Trust, Security & Data Governance
(信頼性・セキュリティ・データガバナンス)
【The English version is placed after the Japanese version.】
本規約は日本語版(正文)と英語版(参考訳)を掲載しています。
日本語版と英語版に相違がある場合は、日本語版が優先されます。
These Terms are provided in Japanese (authoritative version) and English (reference translation).
In the event of any discrepancy between the Japanese and English versions, the Japanese version shall prevail.
Trust, Security & Data Governance
信頼性・セキュリティ・データガバナンス
必要以上に、データを保持しない。
QYNEは、経営者やビジネスプロフェッショナルが、重要な経営課題や意思決定について考えるためのサービスです。
そこでは、事業上の機密性が高い情報が扱われる可能性があります。
そのためQYNEでは、データ保護について、シンプルな原則を置いています。
サービス提供に必要な範囲を超えて、データを保持しない。
QYNEは、独自のFoundation Model(基盤モデル)を保有していません。
また、ユーザーが入力した経営課題を長期的に蓄積し、恒久的な顧客課題データベースを構築することを前提としたサービスではありません。
QYNEは、Web、AI処理、ワークフロー、決済などの主要機能について、外部のクラウド・AIサービスを利用しながら、通常のQYNE運営側で保持する情報を最小化する設計を採用しています。
QYNEのデータ取扱い概要
主なアカウント識別情報
メールアドレス
アカウント管理環境
Wix
通常の入力課題について、QYNE運営環境で保持する期間
最大24時間
24時間経過後に、通常のQYNEカスタマーサポートが過去の入力課題を確認できるか
原則として確認できません
Dify上の技術的なワークフローログ保持期間
最大30日
Difyの技術ログを通常のユーザー履歴・お問い合わせ対応に利用するか
利用しません
通常利用の経営課題を、ユーザーに紐付けた恒久的なデータベースとして保存するか
保存しません
入力課題の研究利用
無料トライアルでユーザーが明示的に同意した場合のみ
研究用データとメールアドレスの直接的な紐付け
行いません
入力された経営課題をQYNE独自のFoundation Modelの学習に利用するか
利用しません
QYNEが企業の最終意思決定を自動的に行うか
行いません
最終的な意思決定責任
利用者および利用企業にあります
QYNEに入力された経営課題の取扱い
QYNEでは、入力された経営課題を次の3種類に分けて管理しています。
-
サービス提供のために一時的に利用される通常の運用データ
-
システム運用上の技術ログ
-
無料トライアル利用者が明示的に研究利用へ同意した場合の研究用データ
それぞれ、保存目的と取扱いが異なります。
1. 通常利用時の入力課題
ユーザーがQYNEに経営課題を入力すると、その情報は、QYNEによる問い設計およびAIで利用するための構造化された出力を生成する目的で処理されます。
QYNE運営環境での保持
通常利用で入力された経営課題は、QYNEの通常運営環境から入力後24時間以内に削除されます。
そのため、24時間を経過した後は、QYNEの通常の運営スタッフやカスタマーサポート担当者が、過去に入力された経営課題を確認できない場合があります。
QYNEは、過去に入力した経営課題を長期間保存し、ユーザーが後から履歴として参照することを目的としたサービスではありません。
後から必要になる可能性のある入力内容や出力結果については、利用者ご自身の環境で保存してください。
2. システム上の技術ログ
QYNEでは現在、AIワークフロー基盤の一部としてDifyを利用しています。
現在QYNEが利用しているDify環境では、入力された内容を含む技術的な実行ログが最大30日間保持される場合があります。
30日を経過した対象ログは、現在のDify環境に設定されているログ保持条件に従って削除されます。
これらの技術ログは、QYNEがユーザーの過去の経営課題を管理するための「顧客履歴データベース」として保存しているものではありません。
また、通常のお問い合わせ対応のために検索・参照することを目的としていません。
技術ログへのアクセスは、権限を付与されたシステム管理担当者に限定し、以下のような技術上必要な目的に限って行います。
-
システム保守
-
障害調査
-
技術的不具合の原因確認
-
セキュリティ上の調査
-
サービスの正常性・完全性確認
技術ログが一定期間存在することは、QYNEが30日間のユーザー履歴閲覧サービスを提供していることを意味しません。
過去に入力した内容についてお問い合わせいただく場合
