Privacy Policy
How ETS Labs collects, uses, shares, and protects personal data across the QEval® website and platform. Your rights under applicable privacy law and how to exercise them.
ETS Labs is a division of Etech Global Services, LLC
1903 Berry Drive, Nacogdoches, TX 75964, United States
Tel: +1 936-559-2258
This Privacy Policy describes how ETS Labs ("ETS Labs," "we," "us," "our") collects, uses, discloses, and protects personal data when you visit qeval.ai, request a demo, engage with our marketing, apply for a role, or otherwise interact with us as a website visitor, prospect, or job applicant. It also explains our role when enterprise clients use the QEval® platform to process call recordings and interaction data on behalf of their own customers.
Who we are
QEval® is a contact center quality analytics and performance management platform developed by ETS Labs, the applied AI division of Etech Global Services, LLC. ETS Labs is headquartered at 1903 Berry Drive, Nacogdoches, Texas 75964, United States. References to "QEval®," "ETS Labs," "we," "us," and "our" in this policy refer to ETS Labs and, where applicable, Etech Global Services, LLC.
For personal data covered by the EU GDPR and UK GDPR, ETS Labs acts as a data controller for data processed for our own purposes (marketing, recruitment, website analytics) and as a data processor when we provide the QEval® platform to enterprise clients under a written agreement. The distinction is explained in the next section.
Two roles, two sets of rules
Controller (this policy applies)
When you visit qeval.ai, request a demo, subscribe to marketing, or apply for a job, ETS Labs is the data controller. This policy governs that data.
Processor (client's policy applies)
When an enterprise client uses the QEval® platform to process their agents' calls and customer interaction data, ETS Labs is a data processor. The client is the controller. That data is governed by the client's privacy notice and our Data Processing Agreement, not this policy.
When ETS Labs acts as a processor, our platform processes call recordings, transcripts, evaluation scores, and associated metadata strictly under the client's instructions and in accordance with our Data Processing Agreement. ETS Labs does not use client call data for its own marketing, product development benefiting other clients, or any purpose beyond delivering the contracted service. Enterprise clients may request a copy of our Data Processing Agreement by contacting privacy@qeval.ai.
What we collect
Website visitors and marketing contacts
- Name and job title
- Business email address and telephone number
- Company name, size, and industry
- IP address and approximate location (city or region level)
- Browser type, device type, operating system, and referring URL
- Pages visited, session duration, and interactions with site features including the ROI calculator
- Cookie identifiers and similar tracking technologies (see our Cookie Policy)
- Information you provide when submitting a demo request, contact form, or webinar registration
Job applicants
- Resume, CV, and cover letter
- Work history, education, and skills
- Information you provide during interviews or assessments
- References, where you provide them
- Background check results, where permitted by applicable law and with appropriate notice
What we do not collect through the website
We do not knowingly collect biometric identifiers, genetic data, health data, payment card numbers, or Social Security numbers through qeval.ai. Where our platform clients provide us with personal data for processing in a contact center program, including data that may be subject to HIPAA or PCI DSS, we handle that data under the client's instructions, our Data Processing Agreement, and our certified security controls described in the Security section below.
How we use personal data
- Deliver and improve the website and its features
- Respond to demo requests, proposals, and support inquiries
- Send marketing communications about QEval® products and services where permitted and subject to opt-out
- Assess job applicants and retain candidate profiles for future openings where you consent
- Detect, prevent, and investigate fraud, abuse, and unauthorized access
- Comply with legal obligations including tax, audit, and sanctions screening
- Defend and establish legal claims
We do not sell personal data. We do not share personal data for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, the California Privacy Rights Act, and equivalent state privacy laws.
Legal basis for processing (GDPR and UK GDPR)
Where the EU GDPR, UK GDPR, or Swiss Federal Act on Data Protection applies, we rely on the following legal bases:
- Contract — to respond to proposals, provide access to requested resources, and deliver contracted services.
- Legitimate interest — to market to business contacts at target accounts, secure our network, measure site performance, and prevent fraud, where those interests are not overridden by your rights.
- Consent — for non-essential cookies, marketing to individuals in jurisdictions that require opt-in, and voluntary disclosures in job applications.
