Legal

Privacy Policy

Good Quarter Company · Effective August 23, 2026

This policy explains how Good Quarter Company (“GQC”, “we”, “us”), based in Toronto, Canada, collects, uses, and protects information when you use our products and services — including PYX, our governed analytics delivery platform; our applications for the Celonis platform; and the websites we operate around them (together, the “Services”). By using the Services you agree to the practices described here. Questions go to privacy@goodquartercompany.com.

Information we collect

Account information. Your name, work email address, and workspace membership, provided when you or your organization sets up access.

Workspace content. The material you create in our products — in PYX, for example: requirements, semantic models and metric definitions, control configurations, governance designs, comments, and decision records. This content belongs to your organization; we process it only to provide the Services.

Connection configuration. To deploy to and read from your data platform (for example a Databricks workspace or a Celonis environment), our products store connection details you supply, including workspace URLs and access credentials. Credentials are stored encrypted and used solely to perform the operations you configure.

Data from connected systems. When you run controls, evidence collection, lineage capture, witness queries, or process analyses, our products process metadata about your estate (schemas, tables, columns, data models, process models, job runs) and limited samples of query results your configuration requests. This is processed on your organization’s behalf and, in PYX, retained as part of your workspace’s evidence record. Where a GQC application runs entirely inside your own platform environment (for example an app installed in your Celonis environment), your data is processed there under your platform agreement and is not transmitted to us.

Usage and telemetry. Log data, feature usage, and AI-usage metering (for example, token counts per workspace) collected to operate, secure, and bill the Services.

Cookies. We use cookies for sign-in sessions and preferences only. We do not use advertising or cross-site tracking cookies.

How we use information

We use the information above to provide and improve the Services, authenticate access, execute the deployments and controls you configure, retain the evidence and audit records the product exists to keep, provide support, meter usage for billing, and meet our legal obligations. We do not sell personal information, and we do not use your workspace content to train machine-learning models.

AI features

Some of our products send content you provide (for example, a requirement description or a chat message) to third-party large-language-model providers to generate a response. These providers process the content to return the result and are contractually restricted from using it for their own purposes. AI usage is metered per workspace.

Sharing

We share information only with service providers who help us run the Services — cloud hosting and content delivery, managed databases, AI model providers, and email delivery — each bound by confidentiality and data-protection obligations; with your organization (your workspace administrators can see the content and activity in their workspace); and where required by law. We do not sell or rent personal information to anyone.

Retention

Workspace content and evidence records are retained for as long as your organization’s agreement with us is active, because durable records are the point of the product. On termination, your organization may request export and deletion; we delete or anonymize personal information within 90 days of a verified request, except where law requires longer retention. Operational logs are kept for shorter, rolling periods.

Security

Information is encrypted in transit and at rest. Platform credentials are stored encrypted, access is limited to what the Services need, and access to production systems is restricted and logged. No system is perfectly secure; if we learn of a breach affecting your information we will notify affected organizations without undue delay.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to certain processing — including rights under Canada’s PIPEDA and, where it applies, the EU/UK GDPR. Because we usually process workspace data on behalf of your organization, requests about workspace content are best directed to your administrator; for anything else, contact us and we will respond within 30 days. You may also complain to your local privacy regulator, including the Office of the Privacy Commissioner of Canada.

International transfers

Our service providers may process information in countries other than yours, including the United States. Where required, we use appropriate safeguards such as standard contractual clauses for these transfers.

Children

The Services are business tools for adults. We do not knowingly collect information from anyone under 16.

Changes

We will post any changes to this policy on this page and update the effective date above. Material changes will be announced to workspace administrators in advance.

Contact

Good Quarter Company, Toronto, Ontario, Canada · privacy@goodquartercompany.com