Your thoughts are needed - 9th annual QorusDocs State of the Industry Benchmark Survey. Take Survey
QorusDocs has completed a Service Organization Controls 2 Type II (SOC 2 Type II) audit with an independent 3rd-party evaluator certified by The American Institute of CPAs (AICPA). This audit uses the Trust Services Principles (Security and Privacy), published by AICPA, to evaluate the effectiveness of a service organization’s controls. QorusDocs can provide SOC 2 Type II report and attestations of compliance, upon request, at security@qorusdocs.com. QorusDocs is committed to continuous compliance and has implemented measures to keep the implemented SOC controls current.
QorusDocs stores a minimum of Personally Identifiable Information (PII), and only as defined by our Client to deliver the Services. QorusDocs follows the policies below that are relevant to General Data Protection Regulation (GDPR):
For more details about Qorus GDPR compliance, contact security@qorusdocs.com.
QorusDocs uses EU Standard Contractual Clauses (SCCs) and UK SCCs as legal mechanisms for data transfer because they provide a secure framework for cross-border data flows. These clauses ensure compliance with data protection laws when transferring personal data from the European Economic Area (EEA) and the UK. By incorporating SCCs into contracts, we demonstrate our commitment to safeguarding user privacy and mitigating risks associated with data transfers across different jurisdictions.
The Data Processing Agreement (DPA) serves as a legally binding contract that outlines the rights and obligations of the parties involved in processing personal data. The DPA sets out the scope, nature, and purpose of processing, the types of data involved, and the responsibilities of both parties to protect the privacy and security of the data.
QorusDocs is acting as a Data Processor under the GDPR or a Service Provider under the CCPA. We comply with prevailing privacy laws and regulations. We ensure that our sub-processors are also compliant and enter into the necessary DPA/SCC legal agreements to satisfy the requirements of the laws.
QorusDocs upholds stringent security protocols and procedures to safeguard personal information, aligning with regulatory standards such as the GDPR and CCPA. Technical measures encompass both physical and electronic protections, including encryption and access restrictions. Organizational measures pertain to the implementation of policies and procedures that guarantee secure data handling by employees, consistent with privacy legislation. Collectively, these strategies provide a robust shield against threats to data security.
QorusDocs has a privacy policy, which outlines the steps we take to protect clients’ information. The policy is date-stamped and publicly available here. QorusDocs privacy policy is aligned to GDPR.
In addition to multiple internal security and privacy controls, QorusDocs uses Microsoft Azure as its hosting provider to ensure our software takes advantage of over 90 compliance certifications and a series of tools that simplify and accelerate cloud compliance.
Our team is standing by to address any additional questions or concerns you might have about QorusDocs’ security and compliance features.
Please contact our Security and Compliance team at security@qorusdocs.com for assistance.