GDPR Privacy Policy
At That Is A Q, we respect your privacy and are committed to protecting your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws. This policy explains how we collect, use, store, and safeguard your information when you interact with our services, website, or business operations.
1. Data Controller
The data controller responsible for your personal information is:
[Registered Company Address]
[City, Postal Code, Country]
Email: dpo@thatisaq.com
Phone: [Phone Number]
We may appoint a Data Protection Officer (DPO) to oversee compliance. You may contact the DPO at the email above.
2. Information We Collect
We collect only the data necessary to deliver our services, maintain compliance, and improve your experience. This includes:
- Identity Data: Name, title, username, or similar identifiers.
- Contact Data: Email address, phone number, mailing address.
- Technical Data: IP address, browser type, device information, access logs, and usage analytics.
- Transaction Data: Payment details, invoice history, and service agreements (processed securely via PCI-compliant third parties).
- Communication Data: Records of correspondence, support tickets, and feedback.
3. How We Collect Data
We collect data through:
- Direct interactions (forms, emails, phone calls, meetings)
- Automated technologies (cookies, server logs, analytics platforms)
- Third parties (payment processors, business partners, publicly available sources where lawful)
4. Legal Basis for Processing
We process your personal data under one or more of the following GDPR lawful bases:
- Contractual Necessity: To fulfill service agreements and provide requested products.
- Legitimate Interests: To improve our services, prevent fraud, and maintain secure systems (balanced against your rights).
- Consent: Where explicitly provided (e.g., newsletters, marketing communications).
- Legal Obligation: To comply with tax, accounting, and regulatory requirements.
5. How We Use Your Data
Your information may be used to:
- Provide, maintain, and improve our services
- Process transactions and issue invoices
- Communicate about updates, support, or service changes
- Analyze usage trends and optimize performance
- Comply with legal, tax, and security obligations
- Send targeted marketing (only with explicit opt-in consent)
6. Sharing & Disclosure
We do not sell your personal data. We may share information only with:
- Service Providers: Hosted infrastructure, payment gateways, analytics, and CRM tools operating under strict Data Processing Agreements (DPAs).
- Legal Authorities: When required by law, regulation, or valid legal process.
- Business Transfers: In the event of merger, acquisition, or asset sale, with notice and continued compliance obligations.
All third-party processors are vetted for GDPR compliance and data security standards.
7. Data Retention
We retain personal data only as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. General retention periods include:
- Client records: Duration of engagement + 7 years (tax/legal compliance)
- Marketing contacts: Until unsubscribe or 24 months of inactivity
- Analytics/Log data: 12 months (anonymized thereafter)
You may request earlier deletion at any time, subject to legal retention obligations.
8. Your GDPR Rights
Under the GDPR, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request deletion where legally permissible.
- Restriction: Limit processing in certain circumstances.
- Data Portability: Receive your data in a structured, machine-readable format.
- Objection: Opt out of direct marketing or legitimate interest processing.
- Withdraw Consent: At any time, without affecting prior lawful processing.
To exercise any right, contact our DPO. We will respond within 30 days, extendable by 60 days for complex requests. No fee applies unless requests are manifestly unfounded or excessive.
9. International Transfers
Your data may be processed in countries outside the European Economic Area (EEA). Where this occurs, we ensure adequate protection via:
- European Commission Adequacy Decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules or approved transfer mechanisms
We implement technical and organizational safeguards to maintain data integrity during transfers.
10. Cookies & Tracking
Our website uses cookies and similar technologies for:
- Essential: Security, session management, and core functionality
- Analytics: Understanding traffic and improving performance (aggregated & anonymized)
- Marketing: Personalization and ad relevance (only with consent)
You may manage preferences via browser settings or our on-site cookie banner. Disabling essential cookies may impact functionality.
11. Security Measures
We implement industry-standard technical and organizational safeguards, including:
- End-to-end encryption (TLS 1.3+ for transit, AES-256 for rest)
- Role-based access controls and multi-factor authentication
- Regular security audits, penetration testing, and vulnerability management
- Employee training and strict confidentiality obligations
- Incident response protocols aligned with GDPR 72-hour breach notification requirements
12. Contact & DPO
For privacy inquiries, data subject requests, or concerns about this policy, contact:
Email: dpo@thatisaq.com
Address: [Full Registered Address]
Phone: [Contact Number]
You also have the right to lodge a complaint with your local supervisory authority (e.g., [Insert Relevant EEA Data Protection Authority]).
13. Policy Updates
We may update this policy to reflect changes in services, legal requirements, or best practices. Material changes will be communicated via email or prominent website notice. The "Last Updated" date at the top of this page indicates when revisions were made.
By continuing to use our services after changes take effect, you acknowledge and agree to the updated terms.