1. Who We Are (Data Controller)
ProductQuant
28 Fraser Street, West Launceston
Tasmania 7250, Australia
Contact: [email protected]
Website: https://productquant.dev
ProductQuant is the data controller for personal data collected through this website. If you have any questions about this policy or wish to exercise your rights, please contact us at [email protected].
We recommend creating this dedicated email alias ([email protected]) to handle privacy requests.
2. What Personal Data We Collect, How, and Why
We collect personal data only when you interact with our site or services. The table below describes each data category, its source, purpose, legal basis, and retention period.
| Data Category | Source | Purpose | Legal Basis (GDPR) | Retention |
|---|---|---|---|---|
| Name, email, company name, phone | Contact forms, scheduling tools, newsletter signup | Respond to inquiries, provide services, send marketing communications (with consent) | Consent (Art. 6(1)(a)); Contractual necessity (Art. 6(1)(b)) | Duration of business relationship + 2 years |
| Payment data (card details, billing info) | LemonSqueezy payment processor | Process purchases, billing, tax compliance | Contractual necessity (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) | Per LemonSqueezy's retention policy (Merchant of Record) |
| Usage data (pages visited, clicks, events, feature usage) | PostHog, Yandex Metrica | Product analytics, user experience improvement, heatmaps | Consent (Art. 6(1)(a)) | 13 months (PostHog default); 12 months (Yandex Metrica) |
| IP address | PostHog, Yandex Metrica, Cloudflare | Geo-location, security, fraud prevention, analytics | Consent (analytics purposes); Legitimate interest (security, Art. 6(1)(f)) | Session or 30 days (anonymized thereafter) |
| Session recordings (mouse movements, clicks, scrolls) | PostHog Session Replay, Yandex Webvisor | UX analysis, product improvement | Consent only (Art. 6(1)(a)) | 30 days |
| Email engagement (opens, clicks) | MailerLite | Email marketing performance measurement | Consent (Art. 6(1)(a)) | Until unsubscription |
| Scheduling data (name, email, timezone, meeting notes) | Calendly, Cal.com | Meeting scheduling and follow-up | Contractual necessity (Art. 6(1)(b)) | Per Calendly/Cal.com retention (typically 12 months post-meeting) |
| Form responses (varies by form purpose) | Tally, Formspree, Typeform | Collect inquiries, feedback, applications | Consent (Art. 6(1)(a)) | 2 years post-submission |
| Chat/communication data | Intercom, Crisp | Customer support, product inquiries | Legitimate interest (Art. 6(1)(f)) | 12 months post-conversation |
| CRM data | HubSpot | Lead management, sales pipeline, marketing | Consent (Art. 6(1)(a)); Legitimate interest (Art. 6(1)(f)) | Duration of business relationship + 2 years |
| Audience measurement data (browser, device, timestamp) | usbrowserspeed.com | Anonymous audience measurement and advertising measurement | Consent (Art. 6(1)(a)) | 30 days |
3. Legal Bases for Processing (GDPR / UK GDPR)
We process personal data on the following legal bases:
- Consent (Art. 6(1)(a)): For analytics, session recording, marketing cookies, audience measurement pixel, and email marketing. You may withdraw consent at any time by adjusting your cookie preferences or contacting us.
- Contractual necessity (Art. 6(1)(b)): For delivering services you have purchased, processing payments, and scheduling meetings.
- Legitimate interest (Art. 6(1)(f)): For website security (Cloudflare WAF, DDoS protection), fraud prevention, and direct email communication with existing clients (soft opt-in under PECR).
- Legal obligation (Art. 6(1)(c)): For tax records, invoicing, and compliance with applicable laws.
