Privacy Notice

Last updated: 22 July 2026

1. Who we are

TPQA Consulting ("we", "us") operates the GxPAnswers service and is the data controller for personal data processed through the Service. Our registered address is 6 Logie Drive, Buckie, Moray, AB56 4TW, United Kingdom. You can contact us about privacy matters at theo@tpqaconsulting.co.uk.

This notice explains what personal data we collect, why, on what legal basis, who we share it with, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Personal data we collect

  • Account data — email address and authentication identifiers when you sign up or sign in.
  • Usage and telemetry — counts of questions asked, timestamps, quota status, and coarse product-analytics events (e.g. which pages you visit).
  • Prompt content — the questions you submit are sent to our AI model provider to generate an answer. We do not retain your prompts or answers on our servers beyond the transient processing needed to return the response.
  • Conversation history — stored locally in your browser (localStorage) on your device. It is not transmitted to us unless you send it to us as part of a support request.
  • Device / connection data — IP address, user agent, and similar metadata captured by our hosting provider for security and abuse prevention.
  • Support correspondence — messages you send us and our replies.
  • Billing data — collected directly by Paddle as Merchant of Record; see section 5.

3. How we use it and on what basis

  • To create your account, provide the Service, and enforce fair-use quotas — performance of a contract (UK GDPR Art. 6(1)(b)).
  • To keep the Service secure, prevent fraud and abuse, and improve product quality — legitimate interests (Art. 6(1)(f)).
  • To respond to support enquiries — legitimate interests and, where relevant, contract performance.
  • To comply with tax, accounting, and other legal obligations, largely via Paddle — legal obligation (Art. 6(1)(c)).
  • If we ever send optional marketing, it will be on the basis of your consent (Art. 6(1)(a)), which you can withdraw at any time.

4. Cookies and analytics

We use strictly necessary cookies to keep you signed in and to remember your privacy preferences. We use a privacy-friendly analytics service to count aggregate page views and understand usage; it does not build cross-site advertising profiles. We do not use third-party advertising or marketing cookies.

5. Who we share data with

  • Hosting, authentication, and database providers (Lovable and Supabase) — to run the Service.
  • AI model provider (currently Google, for the Gemini family of models) — to generate answers to your prompts.
  • Paddle.com Market Limited — our Merchant of Record. Paddle collects and processes your billing information, payment details, tax information, and invoices, and is the data controller for that information under its own privacy policy.
  • Professional advisers (legal, accounting) where necessary, and public authorities where we are legally required to disclose.

We do not sell your personal data.

6. International transfers

Some of our service providers process data outside the United Kingdom and the European Economic Area, including in the United States. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, and applicable adequacy decisions.

7. How long we keep data

  • Account data: while your account is active, and for up to 12 months after closure to handle disputes, refunds, and legal requirements.
  • Usage logs and security logs: up to 12 months.
  • Support correspondence: up to 24 months.
  • Billing records held by Paddle: retained by Paddle in line with its own policies and applicable tax law.

After these periods we delete or anonymise the data unless we are legally required to keep it for longer.

8. Your rights

Under the UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw any consent you have given; and
  • complain to the UK Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, email theo@tpqaconsulting.co.uk with the heading "GDPR". We will respond within one month.

9. Security

We use appropriate technical and organisational measures to protect personal data, including TLS in transit, encryption at rest via our hosting provider, least-privilege access controls, and regular review of our security posture. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

10. Changes to this notice

We may update this notice from time to time. When we do, we will change the "Last updated" date above and, for material changes, notify you via the Service or by email.