QanolaMultiply yourself
Qanola — Privacy Policy & Data Processing Terms

Operated by Away HR Opportunities Ltd, HE 351183, Themistokli Dervi 3, Julia House, 1066, Nicosia, Cyprus

Last updated: 13 July 2026

This document covers two related things: how we handle data for registered Qanola users (Part B — Data Processing and Storage) and how we handle data for website visitors and waitlist subscribers (Part C — Privacy Policy). Our Terms and Conditions are published separately at qanola.com/terms.

For anything related to this document, write to privacy@qanola.com.


Part B — Data Processing and Storage

This part explains what data we handle on your behalf, where it lives, what we do with it, and what we don't do with it. It applies once you create a Qanola account.

B1. The data we handle

Away HR Opportunities Ltd acts as the data controller for account data and as your data processor for work data. You are the data controller for the work data you bring into Qanola; we process it on your instructions for the purposes described below.

We split the data into three buckets, because the rules are different for each.

Account data. What you give us to have an account: your email, your name if you choose to share it, your password (stored as a salted hash, never in clear), and your billing details if you're on a paid plan. We are the controller for this data.

Work data. Everything you bring into Qanola so it can be useful to you: emails you connect, calendar events, documents, notes, tasks, contacts, voice memos, and any content you paste into a conversation. This may include personal data about third parties — for example, the people you email. You are the controller for this data; we are your processor. Except where expressly stated otherwise, Away processes Work Data solely on your behalf and under your instructions and does not independently determine the purposes or means of processing such Work Data.

Usage data. A minimal log of how you use the product (which features you opened, error reports, approximate timing) so we can keep the service working and improve it. We don't link it to advertising profiles and we don't sell it.

We don't ask for and don't want data we don't need. If a feature would require a sensitive category of data (health, political views, and the other special categories under GDPR Art. 9), we'll tell you before you turn it on, and you can decline.

B2. What we do with it

You authorise Away to process, transmit, format, store, and technically interact with connected systems and third-party services solely as necessary to provide the functionality requested by you through Qanola.

We only process your data for purposes that are obvious from the product:

  • To run the chief-of-staff features you asked for — reading what you connected, suggesting actions, drafting messages, scheduling, organising.
  • To keep your account working — authentication, billing, support when you ask for it.
  • To keep the service safe and reliable — preventing abuse, fixing bugs, recovering from incidents.
  • To improve Qanola — only using aggregated or properly de-identified information, never your raw work data, unless you explicitly opt in to share a specific example with us. We may generate and use aggregated, statistical, anonymized, or de-identified information derived from the service for analytics, security, operational, benchmarking, and product-improvement purposes, provided such information does not identify you or any individual.

Legal basis under GDPR: performance of our agreement with you (Art. 6(1)(b)) for everything needed to deliver the product, our legitimate interest (Art. 6(1)(f)) for security and minimal improvement, and your consent (Art. 6(1)(a)) for anything else — clearly asked for, never bundled.

B3. AI and your data

We do not train AI models on your work data. Not ours, not anyone else's. Your emails, documents, contacts, and conversations are not used to train, fine-tune, or evaluate any model — by us or by the AI providers we rely on. We require this contractually from our model providers, and we'll name the specific providers and link to their data-use commitments on this page once they're locked in.

When Qanola needs to call an AI model to do its job (summarise a thread, draft a reply, plan your week), your data is sent to that model only for the time needed to produce the answer. The model providers we work with are bound to not retain your inputs or outputs beyond what's strictly needed to serve the request and meet their own short abuse-prevention windows.

You can ask us at any time which model providers are in the loop for a given feature, and we'll tell you.

B4. Where your data lives

We host Qanola's databases and file storage in the European Union by default. Where a specific feature requires a provider outside the EU (for instance, a particular AI model only offered from another region), we'll tell you and use one of the transfer mechanisms the GDPR allows — typically the European Commission's Standard Contractual Clauses, plus any additional safeguards (encryption, access controls) needed for the specific provider.

We'll list the regions and providers on this page once they're locked in. Until then, the principle is the one above: EU by default, named exceptions, appropriate safeguards.

B5. Sub-processors

To run Qanola we rely on a small number of trusted providers, each handling a specific job under a written agreement with us. We'll publish the current list on this page, with the role of each provider and its location, before the product ships. The list will cover, at minimum:

  • the cloud infrastructure where databases and files live,
  • the AI model providers used for inference,
  • the payment processor (for paid plans),
  • the email and notification provider,
  • the error-monitoring and observability tools.

