Privacy policy
Last updated 16 August 2026
QVUNTA is project-management software for construction companies. A contracting company (“the Company”) uses QVUNTA to run its projects, record site evidence, control costs and produce formal documents. Its customers (“Clients”) receive a read-only portal.
1. What we collect, and why
| Category | What it is | Why |
|---|---|---|
| Identity & account | Name, email address, account ID, password (stored hashed by Firebase Authentication), optional profile photo | To sign you in and to attribute actions to a person in audit trails and on documents |
| Company & membership | Company name, commercial registration and VAT numbers, address, phone, logo and stamp, your role, membership status | To separate one company's data from another's, to decide what you may do, and to put a letterhead on generated documents |
| Client records | Client name, contact person, email, phone, address, portal access | To address documents and to give a Client access to their own project |
| Project content | Projects, tasks, comments, issue reports, material requests, site updates, timeline entries | Core functionality |
| Messages | Messages between Company staff and Clients, with author and time | Project communication |
| Photos & files | Site evidence photographs, handover photographs, item images, attachments, signature images, scanned signed copies | Evidence of work done and supporting documents. Photographs may incidentally include people on site |
| Financial records | Cost items, quotations, purchase orders, deliveries, vendor payments, client receipts, contract values, variation amounts, VAT, company bank account details | Cost control and commercial documents |
| Audit records | Who did what, when, what changed, and any stated reason | So that a contract, certificate or approval can be relied on later |
| Generated documents | PDFs containing names, signatures, company identifiers and figures | The service's deliverable |
| Recipient address, subject, body, PDF attachment, delivery status | To send a document when you choose to | |
| Notifications & settings | In-app notifications, theme, language, region | To run the app the way you set it |
2. Where it is processed
QVUNTA runs on Google Firebase. These are our only sub-processors:
| Sub-processor | Purpose |
|---|---|
| Firebase Authentication | Sign-in and sessions |
| Cloud Firestore | Primary datastore |
| Cloud Storage for Firebase | Photographs, attachments, generated PDFs |
| Cloud Functions | Server-side logic, document generation |
| Google Secret Manager | Backend credentials |
| Gmail API | Sending a document by email when you ask |
| Google Sign-In | Optional sign-in method |
Google processes this data on infrastructure that may be located outside your country, including in the United States, under Google's own terms as our processor. Using QVUNTA means data may be processed internationally in that way.
3. How it is protected
- All traffic is encrypted in transit (HTTPS/TLS). Data is encrypted at rest by Google.
- Access is enforced on our servers, not merely hidden in the app. Your role is resolved server-side from live membership on every request.
- Companies and projects are isolated from one another.
- Generated PDFs and scanned signed copies are stored privately and are not reachable by a public link. They are served only through an authorised request, and their integrity is re-checked each time.
- Records that carry legal or financial weight are immutable — they are superseded or voided, never quietly edited.
4. How long it is kept
- Account data — for as long as your account exists (see section 5).
- Project, financial and document records — these belong to the Company, not to an individual, and are kept for as long as the Company keeps them.
- Audit records and issued documents — retained permanently. A signed contract, an issued certificate or an approved variation must remain provable, and a document already delivered to a Client or an authority cannot be recalled.
5. Deleting your account
You can delete your QVUNTA account from inside the app: Settings → Delete account. There is a fuller explanation, including what happens if you can no longer sign in, on our account deletion page.
Deleted: your profile (name, email, photo, preferences), your sign-in credentials and Firebase Authentication account, your company and project access, and your device session.
Anonymised: your identity is detached from audit records — the entry keeps what happened and when, and your name and account ID are replaced with a permanent non-identifying marker.
Retained: the Company's own business records — projects, contracts, certificates, variation orders, handovers, financial entries and documents already issued. These are the Company's records rather than yours, and deleting an account does not erase them. Where your name is already printed inside a document that has been issued to a Client or an authority, that document cannot be altered.
If you are the owner of a company, you must first transfer ownership to another active member of that company. This exists so a company is never left with no one able to administer it.
6. Your choices
- You can view and correct your profile in the app at any time.
- You can delete your account as described above.
- Where data was entered about you by a Company, ask that Company; we will support them in responding.
- Depending on where you live you may have further rights over your personal data. Contact us and we will explain what we can do.
7. Children
QVUNTA is business software and is not directed at children. We do not knowingly collect data from children.
8. Changes
If this policy changes we will update the date at the top of this page. Material changes affecting how we handle personal data will be signalled in the app.
9. Contact
Questions about this policy or about your data: privacy@qvunta.com. See also our support page.
QUESTIONS
- Privacy — privacy@qvunta.com
- Support — support@qvunta.com
- Security — security@qvunta.com