This Privacy Policy explains how Q5 Systems Ltd. handles information in the Q5SMS authenticated web application and the related Q5 mobile applications. It should be read together with the Customer’s applicable agreements, instructions, and legal obligations.
1. Who we are and what this policy covers
Q5 Systems Ltd. (“Q5,” “we,” “us,” or “our”) is the developer and publisher of Q5SMS and the Q5 mobile applications covered by this Privacy Policy. This policy explains our general practices for handling personal information and other data through the authenticated Q5SMS web application and the following Android and iOS applications: Q5 Safety Event (also called Q5 Event), Q5 Assessment (also called Q5SMS Audit or Inspection), Q5SMS Documents, and Q5SMS COR.
This policy applies to Q5-hosted and customer-hosted deployments of those applications. It does not apply to the public q5systems.com marketing website or to third-party websites and services that have their own privacy notices.
2. Business-to-business service and responsibility for Customer Data
Q5SMS is a business-to-business safety, quality, compliance, and operational-management service. Access is provided through the user’s employer or another organization that contracts with Q5 (the “Customer”). Accounts are provisioned and administered by the Customer; individual users do not independently create Q5SMS accounts through the covered applications.
The Customer owns and controls the information entered, uploaded, configured, generated, or stored for that Customer in Q5SMS (“Customer Data”). The Customer determines why Customer Data is collected, which users may access it, how it may be used or disclosed, and how long it must be retained, subject to the Customer’s agreements and applicable law. Each Customer is assigned a separate Q5SMS site and database so that its Customer Data is separated from the Customer Data of other Customers.
Q5 processes Customer Data as a service provider or processor to develop, provide, host where applicable, secure, maintain, and support Q5SMS in accordance with the Customer’s instructions and applicable agreements. Q5 separately determines limited processing necessary for service administration, diagnostics, security, support, the protection of legal rights, and compliance with law.
This policy describes Q5’s general practices. The applicable Master Services and Licensing Agreement, Purchase Order, data protection agreement, Customer instructions, or law may establish more specific or additional requirements. Consistent with the Q5 Master Services and Licensing Agreement, the Customer owns its Customer Data; Q5 treats Customer Data as confidential, receives only the limited rights needed to provide the services, and handles return, deletion, or legal preservation in accordance with the applicable agreement and law.
3. Information handled through Q5SMS
Depending on the applications, modules, Customer configuration, and features used, Q5SMS may handle the following categories of information:
- Account and professional information. Names, usernames, business email addresses, employee or personnel identifiers, organization, site, team, roles, permissions, assignments, authentication records, and login history.
- Operational Customer Data. Information entered, uploaded, generated, or processed through Q5SMS modules and related workflows, such as audits, inspections, assessments, incidents, events, hazards, risks, actions, training and skills, documents, forms, reporting, and related workflow and audit records.
- Photos, attachments, and files. Photographs, documents, scanned files, and other content supplied by users or Customers.
- Location information. GPS coordinates or other location details that are configured, manually entered, or optionally collected through a supported mobile feature. Location use depends on the application, Customer configuration, device permission, and user action.
- Technical and usage information. IP address, browser or device type, operating system, app and SDK version, session records, server logs, installation or app-instance identifiers, app interactions, map interactions, crash state, stack traces, and diagnostic information.
- Support information. Support communications and diagnostic materials supplied by Customer representatives or generated while investigating an issue.
- Anonymous reports. Report content and related technical or security logs where a Customer enables anonymous reporting. Although the report form may not require the reporter’s identity, the content or technical records may still contain or permit inferences about individuals.
Customer-configured operational records may contain personal information or sensitive information depending on the Customer’s configuration and what users enter or upload. Customers and users should enter only information that is appropriate, authorized, and necessary for the applicable business purpose.
4. How information is collected and used
Q5SMS receives information from users, Customer administrators, Customer configurations, devices and browsers, use of the service, support interactions, and integrations selected by the Customer.
