Legal
Privacy Policy
Effective date: July 17, 2026
This Privacy Policy explains how Quathos LLC (“we”, “us”), operator of the Qsendyx platform, collects, uses and protects personal data when you use the Service.
1. Who we are
Qsendyx is a communications platform (CPaaS) for sending SMS and email (transactional, OTP and campaigns) through a web portal, an API with tokens, and webhooks. It is owned and operated by Quathos LLC, a company based in Dallas, Texas, United States. For any privacy request, contact us at contact@qsendyx.com.
Qsendyx is a software and orchestration layer over third-party carriers and email providers; we are not a telecom operator. It is offered as a multi-tenant service. When your organization is the customer, it acts as controller of the personal data it processes through the platform (including the recipient data in your contact lists), and Quathos LLC acts as processor on its behalf.
2. Data we collect
We collect only the data needed to operate the Service:
- Account data: name, email address and a hash of your password (we never store passwords in plain text).
- Organization data: company name, members and settings of your tenant.
- Contact and recipient data: the phone numbers, email addresses, names and consent status you upload or send to.
- Message data: the content and metadata of the SMS and email you send: subject, body, sender, recipient and timestamps.
- Delivery and engagement events: sent, delivered, bounced, failed, complaint, opened and clicked, as reported by carriers and email providers.
- Suppression data: opt-outs, STOP requests, hard bounces and complaints, kept to stop us sending to those recipients again.
- API tokens: stored only as a prefix, a hash of the secret and its last characters; the plaintext is shown once, at creation.
- Billing data: your credit ledger and usage. Card payments are handled by our payment provider. We do not store full card numbers.
- Technical cookies: session, CSRF and preference cookies (see the Cookie Policy).
3. How we use data
We use personal data to:
- Send your messages and track their delivery and engagement.
- Authenticate users and keep accounts and tenants isolated and secure.
- Send transactional messages about your own account (confirmations, alerts, receipts).
- Prevent fraud and abuse (spam, SMS pumping, phishing and OTP abuse) and comply with legal obligations.
- Meter usage, charge paid plans and pay-as-you-go credits, and support customers.
4. Legal bases
Depending on the applicable law, we process personal data on the bases of performance of a contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, and, where required, consent. Consent to receive your messages is obtained by you from your recipients, not by us. For customers in Brazil, processing follows the LGPD (Lei nº 13.709/2018).
5. How we share data
We do not sell personal data. We share it only with service providers that help us run the platform (cloud hosting, SMS aggregators, email delivery providers and payment processing) under contracts that limit their use of the data. To deliver a message, its content and recipient are necessarily passed to the carrier or email provider that transmits it. We may also disclose data when required by law or to protect our rights and users.
6. International transfers
Quathos LLC is based in the United States and may process data there and in other countries where our providers operate. Where the law requires it, we use appropriate safeguards for international transfers.
7. Data retention
We keep personal data for as long as your account or your organization’s account is active and as needed to provide the Service. Message metadata and delivery logs are retained to provide analytics, billing and abuse investigation. Suppression records are retained for as long as needed to honor opt-outs. After that, data is deleted or anonymized, subject to legal retention duties.
8. Security
We apply technical and organizational measures including tenant isolation enforced at the database layer (Row Level Security), password hashing with argon2id, API tokens stored only as hashes, DKIM private keys encrypted at rest, an immutable append-only billing ledger, and signed, idempotency-checked provider webhooks. See our Security page for detail. No system is perfectly secure, but security is built into the platform’s design.
9. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, as well as portability, information about processing and, where processing relies on consent, its withdrawal. To exercise these rights, contact contact@qsendyx.com. If your data is processed on behalf of an organization (tenant), for example because you are a recipient of messages a customer sent through Qsendyx, we will direct your request to that organization as controller.
10. Children
The Service is not intended for individuals under 18, and we do not knowingly collect their personal data.
11. Changes
We may update this Policy. Material changes will be signaled by updating the effective date above and, where appropriate, by notice within the Service.
12. Contact
Questions about privacy? Email us at contact@qsendyx.com.