Trust Center
Security and privacy documented, not asserted
Insight about people demands strict safeguards. This page describes how QuestPulse is built, operated and governed, and where responsibility sits.
Documentation
Security and privacy in QuestPulse
- Security architecture
- Separated environments, least privilege between components, encryption in transit and at rest, and logging of administrative operations.
- Data flow and data location
- Data is stored and processed within the EEA, on Azure Norway East. Data flow from collection to aggregated insight is documented per environment.
- Access control
- Login through your own identity provider using SSO. Access is role based, granted per organisational area and logged.
- Aggregation and protection of the individual
- Individual answers are never shared with the employer. Insight appears only when the group is large enough to prevent identification.
- Retention and deletion
- Retention is set per data category and agreed in the data processing agreement. Data is deleted or returned on termination.
- Sub-processors
- A current list of sub-processors, their purpose and location is provided as an annex to the data processing agreement.
- Incident handling
- Defined routines for detection, classification, notification and follow-up, with agreed notification deadlines towards the controller.
- Continuity and recovery
- Backup, recovery routines and defined recovery objectives, described in the operational documentation.
- Privacy
- Built to GDPR article 25 with data minimisation. You are the controller, QuestPulse is the processor under an article 28 agreement.
- Model governance and human control
- Automated analysis is used to prioritise and summarise, never to make decisions about individuals. Output is explainable and can be overridden by a person.
- Agreements and documentation
- Data processing agreement, sub-processor annex and security documentation are shared on request as part of a procurement or evaluation process.
- Security contact point
- Security enquiries, vulnerability reports and documentation requests go to support@questpulse.no.
01
02
03
04
05
06
07
08
09
10
11
12
Documentation
Request the DPA and security documentation
Note in the message field which documentation you need, and we will send it over.
hei@questpulse.no
support@questpulse.no
Digital Coach Hub AS