QYNEの通常のカスタマーサポート環境は、入力された経営課題を長期的に保存・検索するための設計ではありません。
そのため、通常の24時間の運用期間を経過した後にお問い合わせいただいた場合、QYNEの運営スタッフが、過去に入力された経営課題の内容を確認・再現・復元できない場合があります。
システム基盤上に技術ログが一時的に残っている場合がありますが、これらは通常のお問い合わせ対応のためのアーカイブとして利用するものではありません。
後から必要になる情報については、利用者ご自身で保存してください。
3. 研究利用について ― 無料トライアルのみ
QYNEの無料トライアルでは、入力した課題データの研究利用について、ユーザー自身が選択できる仕組みを設けています。
無料トライアル利用時に、
「入力したデータ(課題)をQYNEの研究用に使用してもよい」
という項目について、ユーザーが明示的にチェックして同意した場合に限り、該当する課題データをQYNEの研究目的で保存・分析する場合があります。
研究利用への同意は任意です。
研究利用に同意しなくても、無料トライアルの基本的な機能をご利用いただけます。
ユーザーによる明示的な同意がない場合、入力された課題をQYNEの研究用データとして意図的に保存することはありません。
QYNEにおける「研究」とは
研究利用に同意いただいたデータは、主に以下の目的で利用します。
経営課題の傾向分析
ユーザーがどのような経営課題、意思決定上の不確実性、判断上の悩みをQYNEに入力しているかを分析し、サービス改善に活用します。
問い設計ロジックの改善
QYNEが、重要な論点、見落とされている可能性のある視点、制約、戦略上のトレードオフ等を、より適切に提示できるよう改善します。
プロンプト品質の評価・改善
QYNEが生成するプロンプトについて、構造、有用性、網羅性、関連性等を評価し、改善します。
QYNEサービスの改善
QYNEの機能、ユーザー体験、問い設計手法、意思決定支援方法その他のサービス品質改善に利用します。
研究利用は、顧客の経営課題を利用してQYNE独自のFoundation Modelを構築することを意味するものではありません。
研究用データとアカウント情報の分離
無料トライアル利用者が研究利用について明示的に同意した場合、対象となる課題データは、研究目的のデータとしてWix環境内に別途保存されます。
研究用データは、ユーザーのメールアドレスとは直接紐付けません。
QYNEでは、研究目的に不要なユーザー識別情報を研究データへ付加しないことを基本方針としています。
ただし、ユーザーが入力した経営課題本文そのものに、
-
個人名
-
企業名
-
顧客名
-
未公開の数値
-
取引内容
-
その他、個人や企業を識別し得る情報
が含まれている可能性があります。
そのためQYNEでは、研究利用に同意された課題データについて、単純に「匿名データ」とは表現していません。
必要に応じて、ユーザー自身で不要な固有名詞や機密情報を入力しない、または置き換えることを推奨します。
研究用データは通常の運用データとは異なります
通常利用における24時間以内のQYNE運営環境からの削除、およびDifyにおける最大30日間の技術ログ保持は、通常のサービス提供に伴うデータ処理についての取扱いです。
一方、無料トライアル利用者が明示的に研究利用へ同意した場合、その対象課題については、研究目的のデータとして別途取り扱います。
つまり、研究利用への明示的な同意は、QYNEの通常の非恒久保存モデルに対する、限定的かつ明示的な例外です。
AIモデルの学習について
QYNEは独自のFoundation ModelまたはLarge Language Modelを保有していません。
QYNEに入力された経営課題を、QYNE独自のFoundation Modelを学習させる目的で使用することはありません。
研究利用への明示的な同意がある場合も、その目的は、
-
経営課題の傾向分析
-
問い設計ロジックの改善
-
プロンプト品質評価
-
QYNEサービス改善
です。
QYNEでは、必要なAI処理のために外部のAI基盤を利用しています。
OpenAI APIにおけるデータの取扱い
QYNEでは、AI処理基盤の一部としてOpenAI APIを利用しています。
OpenAIは、APIプラットフォームを通じて送信された入力・出力データについて、顧客が明示的にオプトインしない限り、モデルの学習・改善に使用しない方針を公開しています。
また、OpenAIは対象となるAPIおよびビジネス向けサービスについて、SOC 2 Type 2の独立監査や複数のISO認証等に関する情報を公開しています。
これらはOpenAIに対する監査・認証であり、QYNE自身が同じ認証を取得していることを意味するものではありません。
QYNEのサービス構成
QYNEは、自社内に大規模な顧客データ基盤や独自Foundation Modelを構築するのではなく、Web、ワークフロー、AI、決済等について、専門の外部サービスを利用して構成されています。
現在、主に以下のサービスを利用しています。
