Legal

Privacy Policy

Last updated: August 2026

1. Who we are

Qelta ApS ("Qelta", "we", "us") operates the website qelta.ai and provides the Qelta platform for quality assurance of compliance case work.

  • Company: Qelta ApS
  • CVR: 46661885
  • Registered address: Strandvejen 73B, st. tv, 2100 København Ø
  • Contact for privacy matters: contact@qelta.ai

2. Scope — and the two different roles we hold

This policy explains how we handle personal data. Because we act in two distinct capacities under the GDPR, it is important to separate them:

(a) We are the data controller for personal data we collect in our own right: visitors to qelta.ai, people who contact us or request a demo, business contacts, and the account details of individual users at our customers. Sections 3–11 of this policy describe that processing.

(b) We are a data processor for the case content, documents, and records our customers submit to the Qelta platform. That data belongs to the customer, who determines the purposes and means of its processing. Our handling of it is governed exclusively by the written agreement and Data Processing Agreement (DPA) concluded with that customer — not by this policy. Individuals whose data appears in customer case files should direct requests to the relevant customer as controller; we will support our customers in responding to such requests as required under the DPA.

3. Personal data we collect as controller

Contact form. Name, email address, and your message. Optionally, your company and role.

Demo requests. Name, email address, and your selected date and time. Optionally, your company and role.

Business correspondence. Contact details and correspondence content when you communicate with us by email or through professional networks, including in the course of our sales and business-development activity.

Platform account data. For individual users at customer organisations: name, business email address, organisational role, authentication data, and access logs recording use of the platform. Access is granted only to users authorised under a customer agreement.

Error diagnostics. When an error occurs in the platform, our error-tracking provider records technical diagnostic information (such as error type, stack trace, and the technical context needed to reproduce the fault). We do not use session recording or replay.

Technical data. IP address and standard server log data (browser, pages requested, timestamps), processed by our hosting infrastructure to deliver and secure the website.

Analytics. Aggregate website usage measurement (page views, referrers, country-level location). Our analytics operates without cookies and without tracking individuals across sites.

We do not knowingly collect special categories of personal data through our website, and we ask that you do not include sensitive personal information in contact-form messages.

PurposeDataLegal basis (GDPR Art. 6)
Responding to enquiries and demo requests; following up on interest in QeltaContact and demo form dataLegitimate interest 6(1)(f) — responding to people who approach us about our services
Business development and sales correspondence with professional contactsBusiness contact dataLegitimate interest 6(1)(f) — B2B relationship building
Providing, securing, and supporting platform access for authorised usersAccount and access-log dataPerformance of a contract 6(1)(b) with the customer / legitimate interest 6(1)(f) in platform security
Operating, securing, and improving the websiteTechnical and analytics dataLegitimate interest 6(1)(f)
Meeting legal, accounting, and record-keeping obligationsAs applicableLegal obligation 6(1)(c)

We do not sell personal data, and we do not use personal data collected as controller for advertising profiling or automated decision-making producing legal effects.

5. Sub-processors and service providers

We engage the following providers, each under a data processing agreement. This list is kept current; material changes will be reflected here.

Website and business operations

ProviderPurposeLocation / safeguard
Vercel Inc.Website hosting, content delivery, server logs, aggregate analyticsEU
ResendDelivery of website form submissions to our inboxUnited States — Standard Contractual Clauses
Google Ireland Ltd. (Google Workspace)Receiving and storing business correspondenceEU

Platform

ProviderPurposeLocation / safeguard
Railway Corp.Hosting of the Qelta platform (app.qelta.ai) — application, storage, computeEU West (Amsterdam)
OpenAI Ireland Ltd.Language-model processing powering automated reviewEU
Google Cloud (Vertex AI)Language-model processing powering automated reviewEU (multi-region)
Clerk Inc.Authentication and identity management for platform users — no case contentUS
Functional Software, Inc. (Sentry)Application error tracking and diagnostics — no session recording or replayEU

Where case content is processed. All customer case content submitted to the Qelta platform is stored and processed within the European Union, including all language-model processing. Case content is not transferred outside the EU/EEA.

Model providers and your data. We do not use customer data or case content to train any model. Our model providers are engaged on terms that prohibit the use of data submitted through our platform to train or fine-tune their models.

Authentication data. Our identity provider, Clerk, processes authentication data — user name, business email, and session data — in the United States under Standard Contractual Clauses. This is limited to account and sign-in information; no case content is processed by Clerk.

A full and current list, including changes over time, is maintained at qelta.ai/legal/sub-processors.

Where a provider processes data outside the EU/EEA, transfers are protected by an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or by the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate. We assess such transfers before engaging a provider and, where a customer requires EU-only processing, we will say so plainly rather than imply coverage we do not have.

We may also disclose personal data where required by law, or where necessary to establish, exercise, or defend legal claims.

6. How long we keep it

  • Contact and demo submissions: up to 24 months after our last meaningful contact with you, unless an ongoing relationship or legal obligation requires longer.
  • Business correspondence: for the duration of the relationship and up to 24 months thereafter.
  • Platform account and access-log data: for the term of the customer agreement and up to 12 months thereafter, or as specified in that agreement.
  • Server logs: up to 90 days, per our hosting providers' standard schedules.
  • Analytics: retained only in aggregate form that does not identify individuals.
  • Records required for accounting purposes are retained for five years as required under Danish bookkeeping law.

7. Security

We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including encryption in transit, access control on a need-to-know basis, authentication controls on platform access, and logging of access to customer environments. Specific security commitments applicable to customer data are set out in the customer agreement and DPA.

No system can be guaranteed to be perfectly secure, and we do not represent otherwise.

8. Your rights

Where we act as controller, you have the right to request access to your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing based on legitimate interest; and to receive your data in a portable format. To exercise these rights, email contact@qelta.ai. We will respond within one month, and will tell you if we need longer.

If your data reached us through a Qelta customer's case files, we act as processor and will refer you to that customer as controller.

You may also complain to the Danish Data Protection Agency — Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk — or to the supervisory authority where you live or work.

9. Cookies

The website operates without non-essential cookies. We use no advertising pixels, no cross-site trackers, and no cookie-based analytics, and therefore display no consent banner.

10. Children

Our services are provided to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16 through our website.

11. Changes to this policy

We may update this policy. The current version, with its "last updated" date, is always published on this page, and we will highlight material changes.

12. Contact

Qelta ApS · CVR 46661885 · Strandvejen 73B, st. tv, 2100 København Ø, Denmark · contact@qelta.ai