Skip to main content
Quick Brains

Privacy policy

This policy explains what personal data Quick Brains SRL collects through quickbrains.ai and in the course of working with clients, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR).

Last updated: TODO: date the privacy policy was last reviewed, e.g. 2026-10-01

Who is responsible for your data

The controller of your personal data is:

Quick Brains SRL
Str. Constructorilor nr. 24, Corp C4, Ap. 7, 300571Timișoara, Timiș County, Romania
Fiscal code (CUI): 42724670
Trade Register no.: J2022005559352
Email: TODO: hello@quickbrains.ai

We are not required to appoint a data protection officer. For any privacy question or request, email us at the address above.

What we collect and why

Contact form

When you send us a message, we receive your name, email address, company (optional), the service you are interested in (optional) and your message. We use this only to reply to your enquiry and, if you ask, to prepare a proposal. The legal basis is taking steps at your request before entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in answering business enquiries (Art. 6(1)(f) GDPR).

Booking a call

If you book a call, the booking is handled by Cal.com, which collects your name, email address, chosen time and any notes you add. We use this to hold the call and prepare for it. The legal basis is Art. 6(1)(b) GDPR.

Client projects

When we work for you, we process the contact details of your team and any personal data contained in the systems we work on, such as test accounts or staging data. For data we process on your behalf, we act as your processor under a separate data processing agreement. We work on staging environments and test data wherever possible.

Website visits

This website does not use cookies or tracking pixels. Our hosting provider processes technical data such as your IP address, browser type and the time of your request in server logs, to deliver the site and protect it from abuse. The legal basis is our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR). Web analytics: none.

Who we share data with

We don't sell personal data. We use the following service providers (processors), each bound by a data processing agreement:

  • Website hosting: TODO: hosting provider, e.g. Cloudflare, Inc. (USA)
  • Contact form delivery: Web3Forms
  • Call booking: Cal.com, Inc. (USA)
  • Email: TODO: email provider, e.g. Google Workspace (Google Ireland Ltd.)

Where a provider processes data outside the European Economic Area, the transfer relies on an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework, for certified companies) or on the European Commission's standard contractual clauses.

How long we keep data

  • Enquiries that do not lead to a contract: TODO: retention period for enquiries, e.g. 12 months
  • Client correspondence and project records: TODO: retention period for client records, e.g. duration of contract + 3 years
  • Invoices and accounting records: TODO: accounting retention period (confirm with your accountant), as required by Romanian law
  • Server logs: as set by our hosting provider, typically a few days to a few weeks

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you
  • have inaccurate data corrected
  • have your data erased, where we have no legal obligation to keep it
  • restrict or object to our processing, including processing based on legitimate interest
  • receive your data in a portable format
  • withdraw consent at any time, where processing is based on consent

To exercise any of these rights, email us. We respond within one month. You also have the right to lodge a complaint with a supervisory authority. In Romania, that is the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), www.dataprotection.ro. You can also contact the authority in the EU country where you live or work.

Security

We protect personal data with access controls, encryption in transit, least-privilege access to client systems, and by keeping client data out of tools that are not covered by a data processing agreement.

Changes to this policy

We update this policy when our processing changes. The date at the top shows when it was last revised. Company details are on our legal notice.