Legal · Privacy policy · Plain language first

How Kustiq handles your data, in plain language.

Kustiq is a B2B contact-research tool that processes only the data needed to research the companies you ask about and to bill you for it. We do not sell personal data, do not run third-party ad trackers, and do not train AI models on your inputs.

Updated May 16, 2026· v2.2GDPRCCPAController · Analytics Lab S.R.L.Lang · English (EN)
Data-protection contact: support@kustiq.com. Kustiq has not appointed a DPO under Art 37 (processing volume below threshold). Article 15 to 22 requests, breach reports, and erasure escalations all route to that inbox; the faster, ticketed route is /support.
Free tier · 1 profile / week (anonymous), 3 / week (signed in)EU + US sub-processors onlyNo third-party trackersNo AI training on your dataTrust posture →
On this page · 16 sections
§ 01 · Who we are

Who we are, and how to reach us.

Kustiq is a product of Analytics Lab S.R.L., a Romanian company registered at the Bucharest Trade Register (CUI RO50212590, Reg J2024011530406), with its registered office at Int. Gheorghe Simionescu 19, 014155 Sector 1, Bucharest, Romania. We are the controller of personal data processed through kustiq.com.

Kustiq has not appointed a Data Protection Officer because its processing activities do not require one under GDPR Article 37. All data-protection inquiries route to a single inbox monitored every business day at support@kustiq.com. The faster, ticketed route for rights requests is /support: every request gets a tracking ID and a named owner.

EU-based users may also lodge a complaint directly with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, or with the supervisory authority in their country of residence.

§ 02 · What we collect

What data we collect, and why.

We collect the minimum data needed to answer the questions you ask Kustiq and to keep your account secure. There are four categories. Each maps to a single legal basis under GDPR Article 6.

Account data

→ Art 6(1)(b) · Contract
  • Email, hashed password, optional name. Sign-in via Google, GitHub, or LinkedIn returns name and email only.
  • Sign-in metadata (IP, user-agent) kept short-term for fraud review.

Company data you submit

→ Art 6(1)(b) · Contract
  • Domains and emails you provide for profiling.
  • Free tier: 1 profile / week (anonymous), 3 / week (signed in).

Generated profiles

→ Art 6(1)(f) · Legitimate interest
  • Public B2B information assembled from web sources, then processed by AI classification plus deterministic verification.
  • Aggregated to your workspace only. Never sold or syndicated.

Billing data

→ Art 6(1)(b) · Contract
  • Invoice address and VAT ID. Card numbers held by Stripe, not by us.
  • Last-4 digits and expiry stored for receipt rendering.
In plain termsWe need your email to give you an account. We need a payment method to charge you when you upgrade. Everything else exists because you asked Kustiq a question and we kept the answer in your workspace so you can come back to it.
§ 03 · Cookies & trackers

Cookies, trackers, and what we don’t run.

Kustiq sets only the cookies strictly required for authentication and session management. We do not load Google Analytics, Meta Pixel, LinkedIn Insight, TikTok Pixel, X Pixel, or any other third-party advertising tag. You can verify this in your browser DevTools and on our Trust & Security page.

  • sb-[project]-auth-token · Supabase auth session, persistent until logout.
  • sb-[project]-auth-token-code-verifier · PKCE verification during OAuth, session only, cleared after auth.

Marketing pages run a self-hosted analytics pipeline (see § 12) on our own infrastructure.

In plain termsDoes Kustiq run advertising trackers? No third-party ad tags, no Google Analytics, no Meta Pixel. The only cookies are first-party and functional. Analytics are first-party only.
§ 04 · No sale of data

We do not sell or rent personal data.

Kustiq does not sell personal data, does not rent mailing lists, and does not run a “data co-op” where one customer’s research becomes another customer’s lead. The contents of your workspace are visible only to you and the teammates you invite. Aggregated, anonymised usage statistics may inform product improvement; nothing in those statistics can be tied back to an individual user or account.

Under CCPA / CPRA, this means Kustiq has not “sold” or “shared” personal information of California residents in the previous 12 months. We will continue not to.

In plain termsDoes Kustiq sell data? Not to advertisers, not to brokers, not to AI companies, not to anyone. The output of your queries lives in your workspace and stays there.
§ 05 · Your rights

Your rights under GDPR and CCPA.

