1. Introduction and Scope
This Privacy Policy explains how QuickAIHQ (referred to as "we", "us", or "our Agency") collects, uses, stores, and protects Personal Data.
This policy covers quickaihq.com. Our other properties have their own policies: the UK SaaS Compliance Index (directory.quickaihq.com) and our Reactivation Revival service (saas.quickaihq.com) each link to theirs in the site footer.
Our processing activities are governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
We are registered with the ICO, registration reference ZC188656.
QuickAIHQ is a trading name of Holistic IIUniverse Ltd (Company No 11302315), a company registered in England and Wales.
2. Definitions of Legal Roles
In the context of the services we provide, the following roles are defined under UK GDPR:
| Role | Definition | Our Relationship |
|---|---|---|
| Data Controller (Our Client) | The business that determines the purposes and means of processing Personal Data. | Our client is the Controller of the business information they provide in the intake form. |
| Data Processor (QuickAIHQ) | The entity that processes Personal Data on behalf of the Controller. | We act as the Data Processor when analysing intake form data to produce the compliance gap report and PECR & UK GDPR compliance review, processing data strictly according to the client's instructions. |
| Data Controller (QuickAIHQ — for Agency Data) | For data about our direct clients (name, email, payment records) and website visitors, QuickAIHQ acts as the Data Controller. | QuickAIHQ acts as the Data Controller. |
3. Personal Data We Collect
We collect and process the following categories of Personal Data:
3.1 Audit Client Data (Data about QuickAIHQ clients)
- Identity and Contact Data: Name, business name, email address.
- Payment Data: Payment confirmation via Stripe (we do not store card details).
- Technical Data: IP address, browser type, and website usage data collected via Google Analytics.
- Intake Form Data: Business operational information, current tool stack, and workflow details provided voluntarily by the client to enable delivery of the Compliance Audit service.
4. How We Use Personal Data
We use Personal Data only as necessary to provide, maintain, and improve our services. We do not sell any Personal Data.
4.1 Delivering the Compliance Audit Service
- Intake form processing: Analysing the information you provide to produce your compliance gap report and PECR & UK GDPR compliance review.
- Service communication: Sending your completed report and compliance pack, and responding to follow-up questions by email.
- Payment administration: Confirming payment and issuing invoices on request.
- Ongoing monitoring: For clients on a Watch or Watch + Records subscription, re-assessing your site each month and, for Watch + Records, helping maintain your consent records and processor register based on information you provide.
4.2 Website and Analytics
We use Google Analytics to understand how visitors use quickaihq.com. Google Analytics uses cookies to collect anonymised data including pages visited, time on site, and browser type. This data is used to improve the website and is not linked to individual identities. See Section 8 for cookie details.
5. Third-Party Service Providers
We engage the following trusted third-party processors to deliver our services. Each operates under a Data Processing Agreement and stores data within the UK or European Economic Area unless otherwise stated:
| Provider | Purpose | Data Location |
|---|---|---|
| Tally | Intake form collection and submission | EU hosted — GDPR compliant |
| Formspree | Form submission processing | Formspree Inc., USA — transfers protected by the UK International Data Transfer Addendum / Standard Contractual Clauses |
| Anthropic (Claude — paid plan) | AI-assisted analysis of intake form data to produce audit reports | EU/UK processing available via AWS Bedrock — DPA in place |
| Google Workspace (Docs and Sheets) | Report drafting and document storage | EU/UK data residency available — DPA in place |
| Fastmail | Client email communications | Austria (EU) hosted — GDPR compliant |
| Stripe | Payment processing | EU data residency — DPA in place |
| Google Analytics | Website analytics | US hosted — Standard Contractual Clauses in place. Anonymised data only. |
| Vercel | Website hosting for quickaihq.com | EU region available — processes standard web server logs |
| GitHub | Website code hosting | US hosted — processes no personal client data directly |
| Canva | Image and design creation | Does not process client personal data |
Important note: QuickAIHQ uses only paid, DPA-covered AI tools when processing client personal data. Free versions of AI tools, which do not provide Data Processing Agreements, are not used for any client data.
