Privacy Policy
The short version: this website tracks nobody, we sell nothing about you, and the data your laboratory stores in RainerQMS is yours — we process it only on your instructions. The long version follows, clause by clause.
§ 1Who we are
RainerQMS is operated by Rainer Technologies ("Rainer", "we", "us"). We build quality management software for laboratories. For personal data described in this policy, Rainer acts as the data controller, except for data our customers store inside their RainerQMS workspace, where we act as a processor under our Data Processing Agreement.
§ 2Data we collect, and why
Website visitors
This website sets no cookies and runs no analytics or tracking scripts. Our hosting infrastructure keeps short-lived server logs (IP address, user agent, requested URL, timestamp) for security and abuse prevention — legal basis: legitimate interest in operating a secure service.
Prospects and correspondents
If you request a demo or email us, we process the details you send — name, work email, organization, laboratory type, message — to respond and follow up. Legal basis: pre-contractual steps taken at your request, and legitimate interest in operating our business.
Customers and their users
To provide the service we process account data (name, work email, role, authentication events) and billing data (invoicing contact, plan, payment records). Legal basis: performance of a contract; legal obligation for accounting records.
Service data (as processor)
Documents, quality records, signatures and audit trails your laboratory stores in RainerQMS are processed only on your documented instructions, under the DPA. Your organization is the controller of that data.
§ 3What we don't do
- We do not sell personal data, ever.
- We do not use customer records to train machine-learning models.
- We do not run advertising or share data with ad networks.
§ 4Sharing and subprocessors
We share personal data only with the subprocessors needed to run the service (hosting, email delivery, payment processing), each bound by a written agreement at least as protective as ours. The current subprocessor register is published in the DPA, § 8. We may also disclose data where the law requires it — and where allowed, we will tell you first.
§ 5International transfers
Where personal data is transferred outside the EEA, the UK or Switzerland, we rely on adequacy decisions or the EU Standard Contractual Clauses (2021/914), with supplementary measures where appropriate.
§ 6Retention
Demo and correspondence data: up to 24 months after last contact. Account data: for the life of the contract plus the period required for legal and accounting obligations. Service data: retained per your instructions and returned or deleted on termination (see DPA § 13). Server logs: up to 90 days.
§ 7Security
Strict tenant separation, encryption in transit, hashed credentials, role-based access, MFA and append-only audit logging — described on our Security page.
§ 8Your rights
Depending on your jurisdiction, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing is based on consent. Write to privacy@rainerqms.com — we respond within 30 days. You may also lodge a complaint with your supervisory authority.
If your data lives inside a customer's RainerQMS workspace, we will refer your request to that laboratory (the controller) and assist them in answering it.
§ 9Children
RainerQMS is a professional tool for laboratory work. It is not directed at children, and we do not knowingly collect data from anyone under 16.
§ 10Changes to this policy
This policy is a controlled document: material changes increment the revision, update the effective date, and — for customers — are notified by email before they take effect.
§ 11Contact
Privacy questions: privacy@rainerqms.com. Postal address and company identification are published in the legal notice.