QARACloud
Terms of Use Privacy Policy Back to app

Privacy Policy

Effective date: July 11, 2026

This Privacy Policy explains what personal data QARACloud collects, why, and your rights. QARACloud is an informational service over public FDA data; we collect the minimum data needed to run accounts and keep the Service secure. We do not sell your personal data.

1. Who we are (Controller)

QARACloud ("we", "us"), operated by BHP Consulting LLC, 1207 Delaware Ave # 1939, Wilmington, Delaware, United States, is the controller of the personal data described here. Contact: support@qaracloud.com.

2. Data we collect

  • Account data: the e-mail address you provide when you register (and a username derived from it). You log in with your e-mail.
  • Authentication & security data: a securely hashed version of your password (we never store it in plain text) and session identifiers.
  • Essential cookies: sessionid (keeps you logged in) and csrftoken (protects against cross-site request forgery). These are strictly necessary for the Service to function. We do not use advertising or tracking cookies.
  • Technical logs: standard server logs such as IP address, date/time, requested pages, browser/user-agent, and error information, used for security and operation.

We do not intentionally collect sensitive personal data, and the Service is not intended to process health information about identifiable individuals.

3. How we use your data

  • To create and manage your account and authenticate you.
  • To operate, maintain, and secure the Service (including fraud/abuse prevention).
  • To communicate essential account or security notices.
  • To comply with legal obligations and enforce our Terms of Use.

4. Legal bases (GDPR / LGPD)

Where applicable, we process data based on: performance of a contract (providing the account and Service); our legitimate interests (security, preventing abuse, improving reliability); compliance with legal obligations; and your consent where specifically requested.

5. Cookies

We use only strictly necessary cookies (session and CSRF protection). Because they are essential to sign in and use the Service securely, they cannot be disabled without breaking core functionality. We do not use analytics, advertising, or cross-site tracking cookies.

6. Sharing and third parties

  • Hosting: the application and database are hosted on Heroku (a Salesforce company) on infrastructure located in the United States. They process data on our behalf.
  • Interface components: certain user-interface scripts and styles are delivered to your browser from a third-party content delivery network (Syncfusion CDN) when you load a page.
  • External FDA links: when you click a link to an FDA page or document, you leave our Service and are subject to the FDA's own policies.
  • We do not sell or rent your personal data, and we share it only as needed to run the Service or when required by law.

7. International data transfers

Our application and databases are hosted in the United States, and some of our processors are located in the United States. For users in the European Economic Area, the United Kingdom, or Brazil, transfers of personal data to the United States are made under appropriate safeguards — namely the EU-U.S. / UK / Swiss Data Privacy Framework (where the processor is certified) and/or the European Commission's Standard Contractual Clauses (SCCs), together with equivalent measures under the Brazilian LGPD. Our key processors (Stripe and our hosting provider) provide these safeguards under their data-processing terms.

8. Data retention

We keep your account data (profile, watches, monitored products, subscription record) for as long as your account is active. Search logs, which may contain your e-mail and IP address, are automatically deleted after 90 days. When you delete your account — which you can do at any time from Account → Delete account — we permanently delete your personal data, and any active subscription is canceled with our payment processor. Limited records may be retained only where the law requires it (for example, invoicing and tax records held by our payment processor).

9. Security

We apply reasonable technical and organizational measures, including HTTPS/TLS encryption in transit, password hashing, CSRF protection, access controls, and security-focused configuration. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Your rights

Depending on your location (e.g., under the EU GDPR or Brazil's LGPD), you may have the right to: access your data; correct inaccurate data; request deletion; restrict or object to processing; data portability; and withdraw consent. To exercise these rights, contact support@qaracloud.com. You may also lodge a complaint with your local data-protection authority (e.g., the ANPD in Brazil).

11. Children

The Service is intended for professional/business use and is not directed to children. We do not knowingly collect personal data from minors.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the "Effective date". Please review it periodically.

13. Contact

For any privacy question or request: support@qaracloud.com.

Note: This document is provided for general use and does not constitute legal advice. We recommend review by qualified counsel for your specific circumstances.

© 2026 QARACloud · BHP Consulting LLC — Informational use only. Always confirm data against the official U.S. FDA sources before relying on it.