What we process and why
Account data (name, work email, company, job title, hashed password) — to provide and secure the service (basis: performance of a contract).
Your AI-system register & compliance data — processed on your instructions to deliver the monitoring you configure. For this data your organisation is the controller and we are the processor, governed by a Data Processing Agreement entered into at onboarding.
System snapshots (work email, optionally company, name and job title, system name, purpose, audience, data category, lifecycle, organisation context, system role, workload inputs, a private access token and the generated result) — to generate, save and return the result after your explicit submission (basis: consent). The token is an unguessable bearer link; anyone with the complete link can open that result. Optional system-specific follow-up is sent only when separately selected and can be disabled from the email preference link. If you choose to continue into a Trusq account using the same email address, the system name, purpose and role are transferred once into that account and then processed as part of your AI-system register.
Commercial enquiries (the business contact and scope information you choose to provide) — to assess and respond to commercial interest (basis: consent / legitimate interest).
Server & audit logs (IP address, requested page, time, browser type) — for security and aggregated, non-identifying statistics (basis: legitimate interest). We use a self-hosted, cookieless Umami analytics instance on EU infrastructure to measure page and funnel events. Trusq also increments fixed daily aggregate counters for pricing interactions, Article 50 check results/follows and snapshot gates/completions. These counters contain no visitor identifier, cookie, IP address, browser details, referrer or free-form content; no raw event record is retained. Requests with explicit automation signatures are excluded from those funnels and counted only as fixed daily event/reason totals, under the same no-identifier boundary.
AI processing
Content you register may be processed by our EU AI provider to draft documents and answer questions, always grounded in cited sources and reviewed by a human before it counts. Your content is not used to train its models.
Retention
Account data: for the duration of your subscription plus 90 days. System snapshots and commercial enquiries: up to 24 months, or until you ask us to remove them. Server and audit logs: 90 days. (Where billing applies in future, invoice data is kept for 7 years under statutory tax retention.)
Your rights
You have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent at any time — email
privacy@trusq.io. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).