Trust Center

Security & Compliance

Qualead is built for demanding venues. Here are the essentials your IT department and DPO need to know. Detailed documentation is available on request.

EU

Data hosted in the European Union

AES-256

Encryption of sensitive credentials

OAuth 2.0

Microsoft sign-in, no password stored

GDPR

Article 30 register kept up to date

Security measures

What protects your data

Hosted in the European Union

Your data is stored in the European Union, with a SOC 2 Type II certified host running on ISO 27001 certified data centres.

Microsoft OAuth 2.0 authentication

The Outlook connection relies exclusively on Microsoft's OAuth 2.0 protocol. Qualead never sees or stores your password, and you can revoke access at any time.

Data encryption

All communications are encrypted (HTTPS). Sensitive credentials are encrypted with AES-256 before storage, with keys kept separately from the data.

Per-venue data isolation

Each venue has its own isolated data space. No data is shared between customers.

No AI training on your data

The content of your requests is never used to train artificial intelligence models, neither by Qualead nor by its providers.

No automatic sending

Qualead can never send an email on behalf of your team. Every reply is placed as a draft in Outlook, and sending always remains manual.

Your inbox

Qualead works for you, never in your name

Qualead connects to Outlook through Microsoft's official authorisation. It only accesses what it needs, and you stay in control at all times.

What Qualead does

  • Spots event requests as soon as they arrive
  • Tags them with a “Qualead” label in Outlook
  • Checks your calendars to confirm a date
  • Prepares a draft reply, ready for you to review

What Qualead will never do

  • Send an email on your behalf
  • Change the content of your emails or delete them
  • Create or edit an event in your calendar
  • Access your contacts, OneDrive or Teams
  • Know your Microsoft password

Access can be revoked at any time from your Microsoft account

Compliance

GDPR & data protection

Roles of the parties

For your prospects' requests, your venue is the data controller and Qualead acts as a processor (Article 28 GDPR). For your account data, Ellevate, publisher of Qualead, is the data controller.

Legal basis for processing

Legitimate interest (Article 6.1.f GDPR) for processing incoming professional event requests. Contract (Article 6.1.b) for user account data.

Retention period

Briefs and leads are retained while the account is active. Deletion on request within 30 days. Technical logs are retained for 90 days.

Sub-processors and transfers

Sub-processors selected for their security guarantees. Data stored in the European Union; any transfer outside the EU is governed by the European Commission's Standard Contractual Clauses.

Data subject rights

Access, rectification, deletion, portability exercisable by email at qualead@ellevate.fr. Response guaranteed within 30 calendar days.

Article 30 Register

A processing register compliant with Article 30 of the GDPR is maintained and available on request for validation by your DPO or IT department. DPO contact: qualead@ellevate.fr.

The full list of sub-processors is available in our privacy policy.

A question from your IT department?

We respond to any security questionnaire, audit request, or technical validation. Send us your questions directly.