- Legal obligation — for tax records, responses to lawful requests from public authorities, and other compliance obligations.
We do not rely on the "By using our site, you consent to this privacy policy" formulation as a legal basis. Consent to the policy is not a valid GDPR legal basis for any specific processing activity.
How we share personal data
We share personal data with a limited set of recipients:
- Corporate affiliates of ETS Labs and Etech Global Services in the United States for unified operations.
- Service providers under written contract, including cloud hosting (AWS US East), email marketing, CRM (HubSpot), analytics, background check, payroll, and audit providers. Each is bound by confidentiality and data protection terms.
- Professional advisors such as outside counsel, auditors, and insurers.
- Government or regulators when required by law, including in response to subpoenas, court orders, or regulator investigations.
- Acquirers in the context of a merger, financing, reorganization, or asset sale, subject to confidentiality obligations.
We do not sell personal data to third parties. We do not share personal data with third parties for their own marketing purposes.
International data transfers
ETS Labs is headquartered in the United States. All platform data is hosted in AWS US East regions and is not transferred outside the United States at any stage of the analytical lifecycle. For personal data of website visitors, marketing contacts, and job applicants that originates in the European Economic Area, the United Kingdom, or Switzerland, ETS Labs relies on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) — ETS Labs uses the European Commission's 2021 Standard Contractual Clauses as the primary transfer safeguard. For transfers where an EU-based client is the data controller and ETS Labs is the processor, Module 2 (controller-to-processor) applies. For transfers to subprocessors, Module 3 (processor-to-sub-processor) applies where relevant.
- EU-US Data Privacy Framework — where ETS Labs participates in the EU-US Data Privacy Framework. ETS Labs maintains SCCs as a backup safeguard so that a valid transfer mechanism remains in place regardless of the framework's status.
- UK International Data Transfer Addendum — for transfers from the United Kingdom.
- Swiss-US Data Privacy Framework — for transfers from Switzerland where applicable.
For the full description of our transfer mechanisms and the principles we follow, see our International Data Transfers page. A Data Processing Agreement incorporating the applicable SCCs is available on request from privacy@qeval.ai.
Security
ETS Labs maintains an information security program designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. Platform-level controls include:
- Data encrypted at rest using AES-256 and in transit using TLS 1.2 or higher
- Role-based access control (RBAC) and multi-factor authentication required for all systems handling personal data; access granted on a least-privilege basis and reviewed regularly
- Network security enforced through firewalls, intrusion detection systems, and endpoint protection
- Comprehensive audit logging of all access to client data, retained for a minimum of 12 months
- PCI-sensitive information redacted in real time using Automated Speech Recognition before storage; original recordings are deleted in compliance with PCI DSS standards
- Annual third-party penetration testing with a documented remediation SLA; regular internal vulnerability assessments
- Business continuity and disaster recovery plan established and tested at least annually
- All employees undergo background checks and complete security awareness training within 30 days of hire and at least annually thereafter
ETS Labs is certified for SOC 2 Type II, ISO 27001:2022, HIPAA, PCI DSS (SAQ D, SP and ROC Prep), and NIST 800-53. SOC 2 Type II reports, ISO certificates, and penetration test reports are available to enterprise clients under NDA at trust.etslabs.ai. See our Security and Trust page for further detail.
Data retention
We retain personal data only as long as necessary for the purpose collected and to satisfy legal, regulatory, accounting, and reporting obligations. Representative retention periods:
| Category | Retention period |
|---|---|
| Website analytics and session data | 14 months from last visit |
| Marketing contacts (prospects, newsletter subscribers) | Until opt-out or 24 months of inactivity, whichever is earlier |
| Demo and contact form submissions | 36 months from submission, or for the duration of an active commercial relationship |
| Job applicant data (unsuccessful candidates) | 12 months after position is filled, unless you consent to a longer period |
| Platform media files (call recordings) — client data | 90 days, unless the client's DPA specifies otherwise |
| Platform call transcriptions — client data | 365 days (modifiable by client instruction under the DPA) |
| Platform evaluation data — client data | 18 months in primary database, then archived for 5 years; retrievable within 3 to 5 business days |
| Security and access logs | Minimum 12 months |
| Tax and financial records | 7 years as required by applicable law |
Data breach notification
In the event of a personal data breach, ETS Labs will notify the relevant supervisory authority within 72 hours of becoming aware where required by GDPR or UK GDPR, and will notify affected individuals as required by applicable law. For enterprise platform clients, ETS Labs will notify the client within 24 hours of detection of any breach affecting their data, with details of the breach, affected data, remediation steps, and mitigation strategies. ETS Labs will investigate and mitigate risks within 48 hours of detection and provide a formal root-cause and corrective-measures report. If you believe your account or data has been compromised, contact security@qeval.ai.
