How QuantJourney collects, uses, shares and protects personal data across its websites, product reviews and Services.
1. Scope and responsibility
This Privacy Policy explains how Quant Journey, operating under the QuantJourney brand (“QuantJourney,” “we,” “us,” or “our”), collects, uses, shares and protects personal data when you visit our websites, apply for a role, request a product review, communicate with us or use a service that links to this Policy.
This Policy covers quantjourney.cloud and relevant QuantJourney subdomains, including the QuantJourney hiring page, OneBook, Backtester, API, documentation, forms, product evaluations, implementations, support and related business interactions (the “Services”). A service-specific notice, order form or data-processing agreement may provide additional terms and will control for the processing it expressly covers.
2. Information we collect
Information you provide
- Name, work email, firm, role, firm type and other professional contact details.
- Demo, access, support and contact requests, including the workflow, current technology stack or product interest you describe.
- Communication preferences, product feedback and information you choose to share during an evaluation or implementation.
- Recruitment information you submit, such as the role selected, name, email address, location, profile link, CV, cover letter and application note.
- Account, billing and commercial-contact information where a paid relationship is established.
Service and technical information
- IP address, browser, device, operating system, language, referring page, timestamps and pages or features used.
- Account identifiers, authentication events, tenant membership, permissions, API-key metadata and account status.
- Request, response, error, security, usage and audit metadata needed to operate and protect the Services.
- Integration, source, calculation and workflow metadata associated with a client-authorised configuration.
Customer Data and connected sources
A QuantJourney environment may process holdings, cash, orders, transactions, research, theses, evidence, models, policies, risk results, approvals, reports, prompts, files and other information deliberately submitted or connected by an authorised client or user (“Customer Data”). We may also receive data from identity, payment, scheduling, communication or client-authorised data and operating-system providers.
3. How and why we use information
We use personal data where reasonably necessary to:
- respond to product-review, access, implementation, support and other business requests;
- receive, assess, communicate about and administer recruitment applications;
- create and administer accounts, authenticate users and apply permissions;
- provide, configure, maintain and improve the Services requested by a client;
- maintain source lineage, security records, audit events and replay evidence;
- monitor reliability, troubleshoot errors, prevent abuse and investigate security events;
- manage contracts, billing, tax, compliance, disputes and legal obligations; and
- send requested or legally permitted product communications, with an unsubscribe option where applicable.
6. Client environments and data authority
The applicable client agreement defines the authorised users, purposes, integrations, source authority and processing boundaries for Customer Data. The client is responsible for the data and access it chooses to provide and for administering its users, roles and service identities.
Client information is not treated as a shared cross-client investment-decision dataset. Customer Data is processed to provide, secure, implement and support the relevant Service and as otherwise authorised in the applicable agreement.
7. International processing and data residency
QuantJourney and approved providers may process personal data in countries other than your own. Where applicable law requires a transfer mechanism, we use a recognised lawful mechanism or contractual safeguard.
For a dedicated environment, an order form, deployment specification or data-processing agreement may define the approved cloud environment, hosting region, data-residency requirements and additional controls.
8. Retention
We retain personal data only for as long as reasonably needed for the purpose for which it was collected, including the life of an account or contract, support and security follow-up, billing and tax requirements, dispute periods, backup cycles and legal obligations.
Recruitment information, including application documents, is retained only for recruitment, related follow-up, security, recordkeeping and applicable legal obligations, and is reviewed against those purposes when it is no longer needed.
Customer Data in a dedicated environment is retained, exported and deleted in accordance with the client agreement, configured retention settings and applicable legal-hold requirements.
9. Security
We use technical and organisational measures designed to protect personal data and Customer Data in proportion to the Service and risk. No internet transmission or storage system is completely secure, and we cannot guarantee absolute security.
Clients and users are responsible for protecting their devices, credentials and API keys, configuring authorised access and promptly reporting suspected compromise.
10. Your rights and choices
Subject to applicable law, you may have the right to:
- access, correct or delete your personal data;
- object to or restrict processing;
- receive portable data you supplied where legal requirements are met;
- withdraw consent and unsubscribe from optional communications; and
- complain to the data-protection authority responsible for your location.
11. Children
The Services are designed for professional and institutional users and are not directed to children. We do not knowingly collect a child’s personal data in violation of applicable law. Contact us if you believe a child has submitted personal data without the required authorisation.
12. Changes to this Policy
We may update this Policy to reflect changes to our Services, providers, legal obligations or processing. We will publish the revised version and update the effective date. Where appropriate, we may also notify the relevant account contact of a material change affecting a paid Service.
13. Contact
To ask a privacy question or exercise a right, email [email protected] and identify the relevant Service, account and request. If an order form, enterprise agreement or service-specific notice identifies a different controller or privacy contact, use the details stated there.