QueueBond.onlineGrid-access capital intelligence

Legal documents

QueueBond’s Terms of Service, Privacy Policy and Security Overview. Expand a document to read it here, or open its dedicated page.

Terms of ServiceExpandCollapse

Effective Date: 02/10/2020 Last Updated: 02/10/2020

These Terms of Service (“Terms”) govern access to and use of QueueBond, including the QueueBond website, web application, APIs, documentation, and related services (collectively, the “Service”), provided by Nevil Biju & Vivek R, doing business as QueueBond (“QueueBond,” “we,” “us,” or “our”).

General/Support: hello@queuebond.online

Legal Contact: queuebondos@gmail.com Privacy: queuebondos@gmail.com Security: queuebondos@gmail.com

1. What QueueBond Does

QueueBond is a business software platform designed to help organizations manage the operational, evidentiary, financial, decision-making, and reporting consequences associated with grid access and interconnection work.

Depending on the Service configuration, QueueBond may provide functionality for project records, grid and operator information, requirements, evidence, documents, conditions and dependencies, security and capital records, changes, scenarios, decisions, actions, outcomes, audit history, reporting, integrations, and AI-assisted workflows.

QueueBond is a software platform.

QueueBond does not itself constitute legal advice, financial advice, investment advice, tax advice, engineering advice, regulatory advice, accounting advice, interconnection representation, utility representation, grid-operator representation, or any other professional advice.

Information presented by QueueBond, including calculations, scenarios, classifications, alerts, summaries, extracted information, recommendations, forecasts, AI-generated content, or reports, should be appropriately reviewed before being used as the basis for a material legal, regulatory, financial, engineering, safety, commercial, or operational decision.

2. Acceptance and Authority

By creating an Account, accepting these Terms, entering an order for the Service, or using the Service, you agree to these Terms.

If you access QueueBond on behalf of an organization, you represent that you have authority to bind that organization.

In that situation, “you” and “Customer” refer to that organization, and you represent that you are authorized to act for it.

If you use QueueBond as an individual and not on behalf of an organization, “you” refers to you personally.

Where QueueBond and a Customer have entered into a signed SaaS agreement, order form, Data Processing Agreement, security addendum, or similar written agreement, that agreement controls where it expressly conflicts with these Terms.

3. Accounts

You must provide reasonably accurate information when creating an Account and keep material Account information reasonably current.

You are responsible for activity carried out through your Account except to the extent directly attributable to QueueBond's breach of its applicable security obligations.

You must:

  • protect your credentials;
  • not intentionally share individual credentials;
  • use appropriate authentication controls;
  • promptly remove users who no longer require access; and
  • notify QueueBond if you reasonably believe that an Account or credential has been compromised.

QueueBond may require identity or organizational verification where reasonably necessary to maintain security, prevent fraud, or administer the Service.

4. Authorized Users and Workspaces

Customers may designate Authorized Users and assign permissions available within the Service.

The Customer controls which of its Authorized Users may access its Workspace and Customer Content.

The Customer is responsible for:

  • selecting appropriate roles;
  • reviewing permissions;
  • controlling internal access;
  • removing former personnel;
  • ensuring Authorized Users comply with these Terms; and
  • determining which information individual users should be permitted to view or modify.

QueueBond is not responsible for a Customer's deliberate decision to grant an individual access that the Customer itself authorized.

5. Customer Content

5.1 Customer Ownership

As between the parties, the Customer retains its rights and ownership in Customer Content.

“Customer Content” means documents, project information, records, data, evidence, images, attachments, communications, notes, prompts, instructions, financial information, operational information, and other material submitted to or stored in QueueBond by or for the Customer.

Nothing in these Terms transfers ownership of Customer Content to QueueBond.

5.2 Limited Processing License

The Customer grants QueueBond a limited, non-exclusive, worldwide license to host, store, reproduce, transmit, process, display, format, index, back up, and otherwise process Customer Content only as reasonably necessary to:

  1. provide the Service;
  2. authenticate users;
  3. enforce access controls;
  4. respond to Customer instructions;
  5. provide requested support;
  6. prevent fraud, abuse, security incidents, and unauthorized use;
  7. maintain and improve Service reliability and security;
  8. comply with applicable law; or
  9. establish, exercise, or defend legal claims.

This license does not give QueueBond a right to sell Customer Content or commercially exploit identifiable Customer Content for unrelated purposes.

The license ends for Customer Content after deletion from active QueueBond systems, subject to lawful retention, backups, security records, dispute preservation, and other legitimate retention requirements.

5.3 Customer Authority

The Customer represents that it has the rights and permissions reasonably necessary for QueueBond to process Customer Content in accordance with the Customer's instructions and applicable agreements.

The Customer remains responsible for determining whether particular information should be uploaded to a third-party SaaS service.

5.4 Personal and Sensitive Information

Customers should only place the minimum personal information reasonably necessary into QueueBond.

