Privacy Policy
Last Updated – August 19, 2026
1.Introduction
1.1. We Qyrus Inc, and our affiliates/ entities (Qyrus, we, our, us, Company), value your privacy and are responsible for processing of your Personal Data, as described in this Privacy Policy (Policy), while acting as the Data Controller of such Personal Data, unless otherwise specified. Qyrus entities, around the world, provide a cloud-based all-in-one software testing platform.
2. When does this Policy apply to you?
2.1. This Policy applies to the processing of Personal Data that we collect, and receive from you, when you choose to:
- Access, visit, or interact with our websites, including browsing, accessing links, resources, and any content available on our websites;
- Access, visit or interact with our channels across social media platforms;
- Communicate with us, via chatboxes, e-mail, phone calls;
- Use of our services;
- Participate in any surveys, research, or such other data collection activities which are facilitated by us;
- Register and participate in any events, webinars, trainings which are hosted by us.
2.2. We clarify that this Policy applies to you, only where Qyrus acts as a data controller, and does not extend to your use of Qyrus products or services, which has been availed by our customers and you are an authorized or permitted user, in such cases we act only as a data processor. We urge you to familiarize yourself with such policies and procedures of the customer.
3. Personal Data Processing, Grounds, and Sources
3.1. Qyrus collects and processes your data, where it has a legal basis to do so, and only in the context in which it is collected, as per the details provided in this Policy.
3.2. We collect your data only, when we have:
- your consent;
- to meet a contractual obligation;
- legitimate interest to do so;
- to act in compliance with the laws.
To help you understand better, we have the following information about our collection practices and processing activities.
Data We Collect | Source of Personal Data | Specified Purposes for Collection |
Identifiers like your name, organization, work e-mail address, telephone number, country, and information you provide on the website to register to receive any communications from us, download content. | Personal data provided directly by individuals, in their interaction with the website. | To administer customer accounts, provide and support the Service, manage billing and contractual obligations, maintain audit and security logs, resolve disputes, troubleshoot technical issues, enforce agreements, comply with applicable legal requirements and operate our business. |
Contact information, financial and billing information, such as billing name and address, credit card number or bank account information | Personal data is provided directly by individuals, in their interaction with the website. | To make available any purchases made by you on our website. |
Name, Contact Details, Voice, and any other Personal Data voluntarily shared by you. | Communications made via phone calls. | To address any query, sales related assistance, concerns, that you seek via a phone conversation. |
Your Internet Protocol (IP) address, browser type and language, device characteristics, referring URLs, pages viewed, links clicked, timestamps and similar interaction data. | Information collected automatically through cookies and similar technologies as described in our Cookie Policy. | To identify you, remember your actions on our websites and platform, minimize your efforts to interact with us and provide seamless personalized experience on your device. |
Your name, e-mail address, telephone number, company name, job title and related contact details. | Information you have provided in responding to any survey. | Research purposes, to improve our Services. |
Name, business contact details (such as work email address, business telephone number), company affiliation and job title, communication records exchanged in the court of business interactions | Information collected directly from the representatives or obtained in the course of business communications, contractual discussions, networking activities, referrals, or publicly available business contact information. | Initiating, managing, and terminating business relationships, contract administration and performance, vendor and partner due diligence, compliance with legal and regulatory obligations, and operational and administrative business activities. |
Personal data relating to other representatives of the same customer organization. | Information uploaded by customer representatives. | Processed solely for the specific purpose for which it was submitted and in accordance with the applicable customer agreement. |
Your full name, e-mail address, telephone number, resume, educational background, professional qualifications, prior experience details, expected compensation, notice period, LinkedIn profile and current location. | Information submitted by prospective job candidates directly. In limited circumstances, personal data may also be obtained from authorized third-party recruitment agencies, professional networking platforms, background verification providers (where applicable and legally permitted), or references provided by the candidate. | For purposes related to recruitment and hiring. |
Details of your current employer, references, professional portfolio links, social media profiles, cover letters, or other information voluntarily submitted. | Personal Data which may be optionally provided by job candidates as part of the application process. | For purposes related to recruitment and hiring, as detailed above. |
Name, e-mail address, phone number, company name, time and date of arrival, image or video (CCTV footage), identification proof (if required) | Personal Data which is provided to our personnel, when you visit our premises, offices. | To register visitors, and for ensuring safety and security of the premises, employees of the organization. |
3.3. When you are providing your consent for us to process your Personal Data for job applications, may withdraw consent at any time; however, withdrawal may affect our ability to continue considering the application.