4. Data Processors (Third-Party Service Providers)
We use the following service providers to process personal data. Each has been contractually bound to process data only on our instructions and in compliance with applicable data protection law.
| Processor | Purpose | Location(s) | Transfer Mechanism | Sub-processors |
|---|---|---|---|---|
| PostHog Inc. (2261 Market St #4008, San Francisco, CA 94114, USA) | Product analytics, session replay, feature flags | USA (Cloud US) | EU-US Data Privacy Framework (DPF) + Standard Contractual Clauses (2021) + Data Processing Agreement | AWS, Google Cloud, Cloudflare (per PostHog sub-processor list) |
| Yandex Metrica | Traffic analytics, heatmaps, webvisor session replay | Netherlands (EU-hosted data processing) | Standard Contractual Clauses (2021 Module 2) | Yandex group entities |
| LemonSqueezy (Stripe company) | Payment processing, Merchant of Record | USA | EU-US DPF + SCCs | Stripe, tax compliance partners |
| MailerLite | Email delivery, newsletter management | USA / EU (depending on account) | Data Processing Agreement + SCCs | AWS |
| Calendly | Meeting scheduling | USA | EU-US DPF + SCCs | AWS, Google Cloud |
| Cal.com | Meeting scheduling | EU / USA | SCCs + DPA | Hetzner, AWS |
| HubSpot | CRM, lead management, marketing automation | USA | EU-US DPF + SCCs | AWS, Google Cloud |
| Tally | Form builder | EU (Ireland) | SCCs | Google Cloud |
| Formspree | Form processing | USA | EU-US DPF | AWS |
| Typeform | Form and survey builder | Spain / USA | SCCs + DPA | Google Cloud, AWS |
| Intercom | Live chat, customer messaging | USA | EU-US DPF + SCCs | AWS, Google Cloud |
| Crisp | Live chat, customer support | France / EU | SCCs | OVHcloud, Scaleway |
| Cloudflare Inc. | CDN, DNS, DDoS protection, web security | Global edge network | EU-US DPF + SCCs | N/A |
| usbrowserspeed.com | Third-party audience measurement and advertising-measurement partner | USA | Standard Contractual Clauses | N/A |
5. International Data Transfers
Your personal data may be transferred to and processed in countries outside your home jurisdiction. We ensure appropriate safeguards are in place for all cross-border data transfers:
From EU/EEA to the USA: - Transfer is based on the EU-US Data Privacy Framework (DPF) adequacy decision (European Commission Implementing Decision of 10 July 2023) for DPF-certified recipients. - As a fallback, we have executed Standard Contractual Clauses (2021 Commission Implementing Decision (EU) 2021/914, Module 2 or 3) with all US-based processors. - For non-DPF-certified processors, SCCs are the sole transfer mechanism.
From the UK to the USA: - We use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as published by the ICO.
From Australia: - Under APP 8, we ensure that overseas recipients are bound by substantially similar privacy protections, or we notify you and obtain your consent before transferring your data.
From Singapore: - Under the PDPA (Part 9), we ensure comparable protection through contractual clauses with overseas recipients.
From Israel: - Israel has an EU adequacy decision (2011/61/EU). Transfers from Israel to non-adequate jurisdictions are safeguarded by model clauses consistent with Amendment 13 requirements.
From Canada (Quebec): - Under Quebec Law 25, we conduct a privacy impact assessment before transferring personal data outside Quebec and ensure equivalent protection through contractual agreements.
6. Your Rights — Per Jurisdiction
6.1 EU/EEA Visitors (GDPR)
If you are located in the European Economic Area, you have the following rights:
- Right of access (Art. 15 GDPR) — Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten," Art. 17) — Request deletion of your personal data.
- Right to restriction of processing (Art. 18) — Request that we limit how we use your data.
- Right to data portability (Art. 20) — Receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21) — Object to processing based on legitimate interests, including profiling.
- Right to withdraw consent (Art. 7(3)) — Withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint — With your local data protection authority (DPA) or with our lead supervisory authority.
To exercise these rights, contact us at [email protected]. We will respond within one month.
6.2 UK Visitors (UK GDPR / DPA 2018)
UK residents have the same rights as under the GDPR (mirrored under the Data Protection Act 2018 and UK GDPR). You may also lodge a complaint with the Information Commissioner's Office (ICO): https://ico.org.uk
6.3 California Visitors (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights:
- Right to know — Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose for collection, and the categories of third parties with whom we share it.