You have a full set of rights over the personal data we hold about you. The fastest way to exercise any of them is to file a ticket at /support: every request gets a tracking ID, an SLA, and a named owner. You can also email support@kustiq.com directly.

Right of accessGDPR Art 15 · CCPA § 1798.110
Receive a copy of all personal data we hold about you, in a machine-readable JSON archive.
Right to rectificationGDPR Art 16
Correct any inaccurate or incomplete personal data. Most fields are self-serve in account settings.
In-product
Right to erasureGDPR Art 17 · CCPA § 1798.105
Delete your account and all associated data. See § 10 for the runbook and SLA.
Right to portabilityGDPR Art 20
Export your full workspace as JSON, CSV, or PDF. Self-serve from /dashboard/export.
In-product
Right to objectGDPR Art 21
Object to processing based on legitimate interest. We will stop unless we can show compelling overriding grounds.
Right to restrictionGDPR Art 18
Pause processing while a dispute about accuracy or lawfulness is resolved.
Right to withdraw consentGDPR Art 7(3)
Withdraw consent for any consent-based processing (for example marketing emails). The withdrawal does not affect prior lawful processing.
In-product
Right to lodge a complaintGDPR Art 77
File with the Romanian DPA (ANSPDCP) or your local supervisory authority. We would prefer you tell us first; you do not have to.
CCPA non-discriminationCCPA § 1798.125
Exercising any privacy right will not change pricing, throttle the service, or affect the quality of results you see.
Service-wide

We respond to verified requests within 30 days (GDPR) or 45 days (CCPA), whichever is shorter. Requests sent through /support typically resolve faster.

§ 06 · AI processing

How we use AI, and what we don’t do.

When you submit a domain or company email for profiling, Kustiq gathers public B2B information from the web and runs it through a language-model inference call (a single API request to Anthropic, stateless: the model sees the input, returns the answer, and forgets). The output is paired with deterministic verification: SMTP handshake, Browserless rendering, 12-factor rule-based churn engine.

Anthropic contractually disables training on customer data for API traffic from Kustiq’s account. Kustiq itself does not train, fine-tune, or distill any models on your inputs and does not maintain a customer-data corpus. Generated profiles are AI-assisted starting points; they should not be treated as verified fact without human review.

In plain termsDoes Kustiq train AI on my data? Not us, and not the providers we send inference calls through. The model sees your question, returns an answer, and forgets.
§ 07 · Retention

How long we keep things.

Different categories have different lifetimes, all driven by the smallest of: legal obligation, contractual necessity, or reasonable operational need.

  • Account record · kept while your account is active, removed within 30 days of deletion.
  • Workspace contents · same lifetime as the account. Self-export at any time. Hard-deleted on erasure request.
  • Billing records · 7 years (Romanian commercial-law obligation) for issued invoices. Card metadata held by Stripe under their retention.
  • Sign-in metadata · kept short-term for fraud review.
  • Cached web pages and search results · used transiently to generate profiles; cached copies kept up to 90 days for response-time reasons, then purged.
  • Database backups · automatically purged within 7 days of the primary deletion.
  • First-party analytics · see § 12.
§ 08 · Transfers

International transfers.

Kustiq is operated from Romania. API-server processing runs on Hetzner infrastructure in Germany (EU). Database hosting is on Supabase in the United States, encrypted at rest under SCCs + DPF. The full sub-processor table at § 11 lists the region per vendor.

For transfers to sub-processors based in the United States, Kustiq relies on either the EU-US Data Privacy Framework, where the vendor is certified, or on the European Commission’s Standard Contractual Clauses (EU) 2021/914 Module 2 (controller to processor). The choice per vendor is shown in the § 11 table.

§ 09 · Security

How we secure your data.

Encryption at rest (AES-256) for database and backup volumes hosted by Supabase. Encryption in transit (TLS) on every external connection and on internal hops, with HSTS on customer-facing endpoints. API keys are stored as SHA-256 hashes, never in plaintext. Webhook payloads are signed with HMAC-SHA256.