Wix
主な役割
-
Webアプリケーション
-
アカウント関連機能
-
メールアドレスの管理
-
研究利用に同意された課題データの保存
Dify
主な役割
-
AIワークフロー
-
AIオーケストレーション
-
プロンプト処理
現在QYNEが利用しているDify環境では、対象となる技術的な実行ログが最大30日間保持されます。
Make
主な役割
-
ワークフロー自動化
-
サービス間のデータ処理
Make上で処理されるデータは、QYNE側のワークフロー設定およびMake側のサービス設定に基づいて取り扱われます。
OpenAI API
主な役割
-
AI推論
-
モデル処理
Stripe
主な役割
-
決済処理
QYNEは、ユーザーのクレジットカード情報をQYNE独自の決済データベースに保存することを前提としたシステムを構築していません。
簡略化したデータフロー
ユーザー
↓
QYNE Web Interface
Wix
↓
Workflow / AI Orchestration
Dify / Make
↓
AI Processing
OpenAI API
↓
QYNE Output
↓
ユーザー
決済に関する処理は、必要に応じてStripeを通じて別途行われます。
利用している外部サービスのセキュリティ・コンプライアンス
QYNEでは、主要なシステム機能について、第三者によるセキュリティ監査や国際的な情報セキュリティ認証に関する取り組みを公開している外部サービスを利用しています。
Wix
Wixは、SOC 2 Type 2、PCI DSS Level 1、ISO/IEC 27001を含む複数のセキュリティ・コンプライアンスプログラムを公開しています。
QYNEでは、Web環境およびアカウント関連機能としてWixを利用しています。
Dify
Difyは、SOC 2 Type IIおよびISO/IEC 27001:2022等に関する第三者監査・認証への対応を公開しています。
QYNEでは、AIワークフローおよびオーケストレーション基盤としてDifyを利用しています。
Make
Makeは、SOC 2 Type II、SOC 3およびISO/IEC 27001等に関するセキュリティ・コンプライアンスプログラムを公開しています。
QYNEでは、ワークフロー自動化およびサービス間処理にMakeを利用しています。
OpenAI
OpenAIは、対象となるAPIおよびビジネス向けサービスについてSOC 2 Type 2の独立監査を受けていること、およびISO/IEC 27001等の認証に関する情報を公開しています。
Stripe
Stripeは、SOC 1・SOC 2レポートおよびPCI DSS Level 1等の決済・セキュリティ基準への対応を公開しています。
QYNEでは、決済処理にStripeを利用しています。
重要:これらはQYNE自身の認証ではありません
Wix、Dify、Make、OpenAI、Stripe等が取得・維持している認証、監査、コンプライアンスプログラムは、それぞれのサービス提供会社および対象サービスに対するものです。
これらのサービスをQYNEが利用していることによって、QYNE自身が、
-
SOC 2 Type II
-
ISO/IEC 27001
-
PCI DSS Level 1
等を取得したことにはなりません。
QYNEは、第三者サービスの認証をQYNE自身の認証として表示しません。
QYNEのセキュリティはShared Responsibilityに基づきます
第三者監査済みのインフラを利用していることによって、QYNE自身のセキュリティ責任がなくなるわけではありません。
QYNEは、自ら管理できる範囲について責任を負います。
これには、状況に応じて以下が含まれます。
-
サービス設定
-
管理者アクセス
-
認証情報・APIキー管理
-
データフロー設計
-
データ最小化
-
データ保持設定
-
外部サービスの選定
-
プライバシー情報の開示
-
インシデント対応
-
顧客データの適切な利用
第三者サービスの認証は、そのサービス提供会社の管理体制に関する一定の保証を提供するものです。
QYNE自身による設定・利用・管理の責任を代替するものではありません。
なぜQYNEは「データ最小化」を重視するのか
QYNEの価値は、ユーザーが入力した過去の経営課題を大量に蓄積することに依存していません。
QYNEが提供する価値は、
「AIに答えを求める前に、自分は何を考えるべきなのか」
を構造化することです。
その処理が完了した後、通常利用においてユーザーの経営課題をQYNE側で長期間保持し続ける必要性はありません。
そのためQYNEは、通常利用において、長期保存よりも限定的なデータ保持を優先しています。
人間が最終的な意思決定を行います
QYNEは、意思決定を構造化するためのサービスです。
企業の意思決定を自律的に行うAIではありません。
QYNEは、以下のような内容の整理を支援します。
-
見落としている可能性のある論点
-
戦略上のトレードオフ
-
前提条件
-
制約
-