- Right to delete — Request deletion of personal information we have collected from you.
- Right to opt out of sale/sharing — You have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) signal as a valid opt-out request. See our Do Not Sell or Share My Personal Information page for details.
- Right to non-discrimination — We will not discriminate against you for exercising any of your CCPA rights.
- Right to correct — Request correction of inaccurate personal information (CPRA § 1798.106).
- Right to limit use of sensitive personal information — We do not collect sensitive personal information as defined by the CPRA.
- Right to designate an agent — You may designate an authorized agent to exercise your rights on your behalf.
To exercise your rights, contact us at [email protected] or use our preference center. We will verify your identity within 45 days.
6.4 Canadian Visitors (PIPEDA / Quebec Law 25)
Federal (PIPEDA): - Right to access personal information held by us. - Right to challenge accuracy and request correction. - Right to withdraw consent at any time. - Right to be informed of a data breach affecting your data. - Right to complain to the Office of the Privacy Commissioner of Canada (OPC): https://www.priv.gc.ca
Quebec (Law 25): Quebec residents have additional rights under Law 25 (formerly Bill 64), effective September 2024: - Explicit opt-in consent is required for any collection, use, or disclosure of personal information, including cookies and tracking technologies. - Right to data portability — You may request your data in a structured, commonly used format. - Right to be forgotten — Request deletion of your data and de-indexation from publicly accessible information. - Right to human review of automated decisions — If we use automated decision-making, you may request a human review. - Privacy by default — Our privacy settings are configured to the most protective level by default. - Right to complain to the Commission d'accès à l'information (CAI): https://www.cai.gouv.qc.ca
6.5 Australian Visitors (Privacy Act 1988 / APPs)
If you are in Australia, the Privacy Act 1988 (as amended in 2024) and the Australian Privacy Principles (APPs) grant you:
- Right to access (APP 12) — Request access to personal information we hold about you.
- Right to correction (APP 13) — Request correction of inaccurate information.
- Right to anonymity or pseudonymity (APP 2) — Where lawful and practicable, you may interact with us anonymously.
- Right to complain to the Office of the Australian Information Commissioner (OAIC): https://www.oaic.gov.au
The 2024 amendments to the Privacy Act also introduced a statutory tort for serious invasion of privacy and enhanced transparency obligations for automated decision-making (effective December 2026).
6.6 Singapore Visitors (PDPA)
If you are in Singapore, the Personal Data Protection Act (PDPA) grants you:
- Right to access (s. 21) — Request information about the personal data we hold and how it has been used or disclosed.
- Right to correction (s. 22) — Request correction of errors in your personal data.
- Right to withdraw consent (s. 16) — Withdraw consent for the collection, use, or disclosure of your data.
- Right to data portability — The PDPC has indicated its intent to introduce data portability requirements.
- Right to complain to the Personal Data Protection Commission (PDPC): https://www.pdpc.gov.sg
6.7 Israel Visitors (Privacy Protection Law / Amendment 13)
If you are in Israel, the Privacy Protection Law 5741-1981, as amended by Amendment 13 (effective 14 August 2025), grants you:
- Right of access — Request access to your personal data within 45 days (extendable by 30 days).
- Right to correction — Request correction of inaccurate personal data.
- Right to deletion ("right to be forgotten") — Request deletion of your personal data.
- Right to object — Object to processing of your personal data.
- Right to data portability — Request your data in a machine-readable format.
- Right to withdraw consent — Withdraw consent at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to complain to the Israeli Privacy Protection Authority (PPA): https://www.gov.il/en/departments/the_privacy_protection_authority
7. Cookies and Similar Technologies
We use cookies and similar tracking technologies for analytics, audience measurement, and site functionality. For a complete list of cookies, their purposes, and retention periods, see our separate Cookie Policy.
You can manage your consent preferences at any time by clicking the "Cookie Settings" link in the footer or by using the preference center. Withdrawal of consent is as easy as giving it.