3.4. There may be instances where you provide Personal Data about others, to us and/ or our service providers, and you represent and undertake that you have: the authority to provide such Personal Data about others; you have their consent, as is required, to provide their Personal Data to us for processing; acknowledged that such Personal Data will be used in accordance with this Policy.
If you are concerned that your Personal Data has been made available to us in an inappropriate and unauthorized manner, please write to us at: DPO@qyrus.com.
4. Why we process your Personal Data?
4.1. We process your Personal Data to provide you with a wide range of services, and rely on the legal bases which enable us to act in accordance with applicable laws.
Purpose | Legal Basis for Processing |
Providing our websites; and, channels on social media platforms. | Qyrus’s legitimate interest in operating its own website provides relevant content to existing and prospective customers, about our product and service offerings, and related information about the companies, presence, outreach. |
Providing our services | Qyrus’s legitimate interest in offering the best services to you. |
Registering details of the visitors of the premises. | Qyrus’s legitimate interest in protecting its own offices, premises, amenities, employees, visitors, physical resources, and to ensure that corporate resources, including confidential information is protected against any unauthorized access. |
Security of the websites, improving accessibility, features, and contents appearing on the websites. | Qyrus’s legitimate interest in providing a safe, secure, updated, relevant, user-friendly, website to the visitors of the website. to improve security and protect our rights, your rights and that of others. |
Registrations for events, webinars, promotions or any contests being hosted by Qyrus. | Qyrus’s legitimate interest in hosting events, webinars, promotions and contests, and your consent, where required. |
Display of personalized advertisements, relevant content. | Qyrus’s legitimate interest in advertising its services or, where necessary, to the extent you have provided your prior consent for this. You can control your Personal Data, and its use for advertising purposes, as per this Policy. |
Safety and security of premises, offices, amenities, employees, visitors. | Qyrus’s legitimate interest in protecting offices, premises, amenities, employees, visitors. Where necessary, use of video surveillance (CCTV), to comply with our legal obligations. |
Following up on sales leads, inquiries, and improving sales process as is available on the websites. | Qyrus’s legitimate interest to communicate with prospective customers, provide details about services, and optimize sales process to increase efficiency. |
Managing service requests | Qyrus’s legitimate interest in fulfilling service requests, and addressing concerns raised in correspondence with you. |
Attending and recording phone calls | Qyrus’s legitimate interest in maintaining highest standards during phone calls, to preserve safe and secure communication and, your consent. |
Creating, managing and operating customer / user accounts | Qyrus’s legitimate interest in management of customer relations, extend support services; and, fulfilling contractual obligations. |
Managing billing, payments and subscriptions | Qyrus’s duty to fulfil contractual obligation, performance of the contract. |
Compliance with legal obligation, protecting Qyrus’s interests | Qyrus’s legal obligation or legitimate interest in protecting against misuse, misappropriation, abuse of our websites or services, protecting business and personal property or safety, pursuing legal remedies, investigating actual or suspected breaches of law, our terms of service or other relevant policies, complying with judicial proceedings, court orders or legal processes, preparing for litigation, responding to lawful requests, or for regulatory, tax and/or auditing purposes. |
Aggregating datasets collected from you. | Qyrus’s legitimate interest in ensuring data minimization, and limiting the data that is being processed. |
Conducting surveys, and performing market research, analyses. | Qyrus’s legitimate interest to conduct surveys, or research for defined objectives, and where applicable your consent. |
Providing job opportunities, fair compensation. | Qyrus’s legitimate interest to provide employment opportunities, and ensure fair compensation for all employees, and necessary for the performance of a contract. |
4.2. If the law requires that you provide your consent for processing of Personal Data, or where we require such data for fulfilment of a contractual obligation to you, and you do not provide such Personal Data, we may not be able to fulfil such obligations in the contract to you.
