EasyQBR Privacy Policy
Effective date: September 17, 2026
Controller / provider: EasyQBR, LLC, 1452 Redwine Rd, Fayetteville, GA 30215, legal@easyqbr.com
1. Who this is about
EasyQBR is used by managed service providers ("Customers") to prepare reports about the environments of their own clients. This policy explains what we collect about three groups:
- Customer users — the people at a Customer who sign in to EasyQBR.
- Customer clients' data — information about a Customer's clients that reaches us through the vendor systems a Customer connects. For that data the Customer is the controller and EasyQBR processes it on the Customer's instructions.
- Visitors to our sign-in page and public pages.
2. What we collect, and why
2.1 Account information (Customer users)
Your name, work e-mail address, business telephone number, the organization you belong to and your role in it, and the record of your sign-ins: when, from what kind of device, and whether a second factor was used. We collect this to operate your account, to secure it, and to be able to tell an organization's administrators who has access. Multi-factor authentication is required; we store a hashed second-factor secret and hashed recovery codes and never the plain values.
2.2 Organization information
The organization's legal name, display name, address, telephone number, time zone, branding for reports, and the name of the person who accepted our terms on its behalf.
2.3 Vendor credentials
The API keys or tokens a Customer supplies for its vendor systems. These are stored encrypted under a key created for that organization alone and are used solely to read data on the Customer's behalf. They are never shown back to anyone, including EasyQBR staff.
2.4 Data read from vendor systems (Customer clients' data)
Counts, statuses, dates, device inventories, licence figures, security findings and similar operational data about a Customer's clients, as returned by the connected vendors. All access is read-only. We do not retrieve service-desk ticket titles, descriptions or notes, so free-text that may contain personal information about a client's staff does not enter our systems. Where a report lists people by name (for example the licensed users in a client's directory), it is because the Customer's client is the audience for that list and the Customer chose to include it.
2.5 Reports
The documents the Service produces, which contain the data above. They belong to the Customer.
2.6 Technical information
Server logs with request paths, timestamps, response codes and IP addresses, kept for security and diagnosis. We do not use analytics or advertising trackers.
3. What we do not do
- We do not infer who belongs to an organization from an e-mail address or its domain, and we do not connect people or organizations on that basis. Independent businesses can share a domain, and treating them as one would be a breach of both.
- We do not sell personal information, share it for advertising, or use Customer data to train language models.
- We do not send Customer or client data to a language model with any ability to take actions or browse. The model is given figures already computed and returns text about them.
4. Language-model processing
To write the narrative in a report, we send the figures the Service computed, section headings and the Customer's own presentation notes to a language-model provider (see section 7). No vendor credentials, no ticket text and no raw vendor payloads are sent. The provider's output is text only; the Service refuses any number in it that was not among the figures it was given.
5. Access by EasyQBR staff
Our staff can enter a Customer's organization to provide support. Every entry is recorded with the staff member, the organization and the time, and a Customer can ask to see that record. We do not notify a Customer at the time of each entry. Staff can only reach Customer data through the Service's own permission model; there is no separate unlogged path.
6. Retention and deletion
- While an organization exists, its data is kept so reports can be regenerated and compared over time.
- When a Customer user is removed, their personal details are erased from the organization; audit records of what they did are kept, because those records are about the organization's own actions and serve every remaining member.
- When an organization is deleted, all connected data, credentials, reports and its people's personal details are destroyed. We keep the organization's name, address and telephone number, the name of the person who accepted our terms, and our audit of what we did to the organization, for billing and accountability. The organization's account number is never reissued.
- When an account belongs to no organization, it is deleted automatically. An account that belongs to no organization and has not been signed in to for 90 days is erased: its password, two-step verification, recovery codes, sessions and personal details are destroyed. Being removed from an organization starts the 90 days; being added to one stops them. We keep our own audit record that the erasure happened, and it names no address.
- Sign-in and security audit records are kept, because they exist to answer the question "who accessed what, and when" after the fact.
- Backups are kept for 14 days and then overwritten.
7. Sub-processors
We use the following providers to run the Service. Each processes data only as needed for its function.
| Provider | Function | Data involved |
|---|---|---|
| Amazon Web Services (United States, Ohio region) | Hosting, database, encryption keys, file storage | All Service data, encrypted at rest |
| Postmark | Sending invitations, verifications, password resets and sign-in notices | Recipient e-mail addresses and the message content |
| Anthropic | Writing the narrative prose in reports | The computed figures and headings described in section 4 |
We will update this list before adding a provider that processes Customer data.
8. Security
Data is encrypted in transit and at rest. Vendor credentials are encrypted under a per-organization key. Organizations are isolated from one another at the database level. Every account requires multi-factor authentication. Access by our staff is logged. Our source-control and deployment pipeline scans for leaked secrets. No system is perfectly secure; if we learn of a breach affecting your data we will tell the affected Customer's administrators without undue delay after we confirm it.
9. Your rights
Customer users can see and correct their own name and telephone number in the Service and can ask their organization's administrator to remove them. Depending on where you live you may have rights to access, correct, delete or export personal information, or to object to certain processing. Requests about Customer clients' data should go to the Customer, who controls it; we will assist the Customer in answering them. Contact us at legal@easyqbr.com for anything else.
10. International transfers
The Service is hosted in the United States. If you use it from elsewhere, your data is transferred to and processed there.
11. Children
The Service is for businesses and is not directed at anyone under 18.
12. Changes
We may update this policy. We will give notice of a material change by e-mail to each organization's administrators at least 30 days before it takes effect.
13. Contact
EasyQBR, LLC, 1452 Redwine Rd, Fayetteville, GA 30215, legal@easyqbr.com.