Last updated: 16 September 2026.
1. Who is responsible
QA Vault is operated by Alina Lysenko, registered as an individual entrepreneur (sole proprietor) in Ukraine and trading as QA Vault. For privacy enquiries and rights requests, email team@qa-vault.com.
This policy covers the website, waitlist, web application, hosted MCP service and support. QA Vault determines the purposes of its own account administration, communications and service operations. When we process personal data in workspace content on a customer's behalf, the customer's instructions and our Data Processing Agreement govern that processing.
2. Information we process
- Website and waitlist: email address, the form or source of a request, submission date and browser user-agent information. Hosting infrastructure also handles technical request metadata.
- Accounts and teams: email, profile information, authentication records, workspace membership, roles, project access and invitations. A team administrator can provide your email when inviting you.
- Workspace content: test cases and steps, suites, runs, results and snapshots, defects, links, rules, lessons, tags and search abstracts.
- Search and integration data: search queries, information derived from workspace content to support search, API-key identifiers and metadata, MCP session information and actions performed through connected clients.
- Support and operations: messages you send, relevant diagnostic information, activity records and error logs.
- Billing: when you make a purchase, the customer and transaction references, subscription state, seat quantity and billing information necessary to administer your access and assist with payment enquiries.
3. Purposes and legal bases
We process information to provide the service you request, authenticate access, maintain workspace permissions, store test content and make it searchable, administer subscriptions and answer support requests.
Where data-protection law requires a legal basis, processing necessary to provide a contract with you relies on that contract. Account administration for an organisation's authorised users, service security and proportionate misuse prevention rely on legitimate interests where those interests are not overridden by your rights. Statutory recordkeeping and required disclosures rely on legal obligations. Optional communications or technologies that require consent rely on that consent.
A waitlist request asks for one message when access opens. It does not subscribe you to unrelated marketing. You can withdraw the request by contacting us. Accepting the Terms and receiving this privacy information do not constitute blanket consent to every use of personal data.
4. Search processing and connected AI services
To make workspace content searchable and find relevant matches, QA Vault automatically processes test-case text, including descriptions, conditions, steps and search summaries. Specialised search and AI service providers receive relevant content for this purpose, and search queries when you use semantic search. We store information derived from this processing alongside your workspace content to support search.
This automatic processing operates on both free and paid workspaces. It continues after a trial ends or a workspace returns to the free plan, including for newly created or edited content and imports. Restricting access to semantic search does not stop this background processing.
Information derived for search remains linked to the underlying content and is covered by this policy; we do not assume that this processing makes personal data anonymous. Only submit material you are entitled to have processed for these purposes.
When you connect an MCP client or AI assistant, that client receives the data returned within its authorised access. You or your workspace choose the client and its provider. Their own terms, privacy settings and data practices apply to the information they receive.
5. Service providers and other recipients
- Cloud hosting and infrastructure providers: operate the website and application services, handle connection and session information, and store waitlist requests.
- Data storage and account-access providers: store workspace content and account records, authenticate users and support authorised access to the service.
- Search and AI processing providers: process relevant workspace text and search queries to make content searchable and find relevant results, as described above.
- Email delivery and support communication providers: delivery of applicable account and operational messages, and handling communications with support.
- Paddle: purchase, subscription, tax and payment administration for transactions made through Paddle. Paddle processes information for its own payment responsibilities under its Privacy Policy.
Customers who act as controllers of personal data in their workspace content find the named subprocessors, their purposes and locations in the Data Processing Agreement.
Authorised workspace users receive content according to their permissions. Technical resources loaded from third parties, such as externally hosted fonts in the application, also involve requests to their providers. Disclosure can also be necessary to comply with law, protect rights or respond to a security incident.
