This Privacy Policy explains how PreQMS, LLC, a Florida limited liability company ("PreQMS," "we," "us," or "our"), collects, uses, discloses, and protects personal information in connection with our business-to-business software-as-a-service platform and related websites and services (collectively, the "Service").
We designed the Service for medical device companies, software companies, and regulatory and quality professionals. We take privacy seriously and have written this Policy to be transparent about our practices. This Policy is designed to support compliance with applicable privacy laws, including the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other U.S. privacy laws where applicable, and to meet the expectations of enterprise customers.
By using the Service, you acknowledge this Privacy Policy. If you do not agree with it, please do not use the Service.
Because PreQMS is a B2B platform, our role depends on the type of information involved:
If you are an employee, contractor, or other individual whose personal information appears in Customer Data, please direct your privacy requests to the customer that controls that data. We will support our customers in responding to such requests as required by our agreements and applicable law.
2.1 Account Information. When you register for or are invited to the Service, we collect information such as your name, business email address, job title, organization name, and authentication credentials.
2.2 Customer Data. We collect and process the content you and your authorized users submit to or create within the Service, which may include software requirements, design descriptions, use cases, test cases, traceability data, risk documentation, uploaded documents, source code, and prompts. Customer Data may contain personal information that you choose to include. You are responsible for the Customer Data you submit and should only submit content you are authorized to disclose. Customer represents that it has obtained all rights, permissions, and consents necessary to submit Customer Data to the Service and to have it processed as described in this Policy. The Service is not intended to process Protected Health Information ("PHI") subject to HIPAA unless the parties have entered into a Business Associate Agreement ("BAA").
2.3 Billing Information. When you purchase a subscription, our third-party payment processor collects payment and billing details (such as billing name, address, and payment method). We do not store full payment card numbers; those are handled by our payment processor. We retain limited billing records (such as invoices and transaction identifiers) for accounting and legal purposes.
2.4 Usage Data. We collect information about how you interact with the Service, such as features used, actions taken, pages viewed, timestamps, referring pages, and log data. We use Usage Data to operate, secure, analyze, and improve the Service.
2.5 Device Information. We collect technical information about the devices and browsers used to access the Service, such as IP address, browser type, operating system, device identifiers, and general (city- or region-level) location inferred from IP address.
2.6 Cookies and Similar Technologies. We and our service providers use cookies and similar technologies to operate the Service, remember your preferences, maintain sessions, and understand usage. See Section 9 for details, including your choices.
2.7 Analytics. We may use analytics tools to understand how the Service is used so we can improve it. These tools may collect Usage Data and Device Information. Analytics are used only to improve the Service and are not used to profile individuals for advertising.
2.8 Communications. When you contact us for support, sales, or other purposes, we collect the information you provide and records of our communications.
We do not intentionally collect special categories of data (such as health, biometric, or government identifiers) about individuals through our own controller processing. You should not submit such data as Customer Data unless your agreement with us expressly permits it.
As a controller, we use the personal information described above to:
We process Customer Data solely to provide and support the Service in accordance with our customer's instructions and our agreements, including generating AI Output as described in Section 4.
3.1 Access to Customer Data. Access to Customer Data is limited to authorized personnel who require access for support, security, maintenance, legal compliance, or operation of the Service. We do not access Customer Data except as necessary to provide support requested by the customer, operate and maintain the Service, investigate security incidents, comply with law, or as otherwise authorized by the customer.
4.1 Optional AI Features. The Service includes optional AI-assisted features that help draft and analyze content. When you use these features, the prompts and related Customer Data you submit are processed to generate a response ("AI Output"). AI Output that a customer elects to save, retain, modify, or incorporate into its documentation becomes Customer Data.
4.2 Transmission to Third-Party AI Providers. The AI features currently transmit submitted prompts and related Customer Data to Anthropic, PBC ("Anthropic"), the provider of the Claude models, or to any successor or additional third-party AI provider (each, a "Third-Party AI Provider"), solely for the purpose of generating AI Output. You should only submit content you are authorized to disclose to a Third-Party AI Provider.
