1. Who we are
Qelta ApS ("Qelta", "we", "us") operates the website qelta.ai and provides the Qelta platform for quality assurance of compliance case work.
- Company: Qelta ApS
- CVR: 46661885
- Registered address: Strandvejen 73B, st. tv, 2100 København Ø
- Contact for privacy matters: contact@qelta.ai
2. Scope — and the two different roles we hold
This policy explains how we handle personal data. Because we act in two distinct capacities under the GDPR, it is important to separate them:
(a) We are the data controller for personal data we collect in our own right: visitors to qelta.ai, people who contact us or request a demo, business contacts, and the account details of individual users at our customers. Sections 3–11 of this policy describe that processing.
(b) We are a data processor for the case content, documents, and records our customers submit to the Qelta platform. That data belongs to the customer, who determines the purposes and means of its processing. Our handling of it is governed exclusively by the written agreement and Data Processing Agreement (DPA) concluded with that customer — not by this policy. Individuals whose data appears in customer case files should direct requests to the relevant customer as controller; we will support our customers in responding to such requests as required under the DPA.
3. Personal data we collect as controller
Contact form. Name, email address, and your message. Optionally, your company and role.
Demo requests. Name, email address, and your selected date and time. Optionally, your company and role.
Business correspondence. Contact details and correspondence content when you communicate with us by email or through professional networks, including in the course of our sales and business-development activity.
Platform account data. For individual users at customer organisations: name, business email address, organisational role, authentication data, and access logs recording use of the platform. Access is granted only to users authorised under a customer agreement.
Error diagnostics. When an error occurs in the platform, our error-tracking provider records technical diagnostic information (such as error type, stack trace, and the technical context needed to reproduce the fault). We do not use session recording or replay.
Technical data. IP address and standard server log data (browser, pages requested, timestamps), processed by our hosting infrastructure to deliver and secure the website.
Analytics. Aggregate website usage measurement (page views, referrers, country-level location). Our analytics operates without cookies and without tracking individuals across sites.
We do not knowingly collect special categories of personal data through our website, and we ask that you do not include sensitive personal information in contact-form messages.
4. Why we process it, and our legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Responding to enquiries and demo requests; following up on interest in Qelta | Contact and demo form data | Legitimate interest 6(1)(f) — responding to people who approach us about our services |
| Business development and sales correspondence with professional contacts | Business contact data | Legitimate interest 6(1)(f) — B2B relationship building |
| Providing, securing, and supporting platform access for authorised users | Account and access-log data | Performance of a contract 6(1)(b) with the customer / legitimate interest 6(1)(f) in platform security |
| Operating, securing, and improving the website | Technical and analytics data | Legitimate interest 6(1)(f) |
| Meeting legal, accounting, and record-keeping obligations | As applicable | Legal obligation 6(1)(c) |
We do not sell personal data, and we do not use personal data collected as controller for advertising profiling or automated decision-making producing legal effects.
5. Sub-processors and service providers
We engage the following providers, each under a data processing agreement. This list is kept current; material changes will be reflected here.
Website and business operations
| Provider | Purpose | Location / safeguard |
|---|---|---|
| Vercel Inc. | Website hosting, content delivery, server logs, aggregate analytics | EU |
| Resend | Delivery of website form submissions to our inbox | United States — Standard Contractual Clauses |
| Google Ireland Ltd. (Google Workspace) | Receiving and storing business correspondence | EU |
Platform
| Provider | Purpose | Location / safeguard |
|---|---|---|
| Railway Corp. | Hosting of the Qelta platform (app.qelta.ai) — application, storage, compute | EU West (Amsterdam) |
| OpenAI Ireland Ltd. | Language-model processing powering automated review | EU |
| Google Cloud (Vertex AI) | Language-model processing powering automated review | EU (multi-region) |
| Clerk Inc. | Authentication and identity management for platform users — no case content | US |
| Functional Software, Inc. (Sentry) | Application error tracking and diagnostics — no session recording or replay | EU |
Where case content is processed. All customer case content submitted to the Qelta platform is stored and processed within the European Union, including all language-model processing. Case content is not transferred outside the EU/EEA.
Model providers and your data. We do not use customer data or case content to train any model. Our model providers are engaged on terms that prohibit the use of data submitted through our platform to train or fine-tune their models.
Authentication data. Our identity provider, Clerk, processes authentication data — user name, business email, and session data — in the United States under Standard Contractual Clauses. This is limited to account and sign-in information; no case content is processed by Clerk.
A full and current list, including changes over time, is maintained at qelta.ai/legal/sub-processors.
Where a provider processes data outside the EU/EEA, transfers are protected by an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or by the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate. We assess such transfers before engaging a provider and, where a customer requires EU-only processing, we will say so plainly rather than imply coverage we do not have.
We may also disclose personal data where required by law, or where necessary to establish, exercise, or defend legal claims.
6. How long we keep it
- Contact and demo submissions: up to 24 months after our last meaningful contact with you, unless an ongoing relationship or legal obligation requires longer.
- Business correspondence: for the duration of the relationship and up to 24 months thereafter.
- Platform account and access-log data: for the term of the customer agreement and up to 12 months thereafter, or as specified in that agreement.
- Server logs: up to 90 days, per our hosting providers' standard schedules.
- Analytics: retained only in aggregate form that does not identify individuals.
- Records required for accounting purposes are retained for five years as required under Danish bookkeeping law.
7. Security
We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including encryption in transit, access control on a need-to-know basis, authentication controls on platform access, and logging of access to customer environments. Specific security commitments applicable to customer data are set out in the customer agreement and DPA.
No system can be guaranteed to be perfectly secure, and we do not represent otherwise.
8. Your rights
Where we act as controller, you have the right to request access to your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing based on legitimate interest; and to receive your data in a portable format. To exercise these rights, email contact@qelta.ai. We will respond within one month, and will tell you if we need longer.
If your data reached us through a Qelta customer's case files, we act as processor and will refer you to that customer as controller.
You may also complain to the Danish Data Protection Agency — Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk — or to the supervisory authority where you live or work.
9. Cookies
The website operates without non-essential cookies. We use no advertising pixels, no cross-site trackers, and no cookie-based analytics, and therefore display no consent banner.
10. Children
Our services are provided to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16 through our website.
11. Changes to this policy
We may update this policy. The current version, with its "last updated" date, is always published on this page, and we will highlight material changes.
12. Contact
Qelta ApS · CVR 46661885 · Strandvejen 73B, st. tv, 2100 København Ø, Denmark · contact@qelta.ai