Unless expressly agreed otherwise in writing, QueueBond is not intended to be a specialized environment for highly regulated information requiring specialized controls, including classified information, clinical health records, payment-card environments, or other specially regulated datasets.

6. Customer Instructions and Data Processing

Where QueueBond processes Customer Content on behalf of a Customer, QueueBond will process that content for the purposes of providing the Service and according to the Customer's instructions as expressed through the Service and applicable agreements.

QueueBond may use subcontractors and infrastructure providers to provide hosting, authentication, storage, communications, monitoring, AI-enabled functionality, and other components of the Service.

Where a separate DPA applies, the DPA governs the parties' data-processing obligations to the extent provided in that agreement.

7. AI-Assisted Features

QueueBond may provide optional AI-assisted functionality.

Such features may assist with:

  • summarization;
  • extraction;
  • classification;
  • document understanding;
  • identifying apparent relationships;
  • generating draft text;
  • scenario preparation;
  • workflow assistance; or
  • other supported tasks.

AI-generated information is not automatically authoritative merely because it was generated within QueueBond.

AI output may be:

  • incorrect;
  • incomplete;
  • outdated;
  • ambiguous;
  • based on incomplete source information; or
  • inappropriate for a particular business context.

Customers must apply appropriate human review before relying on AI output for consequential decisions.

QueueBond will not intentionally use Customer Content to train a general-purpose AI model for unrelated third-party benefit without the Customer's express authorization.

An AI feature may require information to be transmitted to a model or service provider needed to provide that feature. Applicable subprocessors and service-provider terms govern those external processing activities.

8. Third-Party and Public Information

QueueBond may integrate with or reference:

  • grid operators;
  • utilities;
  • public datasets;
  • regulatory sources;
  • APIs;
  • external databases;
  • public websites;
  • news sources; and
  • other third-party services.

Third-party information may be incomplete, delayed, unavailable, changed, incorrectly published, or subject to third-party licensing and usage conditions.

QueueBond does not guarantee the accuracy, completeness, legality, timeliness, or availability of third-party information.

Customers are responsible for ensuring that information they import or use from external sources is used consistently with applicable rights, licenses, terms, attribution obligations, and law.

QueueBond does not acquire ownership of third-party content merely because the Service displays or processes it.

9. Acceptable Use

You may use QueueBond only for lawful business and operational purposes.

You must not:

  1. violate applicable law;
  2. infringe another party's intellectual-property, privacy, confidentiality, or other rights;
  3. upload malware or harmful code;
  4. bypass or disable security or access controls;
  5. access another customer's information without authorization;
  6. probe or exploit QueueBond infrastructure without authorization;
  7. interfere with Service availability;
  8. intentionally overload the Service;
  9. use the Service for unauthorized scraping;
  10. reverse engineer the Service except where applicable law expressly permits it;
  11. use QueueBond to develop a directly competing product through systematic copying of non-public functionality or protected interfaces;
  12. use AI-generated material as the sole basis for a legally or materially consequential decision where human review is reasonably necessary; or
  13. use the Service for unlawful discriminatory or otherwise prohibited decision-making.

Lawful, authorized security research may be conducted subject to written authorization.

10. Intellectual Property

QueueBond and its licensors retain all rights in:

  • the Service;
  • software;
  • source code;
  • architecture;
  • interfaces;
  • generic workflows;
  • templates;
  • Documentation;
  • trademarks;
  • branding;
  • visual design;
  • non-customer-specific methodologies;
  • improvements; and
  • other QueueBond intellectual property.

The Customer receives only the rights expressly granted under these Terms or an applicable commercial agreement.

Customer Content remains Customer property.

A Customer may use reports, exports, and other outputs containing its own Customer Content for its internal and legitimate business purposes, subject to third-party material incorporated into those outputs.

11. De-identified and Aggregated Information

QueueBond may create aggregated or de-identified information about Service usage, performance, reliability, feature adoption, and similar characteristics, provided that the resulting information is handled so that it is not intended to identify the Customer or an individual.

QueueBond may use such information to:

  • monitor and improve the Service;
  • understand performance;
  • detect abuse;
  • develop features;
  • measure reliability; and
  • produce general industry or product insights.

QueueBond will not treat raw Customer Content as aggregated data merely by changing its format.

12. Feedback

If you provide suggestions, ideas, feature requests, or comments about QueueBond, QueueBond may use those suggestions without restriction or compensation, provided that such use does not disclose Customer Confidential Information or identify the Customer without permission.

The Customer retains ownership of its underlying Customer Content.

13. Free, Trial, Pilot and Beta Features

QueueBond may provide Free, Trial, Pilot, Early Access, Preview, or Beta functionality.

Such functionality may:

  • change;
  • have lower limits;
  • be temporarily unavailable;
  • be discontinued;
  • contain defects; or
  • lack functionality included in paid plans.

QueueBond will not describe a feature as generally available if it has intentionally designated that feature as Beta or Preview.

14. Availability

QueueBond will use commercially reasonable efforts to maintain Service availability.