We'll give you advance notice — by email and by updating this page — before adding or replacing a sub-processor that processes your work data. If you object to a new sub-processor for good reason, we'll work with you to find a path forward, including ending the agreement and giving you your data back if no other option works.

B6. Security

We follow the standard set of practices a serious product is expected to follow: encryption in transit (TLS) for everything; encryption at rest for databases and file storage; least-privilege access for the team, with logged and reviewed access to production systems; secrets stored in a dedicated vault; regular dependency and vulnerability scanning; backups with tested restore procedures.

We won't pretend to certifications we don't have. We'll add concrete details — encryption schemes, audit reports, certifications — as we earn them. If a security incident affects your data, we'll notify you without undue delay and, where required, the relevant supervisory authority within 72 hours, as the GDPR demands.

While we implement reasonable technical and organisational measures designed to protect data, no system can be guaranteed completely secure or immune from unauthorised access, attack, failure, or compromise.

B7. How long we keep your data

While your account is active, we keep your data for as long as you want us to — that's the whole point of a chief of staff.

When you delete something inside the product, it goes to a trash state for 30 days so you can recover it, then it's permanently deleted from active systems. It may persist in encrypted backups for up to 90 days before being overwritten.

When you close your account, we delete your work data within 30 days, and your account data within 90 days, unless we're legally required to keep something — for example, invoices for accounting purposes, which we keep for the legally required period.

You can export your data at any time in a portable format. We'll never hold your data hostage to keep you on the product.

B8. Your rights, and how to use them

Because you're the controller of your work data and we hold account data about you, you have the full set of GDPR rights:

  • access the data we hold,
  • correct it if it's wrong,
  • delete it (we honour this by default — see above),
  • object to or restrict how we use it,
  • receive a copy in a portable format,
  • withdraw any consent you gave.

Most of these you can do yourself from inside the product, once it's live. For anything that needs a human, email privacy@qanola.com. We aim to reply within 30 days, usually much faster. If you feel we haven't done right by you, you can also lodge a complaint with a supervisory authority. Our lead supervisory authority is the Cyprus Commissioner for Personal Data Protection. You may also complain to the data protection authority of the EU member state where you habitually reside or work.

B9. Your responsibilities

You represent and warrant that you have all rights, permissions, consents, and legal bases necessary to provide data, content, prompts, instructions, and connected accounts to Qanola for processing in accordance with these terms.

  • Tell us what to do. Qanola acts on your instructions. If you connect a data source, you confirm you have the right to share that data with a processor like us.
  • Keep your credentials safe. Don't share your account with someone else; create proper invitations instead, once that feature exists.
  • Mind third parties. When you bring in data about other people (the people you email, your contacts), you're the one with the relationship to them — including any duty to inform them, where the law requires it. We'll give you the tools to do this honestly; the obligation stays with you.

B10. Changes to this document

If we make meaningful changes — for example, if we add a sub-processor that handles your work data, or change anything material about how your data is used — we'll update this document and the date at the top, and we'll email you before the change takes effect. For minor edits (wording, links, typos) we'll just update the page.

If you don't agree with a material change, you can close your account and export your data before it takes effect, at no cost.

Where required by applicable data protection law, the terms in this Part B shall apply as a data processing agreement between the parties. The parties may additionally enter into the European Commission's Standard Contractual Clauses or equivalent approved transfer mechanisms where legally required.

B11. Google Calendar Integration

This section governs Away's handling of data obtained through Google APIs when you connect your Google account to Qanola.

What we access. When you connect your Google account, Qanola requests access to:

  • Your list of calendars, so you can choose which calendar Qanola reads from and writes to
  • Your calendar events — to identify your available time slots and avoid scheduling conflicts
  • The ability to create, update, and delete calendar events on your behalf, as directed by you through Qanola

Where a feature only requires knowing whether a time slot is free or busy, we access only that information and do not read event titles, descriptions, or attendee details.

