Qeries

Privacy Notice

Last updated: 28 July 2026 · Version 1.0

1. Who we are

Qeries is an AI analytics platform that lets people ask questions about their organisation's data in plain language.

Qeries is in private preview and is not yet a registered company. Until it is, the controller responsible for the personal data described here is Alexander Metlewicz, based in Dubai, United Arab Emirates. A company is being formed; when it is, this notice will be reissued naming it, and anyone who has given us their details will be told.

For any question about this notice, or to exercise any of the rights in section 8, contact privacy@qeries.com. We answer privacy requests within one month.

2. What this notice covers

There are two different relationships, and it matters which one applies to you.

Data we decide about (we are the controller)

Information about you as a visitor to our website or as a user of the Qeries product: your contact details, your account, and how you use the service. This notice explains what we do with it.

Data our customers put into Qeries (we are a processor)

When an organisation uses Qeries to analyse its own business data, that organisation decides what data to load and why. We process it only on their instructions, under a separate data processing agreement. If your employer uses Qeries and you want to know what they have loaded or ask them to delete it, please contact them — they are the controller, not us.

3. What we collect, and why

3.1 If you contact us through the website

WhatWhyLegal basis
Name, email address, company, industry, company size, department, job title, and anything you write in the message field To reply to you and to understand who is interested in Qeries Your consent, given when you submit the form

3.2 If you request a live demo

WhatWhyLegal basis
Your email address, and a one-time link we send to it To confirm the address is yours and give you access to a demo that runs on synthetic sample data — never on anyone's real data Your consent

3.3 If you use the FAQ assistant on our website

Your questions are sent to our AI provider to generate an answer (see section 5). Please do not enter personal or confidential information into it.

3.4 If you have a Qeries account

WhatWhyLegal basis
Username, email address, display name, job title, role To create and run your account Performance of a contract
Password, stored only as a salted hash — never in readable form To sign you in securely Performance of a contract
Security log: who did what, when, and from which IP address — sign-ins, permission changes, password resets, data exports To detect and investigate unauthorised access, and so that an organisation can see who did what in its workspace Our legitimate interest in keeping the service secure
Usage records: which features and dashboards are used, and how long requests take To keep the service reliable and decide what to improve Our legitimate interest in operating and improving the service
Email addresses you enter to invite colleagues or to receive scheduled reports To send the invitation or the report Performance of a contract
Your name, email address, job title and message when you contact support from inside the product To answer you and to keep a record of what was agreed Performance of a contract

3.5 Cookies and local storage

We use no advertising cookies, no analytics cookies and no third-party trackers. The website and the product make no requests to third-party domains: fonts, scripts and images are all served from our own servers.

What we do use:

NamePurposeExpires
qeries_sessionKeeps you signed in30 days
qeries_site, qeries_viewas Remembers which workspace you are viewing, and administrator preview mode 30 days / 8 hours
qeries_demoYour temporary demo session60 minutes
Browser local storage Your own preferences and question history, kept in your browser only and not sent to us Until you clear it

These are strictly necessary to provide a service you have asked for, so we do not ask for consent to set them.

4. Who we share it with

We do not sell personal data and we do not share it for advertising. We use the following providers to run the service:

ProviderWhat it doesWhere
AnthropicThe AI model behind our analytics features (see section 5)United States
DigitalOceanHosting and backups — where your data is storedFrankfurt, Germany (EU)
Apple iCloud MailSending email, such as invitations and reportsEU / United States
SentryError reports, so we can find and fix faultsEuropean Union
Better StackChecking the service is onlineEU / United States

Error reports are configured to exclude personal data: request contents, cookies, authentication headers and user identity are stripped before an error leaves our servers.

5. How we use AI, and what it sees

This is the part most worth reading. Qeries answers questions by sending some of your data to an AI model operated by Anthropic. We think you should know exactly what.

When you ask a question, the following may be sent:

Under our agreement with Anthropic, this data is not used to train their models.

You can stop specific columns from ever being sent.

Any column in a data source can be marked as withheld from the AI. Its values are then never included — not in the result rows above, and not in the sample values used to match filters — while the column stays fully visible to people on screen and in dashboards. This is the right setting for names, email addresses and free-text notes.

Organisations that prefer their data to go to Anthropic under their own contract rather than ours can supply their own API key in the product settings. We recommend this for sensitive data.

We do not use AI to make automated decisions that produce legal effects or similarly significant effects about you.

6. International transfers

Your data is stored in the European Union (Frankfurt, Germany) and stays there. Some of the providers listed in section 4 are located outside the EU, and we access the service from the United Arab Emirates, so personal data may be transferred to those countries.

Where that happens, these are the safeguards it relies on:

ProviderSafeguard
Anthropic (United States) The European Commission's Standard Contractual Clauses, incorporated into Anthropic's Data Processing Addendum, which forms part of the terms we contract under
DigitalOcean (hosting in the EU; company in the United States) Certification under the EU–US Data Privacy Framework, with the Standard Contractual Clauses applying if that framework ceases to be valid
Sentry No transfer — we use its European region

You can ask us for details of any of these at privacy@qeries.com.

7. How long we keep it

We keep personal data only for as long as we need it for the purpose we collected it. When a period below expires, the data is deleted. You can ask us to delete it sooner — see section 8.

DataKept forWhy that long
Enquiries and demo requests 36 months from your last contact with us Business software decisions are made slowly, and an enquiry today often becomes a conversation a year or two later
Account data For as long as the account exists, then 90 days So an account closed by mistake can be restored, and any billing question can be settled
Security logs, including IP addresses 24 months Security incidents are often discovered long after they happen, and investigating one needs history to compare against
Usage records 24 months, after which we keep only aggregate figures that cannot be traced back to anyone To understand which parts of the product are used and to compare one year with the next
Invitations Deleted 30 days after they are used or expire An invitation has no purpose once it has been accepted
Support requests 36 months To handle follow-up questions and keep a record of what was agreed
Customer business data For as long as the customer's agreement runs, then 30 days The customer decides this, not us — see section 2. The 30 days are a grace period before permanent deletion

We may keep something longer if the law requires it — for example, records needed for tax or accounting — or if it is needed to establish or defend a legal claim. In those cases we keep only what is necessary for that specific reason.

8. Your rights

If the GDPR applies to your data, you have the right to:

To exercise any of these, email privacy@qeries.com. We will respond within one month. We may need to confirm who you are before we act, so that we do not disclose your data to someone else.

If your employer loaded the data into Qeries, please ask them — see section 2.

You also have the right to complain to a data protection supervisory authority. Because we are not established in the European Union, the authority to approach is the one for the country where you live or work, or where you believe the problem occurred. In Austria that is the Österreichische Datenschutzbehörde; every other EU and EEA country has an equivalent. We would rather hear from you first, at privacy@qeries.com, but you are not obliged to contact us before complaining.

9. How we protect it

No service can promise perfect security, but we will tell affected customers without undue delay if a breach affects their data.

10. Children

Qeries is a business product and is not directed at children. We do not knowingly collect data about anyone under 16.

11. Changes to this notice

If we change how we use personal data, we will update this page and change the date at the top. If the change is significant, we will tell account holders directly.