, North Macedonia
Email:
info@epixelsolution.com