Legal
Privacy Policy
Last updated August 25, 2026
CeyhanLabs (“we”, “us”) operates QualityOps, a multi-tenant business application for automotive quality operations. This policy describes what data QualityOps processes, why, and how it is protected. It applies to the QualityOps web application and its connected inbound channels, including the WhatsApp work-report intake described below.
Account and organization information
When someone signs in to QualityOps, we receive their name and email address from Microsoft Entra ID (Microsoft 365 authentication). We store that identity, the organization they belong to, and their role within it. We do not receive or store Microsoft account passwords — authentication is handled entirely by Microsoft’s identity platform.
Microsoft 365 email processing
For tenants who connect a Microsoft 365 mailbox, QualityOps reads incoming messages through the Microsoft Graph API to extract operational information (customer, part number, operation type) using a deterministic, non-AI rule engine. Access and refresh tokens are stored server-side only and are never exposed to the browser or to any other party. We store the minimum needed to trace a decision back to its source — message id, conversation id, subject, sender, and timestamp — and a bounded fragment of the message text that a rule actually matched on. The full message body is never persisted. Attachments are never fetched or stored.
WhatsApp message processing
Tenants may optionally authorize specific phone numbers to submit shift work reports over WhatsApp, using either Twilio’s WhatsApp API or the Meta WhatsApp Cloud API. Every inbound message is verified against that provider’s signature before it is processed, and is matched to a tenant only through an exact, explicitly authorized phone number — there is no open WhatsApp intake and no way to reach the product by messaging an unrecognized number.
The text of a work report is parsed in memory by a deterministic rule engine to identify a part number, quantities, and outcome (such as OK, rework, or defective counts), which is written into the tenant’s spreadsheet workbook. A report that cannot be parsed reliably is held for a human reviewer rather than guessed at. Non-text messages (images, documents, location, audio) are not processed. WhatsApp is used only as a one-way intake channel for work reports; it is not a general product interface and is not used to send notifications, marketing, or any content beyond a short, fixed acknowledgment of receipt.
Pilot enquiries from this website
The pilot form on this website does not transmit anything to our servers. It formats the details you enter — your work email, company, selected use case and operation volume, and any note you add — into a message that opens in your own WhatsApp or email client. Nothing is sent until you send it, and we store nothing on this website. When you do send it, we receive it as an ordinary business enquiry and handle it as sales correspondence in order to respond to you. We do not use it for advertising and we do not sell it. To have an enquiry you sent us deleted, reply to it or write to privacy@ceyhanlabs.com.
Data storage
Data is stored in a PostgreSQL database logically separated by organization — every stored record carries an organization identifier, and every query is scoped to it. Uploaded and generated spreadsheet workbooks are stored as private file blobs accessible only to the owning organization.
Data retention
Personal data collected through email ingestion (sender and recipient details, subject lines, matched message fragments) is retained for up to 365 days from receipt, after which it is automatically redacted — unless it is still attached to an operation that is actively open, in which case it is retained until that operation is closed. Redaction removes the personal content of a record while keeping the record of the decision itself, which is necessary so a message is not silently reprocessed. Authorized WhatsApp phone numbers are retained only while active; revoking one immediately clears the stored number.
Third-party services
QualityOps relies on the following third parties to operate:
- Microsoft Entra ID and Microsoft Graph API — sign-in and email access, for tenants who connect a mailbox.
- Twilio — delivery and verification of WhatsApp work reports, for tenants who use the Twilio integration.
- Meta WhatsApp Cloud API — delivery and verification of WhatsApp work reports, for tenants who use the Meta integration.
- Paddle — billing and subscription management. Paddle, not this application, processes payment details.
- Our infrastructure and database hosting providers, who store the data described above on our behalf.
We do not sell personal data, and we do not use it for advertising.
Your choices
If you believe your data has been processed by QualityOps through a customer’s use of the product and want it reviewed, corrected, or deleted, see our Data Deletion page.
Changes to this policy
We may update this policy as the product changes. Material changes will update the date at the top of this page.
Contact
Questions about this policy can be sent to privacy@ceyhanlabs.com.