thinQit·End-User Pack · Doc 03 · thinQit-branded

thinQit Privacy Statement

This Privacy Statement explains which personal data thinQit processes, why we process it, how long we keep it, and which rights you have.

V1.0April 22, 2026EnglishGDPR articles 13 and 14

1Controller and processor roles

In short

For your account and billing data, thinQit is responsible. For business data your employer puts in the platform, your employer is responsible and thinQit only processes it.

thinQit B.V., Vanadiumweg 25, 3812 PX Amersfoort, is controller for its own account, billing, support, security, and marketing processing.

For business content placed in the platform by a customer, the customer is usually controller and thinQit acts as processor under a data processing agreement.

2Data we process

In short

We process things like your name, e-mail, prompts, and logs. Card numbers go to Stripe; we never store them.

We may process account details, authentication data, usage data, prompts, outputs, technical logs, security logs, billing details, and support communications.

Payment-card details are processed by Stripe. thinQit does not store full card numbers.

3Purposes and legal bases

In short

We use your data to run the service, keep it safe, send bills, and help you. The privacy law (GDPR) allows this.

We process personal data to provide and secure the Service, manage accounts, bill customers, provide support, improve reliability, and meet legal obligations.

Legal bases include performance of contract, legitimate interests, legal obligations, and consent where required.

4AI processing

In short

AI providers such as OpenAI and Anthropic help create answers. Your data is not used to train general AI models.

The Service uses AI providers such as Azure AI Foundry, OpenAI, and Anthropic to generate responses.

thinQit does not train general AI models on customer or user data, and provider contracts restrict training use where applicable.

5Recipients and subprocessors

In short

We share data only with companies we need to run the service, like Microsoft, OpenAI, Anthropic, and Stripe.

We share data only with providers needed for hosting, AI inference, payment processing, support, e-mail, observability, and legal compliance.

Current core providers include Microsoft Azure, OpenAI, Anthropic, and Stripe.

6Retention

In short

We keep data only as long as needed. For example: prompts for 90 days and invoices for 7 years.

Default retention examples: prompts and outputs 90 days, security logs 180 days, billing records 7 years, and support correspondence 24 months after ticket closure.

Customer data is returned or deleted after termination according to the data processing terms.

7Your rights

In short

You can ask to see, fix, or delete your data. E-mail privacy@thinqit.io. You can also complain to the Dutch privacy authority.

You may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent where applicable.

Send privacy requests to privacy@thinqit.io. You may also complain to the Autoriteit Persoonsgegevens.