Temporary interruptions may occur due to:

  • scheduled maintenance;
  • emergency maintenance;
  • security events;
  • cloud infrastructure failures;
  • third-party outages;
  • network failures;
  • software defects;
  • legal requirements;
  • abuse or malicious traffic; or
  • events beyond QueueBond's reasonable control.

No particular availability percentage is promised unless an applicable SLA expressly states one.

15. Changes to the Service

QueueBond may improve, modify, add, remove, or replace features over time.

We will seek to avoid materially reducing core functionality during an active paid commitment without reasonable notice or an applicable contractual remedy.

Changes necessary to:

  • improve security;
  • comply with law;
  • fix vulnerabilities;
  • maintain infrastructure;
  • respond to third-party changes; or
  • prevent abuse

may occur without advance notice where immediate action is reasonably necessary.

16. Fees and Taxes

Paid Services are governed by the applicable pricing page, order form, subscription terms, or SaaS agreement.

Unless stated otherwise, taxes, duties, and similar governmental charges are additional.

QueueBond will not charge hidden fees that were not disclosed through the applicable commercial terms.

If usage-based billing applies, the relevant usage metric and pricing basis will be disclosed in advance.

17. Payment Disputes

Customers should promptly notify QueueBond of disputed invoices.

QueueBond will not treat a good-faith invoice dispute as non-payment while the disputed amount is being reasonably investigated.

Undisputed amounts remain payable according to the applicable terms.

18. Suspension

QueueBond may suspend access where reasonably necessary to:

  • prevent an active security threat;
  • prevent unlawful use;
  • protect other customers;
  • stop material abuse;
  • comply with law; or
  • address material non-payment after reasonable notice.

Where practical, QueueBond will provide notice and an opportunity to correct the issue.

Suspension should be limited to the affected account, feature, user, or activity where reasonably possible.

19. Termination

Termination rights are governed by the applicable subscription or commercial agreement.

For material breach, the non-breaching party will generally provide reasonable notice and an opportunity to cure, except where immediate termination is reasonably necessary because the breach creates a serious legal, security, or safety risk.

Termination does not transfer Customer Content ownership to QueueBond.

20. Data Export and Deletion

Customers should export required Customer Content before terminating their use of QueueBond.

Subject to the applicable plan, technical capabilities, DPA, and legal requirements, QueueBond will provide reasonable mechanisms for data export.

After termination, Customer Content may be deleted according to QueueBond's retention process.

Information may remain for a limited period in:

  • backups;
  • security records;
  • audit records;
  • legal preservation;
  • dispute records; or
  • systems awaiting ordinary deletion cycles.

21. Confidentiality

Each party may receive Confidential Information from the other.

Confidential Information means information that is reasonably understood to be confidential considering its nature and the circumstances of disclosure.

The receiving party will:

  • use it only for the relevant relationship;
  • restrict access to persons who reasonably need it; and
  • apply reasonable safeguards.

Confidential Information does not include information that was:

  • publicly available without breach;
  • already lawfully known;
  • independently developed without use of the other party's information; or
  • lawfully received from another source without confidentiality restrictions.

Disclosure required by law is permitted, subject to legally permissible notice.

These obligations survive termination for as long as the information remains confidential.

22. Security

QueueBond maintains reasonable administrative, technical, and organizational safeguards designed to protect Customer Content.

Details are provided in the QueueBond Security Overview.

No online service can guarantee absolute security.

Customer security responsibilities include maintaining secure credentials, endpoints, integrations, and user permissions.

23. Third-Party Services

Certain QueueBond functionality may rely on external providers.

Third-party services may have:

  • separate terms;
  • separate privacy policies;
  • separate availability;
  • separate APIs;
  • independent security controls; and
  • independent changes or discontinuation.

QueueBond is not responsible for failures caused solely by a third party outside QueueBond's reasonable control.

24. Warranties and Disclaimers

To the maximum extent permitted by law, the Service is provided on an “as available” and “as is” basis except for express warranties contained in a signed agreement.

QueueBond does not warrant that:

  • every external source will remain available;
  • information obtained from third parties will always be accurate;
  • AI output will always be correct;
  • the Service will never experience interruptions;
  • every possible project consequence will be detected; or
  • the Service will satisfy every Customer-specific requirement.

Nothing in these Terms excludes a warranty or consumer/legal right that cannot legally be excluded.

25. Professional Decision-Making

Customers remain responsible for professional and business decisions.

QueueBond may support decisions through information organization, evidence, history, scenarios, calculations, automation, or AI assistance.

Those capabilities are not a substitute for qualified review.

A QueueBond record being marked “authoritative” within the product means it is the authoritative state selected by the Customer's workflow. It does not mean that QueueBond guarantees the underlying external fact.

26. Indemnification

Where permitted by law, the Customer is responsible for third-party claims arising from:

  • Customer Content that infringes a third party's rights;
  • unlawful use of the Service; or
  • material breach of these Terms.

Any QueueBond intellectual-property indemnity should be addressed in the applicable paid SaaS agreement or order form, including exclusions, procedures, defense rights, and remedies.

