Skip to content
QVUNTABUILD BETTER, MANAGE SMARTER
Trust & control

Construction disputes are settled
by documents.

Which puts an obligation on the software that produced them. This page describes how QVUNTA handles access, records and data — in plain terms, with nothing claimed that has not been built.

HOW IT IS PROTECTED

Six things QVUNTA does, and can be held to.

  • 01

    Permission is decided on the server

    Your role is resolved from live company membership on every request. Access is enforced by the backend, not hidden by the interface — a screen you cannot see is also a record you cannot read.

  • 02

    One company cannot reach another

    Companies and projects are isolated from each other at the data layer. Deactivating a member removes their access immediately and drops their project assignments with it.

  • 03

    Records that carry weight do not quietly change

    A signed contract, an approved variation, an issued certificate: these are superseded or voided, never silently edited. What you relied on last year is still what it was.

  • 04

    Documents are private by construction

    Generated PDFs and signed copies are stored privately and are not reachable by a public link. They are served only through an authorised request, and their integrity is re-checked each time.

  • 05

    Every action leaves a trace

    Who did what, when, what changed and any reason given — recorded as an audit trail the owner can read, so an approval can still be accounted for long after the conversation.

  • 06

    No analytics SDK. No ad SDK. No tracking.

    QVUNTA carries no analytics, crash-reporting or advertising SDK, and no advertising identifier. We do not collect your location. We do not track you across other apps or websites, and we do not sell personal data.

What you will not find on this page. QVUNTA holds no security certification and claims none. There is no SOC 2 report, no ISO certificate and no penetration-test badge. When that changes, this paragraph will change with it — until then, treating the absence as an absence is the only honest option.

WHAT WE DO NOT COLLECT

The shortest section, on purpose.

Most of what a construction company puts into QVUNTA belongs to its clients and its staff. The less of it that leaves the system, the better — so almost none of it does.

Biometric app-unlock, if you enable it, is handled entirely by your device. Your fingerprint or face never reaches us.

  • No analytics SDK
  • No crash-reporting SDK
  • No advertising SDK
  • No advertising identifier
  • No location collection
  • No push-notification tokens
  • No cross-app or cross-site tracking
  • No sale or sharing of personal data

SUB-PROCESSORS

Everyone else who touches the data.

QVUNTA runs on Google Firebase. Google may process data on infrastructure outside your country, including in the United States, under its own terms as our processor.

  • Firebase AuthenticationSign-in and sessions
  • Cloud FirestorePrimary datastore
  • Cloud Storage for FirebasePhotographs, attachments, generated PDFs
  • Cloud FunctionsServer-side logic, document generation
  • Google Secret ManagerBackend credentials
  • Gmail APISending a document by email when you ask
  • Google Sign-InOptional sign-in method

Report a security issue

Tell us directly and we will look at it.

security@qvunta.com

Read the privacy policy

What is collected, why, where it goes and how long it stays.

Privacy policy

Delete your account

From inside the app: Settings → Delete account.

How deletion works