ステークホルダーごとの視点
-
意思決定前に答えるべき問い
しかしQYNEが独自に、
-
投資
-
契約
-
調達
-
M&A
-
採用・解雇
-
法的措置
-
財務上のコミットメント
-
その他の重要な企業意思決定
を承認することはありません。
最終的な意思決定権限と責任は、利用者および利用企業にあります。
QYNEは「AIは常に正しい」とは考えていません
生成AIは、不完全、不正確、または誤解を招く情報を生成する可能性があります。
QYNEは、AIに入力される経営課題の構造や問いの質を改善することを目的としています。
QYNEを利用することによって、下流のAIシステムが生成するすべての事実や結論の正確性が保証されるものではありません。
特に、
-
財務
-
法務
-
規制
-
セキュリティ
-
組織
-
経営戦略
に重大な影響を及ぼす意思決定については、重要な事実を独立して検証してください。
機密情報・制限情報を入力する場合
QYNEでは、重要な経営課題を扱うことがあります。
利用者は、自社の、
-
情報セキュリティポリシー
-
生成AI利用規程
-
機密情報管理規程
-
プライバシールール
-
契約上の制約
-
法令・規制上の義務
に従ってQYNEをご利用ください。
外部のクラウドサービスまたはAIサービスへの送信が禁止されている情報については、QYNEへ入力しないでください。
必要に応じて、以下の情報について削除・匿名化・置換を行った上で利用することを推奨します。
-
個人名
-
顧客名
-
未公開の取引内容
-
高度な機密性を持つ財務数値
-
M&A案件名・コードネーム
-
規制対象となる個人情報
-
その他、問い設計に不要な識別情報
エンタープライズ企業による導入審査について
QYNEは、企業が通常行っている、
-
購買審査
-
情報セキュリティ審査
-
法務審査
-
プライバシー審査
-
AIガバナンス審査
-
社内承認
を回避して導入することを推奨しません。
QYNEの導入を検討する企業は、自社の要件に基づいてサービスを評価してください。
主な確認項目には以下があります。
-
データフロー
-
データ保持
-
外部サービス・サブプロセッサー
-
AIプロバイダー
-
プライバシー
-
セキュリティ
-
機密情報管理
-
AIガバナンス
-
契約条件
-
必須認証
データ取扱いサマリー
アカウント情報
主な識別情報
メールアドレス
管理環境
Wix
通常利用で入力された経営課題
QYNE運営環境での保持
最大24時間
24時間経過後の通常カスタマーサポートからの参照
原則として不可
恒久的なQYNE顧客履歴データベース
なし
技術的なワークフローログ
プラットフォーム
Dify
現在のQYNE環境における最大保持期間
30日
目的
システム運用、障害調査、サービス正常性確認、セキュリティ関連調査
通常のカスタマーサポート用アーカイブ
利用しません
アクセス
技術上必要な場合に限り、権限を持つシステム管理担当者に限定
研究用データ
対象
研究利用に明示的に同意した無料トライアル利用者
研究利用への同意
必須
初期設定
同意しない状態
明示的な同意なしでの研究利用
行いません
保存環境
Wix
メールアドレスとの直接的な紐付け
行いません
研究目的
-
経営課題の傾向分析
-
問い設計ロジックの改善
-
プロンプト品質評価
-
QYNEサービス改善
AI学習
QYNE独自のFoundation Model
ありません
入力された課題をQYNE独自Foundation Modelの学習に使用
しません
よくあるご質問
QYNEに入力した経営課題は保存されますか?
通常利用では、入力された経営課題を恒久的な顧客履歴データベースとして保存しません。
QYNEの通常運営環境では最大24時間保持されます。
一方、システム運用上の技術的な実行ログが、現在利用しているDify環境上に最大30日間保持される場合があります。
24時間を過ぎても、QYNEに問い合わせれば過去の入力内容を確認できますか?
原則として確認できません。
QYNEの通常のカスタマーサポート環境は、24時間経過後の入力課題を履歴として検索するための設計ではありません。
Difyに技術ログが残っているなら、そこから過去の入力内容を調べてもらえますか?
技術ログは、システム保守、障害調査、セキュリティ関連の調査など、技術上必要な目的のために保持されています。
通常のユーザー履歴やお問い合わせ対応のための検索サービスとして利用するものではありません。
後から必要になる入力内容や出力結果については、利用者ご自身で保存してください。
QYNEは、入力した経営課題を独自AIの学習に使いますか?
いいえ。
QYNEは、ユーザーの経営課題を学習させた独自Foundation Modelを保有していません。
QYNEは入力された課題を研究に利用しますか?
無料トライアル利用者が、研究利用について明示的に同意した場合に限ります。
明示的な同意がない入力課題を、QYNEの研究データとして意図的に保存することはありません。
研究利用に同意した場合、何に利用されますか?