Nothing in these public Terms creates a broad, uncapped QueueBond indemnity obligation unless expressly agreed.

27. Limitation of Liability

To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or loss of profits, revenues, goodwill, or anticipated savings arising from use of the Service.

For paid enterprise customers, the applicable agreement should define the aggregate liability cap appropriate to the commercial relationship.

For public/free use without a signed commercial agreement, QueueBond's aggregate liability arising out of the Service will not exceed the greater of:

(a) amounts paid by the Customer for the Service during the three months preceding the event giving rise to the claim; or (b) USD 100,

to the extent permitted by applicable law.

Nothing limits liability that cannot legally be limited or excluded.

28. Force Majeure

Neither party will be responsible for delay or failure caused by circumstances beyond reasonable control, including:

  • natural disasters;
  • war;
  • civil unrest;
  • terrorism;
  • major telecommunications failures;
  • widespread cloud outages;
  • government action;
  • labor disruptions; or
  • similar events.

29. Compliance

Customers are responsible for ensuring that their use of QueueBond complies with applicable law.

QueueBond may restrict activity where continued provision would violate applicable sanctions, export controls, court orders, or other legal obligations.

30. Publicity

QueueBond will not publicly announce the Customer relationship, publish a case study, or use the Customer's name/logo for marketing without appropriate permission.

Likewise, Customers should not imply an endorsement or partnership that has not been agreed.

31. Communications

QueueBond may send:

  • security notices;
  • account notices;
  • service notices;
  • transactional messages;
  • support communications;
  • billing communications; and
  • legal notices.

Marketing messages, where sent, will include appropriate preference or unsubscribe mechanisms as required by law.

32. Dispute Resolution

Before commencing formal proceedings concerning a material dispute, the parties should make a good-faith effort to resolve it through written notice and discussion.

The parties should generally allow at least 30 days for that process, except for urgent legal remedies.

Governing Law: The laws of India, without regard to conflict-of-law principles. Venue / Courts: The courts having competent jurisdiction in Kerala, India.

Mandatory rights that cannot lawfully be waived remain unaffected.

33. Changes to These Terms

QueueBond may update these Terms to reflect:

  • new features;
  • changes in law;
  • security requirements;
  • infrastructure changes; or
  • business changes.

For material changes, QueueBond will provide reasonable advance notice where appropriate.

The updated version will state a new effective date.

Changes do not retroactively remove rights that have already accrued.

34. Assignment

Neither party may assign these Terms in a manner that materially changes the relationship without reasonable notice, except where assignment is required as part of a merger, acquisition, corporate reorganization, or sale of relevant assets.

A successor assuming QueueBond's business will remain responsible for applicable commitments.

35. Severability

If part of these Terms is held invalid or unenforceable, the remaining provisions remain in effect.

36. Entire Agreement

These Terms and incorporated policies, together with applicable order forms, DPAs, security agreements, and Documentation, form the agreement governing use of QueueBond unless superseded by a signed agreement.

37. Contact

QueueBond Nevil Biju nevilbiju.dev@gmail.com

Legal: queuebondos@gmail.com Privacy: queuebondos@gmail.com Security: queuebondos@gmail.com Support: hello@queuebond.online

Open the full Terms of Service page ↗

Privacy PolicyExpandCollapse

Effective Date: 02/10/2020 Last Updated: 02/10/2020

This Privacy Policy describes how Nevil Biju and Vivek R, doing business as QueueBond, collects, uses, discloses, retains, and protects personal information in connection with QueueBond's website, application and services.

Privacy Contact: queuebondos@gmail.com

1. Scope

This Privacy Policy applies when you:

  • visit QueueBond websites;
  • create or use a QueueBond account;
  • use QueueBond on behalf of a customer organization;
  • request a demonstration;
  • contact support;
  • communicate with QueueBond;
  • receive transactional communications; or
  • otherwise provide personal information directly to us.

When QueueBond processes information solely on behalf of a customer organization, that customer may determine the purposes for which the information is processed and may have its own privacy obligations and privacy notice.

2. Our Role

QueueBond may act in different roles depending on the processing.

For information that you provide directly to QueueBond, such as account-registration information or support requests, QueueBond may determine the purposes and means of processing.

For information uploaded by a customer into its QueueBond workspace, the customer may determine why that information is processed, while QueueBond processes it to provide the Service.

Under applicable law, these roles may correspond to concepts such as a Data Fiduciary/Data Processor or organization/service provider.

The exact legal classification depends on the specific processing activity and applicable jurisdiction.

3. Information We Collect

Account Information

We may collect:

  • name;
  • email address;
  • organization;
  • job role;
  • account identifier;
  • authentication details;
  • workspace membership;
  • user permissions; and
  • profile information you choose to provide.

OAuth Information

Where Google OAuth or another external identity provider is used, QueueBond may receive information necessary to identify and authenticate your account.

QueueBond does not ordinarily receive your external provider password through standard OAuth authentication.