5. Who do we share your Personal Data with, and why?
5.1. Qyrus may need to share your Personal Data with trusted third-party service providers that support the operation of our business and delivery of our services. These service providers may assist with:
- cloud hosting and infrastructure;
- research and analytics;
- customer relationship management systems;
- marketing, events planning;
- recruitment processing;
- customer support;
- communication tools;
- payment processing;
- professional advisory services;
- security monitoring
5.2. Such service providers are contractually required to process personal data only on documented instructions and to maintain appropriate confidentiality and security safeguards. These service providers also are contractually bound to abide by such conditions which apply to cross-border data transfers, as provided below.
5.3. Aggregated datasets may also be shared with third parties for analysis and improvements to our own services. Sometimes, we also use “usage data” to demonstrate the use and uptake of our services.
5.4. Qyrus may also disclose personal data where required to comply with applicable law, regulation, legal process, court order, or lawful governmental request, or where necessary to protect the rights, property, or safety of Qyrus or others, enforce contractual agreements, or investigate fraud or security incidents.
5.5. If you interact with our social media posts, websites, blogs, anyone who is also accessing the same will be able to see any Personal Data, or any data that you post there.
5.6. Additionally, Personal data may be disclosed in connection with a merger, acquisition, financing, reorganisation, sale of assets, or similar corporate transaction. In such circumstances, personal data will remain subject to applicable confidentiality obligations and data protection safeguards.
6. Cross – border transfer of Personal Data
6.1. We will obtain your consent before processing, sharing, transferring and/or storing your Personal Data outside of your jurisdiction, where required by law.
6.2. Your Personal Data may be transferred to and stored by us overseas, outside of your jurisdiction. Your Personal Data may be processed and stored outside your country or jurisdiction, including in places that are not subject to an adequacy decision by the European Commission or your local legislature or regulator, and that may not provide for the same level of data protection. To avoid inconsistencies, we ensure that the recipient of your Personal Data provides an adequate level of protection and security, by entering into appropriate agreements, including, where required, standard contractual clauses or an alternative mechanism for the transfer of Personal Data as approved by the European Commission (Art. 46 GDPR) or other applicable regulators or legislators.
7. How long do we retain your Personal Data for?
7.1. Qyrus processes personal data in its capacity as a Data Controller, retains Personal Data is for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by applicable law.
7.2. Retention periods are determined based on the nature of the Personal Data, the purposes for which it was collected and processed, contractual obligations, statutory limitation periods, regulatory requirements, dispute resolution needs, and legitimate business interests. Personal Data may be retained for the duration of an active business relationship and for a reasonable period thereafter to comply with legal, accounting, or reporting obligations, enforce agreements, or resolve disputes.
7.3. Once Personal Data is no longer required for lawful purposes, it is securely deleted, anonymized, or irreversibly de-identified in accordance with Qyrus’s internal data lifecycle management and security practices. In the event, we face technical difficulties deleting any data entirely from our systems, we will implement appropriate measures to prevent any further use of such data.
8. Children’s Privacy
8.1. Qyrus websites, its services are not directed at children. For purposes of this section, “child” means a person under the age defined by applicable law in the relevant jurisdiction. For we do not knowingly collect Personal Data from children under the age of 13. We do not knowingly collect Personal Data for children between 13-18 unless we have obtained consent from a parent or guardian, such collection is subject to a separate agreement with us or the visit by a child is unsolicited or incidental, where applicable under such jurisdictions.
8.2. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
8.3. If you believe we have mistakenly or unintentionally collected Personal Data from a child without appropriate consent, please contact us at: DPO@qyrus.com.
9. How do we keep your data secure?
9.1. Qyrus implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include encryption, access controls, monitoring, secure infrastructure management, and formal incident response procedures consistent with industry standards and applicable regulatory requirements.
