EasyQBack to home

Legal

Privacy Policy

Last updated: 3 June 2026  ·  Effective: 3 June 2026

EasyQ ("we", "us", or "our") is committed to protecting your personal data. This policy explains what data we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable Dutch law.

1. Who We Are (Data Controller)

EasyQ is the data controller for personal data processed through our platform.

Company
EasyQ B.V.
Address
The Netherlands
Email
support@gigabyteconsultancy.com
Website
easy-q.nl

For GDPR enquiries or to exercise your rights, contact us at support@gigabyteconsultancy.com.

2. Data We Collect

2.1 Account & Organisation Data

  • Name, email address, and business name when you register
  • Organisation details (KvK number, VAT number) if provided
  • Subscription tier and payment history (via Stripe)

2.2 Customer Data You Process via EasyQ

When your clients contact you through EasyQ-connected channels (WhatsApp, email, etc.), we process:

  • Phone numbers and WhatsApp identifiers
  • Message content (text and voice note transcriptions)
  • Job-related information (address, scope, photos)
  • Quote and invoice data

You are the data controller for your customers' data. EasyQ acts as your data processor under a Data Processing Agreement (DPA).

2.3 Usage & Technical Data

  • Log data (IP address, browser type, pages visited)
  • API call metadata (timestamps, response codes)
  • Dashboard interaction data for product improvement

3. Legal Basis for Processing

PurposeLegal basis
Providing the EasyQ serviceContract (Art. 6(1)(b) GDPR)
Processing paymentsContract + Legal obligation
AI-powered intake & quotingContract + Legitimate interests
Product analytics & improvementLegitimate interests (Art. 6(1)(f))
Legal compliance & fraud preventionLegal obligation (Art. 6(1)(c))
Marketing communicationsConsent (Art. 6(1)(a)), opt-in only

4. Third-Party Processors

We use the following sub-processors to deliver EasyQ. Each is GDPR-compliant and bound by a Data Processing Agreement:

Supabase (PostgreSQL)

Database & authentication · EU (AWS Frankfurt)

OpenAI

AI text generation and voice transcription (Whisper) · USA (SCCs in place)

Meta (WhatsApp Cloud API)

WhatsApp messaging · USA/EU (SCCs in place)

Stripe

Payment processing · USA/EU (SCCs in place)

Google (Calendar API)

Calendar integration (when enabled) · USA/EU (SCCs in place)

We do not sell personal data to third parties for advertising or marketing purposes.

5. AI Processing & EU AI Act

EasyQ uses AI systems (OpenAI GPT-4o and Whisper) to:

  • Understand and respond to incoming messages
  • Transcribe Dutch voice notes
  • Draft quotes and follow-up messages

Human-in-the-loop: No legally binding quote, invoice, or calendar booking is sent without explicit contractor approval. AI outputs are always reviewed before they reach your customers.

EU AI Act transparency: When a customer interacts with EasyQ, they are informed via a greeting message that they are communicating with an AI assistant, not a human employee. This is compliant with EU AI Act Article 52 transparency requirements.

Data submitted to OpenAI is governed by their API data processing terms. OpenAI does not use API-submitted data to train models by default.

6. Data Retention

Data typeRetention period
Account dataDuration of subscription + 2 years
Customer conversation data24 months from last interaction
Invoice & financial records7 years (Dutch tax law requirement)
AI processing logs90 days
Technical/access logs30 days

7. Your Rights Under GDPR

As a data subject, you have the following rights:

Right of access

Request a copy of the data we hold about you.

Right to rectification

Correct inaccurate or incomplete personal data.

Right to erasure

Request deletion of your data where legally permissible.

Right to portability

Receive your data in a machine-readable format.

Right to restrict processing

Limit how we use your data in certain circumstances.

Right to object

Object to processing based on legitimate interests.

To exercise any of these rights, email support@gigabyteconsultancy.com. We will respond within 30 days. If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority) at autoriteitpersoonsgegevens.nl.

8. Cookies

EasyQ uses a minimal set of cookies:

Session cookie

Strictly necessary

Maintains your authenticated session. Cannot be disabled.

Preference cookie

Functional

Remembers UI preferences (e.g., language, tab state).

Analytics cookie

Analytics (consent required)

Anonymous usage analytics to improve the product.

9. Security

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Row-level security (RLS) in our database so tenants cannot access each other's data
  • Access controls and audit logging
  • Regular security reviews

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Autoriteit Persoonsgegevens within 72 hours.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Continued use of EasyQ after changes constitutes acceptance of the updated policy.

11. Contact

For any privacy-related questions or to exercise your GDPR rights:

Email
support@gigabyteconsultancy.com
Subject line
GDPR Request, [your name]
Response time
Within 30 calendar days