Last updated: 28 July 2026 · Version 1.0
Qeries is an AI analytics platform that lets people ask questions about their organisation's data in plain language.
Qeries is in private preview and is not yet a registered company. Until it is, the controller responsible for the personal data described here is Alexander Metlewicz, based in Dubai, United Arab Emirates. A company is being formed; when it is, this notice will be reissued naming it, and anyone who has given us their details will be told.
For any question about this notice, or to exercise any of the rights in section 8, contact privacy@qeries.com. We answer privacy requests within one month.
There are two different relationships, and it matters which one applies to you.
Information about you as a visitor to our website or as a user of the Qeries product: your contact details, your account, and how you use the service. This notice explains what we do with it.
When an organisation uses Qeries to analyse its own business data, that organisation decides what data to load and why. We process it only on their instructions, under a separate data processing agreement. If your employer uses Qeries and you want to know what they have loaded or ask them to delete it, please contact them — they are the controller, not us.
| What | Why | Legal basis |
|---|---|---|
| Name, email address, company, industry, company size, department, job title, and anything you write in the message field | To reply to you and to understand who is interested in Qeries | Your consent, given when you submit the form |
| What | Why | Legal basis |
|---|---|---|
| Your email address, and a one-time link we send to it | To confirm the address is yours and give you access to a demo that runs on synthetic sample data — never on anyone's real data | Your consent |
Your questions are sent to our AI provider to generate an answer (see section 5). Please do not enter personal or confidential information into it.
| What | Why | Legal basis |
|---|---|---|
| Username, email address, display name, job title, role | To create and run your account | Performance of a contract |
| Password, stored only as a salted hash — never in readable form | To sign you in securely | Performance of a contract |
| Security log: who did what, when, and from which IP address — sign-ins, permission changes, password resets, data exports | To detect and investigate unauthorised access, and so that an organisation can see who did what in its workspace | Our legitimate interest in keeping the service secure |
| Usage records: which features and dashboards are used, and how long requests take | To keep the service reliable and decide what to improve | Our legitimate interest in operating and improving the service |
| Email addresses you enter to invite colleagues or to receive scheduled reports | To send the invitation or the report | Performance of a contract |
| Your name, email address, job title and message when you contact support from inside the product | To answer you and to keep a record of what was agreed | Performance of a contract |
We use no advertising cookies, no analytics cookies and no third-party trackers. The website and the product make no requests to third-party domains: fonts, scripts and images are all served from our own servers.
What we do use:
| Name | Purpose | Expires |
|---|---|---|
qeries_session | Keeps you signed in | 30 days |
qeries_site, qeries_viewas |
Remembers which workspace you are viewing, and administrator preview mode | 30 days / 8 hours |
qeries_demo | Your temporary demo session | 60 minutes |
| Browser local storage | Your own preferences and question history, kept in your browser only and not sent to us | Until you clear it |
These are strictly necessary to provide a service you have asked for, so we do not ask for consent to set them.
We do not sell personal data and we do not share it for advertising. We use the following providers to run the service:
| Provider | What it does | Where |
|---|---|---|
| Anthropic | The AI model behind our analytics features (see section 5) | United States |
| DigitalOcean | Hosting and backups — where your data is stored | Frankfurt, Germany (EU) |
| Apple iCloud Mail | Sending email, such as invitations and reports | EU / United States |
| Sentry | Error reports, so we can find and fix faults | European Union |
| Better Stack | Checking the service is online | EU / United States |
Error reports are configured to exclude personal data: request contents, cookies, authentication headers and user identity are stripped before an error leaves our servers.
This is the part most worth reading. Qeries answers questions by sending some of your data to an AI model operated by Anthropic. We think you should know exactly what.
When you ask a question, the following may be sent:
Under our agreement with Anthropic, this data is not used to train their models.
You can stop specific columns from ever being sent.
Any column in a data source can be marked as withheld from the AI. Its values are then never included — not in the result rows above, and not in the sample values used to match filters — while the column stays fully visible to people on screen and in dashboards. This is the right setting for names, email addresses and free-text notes.
Organisations that prefer their data to go to Anthropic under their own contract rather than ours can supply their own API key in the product settings. We recommend this for sensitive data.
We do not use AI to make automated decisions that produce legal effects or similarly significant effects about you.
Your data is stored in the European Union (Frankfurt, Germany) and stays there. Some of the providers listed in section 4 are located outside the EU, and we access the service from the United Arab Emirates, so personal data may be transferred to those countries.
Where that happens, these are the safeguards it relies on:
| Provider | Safeguard |
|---|---|
| Anthropic (United States) | The European Commission's Standard Contractual Clauses, incorporated into Anthropic's Data Processing Addendum, which forms part of the terms we contract under |
| DigitalOcean (hosting in the EU; company in the United States) | Certification under the EU–US Data Privacy Framework, with the Standard Contractual Clauses applying if that framework ceases to be valid |
| Sentry | No transfer — we use its European region |
You can ask us for details of any of these at privacy@qeries.com.
We keep personal data only for as long as we need it for the purpose we collected it. When a period below expires, the data is deleted. You can ask us to delete it sooner — see section 8.
| Data | Kept for | Why that long |
|---|---|---|
| Enquiries and demo requests | 36 months from your last contact with us | Business software decisions are made slowly, and an enquiry today often becomes a conversation a year or two later |
| Account data | For as long as the account exists, then 90 days | So an account closed by mistake can be restored, and any billing question can be settled |
| Security logs, including IP addresses | 24 months | Security incidents are often discovered long after they happen, and investigating one needs history to compare against |
| Usage records | 24 months, after which we keep only aggregate figures that cannot be traced back to anyone | To understand which parts of the product are used and to compare one year with the next |
| Invitations | Deleted 30 days after they are used or expire | An invitation has no purpose once it has been accepted |
| Support requests | 36 months | To handle follow-up questions and keep a record of what was agreed |
| Customer business data | For as long as the customer's agreement runs, then 30 days | The customer decides this, not us — see section 2. The 30 days are a grace period before permanent deletion |
We may keep something longer if the law requires it — for example, records needed for tax or accounting — or if it is needed to establish or defend a legal claim. In those cases we keep only what is necessary for that specific reason.
If the GDPR applies to your data, you have the right to:
To exercise any of these, email privacy@qeries.com. We will respond within one month. We may need to confirm who you are before we act, so that we do not disclose your data to someone else.
If your employer loaded the data into Qeries, please ask them — see section 2.
You also have the right to complain to a data protection supervisory authority. Because we are not established in the European Union, the authority to approach is the one for the country where you live or work, or where you believe the problem occurred. In Austria that is the Österreichische Datenschutzbehörde; every other EU and EEA country has an equivalent. We would rather hear from you first, at privacy@qeries.com, but you are not obliged to contact us before complaining.
No service can promise perfect security, but we will tell affected customers without undue delay if a breach affects their data.
Qeries is a business product and is not directed at children. We do not knowingly collect data about anyone under 16.
If we change how we use personal data, we will update this page and change the date at the top. If the change is significant, we will tell account holders directly.