Privacy Policy
This policy describes how Quarks Data and its products — Essential, Trace, Qida and Aura — collect, use, share and protect the information of the people who interact with our sites, applications, conversational channels and services.
1. Who we are
Quarks Data ("Quarks", "we") is a data and artificial intelligence infrastructure company operating in Venezuela, Central America, the United States and other Latin American markets, through its Essential platform and its products Trace, Qida and Aura, as well as through its applied research practice, Quarks Labs.
This policy applies to the personal data we process as a data controller through our websites, contact forms, mobile applications and conversational channels, and, in certain cases, as a data processor when we process data on behalf of our enterprise customers under a services agreement.
2. Data we collect
Depending on the product or channel you interact with, we may collect:
Identification and contact
- Name, email address, phone number and job title or company.
- Access credentials for our platforms and applications.
Communications
- The content of messages, emails, calls and conversations held through our commercial and support channels, including instant messaging and voice channels.
- Audio recordings or transcripts when a voice channel is used to book appointments, follow up commercially or provide support, always with prior notice.
Transactions and payments
- Billing information and payment history. Full card or bank account details are processed directly by specialized payment providers certified under the PCI-DSS standard; Quarks does not store full card numbers in its own systems.
Product usage
- Usage records for Essential, Trace, Qida and Aura, including events, performance metrics and interactions with artificial intelligence agents.
- Technical data such as IP address, device type, browser and session identifiers.
Sensitive data in specific contexts
When we provide services to customers in healthcare (Qida) or financial services, we may process clinical, treatment adherence or financial data, always under the instruction of the responsible customer and with the corresponding contractual and technical safeguards.
3. How we use data
- Provide, operate and maintain our products and services.
- Process payments, subscriptions and billing.
- Send transactional, support, commercial and follow-up communications by email, messaging or voice.
- Personalize and automate commercial or clinical interactions through artificial intelligence agents.
- Perform analytics, reporting and continuous improvement of our models and products.
- Comply with legal, regulatory and contractual obligations, including applicable sector requirements.
- Prevent fraud, abuse and misuse of our platforms.
4. Legal basis for processing
We process personal data on one or more of the following legal bases, depending on the applicable jurisdiction, including, where relevant, the European Union General Data Protection Regulation and the data protection laws of the countries where we operate.
- Performance of a contract: when processing is necessary to provide a service you requested.
- Consent: for marketing communications or uses that require it, revocable at any time.
- Legitimate interest: for security, fraud prevention and product improvement, balanced against your rights.
- Legal obligation: when an applicable rule requires us to retain or report certain information.
5. Providers and data processors
To operate our products, we share personal data with external providers acting as data processors under contractual instructions and confidentiality and security obligations. These categories include, among others:
- Payment processing: PCI-DSS certified providers that handle charges, subscriptions and fraud prevention.
- Communications and messaging: telecommunications infrastructure providers that enable messaging, voice calls and automated notifications.
- Voice synthesis and processing: providers specialized in voice generation and analysis through artificial intelligence, used in conversational agents.
- Artificial intelligence models: providers of language models and AI inference that process text, voice or structured data to generate responses, summaries or recommendations within our products.
- Cloud infrastructure and hosting: compute, storage and network providers that host our applications and databases.
- Analytics and observability: tools for technical monitoring, error detection and aggregate usage analysis.
All of our providers are contractually required to process data only for the purposes instructed by Quarks, to apply appropriate security measures and not to use the personal data they process on our behalf to train their own models in an unauthorized manner, unless the law provides otherwise or there is express consent.
We do not sell personal data to third parties for advertising or direct marketing purposes.
6. Use of artificial intelligence
Our products, in particular Aura and the conversational agents of Qida, use artificial intelligence systems to qualify contacts, book appointments, follow up commercially and answer questions by text or voice.
- When you interact with an artificial intelligence agent, we indicate it in a reasonable way, especially on voice channels.
- Decisions with significant effects on a person are not made on a solely automated basis without the possibility of human intervention, unless a specific legal basis allows it.
- You may request information about the general logic applied by these systems, as well as request human review, under the terms of the rights section.
7. International transfers
We operate from Caracas, Miami, San José and Bogotá, and we use infrastructure and data processing providers located in different jurisdictions, including the United States and the European Union. This means your personal data may be transferred and processed outside the country where you reside.
Where applicable, we implement recognized transfer mechanisms, such as standard contractual clauses, adequacy assessments or equivalent contractual safeguards, and we apply hybrid architectures when regulatory sensitivity requires it.
8. Data retention
We retain personal data for as long as necessary to fulfill the purposes described in this policy, including compliance with legal, accounting, regulatory or claim defense obligations. Retention criteria vary depending on the type of data and the contractual context with each enterprise customer; once the applicable periods expire, data is securely deleted or anonymized.
9. Information security
We apply reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration or improper disclosure, including:
- Encryption of data in transit and, where applicable, at rest.
- Role-based access control and the principle of least privilege.
- Environment segmentation and activity monitoring across our systems and cloud infrastructure.
- Periodic assessment of critical providers and their security practices.
No system is completely infallible; in the event of a relevant incident, we will act as described in the incident notification section.
10. Your rights
Depending on your location and applicable regulations, you may have the right to:
- Access: know what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request the deletion of your data when it is no longer necessary or you withdraw your consent.
- Portability: receive your data in a structured, commonly used format.
- Objection and restriction: object to certain processing or request that it be restricted.
- Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
To exercise these rights, write to us at privacidad@quarksdata.com. We will verify your identity before processing the request and will respond within the timeframes required by applicable law.
11. Cookies
Our sites and applications may use first-party and third-party cookies, as well as similar technologies (pixels, local storage), to remember preferences, measure site performance and understand how our products are used. You can manage your preferences from your browser settings; disabling certain cookies may limit some functionality.
12. Minors
Our products are intended for companies and professionals, and are not designed to be used by minors. We do not knowingly collect data from minors without the verifiable consent of their parents or guardians, except in the strictly necessary context of healthcare services provided by our customers (for example, Qida), where processing is carried out under the responsibility and instruction of the corresponding healthcare provider.
13. Incident notification
If we detect a security incident affecting personal data in a way that may pose a risk to the people involved, we will notify the corresponding customers or data subjects and, where the law requires it, the competent authorities, within the applicable timeframes.
14. Changes to this policy
We may update this policy to reflect changes in our products, providers or applicable regulations. We will publish the current version on this same page along with the date of the last revision, and, when the change is substantial, we will notify you by a reasonable means.
15. Contact
If you have questions about this policy or about the processing of your personal data, you can write to us at privacidad@quarksdata.com or contact@quarksdata.com.