
PrivacyPolicy
Last updated: 15 February 2026
1. Introduction
Qall Technologies Ltd ("Qall," "we," "us," or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website (www.qall.ai), use our cloud-based insurance CRM platform (the "Platform"), or otherwise interact with us.
We are the data controller for the personal data we collect directly from you. When processing personal data on behalf of our clients (e.g., policyholder or advisor data entered into the Platform), we act as a data processor.
This policy is issued in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, job title, company name, phone number, and business address when you register for an account or request a demo
- Contact Form Submissions: Name, email address, primary business barrier, and message content when you submit a contact enquiry
- Billing Information: Payment card details, billing address, and VAT number (processed securely via our PCI-compliant payment processor)
- Communication Data: Records of correspondence when you contact our support team, participate in surveys, or provide feedback
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, session duration, click patterns, and navigation paths within the Platform
- Device Information: Browser type, operating system, device type, screen resolution, and language preferences
- Log Data: IP address, access times, referring URLs, and server response codes
- Cookies and Similar Technologies: See Section 8 (Cookie Policy) for details
2.3 Client Data (Processed on Behalf of Clients)
When our clients use the Platform, they may upload or input data relating to their advisors, policyholders, commissions, and business operations. This data is processed by Qall strictly in accordance with our clients' instructions and the terms of our Data Processing Agreement (DPA). This may include:
- Advisor names, contact details, and performance metrics
- Policyholder names, policy numbers, and coverage details
- Commission amounts, payment schedules, and override structures
- Lead information including source, status, and conversion data
3. How We Use Your Information
We process your personal data for the following purposes:
- Service Delivery: To provide, maintain, and improve the Platform, including commission calculations, performance analytics, and advisor management tools
- Account Management: To create and manage your account, process subscriptions, and handle billing
- Communication: To respond to enquiries, provide customer support, send service notifications, and deliver product updates
- Analytics and Improvement: To understand how the Platform is used, identify trends, and improve functionality and user experience
- Security: To detect, prevent, and address technical issues, fraud, and unauthorised access
- Legal Compliance: To comply with applicable laws, regulations, and legal processes, including FCA regulatory requirements
- Marketing: To send promotional communications about Qall services, where you have consented or where we have a legitimate interest (you may opt out at any time)
4. Legal Basis for Processing
We rely on the following legal bases under the UK GDPR:
- Contract Performance (Article 6(1)(b)): Processing necessary to perform our contract with you, including providing access to the Platform and processing payments
- Legitimate Interests (Article 6(1)(f)): Processing necessary for our legitimate interests, including improving our services, ensuring Platform security, and conducting business analytics, where those interests are not overridden by your rights
- Consent (Article 6(1)(a)): Where you have given clear consent for us to process your personal data for specific purposes, such as marketing communications
- Legal Obligation (Article 6(1)(c)): Processing necessary to comply with a legal obligation, including tax, accounting, and regulatory requirements
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with the following categories of recipients:
- Service Providers: Trusted third-party providers who assist with hosting (AWS, UK region), payment processing, email delivery, analytics, and customer support — all bound by contractual data protection obligations
- Insurance Partners: Where required to facilitate integrations with insurance carriers and providers as part of the Platform's functionality, and only with your authorisation
- Professional Advisors: Lawyers, auditors, and accountants where necessary for the operation of our business
- Legal Requirements: Where disclosure is required by law, regulation, legal process, or enforceable governmental request
- Business Transfers: In connection with a merger, acquisition, or sale of all or a portion of our business, with appropriate confidentiality protections
6. International Transfers
Your data is primarily stored and processed within the United Kingdom. Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including:
- UK adequacy regulations recognising the recipient country's data protection standards
- International Data Transfer Agreements (IDTAs) or UK Addendum to EU Standard Contractual Clauses
- Binding Corporate Rules where applicable
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Account Data: Retained for the duration of your subscription and for 12 months following termination to facilitate data export requests
- Client Data: Retained for 30 days following account termination, after which it is permanently deleted unless a longer retention period is required by law
- Billing Records: Retained for 7 years in accordance with HMRC requirements
- Contact Enquiries: Retained for 24 months from the date of submission
- Usage and Analytics Data: Retained in anonymised form for up to 36 months
8. Cookie Policy
We use cookies and similar tracking technologies to enhance your experience. The categories of cookies we use are:
- Strictly Necessary: Essential for the Platform to function, including session management, authentication, and security cookies. These cannot be disabled.
- Performance and Analytics: Help us understand how visitors interact with our website and Platform, enabling us to improve functionality and user experience.
- Functional: Enable enhanced functionality and personalisation, such as remembering your preferences and settings.
- Marketing: Used to deliver relevant advertisements and measure the effectiveness of marketing campaigns. These are only set with your consent.
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of the Platform.
9. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data in certain circumstances
- Right to Restrict Processing: Request that we limit the processing of your personal data
- Right to Data Portability: Request your personal data in a structured, commonly used, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes
- Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects
To exercise any of these rights, please contact us at privacy@qall.ai. We will respond to your request within one month, as required by law. There is no fee for making a request unless it is manifestly unfounded or excessive.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- AES-256 encryption for data at rest and TLS 1.3 for data in transit
- Role-based access controls with multi-factor authentication
- Regular vulnerability assessments and penetration testing
- SOC 2 Type II compliance programme
- Automated backup and disaster recovery procedures
- Employee security awareness training and background checks
- Incident response procedures with 72-hour breach notification capability
11. Children's Privacy
The Platform is designed for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by email or through a prominent notice on the Platform at least 14 days before the changes take effect.
We encourage you to review this Privacy Policy periodically for the latest information on our privacy practices.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Qall Technologies Ltd — Data Protection
Email: privacy@qall.ai
Website: www.qall.ai
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Website: ico.org.uk
Telephone: 0303 123 1113