主に以下の目的で利用します。
-
経営課題の傾向分析
-
問い設計ロジックの改善
-
プロンプト品質評価
-
QYNEサービス改善
研究用データは、ユーザーのメールアドレスとは直接紐付けずに管理します。
QYNEはSOC 2を取得していますか?
QYNE自身が単独でSOC 2 Type IIの監査を受けているとは現在表明していません。
一方、QYNEが利用している主要な外部サービスの中には、それぞれSOC 2等の第三者監査や情報セキュリティ認証を取得・維持しているサービスがあります。
これらは各サービス提供会社に対する監査・認証であり、QYNE自身の認証を意味するものではありません。
なぜQYNEは利用している外部サービスの認証情報を公開するのですか?
企業のセキュリティ評価では、
「ベンダー自身がどの認証を持っているか」
だけではなく、
-
データがどこで処理されるか
-
どのサービス提供会社が処理するか
-
どのくらい保持されるか
-
各レイヤーを誰が管理するか
-
どのセキュリティ管理が適用されるか
を確認することが重要だからです。
QYNEでは、自らの責任範囲と、利用する外部サービスが担う責任範囲を区別して説明します。
QYNEの考え方
QYNEは、AIサービスが利用者に対して、
「あなたのデータは絶対に安全です」
と断言することが、最も適切な説明だとは考えていません。
クラウドやAIを利用する以上、あらゆるリスクを完全にゼロにすることはできません。
だからこそ重要なのは、透明性です。
何を取得するのか。
どこで処理するのか。
どのくらい保持するのか。
誰がアクセスできるのか。
何のために利用するのか。
そして、何には利用しないのか。
QYNEは、意思決定支援において大切にしている考え方を、自らのデータガバナンスにも適用しています。
思い込みで判断する前に、考えるべきことを明らかにする。
QYNE Principle
QYNEは、
AIを無条件に信頼してもらうためのサービスではありません。
AIを使いながら、
人間がより良く考えるためのサービスです。
その考え方は、QYNE自身のデータ設計にも反映されています。
保持するデータを減らす。
説明を増やす。
最後の判断は、人間に残す。
最終更新:2026年9月
QYNEのシステム構成、利用する外部サービス、各サービス提供会社の認証・データ処理条件等は、今後変更される場合があります。
外部サービスのセキュリティ、コンプライアンス、データ処理状況が貴社の導入判断に重要な場合は、各サービス提供会社が公開する最新の公式情報をご確認のうえ、貴社の基準に基づくベンダー審査を実施してください。
QYNEの法人導入、セキュリティ、プライバシー、データ処理、調達・審査に関するご質問は、QYNEまでお問い合わせください。
【English】
Trust, Security & Data Governance
Built to minimize what we retain.
QYNE is designed to help professionals think through important business and management issues.
Because those issues may contain commercially sensitive information, our approach to data protection begins with a simple principle:
Do not retain more data than is necessary to provide the service.
QYNE does not operate its own proprietary foundation model, nor is the service designed around building a permanent database of customers' management issues.
Instead, QYNE uses established cloud, workflow and AI platforms for the principal components of the service, while minimizing the amount of information retained directly for normal QYNE operations.
At a Glance
Primary account identifier
Email address
Account environment
Wix
QYNE operational retention of submitted management issues
Up to 24 hours
Routine access by QYNE customer-support staff after 24 hours
No
Technical workflow log retention in the current Dify environment
Up to 30 days
Routine use of Dify technical logs for customer-support history lookup
No
Permanent user-linked database of management issues for normal use
No
Research use of submitted issues
Only with explicit opt-in consent in the free trial
Research data directly linked to the user's email address
No
Use of submitted management issues to train a proprietary QYNE foundation model
No
Autonomous corporate decision-making by QYNE
No
Human decision responsibility
Yes
How QYNE Handles Submitted Management Issues
QYNE distinguishes between:
-
operational data used to provide the service;
-
technical system logs;
-
research data that a free-trial user has explicitly agreed may be used for research.
These categories are handled differently.
1. Normal Service Use
When a user submits a management issue to QYNE, the information is processed for the purpose of generating the relevant question structure and AI-ready output.
QYNE Operational Environment
Submitted management issues available within QYNE's normal operational environment are deleted within 24 hours of submission.
This means that QYNE's regular operating and customer-support staff generally cannot retrieve a user's previous management issue after that period.
QYNE is not designed to provide a long-term history of previously submitted management issues.