6. Legal Basis for Processing
We process Personal Data under the following legal bases:
- Contractual Necessity: To deliver the Compliance Audit service you have purchased. This is our primary basis for processing intake form data and payment records. Where services are requested via the intake form, consent is also collected explicitly via a checkbox at the point of submission.
- Consent: For the use of non-essential cookies. You may withdraw consent at any time without affecting prior processing.
- Legitimate Interests: For website analytics using anonymised Google Analytics data, where our interest in improving the website is balanced against minimal impact on visitor privacy. Where we rely on legitimate interests, we have carried out and documented a balancing assessment, available on request.
- Legal Obligation: To comply with applicable laws and regulations, including financial record-keeping obligations.
7. Data Retention and Security
Retention: Audit client data (intake form responses and report documents) is retained for 24 months after delivery of the service, then permanently deleted. For clients on an ongoing Monitoring Service (Watch or Watch + Records), audit and monitoring data is retained for the duration of the subscription and for 24 months after it ends, then permanently deleted. Payment records are retained for 7 years to comply with UK financial record-keeping obligations. Website analytics data is retained for 26 months in Google Analytics, in anonymised and aggregated form.
Security: We implement appropriate technical and organisational measures to protect Personal Data, including encrypted storage, access controls, and use of only GDPR-compliant, DPA-covered tools for processing client data.
8. Cookies and Tracking
quickaihq.com uses only two categories of cookies:
- Essential cookies (always on): Required for the website to function and to remember your cookie choice.
- Your cookie choice is stored in your browser's local storage under the key
cookie_consent_v2so we can remember your preference. This is strictly necessary and contains no tracking data.
- Your cookie choice is stored in your browser's local storage under the key
- Analytics cookies (only after consent): Set by Google Analytics 4 to measure website usage in aggregate. IP anonymisation is enabled and we do not use the data to identify individuals. These are only loaded if you click "Accept all" or enable analytics in Preferences.
_ga— distinguishes unique visitors (Google Analytics)._ga_Y4BN75WXZR— persists session state for Google Analytics 4.
We do not use advertising cookies and we do not share cookie data with third parties for marketing purposes.
You can change your choice at any time via the Cookie Preferences link in the footer.
9. Your Data Protection Rights
Under UK GDPR, you have the following rights:
- Right to Access: Request copies of your Personal Data.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your data in certain circumstances.
- Right to Restrict Processing: Request limitation of processing.
- Right to Data Portability: Request transfer of your data.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, email contact@quickaihq.com. We will respond within one calendar month.
10. International Data Transfers
Some of our third-party providers store data outside the UK or EEA (notably Stripe and Google Analytics). Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified.
11. Contact Us
For any questions about this Privacy Policy or to exercise your data protection rights, please contact:
Email: contact@quickaihq.com
Address: QuickAIHQ, 4 Craven Hill Gardens, W2 3ES, London, United Kingdom
Data Controller: Holistic IIUniverse Ltd (Company No 11302315), trading as QuickAIHQ.
12. Automated decision-making
We do not use your personal data to make automated decisions that have legal or similarly significant effects on you.
13. Marketing communications
We only send marketing emails to people who have opted in. Every message includes a working unsubscribe link, and unsubscribe requests are honoured immediately and permanently via a suppression list. We do not buy, sell or share marketing lists.
14. How to make a complaint
If you are unhappy with how we have handled your personal data, email contact@quickaihq.com with "Privacy complaint" in the subject line. We will acknowledge your complaint within 30 days and respond substantively without undue delay. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, but we would welcome the chance to resolve your concern first.
15. Changes to This Policy
We will update this policy when our data practices change. The effective date at the top of this page reflects the most recent update. Where changes are material, we will notify active clients by email.
