Transparency

Privacy Notice — QueryTek Tapestry™

This notice describes how (“we,” “us”) handles personal information in connection with the hosted QueryTek Tapestry™ service—the interoperability layer organizations use for identity federation, routing, and partner launches. Tapestry’s technical privacy and jurisdictional posture is specified in repository materials such as SPEC-020 — Privacy Rights and Jurisdictional Compliance Controls; this page is a public summary for visitors and users.

Enterprise relationship: When your employer or another organization (“Customer”) subscribes to Tapestry, they typically govern your use under their policies. Where processing is covered by a Data Processing Agreement (DPA) between us and the Customer, that agreement controls our obligations as a processor for Customer-provided personal information. This notice layers on top for transparency and regional rights.

What we process

Depending on configuration, Tapestry may process categories such as business contact details, identifiers used for authentication and routing (for example names, email addresses, usernames, subject or tenant identifiers), session and security telemetry needed to operate the platform, and audit information. We apply data minimization consistent with Tapestry’s role as a broker and routing plane—partner business content generally remains with the Customer and partner applications unless explicitly configured otherwise.

Why we process it

  • Provide, secure, monitor, and improve the Tapestry service
  • Authenticate and route users per Customer configuration and executed agreements
  • Meet legal, security, and compliance obligations
  • Respond to requests and incidents, and communicate about the service where appropriate

Legal bases (for example contract, legitimate interests, or consent) depend on context and region; your organization’s administrator or privacy office can clarify how your employer instructs processing for workforce use.

Regional privacy rights

Privacy laws vary by location. Tapestry implements jurisdictional controls and workflows aligned with SPEC-020 (for example CCPA/CPRA and PIPEDA where applicable). Depending on your situation, you may have rights to access, correct, delete, or limit certain processing, or to appeal a decision.

  • California (CCPA/CPRA): California residents may have rights to know, delete, and correct personal information. QueryTek Tapestry does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined by the CPRA at the Tapestry interoperability boundary (LDR-023 Accepted posture). Sale/share “opt out” is therefore not applicable to Tapestry-owned processing; use the Privacy Request portal for other rights, or contact your employer/Customer when they are the controller.
  • Canada (PIPEDA): Individuals may have rights of access and challenge to accuracy, subject to exceptions; regional workflows may apply when enabled for the tenant.
  • EEA, UK, Switzerland: If GDPR or UK GDPR applies, you may have rights including access, rectification, erasure, restriction, portability, and objection; transfers outside those regions typically rely on approved mechanisms described in the DPA (for example Standard Contractual Clauses).

How to exercise rights: If you access Tapestry through an employer or Customer, direct most privacy requests to that organization’s privacy or IT contact—they are often the controller. If you contact us directly, we may need to verify your request and coordinate with the Customer when we act as a processor. Tapestry-owned processing requests may also be submitted through the Privacy Request portal.

Privacy inquiries: privacy@querytek.io (monitored mailbox; replace with production alias if different).

Cookies And Similar Technologies

Necessary cookies support sign-in, security, and locale. Optional analytics and functional cookies are off until you opt in. Manage preferences anytime via the cookie banner or Cookie Preferences. Inventory: see the checked-in Cookie Inventory summary below (full register under compliance documentation).

Retention, subprocessors, and transfers

We retain personal information only as long as needed for the purposes above, consistent with Customer instructions, our retention schedules, and law. We use infrastructure and service providers (“subprocessors”) under contractual safeguards. Cross-border transfers use mechanisms appropriate to the jurisdictions involved, as documented in customer agreements.

Updates

We may update this notice from time to time. The effective date reflects the latest revision posted here. Material changes may also be communicated through Customer administrators or contractual channels where required.

Effective: April 22, 2026

This page is informational and does not amend executed contracts. For Customer-specific legal terms, refer to your organization’s agreements with .