Customer Workspace Data

Customers may place information into QueueBond such as:

  • project records;
  • business contacts;
  • vendor information;
  • operator information;
  • requirements;
  • evidence;
  • documents;
  • images;
  • financial/capital information;
  • project decisions;
  • workflow records;
  • communications;
  • audit records; and
  • other business information.

Technical Information

We may collect:

  • IP address;
  • browser information;
  • device information;
  • operating-system information;
  • timestamps;
  • request paths;
  • authentication events;
  • error information;
  • security events;
  • diagnostic information;
  • performance data; and
  • approximate location derived from IP address where reasonably necessary for security or service operations.

4. How We Use Information

We may use personal information to:

  • create and maintain accounts;
  • authenticate users;
  • provide the Service;
  • enforce permissions;
  • maintain workspace security;
  • process customer instructions;
  • provide support;
  • detect fraud and abuse;
  • investigate security incidents;
  • troubleshoot errors;
  • improve reliability;
  • administer subscriptions;
  • send necessary service communications;
  • comply with law;
  • establish or defend legal claims;
  • create aggregated/de-identified service analytics; and
  • provide enabled AI-assisted features.

5. We Do Not Sell Customer Content

QueueBond does not sell Customer Content or personal information for advertising purposes.

We may use appropriately aggregated or de-identified information for legitimate business purposes such as product improvement, reliability analysis, abuse detection, and service planning.

We do not treat identifiable Customer Content as aggregated information simply because it has been placed into a report or database.

6. Legal Grounds

The appropriate legal basis depends on the jurisdiction and processing activity.

Where applicable law requires consent, QueueBond will seek meaningful consent.

Where law permits processing on another basis, QueueBond may process information where reasonably necessary to provide requested services, perform a contract, comply with law, protect security, prevent abuse, establish legal claims, or for another lawful purpose.

For Canadian processing subject to PIPEDA, the privacy program is designed around principles including accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, access, and complaint handling.

For India, the Digital Personal Data Protection Act, 2023 includes provisions concerning notice, consent, legitimate uses, rights of individuals, security, and grievance redressal. The final 2025 Rules use phased commencement dates, so operational obligations should be assessed according to the relevant provision's effective date.

7. Data Minimization

QueueBond seeks to collect information reasonably necessary for stated purposes.

Customers should avoid uploading personal information that is irrelevant to the relevant workflow.

Users should not put unnecessary sensitive information into:

  • project notes;
  • prompts;
  • documents;
  • comments;
  • evidence; or
  • free-text fields.

8. How We Share Information

Customers and Authorized Users

If you use QueueBond through an organization, that organization may access information associated with your account according to its Workspace configuration, permissions, contractual rights, and applicable law.

Service Providers

QueueBond may use providers for:

  • hosting;
  • databases;
  • authentication;
  • storage;
  • email;
  • security;
  • logging/monitoring;
  • support;
  • payment processing;
  • AI/model processing; and
  • other infrastructure.

Legal Disclosures

We may disclose information when reasonably necessary to:

  • comply with law;
  • respond to valid legal process;
  • protect users or customers;
  • protect the Service;
  • investigate fraud or abuse;
  • respond to security incidents; or
  • establish or defend legal rights.

We seek to limit disclosures to what is reasonably necessary.

9. International Data Processing

QueueBond and its service providers may process personal information in countries other than where the individual or customer is located.

Where cross-border processing applies, we will use reasonable contractual, technical, and organizational safeguards appropriate to the applicable law.

Canadian privacy obligations can vary across jurisdictions. Alberta, British Columbia, and Quebec have substantially similar private-sector privacy statutes, while PIPEDA can continue to apply in particular circumstances, including certain cross-border activities.

India's DPDP Act also contains provisions concerning processing outside India.

10. Retention

QueueBond retains personal information only for as long as reasonably necessary for:

  • the relevant purpose;
  • providing the Service;
  • contractual obligations;
  • legal obligations;
  • security;
  • fraud prevention;
  • dispute resolution; or
  • legitimate operational requirements.

Retention periods vary by information type.

Customer Content may be deleted after account termination according to the applicable contract and deletion process.

Some information may remain temporarily in backups, security logs, audit records, or legally preserved records.

11. Access, Correction and Deletion

Depending on applicable law, individuals may have rights to:

  • access personal information;
  • obtain information about its use and disclosure;
  • correct inaccurate information;
  • request deletion or erasure;
  • withdraw consent;
  • submit privacy complaints;
  • object to certain processing; or
  • exercise other statutory rights.

Requests should be sent to:

queuebondos@gmail.com

We may reasonably verify identity before fulfilling a request.

Where QueueBond processes personal information only on behalf of a customer, we may refer the request to that organization or assist it in responding, depending on applicable law.

India's DPDP Act expressly includes access, correction/erasure, grievance redressal, and related rights.

PIPEDA also provides access and correction mechanisms and allows individuals to challenge compliance.

12. Consent Withdrawal

Where consent is the basis for processing, you may withdraw consent subject to applicable legal and contractual limitations.

