Privacy policy
This policy explains how Quality Coach, trading as Vedetta, handles personal data in the Vedetta service and its read-only AI connector.
1. Who is responsible
Quality Coach operates the Vedetta product and is responsible for the processing described in this policy, except where a customer organization acts as the controller of its own workforce and field-report data.
Privacy questions and requests: [email protected]
2. Data we process
Account and organization data
Names, business email addresses, roles, organization membership, authentication records, and account status.
Field-report data
Information submitted to Vedetta by authorized users and Field Reporters, including report text, classifications, configured custom fields, lifecycle state, deadlines, and evidence-presence indicators. The customer organization determines what its users submit.
Connector data
When a user connects Vedetta to ChatGPT, Claude, or another compatible client, Vedetta processes OAuth client and token records, authorization scopes, organization and user identifiers, pseudonymous report references, requested time windows, result counts, and content-free security audit metadata.
Operational data
Security, rate-limit, error, and service-health records needed to protect and operate Vedetta.
3. Connector data boundary
The connector can return approved report summaries and descriptions, report classifications, active custom-field definitions and values, lifecycle and deadline information, evidence-presence indicators, missing requirement keys, and requirements guidance.
The connector does not expose dedicated Field Reporter contact fields, conversation history, open-question text, raw transcripts, voice notes, photos, media notes, media references, GPS coordinates, assignees, manager notes, internal errors, prompts, model traces, or AI operations data.
Approved report text and custom-field values are not semantically redacted. If a customer places a name or contact detail inside an approved report field, that text may be returned to the AI client as report content.
4. Why we process data
- Provide, secure, and support the contracted Vedetta service.
- Authenticate users and enforce organization-scoped permissions.
- Return requested reports and requirements information through the connector.
- Detect abuse, investigate failures, maintain auditability, and meet legal obligations.
- Improve reliability and product quality using minimized operational information.
Depending on the relationship and jurisdiction, processing is based on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where required.
5. Sharing
We use infrastructure, database, hosting, communications, and security providers that process data on our behalf. When a user deliberately connects an external AI client, approved connector responses are sent to that provider under the user's and customer organization's account settings and the provider's terms.
Vedetta does not sell personal data. We may disclose information when required by law, to protect rights and security, or in connection with a corporate transaction subject to appropriate safeguards.
6. Retention and security
Connector access tokens normally expire after 15 minutes. Connector refresh tokens normally expire after 30 days and can be revoked earlier. Content-free connector audit metadata is normally retained for 90 days. Other data is retained according to the customer agreement, operational need, and legal requirements.
Vedetta uses tenant-scoped authorization, encryption in transit, hashed connector credentials, bounded responses, rate limits, and access controls. No internet service can guarantee absolute security.
7. Your choices and rights
Users can disconnect the connector or ask an administrator to revoke access. Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or object to processing, and to receive portable data. Workforce-report requests may need to be directed to the relevant customer organization.
8. International processing and changes
Providers may process data in countries other than the user's country. Where required, appropriate contractual or legal transfer safeguards are used. We may update this policy as Vedetta changes and will publish the effective date on this page.