1. Overview & Scope

At That Is A Q, we process personal data only when we have a valid legal ground to do so. This document outlines the specific legal bases under which we collect, use, store, and share personal information in accordance with applicable data protection regulations, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other relevant jurisdictional laws.

We do not process personal data without a lawful justification. Every processing activity is documented, purpose-limited, and subject to periodic compliance reviews.

2. Applicable Legal Framework

Our data processing activities are governed by a combination of regional and international privacy laws. Where multiple regimes apply, we adhere to the most protective standard. Our primary legal references include:

  • GDPR (EU/UK): Articles 6(1) and 9(2) define the lawful bases for processing.
  • CCPA/CPRA (California): Requires transparency and opt-out mechanisms for sale/sharing of personal information.
  • LGPD (Brazil) & PIPEDA (Canada): Applied where data subjects reside in these jurisdictions.
  • Contractual & Common Law: Governs business-to-business data exchanges and service delivery.

If you are located outside these regions, we will notify you of any additional legal bases applicable to your jurisdiction before processing your data.

4. How These Bases Apply to Your Data

To ensure transparency, we map each processing activity to its corresponding legal basis:

  • Account Registration & Authentication: Contract (performance) & Legitimate Interests (security)
  • Client Onboarding & Project Delivery: Contract (performance) & Legal Obligation (tax/invoicing)
  • Marketing Communications: Consent (opt-in) or Legitimate Interests (existing client relationships, subject to opt-out)
  • Website Analytics & UX Optimization: Legitimate Interests & Consent (for cookies/tracking where required)
  • Customer Support & Ticketing: Contract & Legitimate Interests
  • Employment & Contractor Vetting: Legal Obligation & Legitimate Interests

We will always specify the relevant legal basis at the point of collection via privacy notices, consent banners, or contractual terms.

5. Data Retention & Periodic Review

We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, or to comply with legal, accounting, or reporting requirements. Retention periods vary by data type and processing context:

  • Client/Contract Data: Retained for the duration of the engagement + 7 years (tax/legal compliance)
  • Marketing Contacts: Retained until consent is withdrawn or 24 months of inactivity
  • Analytics & Log Data: Aggregated/anonymized after 12 months
  • Support & Communication Records: Retained for 3 years post-resolution

Expired data is securely deleted or anonymized. You may request earlier deletion where legally permissible.

6. Your Rights Under Data Protection Law

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete information.
  • Right to Erasure: Request deletion where processing is no longer necessary or consent is withdrawn.
  • Right to Restrict Processing: Limit how we use your data while disputes are resolved.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Opt out of processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Effective immediately, without affecting prior lawful processing.

To exercise any of these rights, contact our Data Protection team. We will respond within 30 days, or as required by applicable law.

7. Contact & Supervisory Authorities

If you have questions about how we determine legal bases, wish to exercise your rights, or believe your data has been processed unlawfully, please contact us:

You also have the right to lodge a complaint with a supervisory authority in your jurisdiction. For EU/UK residents, you may contact your national Data Protection Authority. For California residents, complaints may be submitted to the California Privacy Protection Agency (CPPA).

This document forms part of our broader Privacy Policy and Terms of Service. We reserve the right to update this notice as laws or processing activities evolve. Changes will be published on this page with a revised date.