Users who wish to retain their own inputs or outputs should keep a copy in their own environment.
2. Technical Workflow Logs
QYNE currently uses Dify as part of its AI workflow infrastructure.
In the Dify environment currently used by QYNE, technical execution logs may contain submitted input and are retained for up to 30 days.
Logs older than the applicable 30-day period are deleted under the current Dify environment's log-retention configuration.
These technical logs are not maintained as a QYNE customer-history database and are not intended for routine customer-support lookup.
Access to technical logs is restricted to authorized system-administration personnel and is intended for technically necessary purposes such as:
-
system maintenance;
-
troubleshooting;
-
investigation of technical failures;
-
security investigation;
-
service integrity.
The existence of a technical execution log does not mean that QYNE offers a 30-day user-history or retrieval service.
If You Contact QYNE About a Previous Input
QYNE's normal customer-support environment is not designed to retain submitted management issues for long-term retrieval.
As a result, once the normal 24-hour operational period has passed, QYNE staff may no longer be able to confirm, reproduce or recover the management issue that you previously submitted.
Technical workflow logs that may temporarily remain in the underlying system are not used as a routine customer-support archive.
For this reason, users should retain their own copy of any input or output that they may need later.
3. Research Use — Free Trial Only
The QYNE free trial includes an optional research-consent choice.
Users may choose whether to agree to the following:
“I agree that the data (management issue) I submit may be used for QYNE research.”
Research consent is voluntary.
A user can use the core free-trial experience without agreeing to research use.
QYNE stores a submitted management issue as research data only when the user has explicitly opted in to this research use.
If the user does not opt in, QYNE does not intentionally retain that management issue as QYNE research data.
What “Research” Means at QYNE
Research use may include:
Analysis of Management-Issue Trends
Understanding the types of management challenges, uncertainties and decision situations users bring to QYNE.
Improvement of Question-Design Logic
Improving QYNE's ability to identify important perspectives, missing considerations, constraints and strategic trade-offs.
Prompt Quality Evaluation
Evaluating and improving the structure, usefulness, completeness and relevance of prompts generated by QYNE.
Service Improvement
Improving QYNE's functionality, user experience, decision-structuring methodology and overall service quality.
Research use does not mean that QYNE is building a proprietary foundation model from customers' management issues.
Separation of Research Data and Account Information
Where a free-trial user explicitly agrees to research use, the relevant management-issue data is stored separately within the Wix environment for research purposes.
The research record is not directly linked to the user's email address.
QYNE's principle is to avoid attaching user-identifying account information to research data when that information is not required for the stated research purpose.
However, users should understand that the text of a submitted management issue may itself contain:
-
personal names;
-
company names;
-
client names;
-
unpublished figures;
-
transaction details;
-
other potentially identifying information.
For this reason, QYNE does not describe research-consent data merely as “anonymous data.”
Where appropriate, users should avoid entering unnecessary identifying or highly confidential information.
Research Data Is Different From Normal Operational Data
The normal 24-hour operational deletion period and the Dify technical-log retention period apply to normal service processing.
Research data that has been explicitly authorized by a free-trial user is handled separately for the stated research purposes and is not treated as ordinary service-history data.
Research consent is therefore an explicit exception to QYNE's normal non-retention model.
AI Model Training
QYNE does not operate a proprietary foundation model or large language model.
Submitted management issues are not used to train a proprietary QYNE foundation model.
Where research consent has been provided, the purpose of retaining the relevant issue is limited to activities such as:
-
management-issue trend analysis;
-
improvement of question-design logic;
-
prompt-quality evaluation;
-
QYNE service improvement.
QYNE uses external AI infrastructure to perform relevant AI processing.
OpenAI API Data Use
QYNE uses the OpenAI API as part of its AI-processing architecture.
OpenAI states that, by default, data submitted through its API platform — including inputs and outputs — is not used to train or improve OpenAI's models unless the customer explicitly opts in. OpenAI also states that its API and relevant business services have undergone an independent SOC 2 Type 2 examination and are supported by multiple ISO certifications.
These are OpenAI's controls and certifications and should not be interpreted as QYNE's own certification.
QYNE Service Architecture
QYNE is designed using established cloud, workflow, AI and payment-service providers rather than a large proprietary customer-data infrastructure.
The current service architecture principally uses:
Wix
Web application and account-related functions
Dify
AI workflow and orchestration
Make
Workflow automation and service-to-service processing
OpenAI API
AI inference and model processing
Stripe
Payment processing
The exact flow may vary depending on the function being performed.
