Log in

Privacy Policy

Last updated: July 17, 2026

Who we are

Quick-Work is an operations suite — a family of products that share one account, organization, and security model, including contract lifecycle management and asset & inventory management, with more on the way. This policy explains what data the service collects, why, and how it is protected across the suite.

What we collect

  • Account data — your name, email address, and an optional age. No other personal profile information is requested.
  • Organization content — the contract and asset records you and your organization create (supplier names, dates, values, contacts, and links to documents you host elsewhere). We store metadata and links only; we do not store your signed contract documents.
  • Operational data — authentication sessions, in-app notifications, and standard server logs (including IP address) used to run, secure, and troubleshoot the service.

How we use it

We use your data to provide the service: managing your organization’s contracts and assets, sending the reminders and notifications the product exists to deliver, billing per seat where applicable, and keeping the service secure and reliable. We do not sell your data.

How we protect it — encryption & isolation

Your data is encrypted and walled off to your organization. Your records are locked with an encryption key that belongs to your organization alone and is never shared with another customer, so a stolen copy of our database is unreadable — the data and the keys to it are kept apart.

  • Encrypted in transit and at rest. All traffic uses TLS, and all stored data — including backups — is encrypted on disk.
  • Per-organization field encryption. On top of that, sensitive fields are encrypted inside the application, before they ever reach the database, using AES-256-GCM under a key unique to your organization. Each value is tamper-evident and cryptographically bound to your organization — it cannot be read in the context of any other customer’s account.
  • Keys live in hardware, not next to your data. Your organization’s key is itself encrypted (“wrapped”) by a master key held in AWS Key Management Service — hardware-backed and designed so it can never be exported. Every use of the master key is access-controlled and audit-logged, and it rotates automatically each year. Deleting your organization destroys its key, permanently unlocking nothing: encrypted values become unreadable even in historical backups.
  • Only your people, only their scope. Data is decrypted solely to answer an authenticated request from a member of your organization, and access is further limited by role (owner, admin, member, viewer) and by team/group.

What is field-encrypted, and what isn’t — and why

Field encryption covers the content of your records across every Quick-Work product:

  • Contact details — emails, phone numbers, contact persons, and addresses of your suppliers, vendors, clients, sites, people, and employees.
  • Financial values — contract values and payments, asset purchase costs and valuations, project earnings/expenses, funding amounts.
  • Descriptions and notes — the free-text prose on contracts, assets, audits, projects, tasks, decisions, time bookings, and workflows.
  • HR content — candidate contact details and resumes, interview feedback, performance reviews and goals, HR policies, timesheet comments.
  • References and links — document repository links, purchase order and insurance references.
  • Integration credentials — Slack and Microsoft Teams webhook URLs you configure for notifications.

A deliberately small set of fields stays outside field encryption (still encrypted at rest), because the product’s core features run on them in the database:

  • Record names and titles (contracts, suppliers, assets, projects, people) — so search and alphabetical ordering work.
  • Dates (expiry, notice, renewal, action dates) — so the reminder engine can warn you before deadlines, which is the heart of the product.
  • Statuses, phases, and categories — so filters, KPIs, and dashboards can be computed efficiently.
  • Employee work emails — used to match sign-ins to employee records and power the people directory.
  • Support requests you send us — our team reads these to help you, so they are stored readable by design.

To make search, reminders, and dashboards work, our application decrypts your data in order to serve your requests; this is not end-to-end encryption. What it guarantees is that your stored data is unreadable to anyone who obtains the database or a backup, and that it stays isolated to your organization.

Cloudflare Turnstile (bot protection)

To protect sign-in, sign-up, and password-reset from automated abuse, we use Cloudflare Turnstile in its invisible mode. It runs silently in your browser with no checkbox or visible challenge, and issues a token that our servers verify. To do this, Cloudflare may collect information about the request and your device/browser and set a token; this processing is described in Cloudflare’s documentation.

Cloudflare’s handling of this data is governed by the Cloudflare Turnstile Privacy Addendum and the Cloudflare Privacy Policy. We reference the Turnstile Privacy Addendum here as a condition of using invisible mode.

Third parties

Besides Cloudflare (bot protection), the service relies on infrastructure and processors that support its operation — cloud hosting (AWS), transactional email, and, where billing is enabled, our payments provider (Stripe). Each processes data only to provide its function.

Retention & deletion

We keep your data for as long as your account and organization are active. When an organization is deleted, its per-organization encryption key is destroyed with it, rendering that organization’s encrypted fields permanently unreadable — including in historical backups.

Contact

Questions about this policy or your data can be directed to your organization’s administrator or the Quick-Work team.

← Back to Quick-Work