PilotBreak (“we”, “ASKQA”) operates the PilotBreak platform and related audit services at pilot.askqa.app. This policy describes what we collect, why we collect it, and how to contact us.
Data we collect
- Account data — name, work email, organization name, country, and currency preference when you sign up or contact us.
- Pilot portfolio data — AI pilots you register (name, stage, owner, diagnosis scores, governance decisions, and related notes).
- Baseline & proof data — KPI entries, locked baselines, ROI figures, audit trail metadata (who entered a value, source notes, lock timestamps).
- Shadow AI register — tools your team reports, usage estimates, and risk notes.
- Leads & scorecard — if you use the public paralysis scorecard or contact form, we store email, company, country, and your responses to qualify follow-up.
- Technical logs — standard server logs (IP address, user agent, request timing) for security and abuse prevention. We do not sell personal data.
Where data is stored
Application data is stored in PostgreSQL on Neon (hosted on AWS). Session state is not stored server-side; see our Security page for how sessions work.
Cookies
We use a single session cookie (pilotbreak_session) after you log in or enter the read-only demo. It is HTTP-only, signed, and expires after seven days. We do not use third-party advertising cookies on the product.
How we use data
- Provide the PilotBreak workspace, exports, and audit deliverables you request.
- Respond to sales and support enquiries.
- Improve product reliability and prevent abuse (rate limits, security monitoring).
- Meet legal obligations where applicable.
Retention
- Active workspaces — retained while your account is active and for a reasonable period after cancellation so you can export records.
- Leads & scorecard submissions — retained for sales follow-up, typically up to 24 months unless you ask us to delete sooner.
- Server logs — rotated on a short rolling window (days to weeks) unless needed for an incident investigation.
- Demo sandboxes — ephemeral read-only orgs; we may purge inactive demo data periodically.
Exact retention for paid audit engagements is defined in your statement of work. You may request deletion of personal data by emailing us (subject to legal hold or active contract obligations).
Your rights
Depending on your location, you may have rights to access, correct, export, or delete personal data. Contact us to exercise these rights. For EU/UK buyers, see also our Data Processing Note.
Contact
Questions about this policy: pilot@askqa.app