Privacy Policy
Last updated: May 2026
QSol Analytics ("we", "us", "our") is committed to protecting your privacy and ensuring your personal data is handled in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR) where applicable.
This policy explains how we collect, use, store, and protect your personal data when you use our website and services, including the Data Project Finder diagnostic tool.
1. Data Controller
The data controller responsible for your personal data is:
David J. McCannQSol Analytics
United Kingdom
Email: david@qsol-analytics.com
2. Information We Collect
2.1 Data Project Finder Tool
When you use our Data Project Finder diagnostic tool, we collect:
- Problem description: The text you enter describing your business problem (required)
- Contact information: Name, email address, company name (if you choose to unlock the full roadmap)
- Consent records: Your consent to be contacted and acceptance of this privacy policy
- Generated analysis: Classification results, scores, and roadmap generated by our AI system
- Technical data: IP address (for rate limiting only, not permanently stored with your submission)
2.2 Contact Forms and Enquiries
- Name, email address, company name
- Content of your message or enquiry
- Scheduling preferences for bookings
2.3 Automatically Collected Information
We use Plausible Analytics, a privacy-focused analytics service that does not use cookies and does not collect personal data. We collect only aggregated, anonymous data:
- Page views and referral sources
- Country of origin (derived from IP, not stored)
- Device type and browser (aggregated)
3. How We Use Your Information
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide AI-powered problem analysis | Problem description | Contract performance |
| Send your project roadmap by email | Email, name, analysis results | Contract performance |
| Follow up about your enquiry | Contact details, analysis results | Consent (explicit) |
| Notify our team of new leads | Contact details, classification | Legitimate interest |
| Improve our services and tool | Aggregated, anonymised data | Legitimate interest |
| Prevent abuse and rate limiting | IP address (temporary) | Legitimate interest |
| Comply with legal obligations | As required | Legal obligation |
4. Automated Decision-Making and AI Processing
Important: Our Data Project Finder uses artificial intelligence (specifically, large language models provided by OpenAI) to analyse your problem description and generate classifications and recommendations.
4.1 How Automated Processing Works
- Your problem description is sent to OpenAI's API for analysis
- The AI classifies your problem into one of eight project categories
- The AI generates scores for feasibility, value potential, and urgency
- The AI produces a customised implementation roadmap
4.2 Your Rights Regarding Automated Decisions
Under UK GDPR Article 22 and EU GDPR Article 22, you have the right to:
- Human review: Request that a human reviews any automated decision
- Express your view: Provide input on the automated analysis
- Contest decisions: Challenge the classification or recommendations
- Explanation: Receive meaningful information about the logic involved
The automated analysis does not have legal or similarly significant effects on you. It is advisory only and intended to help you explore potential data projects. To request human review or contest any analysis, contact us at david@qsol-analytics.com.
4.3 AI Limitations
AI-generated analysis may contain errors or inaccuracies. Classifications and recommendations should be treated as starting points for discussion, not definitive assessments. We do not guarantee the accuracy of AI-generated content.
5. Data Sharing and Third-Party Services
We do not sell your personal data. We share data with the following service providers:
| Service | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase | Database hosting | EU (Frankfurt) | EU GDPR compliant |
| OpenAI | AI analysis | United States | Standard Contractual Clauses, Data Processing Agreement |
| Resend | Email delivery | United States | Standard Contractual Clauses |
| Vercel | Website hosting | Global (edge) | Standard Contractual Clauses |
| Plausible | Analytics | EU | No personal data collected |
| Telegram | Internal notifications | Various | Contains business data only, not shared externally |
6. International Data Transfers
Some of our service providers are located outside the UK and European Economic Area (EEA), particularly in the United States.
6.1 Safeguards for International Transfers
When we transfer data internationally, we ensure appropriate safeguards are in place:
- UK Adequacy Decisions: Transfers to countries deemed adequate by the UK government
- EU Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
- Standard Contractual Clauses (SCCs): EU and UK-approved contractual safeguards with US providers
- Data Processing Agreements: Binding contractual obligations on data processors
6.2 OpenAI Data Processing
Your problem description is processed by OpenAI's API. OpenAI operates under a Data Processing Agreement with Standard Contractual Clauses. OpenAI does not use API data to train their models. For details, see OpenAI's Privacy Policy.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Project Finder submissions | 2 years from submission | Service delivery and follow-up |
| Lead contact information | 2 years from last contact | Relationship management |
| Contact form enquiries | 2 years from last contact | Enquiry handling |
| Analytics data | 26 months | Website improvement (aggregated only) |
| Consent records | Duration of consent + 3 years | Legal compliance |
| Client project data | As per project agreement | Contractual obligations |
After the retention period, data is securely deleted or anonymised.
8. Your Rights
Under UK GDPR and EU GDPR, you have the following rights:
8.1 Right of Access
You can request a copy of all personal data we hold about you (Subject Access Request).
8.2 Right to Rectification
You can request correction of inaccurate or incomplete data.
8.3 Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data in certain circumstances.
8.4 Right to Restrict Processing
You can request that we limit how we use your data while issues are resolved.
8.5 Right to Data Portability
You can request your data in a machine-readable format for transfer to another provider.
8.6 Right to Object
You can object to processing based on legitimate interests, including direct marketing.
8.7 Rights Related to Automated Decision-Making
You can request human review of automated decisions (see Section 4).
8.8 Right to Withdraw Consent
Where processing is based on consent, you can withdraw at any time without affecting prior processing.
To exercise any of these rights, contact us at david@qsol-analytics.com. We will respond within one month.
9. Cookies
Our website uses Plausible Analytics, which does not use cookies. We do not use any tracking cookies, advertising cookies, or third-party cookies.
Essential technical storage (such as form state) uses browser sessionStorage, which is automatically cleared when you close your browser and is not shared with any third parties.
10. Security
We implement appropriate technical and organisational measures to protect your data:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest (database encryption)
- Access controls and authentication
- Regular security reviews
- Rate limiting to prevent abuse
- Row Level Security on database tables
11. Children's Privacy
Our services are intended for business professionals and are not directed at children under 18. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.
12. Complaints
If you have concerns about how we handle your data, please contact us first at david@qsol-analytics.com. We take all complaints seriously and will work to resolve them promptly.
You also have the right to lodge a complaint with a supervisory authority:
UK Residents
Information Commissioner's Office (ICO)
ico.org.uk
Helpline: 0303 123 1113
EU Residents
You may lodge a complaint with your local Data Protection Authority. A list is available at edpb.europa.eu.
13. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be notified via our website. The latest version will always be available at this URL.
14. Contact Us
For any questions about this privacy policy or our data practices, contact:
David J. McCannQSol Analytics
Email: david@qsol-analytics.com
This privacy policy is compliant with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR). It reflects requirements as of May 2026.