Q5 and the Customer may use or otherwise process the information, as applicable, to:
- authenticate users, administer accounts, and enforce roles and permissions;
- provide offline work, synchronization, data entry, workflow, notification, reporting, document, audit-trail, and other Q5SMS functions;
- configure, host, maintain, update, and support the service;
- respond to support requests and diagnose or correct errors;
- monitor performance, availability, security, misuse, and reliability;
- protect Customers, users, Q5, the service, and legal rights; and
- comply with applicable law, legal process, contracts, and record-preservation requirements.
Where a legal basis is required, processing may be based on Customer instructions, performance of a contract, Q5’s or the Customer’s legitimate operational and security interests, compliance with legal obligations, or consent where required. The appropriate basis depends on the information, purpose, relationship, and applicable law.
Q5 does not sell Customer Data. Q5 does not use Customer Data for third-party behavioural advertising.
5. Mobile applications and offline information
The Q5 mobile applications may store Customer Data locally on a mobile device to support offline work, drafts, downloads, queued uploads, synchronization, and related functions. Depending on the application, local information may include account or site details, operational records, photos, attachments, or downloaded documents.
Protection of local information relies on a combination of application controls, operating-system protections, device security settings, and any mobile-device-management controls applied by the Customer. This policy does not represent that every local copy is encrypted by the application itself. Users and Customers are responsible for protecting devices, applying security updates, using device access controls, and promptly reporting lost or compromised devices.
Local copies may remain until they are synchronized, cleared by an application function, affected by a server-side or Customer-administration change, removed through operating-system or device-management controls, or deleted when the application is uninstalled. The exact result depends on the application, device platform, synchronization state, Customer configuration, and device controls.
7. Hosting, data location, and security
Q5SMS may be hosted by Q5 or hosted by the Customer. Current Q5-hosted production environments are located in Canada. Hosting or processing locations may change where permitted by the applicable agreement, and customer-hosted environments may be located in jurisdictions selected or approved by the Customer.
For Q5-hosted production environments, production databases and backups are encrypted at rest. Q5 requires communications with Q5SMS over public networks to use HTTPS/TLS. Customer-hosted deployments must be configured and operated to meet the security and communications requirements in the applicable agreement; the Customer is principally responsible for its hosting infrastructure, physical safeguards, backups, network configuration, system administration, and data-residency choices.
Q5 uses administrative, technical, and organizational measures appropriate to the service and the risks involved. These measures include access controls, confidentiality requirements, backup and recovery processes, security updates and patching, monitoring, logging, and incident-response procedures. Access to Customer Data is limited to authorized personnel and providers who need it for permitted purposes.
No method of storage or transmission is completely secure. If Q5 becomes aware of a security incident involving information for which Q5 has notification responsibility, Q5 will investigate, take appropriate response measures, and provide notifications as required by applicable law and contract.
8. Service providers, integrations, and disclosures
Q5 uses service providers to operate, secure, maintain, and support Q5SMS. These may include hosting and infrastructure providers, email and communications providers, security providers, support tools, and professional advisers. Providers receive only the information reasonably required for their functions and are subject to applicable confidentiality, security, and data-protection obligations.
Depending on the application and feature used, Q5 mobile applications use Google services such as Firebase Analytics, Firebase Crashlytics, and Google Maps, and the web application may use Google reCAPTCHA. These services may process limited technical information, including:
- Firebase Analytics: app-instance or installation identifiers, application interactions, session or usage information, app and device information, and approximate geographic information derived from network information;
- Firebase Crashlytics: a Crashlytics installation identifier, stack traces, relevant application state, device metadata, crash and non-fatal error information, and diagnostic logs or keys configured by Q5;
- Google Maps: request and device metadata, IP address, a Maps SDK identifier, map interactions such as panning or zooming, stack traces, and crash metrics; and
- Google reCAPTCHA: IP address, browser and device information, interaction data, and security signals used to distinguish legitimate activity from automated abuse.
