«Karvon Labs and Tech» MChJ ("Jotqo", "we", "us"), a limited liability company organized under the laws of the Republic of Uzbekistan (Tax ID / INN 311442884), registered at 20 Begoyim Street, Tashkent 100178, Uzbekistan, provides the Jotqo workflow-automation and casework platform (the "Service"). This policy explains what personal data the Service collects, why, who it is shared with, how long it is kept, and the rights of the people whose data it processes.
Questions about this policy or requests about your data: help@jotqo.com (privacy inquiries and data-subject requests) · us@jotqo.com (formal legal notices).
Jotqo serves two kinds of users, and its role differs between them:
A Data Processing Agreement (DPA) reflecting this processor relationship is available to workspace owners on request at help@jotqo.com.
Provisioned from Firebase Authentication when a user signs in (only after email verification):
The Service uses Google Analytics for Firebase to understand product usage (for example, which features are used and basic device/session information). Our public website may set analytics cookies for the same purpose. We do not sell personal data, and we do not operate third-party advertising trackers. Where required by law, cookie-based analytics rely on your consent, which you can withdraw through your browser or device settings.
| Purpose | Data used | Legal basis (GDPR, where it applies) |
|---|---|---|
| Provide the platform (accounts, workspaces, casework) | Account data, workspace content | Performance of a contract; for workspace content, the controller's instructions |
| Run the workspace's configured AI features | Workspace content sent to the AI subprocessor (§4, §5) | The controller's instructions / contract |
| Send notifications the workspace/user opted into | Telegram chat ids, email addresses | Consent |
| Meter usage and manage credits/billing | Usage + billing records | Contract; legal obligation (accounting) |
| Product analytics | Usage/device/session signals | Consent (where cookie-based); otherwise legitimate interests |
| Prevent abuse and secure the service | App Check / reCAPTCHA signals, rate-limit counters | Legitimate interests |
| Operate and troubleshoot the service | Operational telemetry, audit trail | Legitimate interests |
Workspace content is processed by an AI subprocessor to power the workspace's configured AI features (for example, AI casework steps, grading, the Scout assistant, and knowledge retrieval).
gemini-2.5-flash, gemini-2.5-pro, and gemini-embedding-001 for the knowledge index), accessed through the Gemini API via the Genkit runtime.| Subprocessor | Role | What it processes |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, storage, authentication, compute | All platform data: Firebase Auth, Cloud Firestore (eur3), Cloud Storage & compute (us-central1) |
| Google Gemini (Google) | AI processing | Assembled prompts incl. verbatim workspace/case and file content |
| Google Analytics for Firebase (Google) | Product/usage analytics | Usage, device and session signals |
| Telegram | Notification delivery (opt-in) | Telegram chat id + message content |
| Mailgun | Email delivery | Recipient email address + message content |
| reCAPTCHA Enterprise (Google) | Abuse prevention via Firebase App Check | Abuse/risk signals on web clients |
| Google Secret Manager (Google) | Secret storage | Provider credentials (not customer data) |
| Resend | Operator alert email (operational, not customer data) | Operational alerts to the Jotqo operator |
We will update this page before adding a new subprocessor that processes customer personal data.
eur3 (European multi-region).us-central1 (United States), and case/file content is processed by Google Gemini.Because processing and file storage occur in the United States, personal data may be transferred to and processed in the US. Where such transfers are subject to EU/UK data-protection law, they are made under Google Cloud's Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses (SCCs). An EU-only residency configuration is not offered at launch.
Depending on your jurisdiction, you may have rights to access, export, correct, delete, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on consent.
How requests are handled. Data-subject requests are received at help@jotqo.com and executed by the Jotqo operator using platform-admin tooling. For workspace content, requests should be directed to the workspace owner (the controller); Jotqo will assist the workspace owner as processor.
We aim to respond to requests within 30 days.
If you submit a public form to a Jotqo workspace (for example, a student submitting an assignment or a client submitting an intake form): what is collected is the information you enter and any files you upload; it becomes part of that workspace's case data. The workspace owner is the controller of that data and decides how it is used; Jotqo processes it on the workspace owner's behalf. Direct requests about that data to the workspace owner.
The Service uses Firebase Authentication, enforced email verification, App Check / reCAPTCHA Enterprise for abuse prevention, per-user and per-endpoint rate limits, and Google Secret Manager for provider credentials. If we become aware of a personal-data breach affecting you, we will notify affected controllers and, where required, users and authorities without undue delay in accordance with applicable law. We do not claim any specific security certification at this time.
The Service is designed for use by organizations (such as schools, universities, and educators) and their staff. Account holders must be adults, and the Service is not directed to children for self-registration; we do not knowingly allow a child to create their own Jotqo account.
Where a workspace is used in an education context and student respondents may be minors, the workspace owner (the school or educator) is the controller and is responsible for providing any required notices and for obtaining any parental or school consent required by applicable law (for example, COPPA, FERPA, or GDPR Article 8). Jotqo processes such student submissions solely on the controller's documented instructions, does not use them for its own purposes, and does not build advertising profiles. If we learn that we hold a child's personal data without the required authorization, we will delete it.
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, notify account holders by email. Your continued use of the Service after a change takes effect means you accept the updated policy.
«Karvon Labs and Tech» MChJ · 20 Begoyim Street, Tashkent 100178, Uzbekistan · Tax ID / INN 311442884 · Privacy & data requests: help@jotqo.com · Legal notices: us@jotqo.com.