4.3 No Use for General Model Training. Under Anthropic's commercial API terms in effect as of the Last Updated date, prompts and Customer Data that PreQMS transmits to Anthropic through the API are not used to train Anthropic's general-purpose AI models. PreQMS does not opt in to any program that would permit such training, and PreQMS does not use Customer Data or AI Output to train general-purpose machine learning or artificial intelligence models. Anthropic may retain limited data for a short period for security, abuse-prevention, and legal-compliance purposes in accordance with its own policies.
4.4 Independent Third Parties. Third-Party AI Providers are independent third parties that process Customer Data in accordance with their own privacy policies and contractual commitments. While we carefully select providers, we do not control, and are not responsible for, the independent privacy, security, retention, or processing practices of Third-Party AI Providers. Third-Party AI Providers may change their practices over time, and customers are responsible for reviewing the current policies of any Third-Party AI Provider they choose to use through the Service.
4.5 Changes to Third-Party AI Providers. We may change Third-Party AI Providers from time to time. Material changes affecting the processing of Customer Data will be reflected in this Privacy Policy and our Subprocessor List where appropriate.
4.6 Accuracy and Review. AI Output may be inaccurate, incomplete, outdated, or otherwise unsuitable, and may not reflect current standards or regulatory expectations. AI Output must be independently reviewed, verified, and validated by qualified personnel before any use or reliance. You may not rely solely on AI Output.
The Service does not use personal information to make solely automated decisions that produce legal or similarly significant effects on individuals. AI Features are assistive tools that support human authoring and review, and do not replace human decision-making.
We do not sell personal information. We share personal information only as described below.
6.1 Service Providers and Subprocessors. We share information with third-party service providers and subprocessors that perform services on our behalf — such as cloud hosting, AI processing (Third-Party AI Providers), payment processing, email delivery, and analytics — under contracts that require them to protect the information and use it only to provide services to us. See Section 7 for our subprocessors.
6.2 Within Your Organization. Information within your account may be accessible to other authorized users and administrators of your organization, consistent with the access controls you configure.
6.3 Legal Disclosures. We may disclose information if we believe in good faith that it is necessary to (a) comply with applicable law, regulation, legal process, or governmental request; (b) enforce our agreements and policies; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of PreQMS, our users, or others. Where legally permitted, we will use reasonable efforts to notify the affected customer of a legally compelled disclosure of Customer Data.
6.4 Business Transfers. If PreQMS is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, personal information may be transferred as part of that transaction. The acquiring entity will be bound by obligations substantially consistent with this Privacy Policy, or we will provide notice and choices as required by applicable law.
6.5 With Consent or at Your Direction. We may share information for other purposes with your consent or at your direction.
We engage subprocessors to help provide the Service. Our current subprocessors include, by category:
| Category | Purpose | Provider(s) |
|---|---|---|
| AI processing | Generate AI Output | Anthropic, PBC |
| Cloud hosting / infrastructure | Host and run the Service | Railway |
| Payment processing | Process payments and billing | Stripe |
| Transactional email | Deliver account and service emails | Resend |
We maintain a current list of subprocessors (the "Subprocessor List"), which is available upon request. We may update this list from time to time. Where required by our agreements, we provide advance notice of new subprocessors and an opportunity to object.
We send transactional and administrative communications (such as account notices, security alerts, billing messages, and service updates) that are necessary to provide the Service; you cannot opt out of these while you have an account. We may also send product and marketing communications; you can opt out of these at any time by using the unsubscribe link or by contacting us. Opting out of marketing does not affect transactional communications. We do not sell or rent mailing lists.
9.1 Cookies. We use strictly necessary cookies to operate the Service (for example, to maintain sessions and security) and may use functional and analytics cookies to remember preferences and understand usage. Strictly necessary cookies cannot be disabled without affecting the Service. We do not use advertising cookies.
9.2 Managing Cookies. You can control cookies through your browser settings. Disabling certain cookies may affect functionality. Cookie preferences may change as we add functionality.