Simplified Data Flow
User
↓
QYNE Web Interface
Wix
↓
Workflow / AI Orchestration
Dify / Make
↓
AI Processing
OpenAI API
↓
QYNE Output
↓
User
Payment-related processing is handled separately through Stripe where applicable.
Third-Party Security and Compliance
QYNE deliberately uses established service providers for major infrastructure components.
Each provider maintains its own security, compliance and data-protection program.
Wix
Wix publicly states that its security and compliance program includes SOC 2 Type 2, PCI DSS Level 1 and multiple ISO certifications, including ISO 27001.
QYNE currently uses Wix for its web environment and account-related functions, including management of the user's email address.
Dify
Dify announced in March 2026 that it had completed SOC 2 Type II and ISO 27001:2022 audits for the second consecutive year.
QYNE uses Dify as part of its AI workflow and orchestration infrastructure.
The current QYNE Dify environment retains applicable technical execution logs for up to 30 days.
Make
Make publicly states that it has completed SOC 2 Type II and SOC 3 audits and operates an information-security program certified to ISO 27001.
QYNE uses Make for workflow automation and service-to-service processing.
Data handled through Make is subject to the applicable QYNE workflow configuration and Make service settings.
OpenAI
OpenAI states that its API and relevant business product services have undergone an independent SOC 2 Type 2 examination.
OpenAI also maintains ISO/IEC 27001 and related information-security and privacy certifications for applicable services.
OpenAI states that API inputs and outputs are not used to train its models by default unless the customer explicitly opts in.
Stripe
Stripe is used for payment processing.
Stripe states that it maintains SOC 1 and SOC 2 reports and operates its applicable services in accordance with PCI DSS Level 1 requirements.
QYNE does not design its service around independently storing users' payment-card information in a proprietary QYNE payment database.
Important: These Are Not QYNE Certifications
The certifications, audits and compliance programs described above apply to the relevant third-party providers and to the scope of their respective services.
They do not mean that QYNE itself has obtained:
-
SOC 2 Type II certification or examination;
-
ISO/IEC 27001 certification;
-
PCI DSS Level 1 certification;
unless QYNE separately and explicitly states that it has done so.
QYNE does not present a third party's certification as its own.
QYNE's Security Model Is Based on Shared Responsibility
Using independently assessed infrastructure does not remove QYNE's own responsibility.
QYNE remains responsible for the aspects of the service that it controls, including, as applicable:
-
service configuration;
-
administrator access;
-
credential and API-key management;
-
data-flow design;
-
data-minimization practices;
-
retention settings;
-
subprocessor selection;
-
privacy disclosures;
-
incident management;
-
appropriate use of customer information.
Third-party certifications provide assurance regarding the relevant provider.
They do not substitute for QYNE's responsibility for how those services are configured and used.
Why QYNE Uses a Data-Minimization Model
QYNE's core value does not depend on accumulating a historical database of customers' management issues.
The purpose of QYNE is to help a user determine:
What should I be considering before asking AI what I should do?
Once that task has been completed, QYNE generally has no operational need to maintain the user's management issue indefinitely.
For that reason, QYNE's normal design favors limited retention over long-term accumulation.
Human Decision Responsibility
QYNE is a decision-structuring service.
It is not an autonomous corporate decision-maker.
QYNE may help users identify:
-
missing considerations;
-
strategic trade-offs;
-
assumptions;
-
constraints;
-
stakeholder perspectives;
-
questions that should be answered before a decision is made.
QYNE does not independently authorize:
-
investments;
-
contracts;
-
procurement decisions;
-
mergers and acquisitions;
-
hiring or dismissal decisions;
-
legal actions;
-
financial commitments;
-
other material corporate decisions.
Final decision authority remains with the user and the user's organization.
QYNE Does Not Claim That AI Is Always Correct
Generative AI can produce incomplete, inaccurate or misleading information.
QYNE is intended to improve the structure of the issue presented to AI.
It does not guarantee the accuracy of every fact or conclusion produced by downstream AI systems.
Material facts should be independently verified where a decision may have significant:
-
financial;
-
legal;
-
regulatory;
-
security;
-
organizational;
-
strategic
consequences.
Confidential and Restricted Information
QYNE may be used to structure important management issues.
However, customers should comply with their own organization's:
-
information-security policies;
-
AI-use policies;
-
confidentiality requirements;
-
privacy rules;
-
contractual restrictions;
-
regulatory obligations.
Users should not submit information to QYNE where their organization prohibits that information from being processed by external cloud or AI services.
Where appropriate, users should consider removing or replacing:
-
personal names;
-
customer names;
-
unpublished transaction details;
-
highly confidential financial figures;
-
M&A code names;
-
regulated personal information;
-
other unnecessary identifiers.
