Sharing & Disclosure
At That Is A Q, transparency is foundational. This section outlines how, when, and why we may share or disclose information collected through our services, platforms, and business operations. We are committed to protecting your data while maintaining compliance with global privacy standards.
6.1 Overview
We do not sell, rent, or trade personal information to third parties for marketing purposes. Any sharing or disclosure is conducted strictly under the following principles:
- Consent-driven: We only share what you explicitly permit, except where legally required.
- Minimal & Purposeful: Data shared is limited to what is necessary for the stated business function.
- Secure & Audited: All disclosures go through encryption, access controls, and regular compliance reviews.
6.3 How We Disclose Data
All disclosures follow secure, documented protocols:
| Disclosure Type | Method | Retention Period |
|---|---|---|
| Operational Vendors | Encrypted API / Secure File Transfer | Duration of contract + 12 months |
| Legal/Government | Formal Data Subject Access Request (DSAR) response | As required by applicable law |
| Aggregated Analytics | De-identified & anonymized datasets | Indefinite (non-personal) |
6.4 Third-Party Partners & Processors
We engage trusted service providers to support our infrastructure and operations. These partners are bound by strict Data Processing Agreements (DPAs) that mirror or exceed our privacy commitments. Current categories include:
- Cloud hosting & infrastructure (e.g., AWS, GCP)
- Payment processing & financial compliance
- Customer support & communication platforms
- Analytics & product improvement tools
A full list of active processors and their security certifications is available upon request.
6.5 Legal & Regulatory Disclosures
That Is A Q complies with applicable data protection frameworks, including but not limited to GDPR, CCPA/CPRA, and emerging AI/data governance standards. When legally compelled to disclose information:
- We will review the scope and validity of the request
- We will seek to limit disclosure to the minimum necessary
- We will notify affected individuals unless legally restricted
- We will document all compliance actions for audit purposes
6.6 Cross-Border Data Transfers
As a global digital agency, our infrastructure may process or store data across jurisdictions. All cross-border transfers are protected by:
- Standard Contractual Clauses (SCCs)
- Advanced encryption in transit and at rest
- Regular jurisdictional risk assessments
- User consent mechanisms where required
6.7 Your Rights & Controls
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Object to or restrict certain processing/sharing
- Request data portability in a machine-readable format
- Withdraw consent at any time (where applicable)
To exercise these rights, use our Privacy Request Portal or contact our Data Protection Officer directly.
6.8 Updates to This Policy
We periodically review and update our sharing & disclosure practices to reflect changes in technology, business operations, or legal requirements. Material changes will be communicated via email, platform notice, or prominent website banner. Your continued use of our services constitutes acknowledgment of updated terms.
Questions About Sharing & Disclosure?
Our privacy and compliance team is available to answer questions, process requests, or provide additional documentation.
Email privacy@thatisaq.com →