Your rights
Subject to verification of identity and applicable exceptions, you have the right to:
- Access personal data we hold about you
- Correct inaccurate or incomplete data
- Request erasure in defined circumstances
- Restrict or object to our processing
- Receive a portable copy of data you provided to us
- Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing
- Lodge a complaint with your supervisory authority
To exercise any of these rights, write to privacy@qeval.ai or call +1 936-559-2258. We will acknowledge your request within 48 hours and respond within 30 calendar days. For complex or numerous requests we may extend this period by up to 60 additional days, in which case we will notify you of the extension and reason within the initial 30-day period. We reserve the right to verify your identity before processing a request.
For personal data processed by ETS Labs as a processor on behalf of an enterprise client, data subject requests should be directed to the relevant client. Where a data subject contacts ETS Labs directly about platform data, we will route the request to the appropriate client controller promptly.
US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Jersey, and other states that have enacted comprehensive consumer privacy legislation have the following rights under applicable law:
- Know what personal data we have collected, the purposes of collection, and the categories of third parties with whom it is shared
- Request deletion of personal data we hold, subject to statutory exceptions
- Correct inaccurate personal data
- Opt out of the sale or sharing of personal data. ETS Labs does not sell personal data and does not share personal data for cross-context behavioral advertising
- Limit the use of sensitive personal information. We do not use sensitive personal information for purposes beyond those described in this policy
- Non-discrimination for exercising a privacy right
- Appeal a denied rights request
To exercise these rights, submit a verifiable request to privacy@qeval.ai or call +1 936-559-2258. You may designate an authorized agent in writing. California residents may also use the Global Privacy Control signal to opt out of any sharing; we honor GPC as described in our Cookie Policy.
Children
The QEval® website and platform are directed to businesses and are not intended for children under 16. ETS Labs does not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact privacy@qeval.ai and we will delete it within 15 business days of a confirmed report, subject to any retention obligations required by law.
Marketing communications and DNC
Every marketing email we send includes an unsubscribe link and we honor opt-out requests promptly. For outbound phone marketing, we screen against the National Do Not Call Registry, applicable state DNC lists, and our internal suppression list at least every 31 days. You can ask us to add your number to our internal suppression list at any time by emailing privacy@qeval.ai or by telling an agent during a call.
Cookies
We use first-party and third-party cookies for security, site functionality, performance measurement, and limited marketing. For a full list of cookies, their purposes, durations, and your controls, see our Cookie Policy. You can manage preferences through the banner on first visit or through your browser settings. We honor the Global Privacy Control signal for opt-out of sale or sharing where applicable.
Changes to this policy
We may update this policy to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised policy and update the effective date at the top of this page. Where changes are material, we will provide additional notice through a banner on the site or direct email to affected individuals. Continued use of the website after an update constitutes acceptance of the revised policy in jurisdictions where notice-and-opt-out applies; in consent-based jurisdictions, renewed consent will be requested where required.
Contact us
Send privacy questions, rights requests, or complaints to:
Email: privacy@qeval.ai
Tel: +1 936-559-2258
ETS Labs (a division of Etech Global Services, LLC)
1903 Berry Drive, Nacogdoches, Texas 75964, United States
EU and UK residents who are not satisfied with our response may refer a complaint to their national supervisory authority. Residents of the United States may file a complaint with the relevant state Attorney General. Residents of Ontario, Canada may file a complaint with the Information and Privacy Commissioner of Ontario.