Withdrawal may prevent us from continuing to provide certain functionality.

Withdrawal does not invalidate lawful processing conducted before withdrawal.

13. Cookies

QueueBond may use essential cookies and similar technologies for:

  • authentication;
  • session management;
  • security;
  • maintaining preferences; and
  • functionality.

Where optional analytics or similar technologies are enabled, appropriate notice and controls will be provided where required.

QueueBond does not use cookies to sell Customer Content or personal information for targeted advertising.

14. AI Processing

Some QueueBond features may use artificial intelligence.

Depending on the enabled feature, relevant inputs may be processed through third-party model providers.

AI systems may produce inaccurate or incomplete information.

QueueBond does not make an AI-generated record authoritative merely because an AI system produced it.

QueueBond does not intentionally use Customer Content to train general-purpose AI models for unrelated third-party purposes without appropriate authorization.

Customers should use care when providing personal or confidential information to optional AI features.

15. Security

QueueBond uses reasonable administrative, technical, and organizational measures designed to protect personal information.

These may include:

  • authentication;
  • access controls;
  • role-based permissions;
  • database security controls;
  • server-side isolation of privileged credentials;
  • HTTPS/TLS;
  • security logging;
  • managed infrastructure;
  • secrets management;
  • dependency maintenance; and
  • incident-response procedures.

No system connected to the Internet can be guaranteed to be completely secure.

PIPEDA expects safeguards to be appropriate to the sensitivity of information and emphasizes ongoing assessment of security controls.

16. Security Breaches

If QueueBond confirms a security incident involving personal information under its control, we will:

  • investigate;
  • take reasonable containment measures;
  • remediate the relevant issue;
  • assess affected information;
  • maintain appropriate records; and
  • notify affected parties where legally or contractually required.

Under PIPEDA, organizations subject to the Act may need to report breaches involving a real risk of significant harm, notify affected individuals, and maintain breach records.

17. Accuracy

We seek to keep information under our control reasonably accurate for the purpose for which it is used.

Customers remain responsible for the accuracy of business information they upload or maintain within their Workspaces.

18. Children's Information

QueueBond is a B2B service and is not directed toward children.

We do not knowingly seek to collect children's personal information for purposes not permitted by applicable law.

If you believe a child has submitted information inappropriately, contact queuebondos@gmail.com.

19. Third-Party Services and Links

QueueBond may link to or integrate with third-party services.

Those third parties have their own privacy practices.

QueueBond is not responsible for the privacy practices of third parties operating independently of QueueBond.

20. Business Transfers

If QueueBond is involved in a merger, financing, acquisition, reorganization, or sale of substantially relevant assets, information may be transferred as part of that transaction subject to applicable law.

A transaction does not automatically authorize a new unrelated use of personal information.

21. Legal Requests

Where legally permitted, QueueBond may notify a customer of a governmental or law-enforcement request concerning Customer Content so that the customer may seek appropriate relief.

QueueBond may withhold notice where prohibited by law or where doing so would create a significant security or legal risk.

22. Customer Responsibilities

Customers are responsible for:

  • ensuring they have appropriate rights to process information;
  • giving required notices to individuals;
  • setting appropriate access permissions;
  • maintaining accurate data;
  • following retention requirements;
  • responding to individual requests where they are the responsible organization; and
  • using exported data lawfully.

23. Privacy Complaints

Privacy concerns should be sent to:

queuebondos@gmail.com

We will investigate reasonable complaints and provide a response in a timeframe appropriate to the issue and applicable law.

24. Changes

QueueBond may update this Privacy Policy when:

  • our processing changes;
  • new features are introduced;
  • service providers change;
  • legal requirements change; or
  • security practices evolve.

Material changes will be communicated where required.

The updated policy will show its effective date.

25. Contact

Privacy: queuebondos@gmail.com Legal: queuebondos@gmail.com Security: queuebondos@gmail.com Support: hello@queuebond.online

Open the full Privacy Policy page ↗

Security OverviewExpandCollapse

Effective Date: 02/10/2020 Last Updated: 02/10/2020

QueueBond is designed to provide a controlled environment for managing project, interconnection, evidence, capital, decision, workflow, and operational information.

This Security Overview describes our security approach at a high level.

It is not a certification report, penetration-test report, SLA, security warranty, or substitute for a negotiated enterprise security agreement.

1. Security Principles

QueueBond's security model is built around:

Least privilege

Users should receive only the access appropriate to their role.

Tenant isolation

Customer information should remain within appropriate workspace and authorization boundaries.

Privileged-access separation

Sensitive service credentials are intended to remain server-side.

Database-enforced authorization

Security does not depend exclusively on the application interface.

Traceability

Important workflow events may be recorded so that customers can understand who changed information and when.

Controlled state

Proposed and hypothetical information should not silently become authoritative information.

Defense in depth

Multiple layers of protection are used rather than relying on one control.

2. Application Architecture

QueueBond uses a modern Next.js application architecture with managed cloud services, database services, authentication, and object/storage capabilities where required by the product.