9.3 Do Not Track and Global Privacy Control. Some browsers offer "Do Not Track" ("DNT") signals. Because there is no common industry standard for DNT, we do not currently respond to DNT signals. Where required by applicable law, we honor recognized opt-out preference signals such as the Global Privacy Control ("GPC") for opt-out of "sale" or "sharing."
9.4 No Cross-Context Behavioral Advertising. We do not use the Service to serve targeted advertising and we do not "sell" or "share" personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.
10.1 International Transfers. We are based in the United States, and we and our subprocessors may process personal information in the United States and other countries. These countries may have data-protection laws different from those in your jurisdiction. Where we transfer personal information subject to the GDPR from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK Addendum, and implement supplementary measures where appropriate. Transfer mechanisms may change over time as applicable laws evolve. Customers may request information about the transfer mechanisms applicable to Customer Data.
10.2 Data Residency. The Service and Customer Data are hosted in the United States. Customers may contact us for current information about where their Customer Data is hosted.
We maintain administrative, technical, and physical safeguards appropriate to the nature of the Service and the sensitivity of the data processed, designed to protect personal information, including encryption in transit, access controls, and monitoring. We maintain security logging and monitoring appropriate for detecting unauthorized access and abuse. We will investigate suspected security incidents using commercially reasonable efforts and take commercially reasonable steps to mitigate their impact. Our security measures are continuously evaluated and may change without notice. No system is completely secure, and we cannot guarantee absolute security. You are responsible for using strong, unique credentials, protecting your account, and configuring access appropriately. We will notify affected parties of a security incident where required by applicable law or our agreements.
We retain personal information for as long as needed to provide the Service, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and context. Unless otherwise required by law or contract, Customer Data is deleted in accordance with our retention schedule following termination of the applicable subscription, and is deleted or returned as provided in our agreement with the customer. Backup copies may persist for a limited period before being securely overwritten in the ordinary course. We may retain limited records (such as billing and audit logs) as necessary for legal and accounting purposes, and we may retain de-identified or aggregated data that no longer identifies an individual.
The rights available to you depend on where you are located and applicable law. To exercise any right, see Section 16. We will not discriminate against you for exercising your rights. We may need to verify your identity before responding, and for Customer Data we will direct requests to the relevant customer (controller).
13.1 GDPR / UK GDPR Rights. If you are in the EEA, the UK, or Switzerland, you have the right to: access your personal information; correct inaccurate information; request erasure; restrict or object to processing; data portability; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.
Our legal bases for processing (as a controller) are: performance of a contract (to provide the Service and administer accounts); legitimate interests (to secure, analyze, and improve the Service, and for direct communications, balanced against your rights); consent (where required, such as for certain cookies or marketing, which you may withdraw); and legal obligation (to comply with law).
13.2 CCPA/CPRA Rights (California). If you are a California resident, you have the right to: know the categories and specific pieces of personal information we collect, use, and disclose; delete personal information, subject to exceptions; correct inaccurate personal information; opt out of the "sale" or "sharing" of personal information; and limit the use of sensitive personal information. We do not sell or share personal information, and we do not use sensitive personal information for purposes that require a right to limit. You may exercise these rights yourself or through an authorized agent, and we will not discriminate against you for doing so. Note that much of the personal information we process in a B2B context may relate to your employer's account.
13.3 Other U.S. State Rights. Residents of certain other U.S. states may have similar rights to access, correct, delete, and opt out. We honor these rights as applicable law requires.
14.1 Notice at Collection. The categories of personal information we collect are described in Section 2. We collect this information for the business purposes in Section 3 and disclose it to the categories of recipients in Section 6. We do not sell or share personal information.
14.2 Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing.
The Service is intended for business use by individuals who are at least eighteen (18) years old. The Service is not directed to children, and we do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will delete it. If you believe a child has provided us personal information, please contact us.
To exercise a privacy right, or for any question about this Policy or our practices, contact us at:
PreQMS, LLC
Privacy Requests
2805 Hogan Ln, Crestview, FL 32539
Email: privacy@preqms.com
Website: https://preqms.com
If your request concerns personal information contained in Customer Data, we will refer you to, or coordinate with, the customer that controls that data.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and provide notice by posting the revised Policy or by other reasonable means. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.