Skip to content
qPACS

Legal

Privacy policy.

qPACS is an on-premise product, so the short version is unusually short: your clinical data never touches our systems, and this website collects nothing beyond the enquiry form you choose to fill in.

  • No cookies
  • No analytics
  • No telemetry
  • On-premise by design

Your images never reach us

qPACS runs on your hardware. Studies, reports and patient records stay inside your network — we hold no copy and have no route to one.

No cookies, no analytics

This site sets no cookies and runs no analytics, advertising or tracking scripts of any kind.

Only what you type

The one thing we collect is the demo enquiry form — the details you choose to send, used only to reply.

Last updated 31 August 2026

01Who this covers

This policy explains how IntegCubes — the publisher of qPACS — handles personal information in connection with:

  • this website, www.q-pacs.com, including the demo request form
  • the qPACS Mobile app for Android and iOS
  • enquiries, quotations and support conversations you start with us by email or WhatsApp

It does not cover the patient data held inside a qPACS installation. That is the subject of the next clause, and it is the most important thing on this page.

02Patient data stays on your server

qPACS is installed on hardware you own and control. Studies, images, reports, worklists, orders, user accounts and audit trails live in your PostgreSQL database and your storage, inside your own network.

There is no cloud tier, no routing of images through our infrastructure and no phone-home. Licences are signed and node-locked and are validated offline, so a qPACS server does not need an internet connection at all.

You are the data controller for clinical data

Under GDPR, HIPAA and equivalent regimes, the healthcare organisation operating the qPACS installation is the controller of the patient data within it. IntegCubes is not a processor of that data, because we never receive it.

If we are engaged for support and you choose to give us access to a system holding real patient data, that access is governed by the support or data processing agreement between us — not by this website policy.

03What we collect

Information you give us

When you submit the demo request form — from the contact page or the dialog behind any “Request a demo” button — we receive the fields you complete:

  • Name required
  • Email address required
  • Organisation optional
  • Phone number optional
  • What you are interested in, and roughly how many modalities you run chosen from a list
  • Your message required

Providing these is entirely voluntary, and none of them are needed to browse the site. Please do not include patient details in the message box — we have no need for them, and this is not a secure clinical channel.

Information collected automatically

  • IP address, for abuse protection only — the form endpoint counts submissions per address to block flooding. The counter is held in memory for a ten-minute window and then discarded. It is not written to a database, and it is not attached to the message we receive.
  • Standard server logs — our hosting provider records ordinary request metadata such as IP address, timestamp, URL requested and browser user-agent, in the way any web server does. These are operational and security logs; we do not mine them, build profiles from them or link them to enquiries.

04Cookies and tracking

This website sets no cookies. It runs no analytics package, no advertising or conversion pixels, no session recording, no A/B testing tool and no third-party embeds that could track you across sites.

That is why you are not shown a cookie banner: there is nothing to consent to. Every page except the form endpoint is static HTML served from a CDN.

You can verify this yourself — open your browser’s developer tools on any page of this site and look at the Cookies and Network tabs.

05How we use it

We use the details you send us to:

  • reply to your enquiry and arrange a demonstration
  • prepare a quotation, or answer technical questions about deployment, integration and licensing
  • keep an ordinary business record of the conversation that follows

Where the law requires a lawful basis, ours is legitimate interests — responding to someone who has contacted us about our product — and, where a contract follows, steps taken at your request before entering into it.

We do not sell, rent or share your details with third parties for their own marketing. We do not add you to a mailing list because you asked for a demo. We do not carry out profiling or automated decision-making.

06Who else processes it

Two service providers process data on our behalf so this site can work:

  • Vercel hosting and CDN — serves the pages and runs the form endpoint, and holds the standard server logs described above.
  • Resend transactional email — delivers your enquiry to our mailbox. Your message and contact details pass through it in transit.

Both act only on our instructions. We may also disclose information where we are legally required to, or where it is necessary to establish or defend a legal claim.

07How long we keep it

  • Rate-limit counters — ten minutes, then discarded automatically.
  • Server logs — retained by our hosting provider for a short operational period under their own schedule.
  • Your enquiry — kept in our mailbox while the conversation is live, and afterwards as a business record for no longer than is reasonably useful. Where a contract results, for as long as tax and accounting law requires.

You can ask us to delete your enquiry at any time — see how to request deletion.

08The qPACS Mobile app

qPACS Mobile connects directly to your organisation’s own qPACS server, at the address you enter when you set it up. Traffic goes from the device to that server. It is not routed through us, and we receive nothing from it.

  • You sign in with the account your PACS administrator issued — same credentials, role and permissions as the web viewer.
  • No images, reports or patient data are stored on the device. Studies are streamed for viewing while you are signed in.
  • What the app holds locally is limited to your sign-in session and the connection settings you entered. Signing out or uninstalling removes them.
  • The app contains no advertising SDK and no third-party analytics.

Because your account belongs to your organisation’s installation, requests about that account go to your PACS administrator — we cannot reach it. The deletion page sets out exactly who to ask for what.

09The qPACS software itself

An installed qPACS server sends no usage telemetry, analytics or crash reports to us. Licence validation is performed offline against a signed licence file, so the product functions with no internet connection at all.

Diagnostic logs generated by the software are written to your own server and stay there. If you send us a log file as part of a support request, you control what it contains — please redact patient identifiers before sending.

10Security

This website is served over HTTPS, so the form submission is encrypted in transit. Enquiry data is held in a mailbox protected by the provider’s own authentication controls, and access is limited to the people who need it to answer you.

No transmission over the internet can be guaranteed completely secure. This form is intended for commercial enquiries — please do not use it to send clinical information about an identifiable patient.

11Your rights

Depending on where you live, you may have the right to ask us to:

  • confirm what personal data we hold about you, and give you a copy
  • correct anything inaccurate
  • delete it
  • restrict or object to how we use it
  • provide it in a portable format

Write to info@integcubes.com and we will respond. We do not charge for this and we will not treat you differently for asking. If you are unhappy with our response, you may complain to your local data protection authority.

Deleting your data

Deletion has a page of its own, because the answer depends on which data you mean — an enquiry you sent us, something on your phone, or a clinical account on your hospital’s server. Read the deletion guide.

12International transfers

Our hosting and email providers operate globally, so your enquiry may be processed on servers outside your own country, including in the United States and the European Union.

Where personal data is transferred out of a region that restricts such transfers, we rely on the safeguards those providers have in place, such as standard contractual clauses. This applies only to the enquiry details described in clause 03 — clinical data never leaves your own infrastructure.

13Children

qPACS is a professional product sold to healthcare organisations. This website and the app are not directed at children, and we do not knowingly collect personal information from anyone under 16 through them. If you believe a child has sent us details, contact us and we will delete them.

14Changes to this policy

If this policy changes we will update the page and move the “last updated” date at the top. Material changes will be summarised there so you can see what moved. Continuing to use the site after a change means the revised policy applies.

15Contact us

For any question about this policy, or to exercise any of the rights above:

Data protection enquiries are handled by IntegCubes. We aim to acknowledge within five working days.

This policy describes our practices for this website, the qPACS Mobile app and enquiries made to us. It does not form part of any licence, support or data processing agreement for the qPACS software, and it does not vary the terms of one. Where a signed agreement covers the same subject, that agreement takes precedence.