Legal
QNSI legal documents, trust policies, and operational commitments.
Legal and Trust Center
The authoritative public index is the QNSI Legal and Trust Center. Every page below is generated from the same source that renders it - these are views, not copies.
Core agreements
- Terms of Service - The contract governing use of QNSI.
- Privacy Policy - How HEOSSI handles personal data as controller.
- Data Processing Addendum - Processor terms for Customer Data, including the sub-processor disclosure.
- Cookie Policy - Cookies, analytics, and consent controls.
Legal policies
- Controller Identity and Data Protection Officer - Who the data controller legally is, its Singapore UEN, and the designated Data Protection Officer's business contact - as required by the PDPA and GDPR.
- Sub-processors - The current, complete list of third parties that process Customer Data on QNSI's behalf, their purpose, region, and cross-border transfer mechanism.
- Governing Law and Dispute Resolution - QNSI contracts are governed by Singapore law. Disputes are resolved by arbitration in Singapore under the SIAC Rules - a neutral, globally enforceable forum.
- Acceptable Use Policy - What you may not do with QNSI Cloud - and what happens if you do. Applies to every plan, including the free tier.
- Data Retention and Deletion - How long QNSI keeps each class of data, what happens when you delete something or close your account, and the limits of deletion in a tamper-evident system.
- Billing, Renewal, Cancellation, and Refund Policy - How subscriptions renew, how cancellation works, when fees or credits may be refunded, and what happens to data after a downgrade or termination.
- Government and Law-Enforcement Request Policy - How HEOSSI evaluates legal demands for customer information and when customers are notified.
- Intellectual Property Complaint Policy - How rights holders can report alleged infringement and how customers can respond.
Security policies
- Vulnerability Disclosure Policy - How to report a security vulnerability in QNSI, what we commit to in return, and the safe harbour that protects good-faith research.
- AI and Customer Data - Whether QNSI trains models on your data (it does not), how customer AI workloads are isolated, and what leaves the enclave.
- Incident Response and Breach Notification - How QNSI detects, contains, and communicates a security incident - including the notification timelines we commit to.
- Customer Security Responsibilities - The shared-responsibility boundary for accounts, keys, applications, users, integrations, and regulated workloads.
Compliance policies
- Export Control and Sanctions - QNSI is offered internationally, subject to applicable export-control, sanctions, end-use, and licensing requirements.
- Marketing Communications Policy - Consent, identification, opt-out, and Singapore Do Not Call requirements for QNSI marketing.
- Anti-Bribery, Anti-Corruption and Modern Slavery - HEOSSI's business-conduct commitments - the ones enterprise and government procurement will ask you to evidence.
Operational policies
- Business Continuity and Disaster Recovery - How QNSI is architected to survive failure, how we recover, and what we do not yet promise.
- Accessibility Statement - QNSI's accessibility commitment, the standard we build to, known gaps, and how to report a barrier.
- Support and Maintenance Policy - Support scope, severity handling, maintenance notices, and the difference between response targets and contractual guarantees.
- Service Level Agreement - Availability measurement, exclusions, service credits, claim procedure, and the plans eligible for contractual SLA coverage.
Generated from the single legal source of truth (
apps/web/lib/legal/). Do not edit by hand - edit the source and runpnpm gen:legal-docs. The authoritative published version of every document is on the QNSI Legal and Trust Center.