1. Direct Collection
We collect information directly from you when you actively interact with our services, products, or team. This data is provided voluntarily and is essential for delivering our services.
Account Registration & Profiles
When you create an account for our client portal, newsletter, or product platforms, we collect your name, email address, organization details, and authentication credentials. Optional profile fields may include job title, industry, and communication preferences.
Forms, Surveys & Feedback
Information submitted through contact forms, intake questionnaires, project briefs, or feedback surveys is stored securely and used solely to respond to your inquiry, manage engagements, and improve our offerings.
Direct Communications
When you email us, submit a support ticket, or correspond with our team, we retain the content of those messages along with metadata (timestamps, sender info) to maintain continuity and resolve issues efficiently.
2. Automatic & Technical Collection
Certain data is collected passively through industry-standard technologies to ensure security, performance, and a seamless experience.
| Data Type | Collection Method | Purpose |
|---|---|---|
| Usage Analytics | Cookies, web beacons, session tracking | Understand traffic patterns, optimize UX, measure feature adoption |
| Device & Browser Info | HTTP headers, user-agent strings | Ensure compatibility, troubleshoot technical issues |
| Log Files | Server access logs, API request records | Security monitoring, fraud prevention, audit trails |
| Location Data | IP-based geolocation (approximate) | Compliance routing, localized content delivery |
We do not track individuals across third-party websites without explicit consent. All analytics are aggregated and anonymized where possible.
3. Third-Party & External Sources
In certain cases, we may receive data from trusted external sources to enhance our services or comply with regulatory requirements:
- Business Partners & Integrations: When you connect third-party tools (e.g., CRM, design platforms, cloud services), data may be synced based on your explicit authorization and the scope of permissions granted.
- Public & Government Records: For enterprise clients, we may verify business details through publicly available directories or compliance databases.
- Recruitment Platforms: If you apply to work with us, profile data may be sourced from LinkedIn, GitHub, or other professional networks you authorize.
We only process third-party data when we have a legitimate business reason, legal basis, or your explicit consent.
4. Legal Basis & Transparency
Under GDPR, CCPA, and applicable data protection frameworks, we process personal data only when one or more of the following applies:
- Contractual Necessity: To fulfill agreements, deliver purchased services, or manage client relationships.
- Legitimate Interests: To improve our platforms, prevent fraud, maintain security, and conduct business operations—provided your rights are not overridden.
- Consent: For marketing communications, non-essential cookies, or optional features. You may withdraw consent at any time.
- Legal Obligation: To comply with tax, financial, or regulatory requirements where mandated by law.
5. Your Rights & Contact
You maintain control over your personal information. Depending on your jurisdiction, you may have the right to:
- Access, rectify, or delete your data
- Restrict or object to processing
- Request data portability in a machine-readable format
- Withdraw consent for marketing or tracking
To exercise these rights, update preferences, or ask questions about our data practices, please contact our Data Protection Officer:
Email: privacy@thatisaq.com
Response Time: Within 30 days
Verification: We may request identity verification to protect your account and ensure data security.