Category breakdown:
- Strictly Necessary: Cloudflare (__cf_bm), consent preference cookie (pq_consent_v2). These cannot be disabled.
- Analytics: PostHog (ph_*, _posthog_*), Yandex Metrica (_ym_*). Loaded only with your consent.
- Advertising / Audience Measurement: usbrowserspeed.com pixel. Loaded only with your consent.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2/1.3.
- Encryption at rest: Data stored by our processors is encrypted at rest using industry-standard algorithms.
- Web application firewall: Cloudflare WAF protects against common web vulnerabilities.
- Access controls: Employee access to personal data is limited to those who require it for their role, with multi-factor authentication enforced.
- SOC 2: PostHog maintains SOC 2 Type II certification.
- Regular audits: We conduct periodic security reviews of our infrastructure and processors.
9. Data Protection Officer / Representative / Privacy Officer
We have appointed the following points of contact for privacy matters:
Privacy Officer (Australia, Singapore, Canada):
[email protected]
EU GDPR Article 27 Representative:
We are in the process of appointing an EU representative. Until appointed, please direct all EU GDPR inquiries to [email protected].
UK GDPR Article 27 Representative:
We are in the process of appointing a UK representative. Until appointed, please direct all UK GDPR inquiries to [email protected].
Quebec Law 25 Privacy Officer:
[email protected]
Singapore PDPA Data Protection Officer (mandatory):
[email protected]
Israel Amendment 13 Data Protection Officer:
If required by applicable thresholds, we will designate a DPO. In the interim, contact [email protected].
10. Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Material changes will be notified as follows:
- The "Effective date" at the top of this policy will be updated.
- Active subscribers to our services will be notified via email at least 30 days before material changes take effect.
- A banner on the website may be displayed for a reasonable period.
We encourage you to review this policy periodically.
11. Complaints
If you believe we have handled your personal data in violation of applicable law, you have the right to lodge a complaint with the relevant regulatory authority:
| Jurisdiction | Regulator | Website |
|---|---|---|
| EU/EEA | Your local Data Protection Authority (DPA) | https://edpb.europa.eu/about-edpb/about-edpb/members_en |
| United Kingdom | Information Commissioner's Office (ICO) | https://ico.org.uk |
| Australia | Office of the Australian Information Commissioner (OAIC) | https://www.oaic.gov.au |
| California, USA | California Privacy Protection Agency (CPPA) | https://cppa.ca.gov |
| Canada (Federal) | Office of the Privacy Commissioner (OPC) | https://www.priv.gc.ca |
| Canada (Quebec) | Commission d'accès à l'information (CAI) | https://www.cai.gouv.qc.ca |
| Singapore | Personal Data Protection Commission (PDPC) | https://www.pdpc.gov.sg |
| Israel | Privacy Protection Authority (PPA) | https://www.gov.il/en/departments/the_privacy_protection_authority |
We ask that you please attempt to resolve any complaints with us first by contacting [email protected].
12. Data Retention Summary
| Data Type | Retention Period |
|---|---|
| Analytics data (PostHog) | 13 months |
| Analytics data (Yandex Metrica) | 12 months |
| Session recordings | 30 days |
| Email subscriber data | Until unsubscription + 30 days |
| Contact form data | 2 years post-engagement |
| CRM data | Duration of business relationship + 2 years |
| Consent records | 3 years post-collection |
| Payment records | Per tax law requirements (typically 5-7 years) |
| Aggregated/anonymized data | Indefinite |
| Chat/communication logs | 12 months post-conversation |
13. Data Processing Agreement (DPA) Availability
We have entered into Data Processing Agreements (DPAs) with our sub-processors (PostHog, MailerLite, Calendly, Cal.com, HubSpot, Tally, Formspree, Typeform, Intercom, Crisp, Cloudflare, LemonSqueezy, Yandex Metrica, usbrowserspeed.com). If you are a client who needs to enter into a DPA with ProductQuant as a data processor, please contact [email protected].
This policy was last updated on 30 July 2026. Version 2.0.