Processing locations: cloud hosting and infrastructure providers operate a global network of data centres, including locations in the European Union and the United States; data storage and account-access providers keep account records and workspace content in the European Union (Ireland); search and AI processing providers process workspace text and search queries in the United States and are not restricted to a single region; email delivery and support communication providers process messages in the United States and in other locations of their global infrastructure. QA Vault itself accesses data from Ukraine. Applicable restrictions on international transfers and any required safeguards, such as contractual transfer protections, form part of the arrangements governing that processing. Contact us for information about the safeguards applicable to your data.
6. Browser storage and access records
The application uses browser storage for authentication, preferences, workspace selection and local drafts. Local drafts are stored on your device and are distinct from saved server records. Use care on shared devices and clear site data when appropriate.
Operational records support troubleshooting, access management and proportionate investigation of misuse. Multiple clients or IP addresses do not, by themselves, establish that an account is shared. Access restrictions and privacy enquiries are subject to human review through support.
The website uses Google Analytics 4, provided by Google Ireland Limited, to count visits and see which pages are read. It runs only after you choose Accept in the cookie banner; nothing from Google loads before that. With your consent, Google sets the _ga and _ga_* cookies on this site for up to two years and receives the pages you view, the referring site, approximate location derived from your IP address (Google Analytics does not store the address itself) and rough browser and device information. Google processes this data under its Privacy Policy and Google's data-processing terms; advertising features and Google Signals are switched off. Your choice is kept in your browser under qav-consent. You can change it at any time through Cookie settings in the footer: rejecting stops measurement and removes the analytics cookies for this site.
Other non-essential storage is not used. External websites and clients have their own storage practices.
7. Retention and deletion
Data retention follows the purpose of the record and applicable legal requirements. Ending a trial or subscription does not itself delete the workspace, its content or the information held to support search.
- Waitlist: the relevant retention period covers delivery of the requested access notification or withdrawal of the request, with any necessary evidence of the request retained separately under the applicable schedule.
- Account and workspace records: retention supports the active account or workspace, authorised deletion requests and any applicable legal or dispute obligations.
- Historical content: test-run snapshots and activity records can contain information from a case independently of the current case. Deleting a case and deleting all related historical records are separate operations.
- Operational logs, support records and backups: separate retention periods account for troubleshooting, recovery, legal obligations and the rights of other workspace users.
The following periods apply unless a longer period is required by law, by an ongoing dispute or investigation, or by the rights of other workspace users:
- Waitlist requests: kept until the requested access notification is sent or the request is withdrawn, and deleted within 30 days after that. The notification email that records the request is kept as a support record.
- Account and workspace records: kept while the account or workspace exists, and deleted within 30 days after a verified deletion request or account closure.
- Historical content, activity records and import logs: kept while the workspace exists and deleted with it, unless the customer requests earlier deletion of specific historical records.
- Operational logs (connection, request and error logs generated by the application and its infrastructure): no longer than 30 days.
- Support records: no longer than 24 months after the request is closed.
- Backups: overwritten on a rolling cycle of no more than 30 days; content deleted from the service leaves the backups when that cycle completes.
- Billing references: kept for as long as tax and accounting law requires.
Send deletion and offboarding requests to team@qa-vault.com. A request requires appropriate identity and authority checks. Your personal account request does not automatically authorise deletion of an organisation's entire workspace or other users' records. The response explains any lawful reason for retaining particular data.
8. Your rights
Depending on applicable law and the processing involved, you may have rights to access, correct or erase personal data, receive a portable copy, restrict or object to processing, and withdraw consent without affecting the lawfulness of earlier processing.
Contact us to exercise a right or raise a concern. Requests are handled within the periods required by applicable law. You also have the right to complain to a competent data-protection authority where applicable.
If your request concerns data controlled by your organisation, contact its workspace administrator or privacy contact. QA Vault assists with requests within its responsibilities and the customer's instructions.
9. Changes and contact
This policy carries a revision date. Changes to data processing require the information, notice and, where applicable, consent required before the changed processing begins.
Contact: team@qa-vault.com.