This Privacy Policy explains how the operator handles information when visitors use Qryvios as guests or registered users.
Privacy model in one sentence
This Policy applies to the Qryvios website/application, its guest and registered account flows, dataset upload and processing, backend SQL execution, query history, charting and export features.
It does not automatically apply to third-party sites or services you reach through external links, or to independent recipients with whom you share exported files.
The operator is responsible for personal information it collects for account administration, security, product operation, support and service improvement.
When users upload datasets containing personal information about other people, the operator may act as a processor/service provider on the user's behalf depending on applicable law and contractual context. The exact legal role should be confirmed for target jurisdictions and enterprise customers.
Users remain responsible for determining whether they are permitted to collect, upload, query, visualize and export personal information contained in their datasets.
| Category | Examples |
|---|---|
| Guest identity and access | Guest reference ID, internal principal ID, guest-session status, session credential metadata, guest linking/audit status, and — where Secure Guest Access is enabled — access-code credential data or secure verification material. The public Guest ID is not treated as the secret. |
| Registered account data | Email address, Cognito user identifier (sub), verification/authentication status, account creation/last-login metadata. Password authentication is handled by Cognito; the application should not store plaintext passwords. |
| Uploaded datasets | Original uploaded files such as CSV/XLSX/JSON, processed analytical representations such as Parquet, filenames, size, schema/type information, row counts, validation results and related metadata. |
| Query data and history | SQL text, dataset ID, query ID, status, submitted/started/completed timestamps, duration, row count, result/preview locations, rerun lineage and safe error information. |
| Query results | Browser-friendly result previews and full result artifacts stored in object storage where needed. |
| Charts and preferences | Chart/dashboard configuration, theme preference and similar UI settings. In the current release, these may be stored primarily in browser state/localStorage unless backend persistence is later added. |
| Exports | Files you intentionally generate, such as CSV, JSON, PNG, SVG, PDF or read-only standalone HTML. Client-side exports are created from data already available in the browser and are not automatically re-uploaded solely because they are exported. |
| Technical and security data | Request/correlation IDs, service status, timestamps, performance metrics, error codes and security logs. Depending on configured infrastructure logs, this may also include IP address, user-agent or similar request metadata. |
| Support communications | Information you provide when contacting support, reporting a problem or requesting privacy assistance. |
Depending on applicable law, processing may rely on performance of a contract or steps requested by the user, legitimate interests in operating and securing the Service, consent where specifically requested, and compliance with legal obligations.
If the Service is offered in a jurisdiction that requires more specific legal-basis disclosures, the operator must tailor this section before publication.
Registered authentication is handled through Amazon Cognito.
Identity mappings, principal profiles, dataset metadata and query execution/history metadata are designed to be stored in DynamoDB.
Raw uploads, processed datasets, previews and full query-result artifacts are designed to be stored in Amazon S3.
SQS is used for asynchronous job delivery and should carry minimal identifiers/metadata rather than full dataset content.
CloudWatch and related AWS observability services may process logs, metrics and alarms.
The operator should document the AWS region(s) and production environment locations before publication.
Cloud services may process information outside the user's country. Before production publication, the operator should identify hosting regions and, where required, describe applicable cross-border transfer safeguards or contractual mechanisms.
Retention periods are not finalized in the current product baseline
| Data type | Current policy draft |
|---|---|
| Registered account / identity mapping | Retain while the account is active, then delete or de-identify according to [ACCOUNT DELETION RETENTION PERIOD] and legal/security requirements. |
| Guest identity / audit mapping | Retain for [GUEST ID RETENTION PERIOD]. Linked Guest IDs may be retained as an audit/reference mapping if required for continuity/security. |
| Raw uploaded dataset | Retain until user deletion or [RAW DATA RETENTION PERIOD], subject to backup/lifecycle behavior. |
| Processed dataset / Parquet | Retain while the dataset remains available to the user or for [PROCESSED DATA RETENTION PERIOD]. |
| Query metadata / history | Retain for [QUERY HISTORY RETENTION PERIOD], unless the user deletes it earlier where supported. |
| Query result artifacts / previews | Retain for [QUERY RESULT RETENTION PERIOD], after which results may expire while history metadata remains. |
| Operational/security logs | Retain for [LOG RETENTION PERIOD] based on security, troubleshooting and legal needs. |
| Browser-local chart/theme configuration | Retained in the user's browser until cleared by the user/application; cross-device persistence is not currently guaranteed. |
The Service is designed to use owner-scoped authorization based on a backend-resolved principal identity, rather than trusting user-supplied ownership identifiers.