Enterprise Procurement and Security Review
QYNE does not encourage organizations to bypass their normal:
-
procurement process;
-
information-security review;
-
legal review;
-
privacy review;
-
AI-governance review;
-
internal approval process.
Organizations considering QYNE should evaluate the service against their own requirements.
Relevant review areas may include:
-
data flow;
-
data retention;
-
subprocessors;
-
AI providers;
-
privacy;
-
security;
-
confidentiality;
-
internal AI governance;
-
contractual requirements;
-
mandatory certifications.
Data Handling Summary
Account Information
Primary identifier:
Email address
Environment:
Wix
Normal Submitted Management Issues
QYNE operational availability:
Up to 24 hours
Availability to normal QYNE customer-support operations after 24 hours:
Generally unavailable
Permanent QYNE customer-history database:
No
Technical Workflow Logs
Platform:
Dify
Maximum retention in the current QYNE environment:
30 days
Purpose:
Technical operation, troubleshooting, service integrity and security-related investigation
Routine customer-support archive:
No
Access:
Restricted to authorized system-administration personnel when technically necessary
Research Data
Applicable users:
Free-trial users who explicitly opt in
Research consent required:
Yes
Default consent:
No
Research use without explicit consent:
No
Storage environment:
Wix
Direct linkage to email address:
No
Research purposes:
Management-issue trend analysis, question-design improvement, prompt-quality evaluation and QYNE service improvement
AI Training
QYNE proprietary foundation model:
No
Submitted issues used to train a proprietary QYNE foundation model:
No
Frequently Asked Questions
Does QYNE store the management issue I enter?
For normal service use, QYNE does not maintain submitted management issues as a permanent customer-history database.
The issue is available in QYNE's normal operational environment for up to 24 hours.
Technical execution logs may remain in the current Dify environment for up to 30 days.
Can QYNE customer support retrieve my input after 24 hours?
Generally, no.
The normal QYNE customer-support environment is not designed to provide historical retrieval after the 24-hour operational period.
Temporary technical logs are not maintained as a routine support archive.
If technical logs still exist, can I ask QYNE to retrieve my previous input from them?
Technical logs are reserved for technically necessary system-administration purposes and are not intended to function as a customer-history retrieval service.
Users should retain their own copy of information they may need later.
Does QYNE use my management issue to train its own AI model?
No.
QYNE does not operate a proprietary foundation model trained on users' management issues.
Does QYNE use submitted issues for research?
Only where a free-trial user has explicitly opted in to research use.
Without explicit consent, submitted issues are not intentionally retained as QYNE research data.
What happens if I agree to research use?
The relevant issue may be stored separately in Wix for QYNE research purposes, including:
-
management-issue trend analysis;
-
question-design improvement;
-
prompt-quality evaluation;
-
service improvement.
The research record is not directly linked to the user's email address.
Is QYNE SOC 2 certified?
QYNE does not currently claim a standalone SOC 2 examination.
Several major third-party platforms used by QYNE maintain their own SOC 2 examinations and other security certifications.
Those certifications belong to the relevant providers and do not constitute QYNE's own certification.
Why does QYNE disclose the security certifications of its infrastructure providers?
Because enterprise security is not only a question of which certification logo appears on a vendor's website.
It is also important to understand:
-
where information is processed;
-
which providers process it;
-
how long information is retained;
-
which party controls which part of the system;
-
which security controls apply at each layer.
QYNE therefore distinguishes between its own responsibilities and the independent assurance maintained by its infrastructure providers.
Our Approach
QYNE does not believe that the safest statement an AI company can make is:
“Your data is completely safe.”
No responsible cloud or AI service can eliminate every risk.
We believe a more useful standard is transparency:
What do we collect?
Where is it processed?
How long is it retained?
Who can access it?
What is it used for?
What do we deliberately not do with it?
QYNE applies the same principle to its own service that it applies to decision-making:
Make the important questions visible before making assumptions.
The QYNE Principle
QYNE is not designed to ask users to trust AI blindly.
It is designed to help people think more clearly while using AI.
That principle also defines how we approach data.
Retain less.
Explain more.
Keep the human responsible.
Last Updated: September 2026
QYNE's architecture, third-party services and provider certifications may change over time.
Where a third-party provider's security, compliance or data-processing status is relevant to your organization's assessment, please refer to the provider's current official documentation and complete your organization's own vendor review.
For enterprise security, privacy, procurement or data-handling questions regarding QYNE, please contact QYNE.
