Qubit Docs العربية

Compliance FAQ

These answers describe what the product does and what Qubit's Privacy Policy states. For contractual or certification questions, contact Qubit directly.

Which data protection law does Qubit follow?

Qubit's Privacy Policy states that Qubit processes personal data in accordance with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations. Where customers are subject to other data protection laws, Qubit supports them in meeting their obligations under those laws.

Where is our data processed?

See Data residency.

How long are audit records kept?

Each workspace sets its own retention period in the Security tab, from 30 to 2,555 days. A daily cleanup deletes records older than that period. See Workspace security.

Can we send audit records to our own SIEM?

Yes. Owners and admins can forward every record to an HTTPS endpoint, with each request signed using HMAC-SHA256, or to a syslog collector over TLS in JSON or CEF format. Records can also be exported as CSV or JSON Lines. See Audit Logs.

Can we check that audit records have not been altered?

Yes. Each record stores a hash of its content and the hash of the record before it. Verify integrity on the audit log page checks the chain and reports where it breaks, if it does.

How are passwords and credentials stored?

Account passwords are stored as one-way hashes. Credentials for connected data sources are encrypted at rest, as are other secrets such as the Slack bot token and embed API key secrets.

What happens to our data when we delete a data connection?

The Privacy Policy states that deleting a connection removes the data it loaded into your workspace's warehouse.

How do we make a request about personal data?

The Privacy Policy gives the right to be informed, to access personal data, to ask for it to be corrected or destroyed, to withdraw consent, and to receive a copy in a readable format. Send requests to the contact address in the Privacy Policy. Qubit responds within 30 days and may extend that by a further 30 days for complex requests. Where Qubit processes data on behalf of a customer, requests go to that customer.

What happens if there is a breach?

The Privacy Policy states that if Qubit becomes aware of a breach affecting personal data, it notifies the competent authority within 72 hours, as the PDPL requires, and notifies affected people where the breach is likely to cause them harm.