The application is designed so privileged database credentials are not delivered to ordinary browser users.

Application functionality is separated between:

  • browser-facing functionality;
  • authenticated application operations; and
  • privileged server-side operations.

3. Authentication

QueueBond supports authenticated user accounts and may provide external authentication such as Google OAuth.

Authentication information is used to establish the user's identity and enforce application permissions.

Customers are responsible for protecting identity-provider accounts and their own devices.

Where multi-factor authentication is available, customers are encouraged to enable it.

4. Authorization

QueueBond uses authorization controls designed around:

  • user identity;
  • workspace membership;
  • roles;
  • project access; and
  • privileged operation boundaries.

Database-level security controls, including row-level authorization policies where configured, provide an additional boundary between customer scopes.

The design objective is to prevent one customer or workspace from accessing another customer's information through ordinary client requests.

5. Service Credentials

Privileged credentials are treated as server-side secrets.

They should not be:

  • committed to source control;
  • embedded in browser JavaScript;
  • placed in public configuration; or
  • exposed through ordinary client APIs.

Production credentials are intended to be maintained through deployment/runtime secret mechanisms.

6. Customer Data Isolation

QueueBond is designed as a multi-tenant application.

Customer workspaces have separate logical access boundaries.

Authorization is enforced through multiple application and database controls where applicable.

Customers also have a responsibility to:

  • configure access appropriately;
  • remove users who no longer need access;
  • protect their credentials; and
  • review administrator permissions.

7. Encryption in Transit

QueueBond uses HTTPS/TLS for network connections to the public Service.

Customers should use supported browsers and secure devices.

External providers connected to QueueBond may have separate transport-security policies.

8. Encryption at Rest

QueueBond relies on managed infrastructure and storage services that may provide encryption at rest for relevant components.

The exact implementation depends on the infrastructure component and service configuration.

Customers requiring customer-managed encryption keys, dedicated encryption architecture, specific geographic residency, or other specialized cryptographic requirements should address those requirements contractually before using the Service for such workloads.

9. Files and Documents

QueueBond may store:

  • documents;
  • attachments;
  • images;
  • evidence;
  • reports; and
  • related files.

Access is governed by the applicable authorization controls.

Customers are responsible for protecting exported or downloaded copies after those copies leave QueueBond-controlled systems.

10. Auditability

QueueBond is designed to preserve meaningful workflow history rather than relying entirely on destructive overwriting.

Depending on the feature, records may include:

  • actor;
  • timestamp;
  • state;
  • changes;
  • approvals;
  • decisions;
  • evidence;
  • actions;
  • outcomes; and
  • related references.

Auditability supports accountability but should not be treated as a legal forensic guarantee unless the applicable feature or agreement expressly says so.

11. Authoritative-State Controls

QueueBond can distinguish information such as:

Observed → Proposed → Authoritative

and:

Expected → Decision → Action → Actual → Variance

These controls are intended to reduce the risk of draft, hypothetical, imported, or AI-generated information being silently treated as established fact.

Human review remains important.

12. AI Security

AI-assisted features may use third-party model providers.

Where enabled:

  • relevant inputs may leave QueueBond infrastructure for processing;
  • customers should submit only information necessary for the feature;
  • AI output should be reviewed;
  • sensitive credentials should never be placed in AI prompts;
  • AI output is not automatically authoritative.

QueueBond does not intentionally use Customer Content to train general-purpose AI models for unrelated third-party purposes without appropriate authorization.

The exact providers and feature-specific processing should be disclosed through the applicable subprocessor or AI documentation.

13. Logging and Monitoring

QueueBond uses application and infrastructure logging to help:

  • diagnose errors;
  • maintain availability;
  • investigate security events;
  • monitor authentication activity;
  • detect abuse; and
  • operate the Service.

Logs may contain technical metadata such as:

  • timestamps;
  • request paths;
  • account/workspace identifiers;
  • authentication events;
  • error information;
  • security events; and
  • diagnostic information.

Access to operational logs is restricted according to operational need.

14. Dependency and Vulnerability Management

QueueBond seeks to maintain supported dependencies and address material vulnerabilities according to their assessed severity and practical risk.

Security fixes may sometimes be deployed rapidly without prior customer approval where necessary to protect the Service.

15. Secure Development

QueueBond uses source-controlled software development and deployment practices that may include:

  • version control;
  • automated tests;
  • type checking;
  • build verification;
  • security and authorization testing;
  • browser verification;
  • deployment checks; and
  • production smoke testing.

The development process may evolve over time.

16. Infrastructure Providers

QueueBond may use third-party cloud providers for:

  • application hosting;
  • databases;
  • authentication;
  • storage;
  • email;
  • monitoring;
  • security;
  • AI processing; and
  • related services.

Such providers operate independently controlled infrastructure.

QueueBond manages the application-level configuration and provider relationships relevant to its contractual obligations.

17. Availability

QueueBond seeks to operate a reliable service but does not promise uninterrupted availability unless an applicable SLA says otherwise.