9.2. We follow all necessary measures, however, all methods of storage, transmission of data are not completely secure, and accordingly, we urge you to ensure that you keep password secure, and practice other measures like logging out in a safe manner after sessions, limiting access to your devices, using safe Wi-Fi networks.
10. Your Privacy Rights
10.1. You may be entitled to certain rights relating to your Personal Data, as per the local data protection laws, which apply to you.
10.2. Qyrus respects the rights of individuals under the said laws. Subject to the applicable laws, you may have the right to:
- Access your Personal Data that is held by us;
- Know more about the details of the processing activities;
- Correction of inaccurate personal data and the updation, completion of incomplete personal data;
- Erase or delete your Personal Data;
- Restrict processing of Personal Data by us;
- Object to any processing of your Personal Data;
- Opt-out of the sale or sharing of personal data for cross-context behavioural advertising;
- Transfer of your Personal Data to another Data Controller (portability), to the extent possible;
- Not be subject to a decision based solely on automated processing, including profiling, which produces legal effects (automated decision making);
- Withdraw your consent, at any time, to the extent that Qyrus relies on consent as a ground for processing, and this does not affect the lawfulness of the processing which was undertaken prior to the withdrawal;
- Not be discriminated against for exercising your privacy rights;
- Designate an authorised agent to submit requests on your behalf, subject to proof of authorisation and verification requirements;
- Nominate a person to act on your behalf, in case of death or disability;
- Complain about the use of your Personal Data, appeal a decision regarding your request or exercise of privacy rights;
- Opt out of disclosures to certain third parties.
10.3. Submitting a rights request. You can submit your data subject rights requests, by writing to us at: DPO@qyrus.com.
10.4. We may request information necessary to verify your identity before responding to a request. Qyrus will respond within the timeframes required under applicable law, and we attempt to process your legitimate requests in a month’s time, but it may take longer where we need additional information from you or have to verify your identity.
10.5. Where permitted by law, we may decline requests that are manifestly unfounded, excessive, repetitive, or otherwise not required to be fulfilled. Where a request is denied, we will provide an explanation where required and inform you of any available appeal rights.
10.6. Customer Data – your rights. Qyrus also processes Personal Data submitted by or for a customer to our services. We process such Personal Data as a Data Processor, and on behalf of our customers. We are not responsible for and have no control over the data privacy and security practices of our customers, which may differ from what is captured and explained under this Policy. If your Personal Data has been submitted to us by our customer and you wish to exercise any rights you may have under applicable data protection laws, please inquire with them directly, and such requests shall be processed through them.
10.7. Where applicable, individuals have the right to lodge a complaint with their local supervisory authority or data protection regulator if they believe their personal data has been processed unlawfully or to escalate unresolved grievances if a satisfactory resolution is not achieved.
11. Marketing Communications
11.1. If we process your Personal Data for the purpose of sending you marketing communications, you may manage your receipt of marketing and non-transactional communications from Qyrus by clicking on the “unsubscribe” link located on the bottom of the marketing emails.
11.2. Note that opting out of marketing communications does not stop important business and work communications related to your ongoing relationship with us, such as security information, service details, subscription messages, event registrations.
12. Links to other websites
12.1. Qyrus website may contain links to websites, applications, or services operated by third parties. These links are provided for convenience and informational purposes only. The inclusion of a link to a third-party website does not constitute endorsement, approval, or affiliation unless expressly stated.
12.2. Qyrus does not own, operate, or control such third-party websites or services and is not responsible for their content, security practices, or privacy practices. Any personal data you provide to third-party websites or services is governed by the privacy policies and terms of those third parties, not by this Policy. We encourage you to review the privacy policies and practices of any third-party websites or services before providing personal data or engaging with them.
