Skip to main content

Your thoughts are needed - 9th annual QorusDocs State of the Industry Benchmark Survey. Take Survey

Secure, dependable proposal automation software

We value the trust our client's place in us when they choose QorusDocs for their business. That’s why we go above and beyond when it comes to security and compliance measures.
SOC 2 Type II

QorusDocs has completed a Service Organization Controls 2 Type II (SOC 2 Type II) audit with an independent 3rd-party evaluator certified by The American Institute of CPAs (AICPA). This audit uses the Trust Services Principles (Security and Privacy), published by AICPA, to evaluate the effectiveness of a service organization’s controls. QorusDocs can provide SOC 2 Type II report and attestations of compliance, upon request, at security@qorusdocs.com. QorusDocs is committed to continuous compliance and has implemented measures to keep the implemented SOC controls current.

GDPR

QorusDocs stores a minimum of Personally Identifiable Information (PII), and only as defined by our Client to deliver the Services. QorusDocs follows the policies below that are relevant to General Data Protection Regulation (GDPR):

  • Basis for Processing: QorusDocs collects and processes data to fulfill the performance of our contract with our Clients. Each Client, as the data controller, is responsible for determining the lawful basis for processing data and documenting EU data subject consent, if consent is the lawful basis for processing.
  • Data Storage: All data is stored securely in the United States in Microsoft Azure Datacenters.
  • Data Deletion, Correction, or Extraction: QorusDocs will export, correct, or delete data upon request by the Data Subject if the functionality is not already available self-service. Delete requests must be submitted to security@qorusdocs.com.
  • Marketing: QorusDocs does not market to, nor resell, any Contact Data collected on behalf of the Subscriber.

For more details about Qorus GDPR compliance, contact security@qorusdocs.com.

Standard Contract Clauses (SCCs)

QorusDocs uses EU Standard Contractual Clauses (SCCs) and UK SCCs as legal mechanisms for data transfer because they provide a secure framework for cross-border data flows. These clauses ensure compliance with data protection laws when transferring personal data from the European Economic Area (EEA) and the UK. By incorporating SCCs into contracts, we demonstrate our commitment to safeguarding user privacy and mitigating risks associated with data transfers across different jurisdictions.

Global Data Processing Agreement

The Data Processing Agreement (DPA) serves as a legally binding contract that outlines the rights and obligations of the parties involved in processing personal data. The DPA sets out the scope, nature, and purpose of processing, the types of data involved, and the responsibilities of both parties to protect the privacy and security of the data.

https://www.qorusdocs.com/dpa/ 

Sub-processors

QorusDocs is acting as a Data Processor under the GDPR or a Service Provider under the CCPA. We comply with prevailing privacy laws and regulations. We ensure that our sub-processors are also compliant and enter into the necessary DPA/SCC legal agreements to satisfy the requirements of the laws.

https://www.qorusdocs.com/subprocessors/ 

Technical and Organizational Measures

QorusDocs upholds stringent security protocols and procedures to safeguard personal information, aligning with regulatory standards such as the GDPR and CCPA. Technical measures encompass both physical and electronic protections, including encryption and access restrictions. Organizational measures pertain to the implementation of policies and procedures that guarantee secure data handling by employees, consistent with privacy legislation. Collectively, these strategies provide a robust shield against threats to data security.

https://www.qorusdocs.com/securitymeasures/ 

compliance_privacy

Ensuring your privacy

QorusDocs has a privacy policy, which outlines the steps we take to protect clients’ information. The policy is date-stamped and publicly available here.  QorusDocs privacy policy is aligned to GDPR.

Unparalleled data security in the cloud

In addition to multiple internal security and privacy controls, QorusDocs uses Microsoft Azure as its hosting provider to ensure our software takes advantage of over 90 compliance certifications and a series of tools that simplify and accelerate cloud compliance.

compliance_security

We're here to answer all your security questions

Our team is standing by to address any additional questions or concerns you might have about QorusDocs’ security and compliance features.

Please contact our Security and Compliance team at security@qorusdocs.com for assistance.