Ideqo
Privacy Policy

How Ideqo handles your data

This policy explains what personal data Ideqo collects, why we use it, who helps us process it, and how you can control your data. It applies to the Ideqo web application, onboarding flow, strategy workspace, admin tools, and related account services.

Last updated: 5 September 2026

01

Controller and contact

Ideqo is operated by the Ideqo team. For privacy requests or questions, email privacy@ideqo.cloud. If your contract or invoice names a specific Ideqo legal entity, that entity is the controller for your use of the service.

02

What we collect

  • Account data: email address, name if provided, password hash, sign-in metadata, and account settings.
  • Workspace content: strategy session titles, chat messages, onboarding answers, uploaded files, generated documents, notes, feedback, and export activity.
  • Guest scorecard data: project name, problem and customer answers, an optional website address, the generated scorecard, and an opaque guest token used to recover it after signup. Public page content retrieved from the website is processed to produce the score but is not stored in the guest snapshot.
  • Usage and operations data: feature interactions, quota and usage records, model/runtime information, errors, logs, and security events needed to run and improve the service.
  • Technical data: IP-derived security identifiers, browser and device information, requested pages, timestamps, and similar connection data.
  • Analytics data: page views and product events in Google Analytics 4 only when you accept analytics cookies.
  • Email data: email address and reset-token metadata when you request password reset or account-related messages.

03

Where the data comes from

  • Directly from you when you answer questions, create an account, upload materials, use the workspace, send feedback, or contact us.
  • Automatically from your browser and use of the service, including security, operational, consent, and—only if accepted—analytics data.
  • From a public website you ask Ideqo to review during the guest scorecard or another workflow.

04

Why we use it

  • To create and secure your account, authenticate you, and prevent misuse.
  • To provide the product strategy workspace, including AI-assisted analysis, document generation, file storage, exports, and admin management.
  • To maintain service reliability, debug errors, enforce quotas, and protect the application.
  • To respond to feedback, support requests, and password reset requests.
  • To understand product usage through Google Analytics only after you opt in.

05

Legal basis

  • Contract performance: account access, session storage, AI workflow execution, document generation, exports, and core product features.
  • Legitimate interests: security, abuse prevention, debugging, service improvement, and internal operational reporting.
  • Consent: Google Analytics and non-essential analytics cookies.
  • Legal obligation: records we must keep to comply with applicable law, accounting, or lawful requests.

06

AI processing and workspace content

Ideqo processes your prompts, onboarding answers, uploaded materials, and generated deliverables to provide AI-assisted strategy work. Do not upload content you are not allowed to use or share with the service. AI outputs may be inaccurate or incomplete, so you remain responsible for reviewing and validating them before using them for business decisions. Ideqo scores and guidance are advisory: Ideqo does not make funding decisions and its outputs do not guarantee funding or investor interest. The service does not make solely automated decisions that produce legal or similarly significant effects about you.

07

Service providers and recipients

We use processors and service providers only as needed to operate Ideqo:

  • Hosting, database, storage, and infrastructure providers used to operate the application.
  • Anthropic, which currently supplies the commercial Claude models used to process prompts, relevant uploaded context, and generated strategy materials. Anthropic states that commercial API inputs and outputs are not used for model training by default; Ideqo does not opt workspace content into provider training.
  • Email delivery providers used for password reset and service messages.
  • Google Analytics 4, but only when analytics consent is granted.

We do not sell your personal data. We do not use Google Analytics for advertising, retargeting, or ads personalization in this application. We may also disclose data when required by law, to protect the service and its users, or as part of a corporate transaction subject to appropriate safeguards.

08

International transfers

Some service providers may process data outside Slovakia or the European Economic Area. Where required, transfers rely on an applicable adequacy decision, approved contractual safeguards such as the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. Contact us if you want information about the safeguards relevant to your data.

09

Analytics consent

Analytics is off by default. If you choose "Accept all", Ideqo enables Google Analytics 4 to collect page views and product events such as onboarding progress, board usage, downloads, feedback actions, and pane interactions. If you choose "Essential only", analytics remains disabled. You can change this later through the Cookie Policy or Privacy settings in the account menu.

10

Retention and security

  • Account and workspace data is kept while your account is active and then only as needed for deletion processing, backups, disputes, security, or legal obligations.
  • Unclaimed guest snapshots are scheduled for deletion after 30 days. Once a snapshot is claimed, the separate problem and customer answer fields are cleared from that guest record after being applied to the workspace; the generated scorecard and claim audit fields remain subject to operational retention needs.
  • Password-reset links expire after 30 minutes; related records may be retained briefly for security and abuse prevention.
  • Operational, security, billing, and legal records are retained for the period reasonably necessary for their purpose and applicable obligations.
  • Google Analytics data follows the retention configured in Google Analytics. Browser-side data remains until its stated expiry, completion of the relevant flow, or deletion through your browser or product controls.

We use technical and organizational safeguards appropriate to the service, including hashed passwords and access controls. No internet service can promise absolute security.

11

Your rights

  • Access: ask for a copy of personal data we hold about you.
  • Correction: ask us to correct inaccurate account or profile information.
  • Deletion: ask us to delete your account and associated workspace data, subject to legal or security retention needs.
  • Portability: ask for your workspace content in a usable format where technically feasible.
  • Restriction or objection: ask us to limit certain processing where applicable.
  • Withdraw consent: turn analytics off at any time from Privacy settings.
  • Complaint: contact your local data protection authority if you believe your rights are not being respected.

To exercise a right, email privacy@ideqo.cloud. We may need to verify your identity before acting on a request. You may also lodge a complaint with the Office for Personal Data Protection of the Slovak Republic or the supervisory authority where you live or work.

12

Changes

We may update this policy when the product, providers, or legal requirements change. Material updates will be reflected on this page and, where appropriate, communicated in the product or by email.