13. Additional disclosures to California Residents
13.1. The California Consumer Privacy Act (as amended by the California Privacy Rights Act) requires businesses to disclose whether they sell or share Personal Data. As a business covered by the CCPA, we do not sell Personal Data. We may share Personal Data (in the form of identifiers and internet activity information) with third party advertisers for purposes of targeting advertisements on non-Qyrus websites, applications and services. In addition, we may allow third parties to collect Personal Data from our sites or services if those third parties are authorized service providers who have agreed to our contractual limitations as to their retention, use, and disclosure of such Personal Data, or if you use our sites or services to interact with third parties or direct us to disclose your Personal Data to third parties.
13.2. California law requires that we detail the categories of Personal Data that we disclose for certain “business purposes,” such as to service providers that assist us with securing our services or marketing our services, and to such other entities as provided here. We disclose the following categories of Personal Data for our business purposes:
- Identifiers;
- Commercial information;
- Internet activity information;
- Financial information;
- Professional and employment-related information;
- Education information;
- Geolocation data;
- Audio and visual data;
- In limited circumstances where allowed by law, information that may be protected characteristics under California or United States law; and
- Inferences drawn from any of the above information categories.
13.3. California law grants state residents certain rights, including the rights to know and access specific types of Personal Data, to learn how we process Personal Data, to request deletion of Personal Data, to request correction of Personal Data, to opt-out of sharing your Personal Data for third party advertising purposes, and not to be denied goods or services for exercising these rights.
13.4. If you are a California resident under the age of 18 and have registered for an account with us, you may ask us to remove content or information that you have posted to our website(s). Please note that your request does not ensure complete or comprehensive removal of the content or information, because, for example, some of your content may have been reposted by another user.
13.5. For information on how to exercise your rights, please refer to Section 10 of this Privacy Statement. If you are an authorized agent wishing to exercise rights on behalf of a California resident, please contact us using the information in the “Contacting Us” section herein and provide us with a copy of the consumer’s written authorization designating you as their agent.
13.6. If you would like to opt-out of shares using your cookie identifiers, turn on a Global Privacy Control in your web browser or browser extension. Please see the California Privacy Protection Agency’s website at https://oag.ca.gov/privacy/ccpa for more information on valid Global Privacy Controls. If you would like to opt-out of shares using other identifiers (like e-mail address), please refer to Section 10 of this Privacy Statement.
13.7. We may need to verify your identity and place of residence before completing your rights request.
14. Changes to this Privacy Policy
14.1. Qyrus may update this Policy from time to time to reflect changes in our practices, technologies, legal or regulatory requirements, or business operations. When we make changes, we will revise the “Last Updated” date at the top of this Policy. The updated version will be published on our website and will become effective as of the date indicated.
14.2. If we make a material update, and where required by applicable law we may provide you with prior notice through appropriate channels (such as by posting a notice on our website or by contacting you directly), including website notices or direct communication, or where required under applicable law and feasible, seek your consent to these changes.
14.3. We encourage you to periodically review this Privacy Statement to stay informed about our collection, processing and sharing of your Personal Data.
15. Contact Us:
15.1. Qyrus has appointed a Data Protection Officer; and, in India a Grievance Officer.
15.2. To be able to reach out to us for any queries regarding our privacy practices, this Policy, or wish to exercise your rights, please e-mail us at DPO@qyrus.com
15.3. We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, and you are located in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with the competent supervisory authority.
15.4. We respond to your complaints, concerns written to us on the above addresses, within the legally prescribed time frames, but no later than 30 days.
16. Additional Clarification
16.1. This Policy does not apply to the extent that we process Personal Data, on behalf of our customers, where we act as Data Processors, where applicable. For details about the privacy practices of our customers, who rely on our services as Data Controllers themselves, you will need to reach out to them directly. We do not control or are responsible for the privacy practices of our customers.
16.2. Qyrus Entities
We may serve you through any of our entities, identified below, to comply with the applicable laws, and serve you better, in your own jurisdiction or region:
- Qyrus India Private Limited, incorporated under the laws of the Republic of India;
- Qyrus Inc, incorporated under the laws of the State of Delaware;
- Qyrus Limited, incorporated under the laws of England and Wales.
To reach out to us for any privacy related queries, write to our Data Protection Officer/s, at: DPO@Qyrus.com.