Privacy Policy
Effective Date: July 8, 2026
1. Information We Collect
We collect information you provide directly when creating an account and using the Service, including: name, email address, organization name, role, and contact information. We also collect data you enter into the system, such as quality control records, equipment data, maintenance logs, and uploaded documents. We automatically collect usage data including IP addresses, browser type, device information, and pages visited to improve the Service and ensure security. We also collect first-party product-usage analytics tied to your account — such as which features and modules you use, setup progress, and session-level activity — solely to improve the product. This telemetry never includes patient information, sample identifiers, or free-text content, and it is not shared with any third-party analytics provider.
2. How We Use Your Information
We use your information to: (a) provide, maintain, and improve the Service; (b) process your subscription and payments; (c) send transactional communications including account verification, password resets, QC alerts, and renewal notifications; (d) provide customer support; (e) detect and prevent fraud, abuse, and security incidents; and (f) comply with legal obligations. We do not use your data for advertising purposes and we do not sell your personal information to third parties.
3. Data Storage and Security
Your data is stored on Supabase infrastructure with servers located in the United States. We implement industry-standard security measures including: encryption of data at rest and in transit (TLS 1.2+), role-based access controls enforced at the database level, row-level security policies, multi-factor authentication options, immutable audit trails, and regular security assessments. Access to production systems is restricted to authorized personnel only.
4. Data Retention
We retain your data for as long as your account is active. Upon account termination or subscription cancellation, your data is preserved for 90 days to allow for data export. After the 90-day preservation period, your data is permanently deleted from our active systems, and encrypted backups containing it expire on a rolling schedule over the following 90 days. Audit trail records may be retained for longer periods as required by regulatory compliance obligations. You may request immediate data deletion by contacting support@impartquality.com, subject to any legal retention requirements.
5. Third-Party Services
We use the following third-party services to operate the Service: Supabase (database and authentication), Vercel (application hosting), Resend (transactional email delivery), and Stripe (payment processing). Each third-party provider is bound by their own privacy policies and data processing agreements. We do not share your quality control data, patient information, or laboratory operational data with any third party except as necessary to provide the Service or as required by law.
6. Your Rights
You have the right to: (a) access the personal information we hold about you; (b) request correction of inaccurate information; (c) request deletion of your data (subject to legal retention requirements); (d) export your data in a portable format (CSV/PDF); (e) opt out of non-essential communications; and (f) withdraw consent for data processing where consent is the legal basis. To exercise these rights, contact us at support@impartquality.com. We will respond to all requests within 30 days.
7. Cookies and Tracking
We use essential cookies to maintain your session and remember your preferences (such as dark mode, default laboratory selection, and notification settings). We do not use advertising cookies or third-party tracking pixels. First-party product-usage analytics (see Section 1) are collected in-app under your account and are not cookie-based. Session tokens are stored securely in your browser and expire after your session ends or after a period of inactivity.
8. HIPAA and Healthcare Data
While Impart QMS is designed for IVF laboratories, the Service is a quality management system and is not intended to store protected health information (PHI) as defined under HIPAA. Users should not enter patient-identifiable health information into the system. QC records, equipment data, and laboratory operational metrics do not constitute PHI. If your organization requires a Business Associate Agreement (BAA), please contact us to discuss your specific requirements.
9. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. For users subject to GDPR, we rely on Standard Contractual Clauses and other approved transfer mechanisms to ensure adequate data protection.
10. Children's Privacy
The Service is designed for professional use by laboratory personnel and is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will delete that information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before taking effect. The "Effective Date" at the top of this page indicates when the policy was last revised. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at: Impart Quality Consulting, LLC — Email: support@impartquality.com.