How we use this data. We use Google Calendar data exclusively to provide Qanola's features that require calendar access:

  • Identify your available time slots and prevent double-booking
  • Create, update, or cancel calendar events on your behalf as directed by you
  • Display your availability to others as part of Qanola's functionality

What we do not do with Google Calendar data:

  • We do not use it for advertising, marketing, or profiling purposes
  • We do not sell or transfer it to third parties
  • We do not use it to train, fine-tune, or evaluate any AI model
  • We do not allow humans to read your Google Calendar data except as strictly necessary to deliver or improve Qanola's features, or as required by law

Data minimisation. We request only the level of access necessary for the functionality you use. We do not access calendar settings, sharing configurations, or any data beyond what is described above.

Storage. Google Calendar data is accessed in real time and is not permanently stored on our servers beyond what is required to complete a requested operation. The credentials that maintain your connection are stored encrypted at rest and used solely for that purpose.

Limited Use. Away HR Opportunities Ltd's use of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Strict limitation. Notwithstanding any other provision of this Privacy Policy, Google user data obtained via Google APIs is used solely to provide the calendar-related features you have explicitly enabled. It is not used for advertising, analytics, benchmarking, product improvement, AI model training, or any other purpose beyond operating the specific feature you requested.

Revoking access. You may revoke Qanola's access to your Google Calendar at any time via your Google Account at myaccount.google.com > Security > Third-party apps & services > Qanola > Remove access. Revoking access will disable calendar-dependent features but will not affect other Qanola functionality. We will delete any stored credentials within 30 days of revocation.


Part C — Privacy Policy

Away HR Opportunities Ltd is the data controller for data collected from site visitors and waitlist subscribers. This part covers you before you become a product user; once you create an account, Part B above applies to your work data.

C1. What we collect

Right now, we run a simple landing page with a waitlist. The only personal data we collect is what you choose to give us:

  • Your email address, if you join the waitlist or contact us.
  • Your name or other details, only if you include them in a message to us.

We don't use analytics or advertising trackers on this site. We don't set non-essential cookies. We don't try to identify you when you browse.

Our hosting provider may automatically log technical information (such as your IP address and browser type) for up to 30 days to serve the site securely and prevent abuse. We don't link this to your email or build a profile from it.

We use your email for two things, and two things only:

  • To tell you when Qanola is ready, or to share occasional updates about the product. Legal basis: your consent (GDPR Art. 6(1)(a)), which you give by joining the waitlist. You can withdraw it at any time by replying "unsubscribe" or emailing us.
  • To answer you, if you've written to us. Legal basis: our legitimate interest in responding to people who contact us (GDPR Art. 6(1)(f)).

We don't sell your data. We don't share it with advertisers. We don't use it to train AI models.

C3. Who else sees it

To run the site and the waitlist, we rely on a small number of trusted providers (data processors) who only handle your data on our instructions:

  • A hosting provider to serve the website.
  • An email tool to store the waitlist and send you updates.

When these providers are based outside the European Economic Area, we make sure the transfer is covered by appropriate safeguards (typically the European Commission's Standard Contractual Clauses). We'll name the specific providers here once they're locked in.

C4. How long we keep it

We keep your email for as long as you want to hear from us. If you unsubscribe, we remove your address from the active list within 5 business days. If you ask us to delete your data entirely, we will — unless we're legally required to keep something (we're rarely required to).

C5. Your rights

Under the GDPR, you have the right to access, correct, delete, restrict, port, and withdraw consent over your data. Email privacy@qanola.com and we'll handle it. We aim to reply within 30 days, usually much faster. If you feel we haven't done right by you, you can also lodge a complaint with a supervisory authority. Our lead supervisory authority is the Cyprus Commissioner for Personal Data Protection. You may also complain to the data protection authority of the EU member state where you habitually reside or work.

C6. Cookies

We don't use tracking, advertising, or analytics cookies. The only cookies the site might set are strictly necessary ones to make the page work — and those don't require your consent under EU law.

C7. Children

Qanola isn't aimed at children. We don't knowingly collect data from anyone under 16. If you think we have, write to us and we'll delete it.

C8. Changes to this policy

If we make meaningful changes — for example, if we add a product or start using new tools — we'll update this document and the date at the top. For material changes that affect how your data is used, we'll let you know by email before the change takes effect.


Contact

MatterAddress
General and legallegal@qanola.com
Privacy and dataprivacy@qanola.com
Securitysecurity@qanola.com
Billingbilling@qanola.com

A real human reads each of these inboxes.

© 2026 AWAY HR OPPORTUNITIES LTD
Made in Europe