The particular information processed depends on the application version, configuration, feature, and user activity. Q5 uses these Google services for operational analytics, reliability, crash diagnosis, maps and location-related features, and security - not for third-party behavioural advertising. Google and other providers may process limited information in jurisdictions outside the user’s or Customer’s location.
A Customer may configure or select integrations such as single sign-on, email, reporting, application programming interfaces, or other third-party services. Information sent through a Customer-selected integration is also subject to the Customer’s arrangements with the selected provider and that provider’s privacy practices.
Q5 uses an external mobile-application developer for software-development services. The developer works with source code and synthetic or test data and does not have routine access to production Customer Data. Any exceptional access must be specifically authorized and controlled under Q5’s confidentiality and security requirements.
Q5 may disclose information when required by law, court order, subpoena, or other valid legal process, or when reasonably necessary to investigate misuse, protect the security of Q5SMS, protect Customers or users, enforce agreements, establish or defend legal claims, or protect the rights, safety, or property of Q5 or others. Where legally permitted and appropriate, Q5 will seek to preserve confidentiality and notify the affected Customer.
9. Retention, account administration, and deletion
Customer Data is retained according to the Customer’s instructions and agreement, configured record schedules, operational and audit requirements, applicable legal obligations, unresolved disputes or claims, security needs, and the time reasonably required to provide the service. Because requirements vary by Customer and record type, this policy does not establish one universal retention period.
Disabling or deleting an employee’s Q5SMS account removes or ends that person’s access, but normally does not erase attributable business records, submitted forms, approvals, workflow history, or audit trails. Those records may need to remain for the Customer’s operational, contractual, audit, safety, employment, insurance, or legal purposes. Account credentials and other account-specific information are handled according to Customer instructions, technical requirements, and applicable retention obligations.
When a production deletion is approved, copies may remain in restricted disaster-recovery backups until they expire through normal backup rotation. Information may be preserved longer where required by law, legal hold, security investigation, or unresolved dispute. Backups are maintained for recovery and are not ordinarily used to restore individual deleted records.
Following termination of a Customer’s services, Customer Data is returned or deleted as provided by the applicable agreement and Customer instructions, subject to legal preservation requirements.
10. Access, correction, restriction, and deletion requests
Because the Customer controls Customer Data and user accounts, employees and other authorized users should direct requests to access, correct, restrict, or delete Customer Data or an account to their employer or the Customer’s Q5SMS administrator. Q5 will assist the Customer as required by the applicable agreement and law. Q5SMS does not offer a general self-service right to erase Customer-owned corporate records, and an employee request does not itself authorize Q5 to delete them.
For questions about this policy, or requests concerning support, diagnostic, security, or administrative information controlled by Q5, contact [email protected]. Q5 may verify the requester’s identity and authority and refer a Customer Data request to the applicable Customer.
11. International processing
Q5 is based in Canada, and current Q5-hosted production environments are in Canada. Google and other providers may process limited technical information in other jurisdictions, and customer-hosted deployments may operate in locations selected or approved by the Customer. Where required, cross-border processing is addressed through applicable agreements, provider terms, contractual safeguards, and law.
12. Children
Q5SMS is a business and workforce service. It is not directed to children or intended for personal or consumer use by children. Customers must ensure that users are authorized for workplace access and comply with legal requirements for any information about minors entered into Customer Data.
13. Changes to this policy
Q5 may update this policy to reflect changes in the applications, data practices, service providers, agreements, or legal requirements. Q5 will revise the effective or last-updated date at the top of the policy and provide more specific notice where required by law or contract.
14. Contact Q5
Q5 Systems Ltd.
15 Hallett Crescent, Suite 203
St. John’s, Newfoundland and Labrador, Canada A1B 4C4
Email: [email protected]
When contacting Q5 about a Customer Data request, identify the Customer organization and Q5SMS site involved. Do not send passwords or unnecessary Customer Data by email.