Privacy Policy
Last updated: 24 August 2026
This policy explains how Quantara, operated under the Vista By Lara name, handles personal data across the public website, account onboarding, authenticated BOQ workflows, support and configured commercial services.
It describes the processing evidenced by the current product. It does not claim that every optional integration is enabled for every user or that publication alone establishes compliance with any law.
Who is responsible for the data
Vista By Lara operates Quantara and is the currently published contact for the service. Depending on the customer arrangement, a customer may control project personal data and Quantara may process that data on the customer's instructions.
Quantara is provided by Vista By Lara, operated under eunoia co. for Online Selling. The applicable quotation, order form or agreement identifies the contracting party and customer-specific details for a paid service.
Personal data and service data we process
The categories depend on how a person uses Quantara and which configured features are enabled.
- Contact and business details, including name, email, telephone number, company, country, role, discipline, enquiry and preferred contact method.
- Account, company and authentication records, including user and company identifiers, password hashes, email-verification state, roles, sessions and access status.
- Authorized project content, including uploaded files, extracted text and tables, BOQ items, quantities, units, rates, revisions, templates, generated documents and review records.
- Operational and security records generated by use of the service, such as timestamps, actions, error records and limited request signals where implemented.
- Subscription and billing references, including company contact details, internal company and price references, Stripe customer, checkout, subscription and event identifiers. Quantara's database does not store card numbers.
- Integration records and encrypted OAuth credentials for an integration a user chooses to connect, plus metadata and content for files the user selects to import.
- When a configured voice workflow is used, audio is sent for transcription and the transcript may be interpreted to prepare a change proposal for user review.
- Support and feedback content, including request type, title, description, intended outcome, email, company, route, surface, locale, timestamp and server-derived user or company identifiers where authenticated.
Public forms must not be used to submit passwords, authentication tokens, cookies, confidential drawings, BOQ content, uploaded files, commercial rates or restricted project data.
Why we process information
- Provide and maintain the public website and supported authenticated workflows.
- Register, verify, approve, authenticate and administer user and company accounts.
- Store, extract, organize, review, validate and generate authorized project and BOQ records.
- Present eligible recurring subscription checkout, reconcile subscription events and provide billing management where configured.
- Respond to sales, support, privacy, security and feature requests.
- Protect accounts, investigate misuse, preserve audit records and maintain service integrity.
- Diagnose defects and improve supported workflows using appropriate operational records.
- Meet applicable legal obligations and respond to lawful requests.
Processing grounds
Depending on the context, processing may be necessary to take requested steps or provide a contracted service, based on consent where specifically requested, needed for legitimate operational or security interests, or required by law. A customer must establish its own lawful authority for personal data it uploads.
The applicable basis depends on the relationship and jurisdiction. This policy does not replace a customer-specific assessment or contract.
Recipients and sharing categories
Information is shared only as needed for the selected workflow, service operations, professional advice or legal requirements.
- Infrastructure providers used for application delivery, PostgreSQL data storage, private object storage and operational communications.
- Stripe when an eligible organization uses configured recurring subscription checkout or billing management.
- Google Drive services when a user connects an account and selects supported files to import.
- OpenAI services when a configured voice transcription or interpretation workflow is used.
- The configured SMTP transport when Quantara sends account or service email.
- Professional advisers, authorities or counterparties when disclosure is reasonably necessary and legally permitted.
The providers that apply to a customer depend on the active hosting configuration and optional workflows that customer enables. Customer-specific provider and region details may be confirmed in the applicable written agreement.
Processing outside the UAE
Configured infrastructure, payment and optional integration providers may process data outside the UAE. Users should review the subprocessor page and any customer-specific data processing terms before enabling an optional provider.
Where customer data is processed across borders, the applicable provider, region and transfer terms are addressed through the provider terms and any customer-specific written agreement.
Retention and deletion
Data is retained only for as long as reasonably needed for the service, security, dispute handling and applicable legal obligations, then deleted or anonymized where appropriate. Project deletion behavior varies by record type: some project records are archived, while supported file and generated-document deletion paths remove database records and attempt to remove stored bytes.
Retention periods vary by data category, account status, security needs and legal obligations. Customer-specific retention or deletion requirements should be agreed in writing before sensitive project data is uploaded.
- Authentication sessions expire after 30 days and are removed on logout or when expiry is detected.
- Email-verification links expire after 24 hours.
- Password-reset links expire after one hour.
- Google Drive OAuth state expires after 10 minutes.
- Proposal passcode access grants expire after 30 minutes.
Your privacy choices and rights
Subject to applicable law and valid exceptions, a person may use the contact channel below to request action regarding personal data connected to Quantara.
- Request access to personal data and information about its processing.
- Request correction of inaccurate or incomplete personal data.
- Request deletion where the data is no longer required or another lawful reason applies.
- Request restriction or suspension of processing where applicable.
- Object to processing or withdraw consent where the relevant legal conditions apply.
- Raise a concern with Quantara and, where available, the competent data-protection authority.
View UAE Federal Decree-Law No. 45 of 2021 on the official UAE Legislation portal.
Security and incident handling
Quantara uses first-party authentication, hashed passwords and session tokens, company and project authorization checks, private production object-storage configuration, audit records, and encryption of stored OAuth credentials for implemented integration paths. No system can guarantee absolute security.
Suspected unauthorized access or a personal-data incident should be reported through the contact channel below. Quantara will investigate, contain and document the event and provide notices when the applicable facts and law require them; no unverified fixed notification deadline is promised here.
Business users and policy changes
Quantara is intended for business and professional use and is not directed to children.
Material updates will be published on this page with a revised date. Contract-specific changes may also be communicated through the agreed business channel.
Contact and privacy requests
Use the verified channels below for privacy rights, security reports, legal questions and support. Do not send passwords, authentication tokens or confidential project documents by email or WhatsApp.
- Email: solution@vistabylara.com
- Telephone: +971 50 799 4292
- WhatsApp: +971 50 799 4292