Legal
Privacy Policy
Last updated: September 2026
This policy explains what information QUORUM60 processes and why. It is complemented by a plain-English Privacy & Data Use summary.
Children — 18 or over only
QUORUM60 is not intended for children under 18. We do not knowingly collect personal data from anyone under 18.
We record only that you confirmed you are 18 or over (with a timestamp and policy version). We do not collect your date of birth or any identity or age-verification documents. If you believe someone under 18 has provided us with personal data, contact us at contact@halorex.com.
Information we process
- Account information you provide (such as your name and email).
- Decision content you submit: your questions, context and any documents you upload.
- Operational and security records needed to run and protect the service (such as audit logs).
How we use it
- To provide the service — running Councils on the decisions and documents you submit.
- To secure the service, prevent abuse and meet our legal and accounting obligations.
AI & service providers
To perform a Council, relevant decision content may be transmitted to approved AI and infrastructure providers acting on our behalf. Only the content necessary for the requested processing is used. Our current providers are listed in the Subprocessors page.
Account isolation
Your projects, documents and decisions are private to your account. They are not visible to other customers.
Retention & deletion
We retain information for as long as reasonably necessary to provide and operate the service, maintain security and records, comply with legal obligations, and resolve disputes. Where applicable, you may request access, export, correction or deletion of your personal data by contacting us.
Contact
For any privacy request, contact Halorex Technologies Limited at contact@halorex.com.
Decision Reliability & analytics
QUORUM60 operates a Reliability Ledger: a minimal set of system-generated Council performance information used to measure and improve Decision Reliability. It does not change the recommendations produced by your Councils.
- What we process: system metrics such as advisor/model, positions and confidence, agreement and dissent, evidence signals, latency, fallback/error, and the structured Outcome Review result. We do not copy your decision text, documents, context, name or email for this purpose.
- Proposed lawful basis: legitimate interests, for the minimum processing needed to derive anonymous reliability statistics. This assessment is subject to internal review before activation.
- Anonymisation: where enabled, this information is transformed into anonymous statistics using coarse categories, with identifiers and free text removed and exact timestamps generalised. Genuinely anonymous data is different from pseudonymous data — removing a name is not, by itself, anonymisation.
- Right to object: you can object to the processing of your personal information for Reliability Analytics. This does not affect your purchased Councils.
- Optional detailed research consent: you may separately agree that we use the detailed content of an Outcome Review for internal product research. This is optional, off by default, and withdrawable.
- Optional testimonial/case-study consent: you may separately agree that an anonymised excerpt may be used as a testimonial. Nothing is published automatically; a person reviews and anonymises any excerpt first, and no name, email, company or identifying decision details are published.
- Withdrawal: you can withdraw either optional consent at any time; we stop future processing under it, delete unpublished testimonial candidates and request takedown of published ones.
- Recipients: reliability information is stored only in our application database and is not shared with other customers. It is never provided to external AI providers to train their models, and it is not sold.
- Retention & deletion: restricted reliability records inherit your account/Council retention and are deleted when your account or the relevant Council is deleted. Information that has already been irreversibly anonymised can no longer be linked to you, and therefore cannot be individually retrieved or deleted.