Availability can be affected by:

  • cloud outages;
  • network failures;
  • third-party dependencies;
  • maintenance;
  • security incidents;
  • software defects;
  • malicious traffic;
  • identity providers; or
  • other circumstances beyond reasonable control.

18. Backups

Backups may be maintained for operational recovery depending on the relevant component.

Backups should not automatically be interpreted as:

  • instant recovery;
  • a user-accessible archive;
  • a contractual RPO;
  • a contractual RTO; or
  • a complete substitute for customer-side backup.

Customers with contractual recovery requirements should address them separately.

19. Incident Response

QueueBond maintains a process for responding to suspected security events.

The process is intended to include:

  1. detection;
  2. assessment;
  3. containment;
  4. investigation;
  5. remediation;
  6. customer/regulatory notification where required;
  7. recovery; and
  8. lessons learned.

20. Customer Responsibilities

Security is shared.

Customers should:

  • protect credentials;
  • enable MFA where available;
  • secure employee devices;
  • manage permissions carefully;
  • remove inactive users;
  • secure API credentials;
  • avoid unnecessary sensitive data;
  • protect exported reports;
  • review AI output;
  • maintain required independent backups;
  • notify QueueBond of suspicious activity; and
  • train Authorized Users appropriately.

21. Security Incidents Affecting Customer Content

If QueueBond confirms unauthorized access to Customer Content caused by an incident within systems under QueueBond's control, QueueBond will take reasonable measures to contain, investigate, and remediate the incident.

Notifications will be made where required by applicable law or contract.

Timing may depend on:

  • legal restrictions;
  • forensic investigation;
  • law-enforcement requirements;
  • customer-specific notification requirements; and
  • containment needs.

22. Subprocessors

QueueBond may use subprocessors for hosting, storage, authentication, email, support, AI, monitoring, security, and related services.

Where a DPA provides customer notice or objection rights regarding subprocessors, that agreement governs.

23. Security Assessments

Enterprise customers may request reasonable information concerning QueueBond's security architecture and controls.

Depending on the customer relationship, QueueBond may provide:

  • security questionnaires;
  • architecture summaries;
  • DPA materials;
  • subprocessor information;
  • policy documents; and
  • other reasonable security documentation.

QueueBond may decline to provide information that would:

  • expose secrets;
  • disclose another customer's confidential information;
  • create a material security risk;
  • reveal exploitable infrastructure details; or
  • require certifications QueueBond does not possess.

24. Certifications

Unless explicitly stated in a current certificate or contractual document, QueueBond does not claim that it is:

  • SOC 2 certified;
  • ISO 27001 certified;
  • FedRAMP authorized;
  • PCI DSS certified;
  • HIPAA certified; or
  • certified under another named security framework.

This page should not be interpreted as such a claim.

25. Responsible Disclosure

Security vulnerabilities may be reported to:

queuebondos@gmail.com

Reports should, where possible, include:

  • affected feature;
  • URL;
  • reproduction steps;
  • impact;
  • timestamps; and
  • safe contact information.

Researchers should avoid:

  • accessing unrelated customer information;
  • modifying or deleting customer data;
  • disrupting the Service;
  • social engineering personnel;
  • denial-of-service activity; or
  • retaining unauthorized access.

Good-faith reports that respect these boundaries are encouraged.

26. Physical Infrastructure

QueueBond may rely on managed infrastructure providers for physical security.

Such providers may maintain controls concerning:

  • facility access;
  • environmental systems;
  • physical monitoring;
  • hardware security; and
  • data-center operations.

QueueBond does not necessarily operate the physical facilities in which all Service infrastructure resides.

27. Data Deletion

Customer Content is handled according to the applicable retention process, customer agreement, and legal requirements.

Some information may remain temporarily in:

  • backups;
  • security logs;
  • legal preservation systems;
  • audit records; or
  • other systems subject to normal retention cycles.

28. Security Changes

QueueBond may change:

  • hosting providers;
  • cloud architecture;
  • security vendors;
  • logging systems;
  • deployment technology;
  • authentication systems; or
  • security controls.

Such changes are made to maintain or improve the Service.

Where a change materially affects an explicit contractual security commitment, the applicable customer agreement governs.

29. No Absolute Security Guarantee

No Internet-based application can guarantee complete protection against every:

  • vulnerability;
  • attack;
  • credential compromise;
  • configuration error;
  • insider threat;
  • supply-chain issue; or
  • infrastructure failure.

The objective of QueueBond's security program is to reduce risk and respond responsibly when incidents occur.

Specific contractual commitments concerning security, uptime, incident notification, encryption, residency, recovery, audit rights, or testing should be stated in a negotiated agreement where required.

30. Contact

Security: queuebondos@gmail.com Privacy: queuebondos@gmail.com Legal: queuebondos@gmail.com Support: hello@queuebond.online

Open the full Security Overview page ↗

LegalTerms of ServicePrivacy PolicySecurity OverviewHome