🔒 Privacy & Data Transparency

How We Use Your Data

Last Updated: October 24, 2025 • Effective Date: November 1, 2025

1. Introduction

At That Is A Q, transparency isn't just a policy—it's a core principle. This document outlines exactly how we collect, process, store, and utilize data when you interact with our website, services, or communications. We believe in building trust through clarity.

Plain English Pledge: We avoid legal jargon where possible. If you have questions about any section, you can contact our Data Protection Officer directly via the link at the bottom of this page.

2. What We Collect

We only gather data that serves a clear, legitimate purpose. This includes:

  • Information You Provide: Contact details, project requirements, billing information, and communications via email, forms, or calls.
  • Usage Data: IP address, browser type, device information, pages visited, and time spent on our site (collected via analytics).
  • Cookies & Local Storage: Functional cookies for site performance, session cookies for security, and optional marketing cookies (opt-in only).

3. How We Use Your Data

Your data is never used for vague or secondary purposes without explicit consent. We process it to:

  • Deliver, manage, and improve our design and development services
  • Process transactions, send invoices, and maintain client records
  • Respond to inquiries, provide technical support, and schedule consultations
  • Analyze site traffic to optimize performance and user experience
  • Send service updates, policy changes, or security alerts (transactional only)

Marketing Communications: We will never send promotional emails without your explicit opt-in. You may unsubscribe at any time with one click.

4. Sharing & Third Parties

We do not sell, rent, or trade your personal data. We may share information only in the following circumstances:

  • Service Providers: Hosted on AWS and encrypted via Let's Encrypt. Third-party tools (e.g., Stripe for payments, Intercom for support) are contractually bound to strict data protection standards.
  • Legal Compliance: When required by law, court order, or to protect the rights, property, or safety of That Is A Q, our clients, or users.
  • Business Transfers: In the event of a merger or acquisition, data will be transferred with appropriate safeguards and notice.

5. Security & Retention

We implement industry-standard technical and organizational measures to protect your data, including TLS 1.3 encryption, role-based access controls, regular security audits, and employee training on data privacy.

Data Retention: We retain personal data only as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, or resolve disputes. Typically, client data is retained for 7 years for accounting purposes, after which it is securely anonymized or deleted.

6. Your Rights & Controls

Depending on your location, you may have the right to:

  • Access, correct, or delete your personal data
  • Restrict or object to processing
  • Request data portability in a machine-readable format
  • Withdraw consent for marketing communications at any time

To exercise these rights, simply contact us using the details below. We will respond within 30 days and verify your identity before processing requests.

7. Questions or Concerns?

Data privacy is a shared responsibility. If you need clarification, want to update your preferences, or report a concern, our team is here to help.

Data Protection Officer

Email: privacy@thatisaq.com

Postal: That Is A Q, 100 Innovation Way, Suite 404, San Francisco, CA 94107

Response Time: Within 48 hours for security incidents, 30 days for data requests.