S3 should use block-public-access and encryption; uploads should use short-lived pre-signed URLs rather than exposing permanent AWS credentials.
DynamoDB and other managed stores use server-side encryption according to configured AWS settings.
SQL execution is restricted to an approved read-only analytical subset and should prevent arbitrary filesystem/network/extension access.
Least-privilege IAM, rate/concurrency limits, structured logging and alerting are used or planned as part of the production hardening baseline.
No security control eliminates all risk. Users should avoid uploading data that exceeds the Service's approved sensitivity/compliance scope.
Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about processing.
Registered users should be able to request account and associated-data deletion through [ACCOUNT DELETION METHOD / SUPPORT PROCESS].
Users can export their own resolved query/chart data using supported export tools. Product exports are not necessarily a complete statutory privacy-data export and should not replace a formal privacy request process where required.
The operator may need to verify identity before fulfilling a privacy request and may retain limited information where required by law or necessary for security/fraud prevention.
Guest users do not necessarily have a verified email identity. The visible Guest ID alone is not sufficient proof that a requester owns the associated resources.
To access, recover or delete guest-owned information, the Service may require the active secure guest session, a valid Secure Guest Access credential/access code, or another verification method implemented by the operator.
If the guest identity has been linked to a registered account, privacy requests should generally be handled through the registered account while preserving any necessary Guest ID audit reference.
The Service is not intended for children below [MINIMUM AGE]. The operator should choose the correct age threshold and parental-consent approach for the markets in which the Service is offered.
The Service performs automated data processing and SQL execution but is not currently designed to make legally significant automated decisions about individuals. If that changes, this Policy must be updated.
The operator will investigate suspected security incidents and provide notifications to affected users or authorities where required by applicable law and based on the nature of the incident.
The operator may update this Policy to reflect product, provider, legal or business changes. Material changes should be communicated through the Service, email or another reasonable channel where required.
Privacy contact: [PRIVACY EMAIL]
Operator: [OPERATOR / COMPANY LEGAL NAME]
Address: [REGISTERED / BUSINESS ADDRESS]
Data protection officer / representative (if required): [DPO / REPRESENTATIVE DETAILS]
Users may also have the right to complain to their local privacy/data-protection authority where applicable.
| Stage | Data handled | Primary location / behavior |
|---|---|---|
| First visit | Guest reference + secure guest session | Backend creates principal/guest identity; browser receives safe display/reference data and a secure session mechanism. |
| Account creation / sign-in | Email, Cognito identity, auth/session data | Cognito authenticates registered users; backend maps the verified identity to the internal principal. |
| Upload | CSV/XLSX/JSON + metadata | Browser uploads through short-lived S3 URL; backend validates and may create processed Parquet. |
| Query submission | SQL text, dataset ID, query metadata | Backend authorizes ownership, persists QUEUED query metadata and sends minimal job identifiers through SQS. |
| Query execution | Authorized processed dataset + SQL | DuckDB worker reads only owner-approved data, enforces read-only limits, writes preview/result artifacts. |
| History/results | Status, timestamps, row count, result pointers | DynamoDB stores metadata/history; S3 stores larger previews/results. |
| Charts | Resolved result + chart configuration | Charts are built in browser; configuration is currently primarily client-side. |
| Exports | Resolved data/config/visualization | CSV/JSON/PNG/SVG/PDF/HTML are generated for user download where supported. Standalone HTML is read-only and must not embed credentials. |
See also the Terms of Service.