Privacy Policy and Data Protection – QAITA

This Privacy Policy defines the strict data security protocols that QAITA ("the Platform", "we", "us" or "our") employs to protect user information processed via https://qaita-ai.net. Located in the World Trade Center in Amsterdam, we are unconditionally committed to protecting your digital privacy in accordance with the General Data Protection Regulation (GDPR) and Dutch privacy legislation.

1. Data Architecture and Collection

To provide a secure and high-quality AI-driven analysis environment, we collect the following categories of personal data:

Identity Data

Full name, date of birth, and official identification documents required for mandatory Know Your Customer (KYC) verification.

Contact Information

Verified email address, active phone number, and registered residential address.

Digital Telemetry

IP addresses, browser specifications, geographical routing data, and detailed logs of your interactions with our AI-driven interfaces.

Compliance Data

Information required to comply with the Dutch Anti-Money Laundering and Terrorist Financing Act (Wwft).

2. Legal Basis for Processing

In accordance with European legislation, we process your personal data on the basis of:

  • Contractual necessity: To manage your account and provide our technical analysis services.
  • Legal obligations: To comply with national regulations imposed by Dutch authorities.
  • Legitimate interests: For fraud prevention, network security, and the optimization of our AI models through anonymized datasets.

3. Security Standards and Retention

QAITA uses enterprise-grade 256-bit AES encryption for all data transfers. Your personal information is hosted on highly secure servers with restricted access within the EEA. We do not retain personal data longer than necessary for the stated purposes or as legally required by Dutch retention obligations (usually 7 years for financial administration).

4. Your Rights under the GDPR

The GDPR grants you full control over your data. You have the right to:

Right of access

Request a copy of the data we hold about you.

Right to rectification

Demand correction of inaccurate or outdated information.

Right to erasure

Request deletion of your data ("Right to be forgotten').

Right to data portability

Receive your data in a structured format.

To exercise these rights, please contact our Data Protection Officer via [email protected].

Effective date: March 28, 2026.

🇬🇧 English