Access to production systems is restricted, authenticated by SSH key, and limited to personnel who require it under the principle of least privilege. Step-up auth (AAL2) is required for sensitive account mutations. Six granular permissions enforce team-level access control inside customer organisations. Kustiq is not SOC 2 or ISO 27001 certified and is not in active audit; the Trust & Security page covers the current security posture in detail.

In the event of a personal-data breach affecting your data, we will notify you and any relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.

§ 10 · Export & deletion

Export everything. Delete everything.

You own everything in your workspace and can take it with you, or remove it completely, at any time. Both routes are self-serve from settings; both are time-bounded.

Export produces a JSON, CSV, XLSX, or PDF archive of every research output and query. Self-serve from /dashboard/export.

How to delete your account.

Three steps, takes under a minute. Production removal proceeds on request; backups roll off on a 30-day schedule.

  1. Open account settings and click Delete account. The confirm dialog tells you exactly what will be removed.
  2. Confirm with your password (or passkey). The account is locked immediately and queued for hard-delete.
  3. If you cannot sign in, write to support@kustiq.com from the email address on file with subject Account deletion request.

SLA · prod removal on request · backups 30d · Article 17 reachable via /support → Erasure

Backups roll off on a 30-day schedule. After day 30, no copy of your data remains in any Kustiq system. We do not maintain offline archives. Anonymised, aggregated data that cannot be linked back to an individual may be retained for product improvement.

§ 11 · Sub-processors

The 12 sub-processors that touch your data.

Sub-processors are vendors Kustiq engages to operate the service. The list below is the complete current set, the role of each, what data they see, where they run, and the legal basis for the transfer when they sit outside the EEA. Full processor terms in the Data Processing Addendum.

Sub-processor register · v2.230-day notice on additions
ServicePurposeData sharedRegionLegal basis
Anthropicanthropic.comLLM inference during profiling. No model training.single-call query bodyUSus-east
Browserlessbrowserless.ioHeadless-browser rendering for JS-required public-web fetches.public URL · page payloadEU/USmulti-region
Cloudflarecloudflare.comTurnstile bot defense on public abuse-prone endpoints.visitor IP · tokenglobal edgeedge
Google Workspaceworkspace.google.comBusiness email and customer-support communications.support_threadUSmulti-region
Hetznerhetzner.comAPI server hosting and data-processing infrastructure.workspace · audit logEU · Germanyown infra
HubSpothubspot.comCRM data sync (when integration enabled).contact · companyUSus-east
Resendresend.comTransactional email (auth, billing, notifications).email address · message bodyUSmulti-region
Saleshandysaleshandy.comOutbound-email delivery for sales communications.prospect_email · sequence_metaUSmulti-region
Serperserper.devWeb-search API for public-data gathering.search query · domainUSus-east
Stripestripe.comCard processing, invoicing, customer portal.email · billing address · VATUSmulti-region
Supabasesupabase.comDatabase hosting, authentication, AES-256 at rest.login · profile_metadataUSmulti-region
Vercelvercel.comFrontend hosting and edge delivery.page_view · session_metaUSedge
12 active sub-processors · 30-day prior notice on additions, breaking changes, region moves.
Full register in DPA
In plain termsWhere is my data stored?API-server processing runs on Hetzner in Germany (EU). Database hosting is on Supabase in the US, encrypted at rest under SCCs + DPF. The full table above is the complete list, and we give 30 days’ notice before adding anyone new.
§ 12 · First-party analytics

First-party analytics, surfaced in full.

All product analytics are collected and stored on our own infrastructure (Hetzner, Germany). No data is sent to Google Analytics, Meta, Mixpanel, Segment, Hotjar, or any third-party analytics provider. The two characteristics worth surfacing directly are below.

What we keep
  • IP address and approximate location (country + city via GeoIP).
  • Page path and event name; first-party only.
  • UTM tags and referring URL.
  • SHA-256 visitor identifier (IP + user-agent) for session deduplication.
  • Reverse-DNS organisation lookup for aggregate traffic analysis.
What we never collect
  • Form contents · no auto-capture on inputs.
  • Cross-site identifiers · no Google, Meta, LinkedIn, or X tags.
  • Session replay · not enabled.
  • Third-party cookies · none set, none accepted.

Analytics processing relies on legitimate interest under GDPR Article 6(1)(f). You may object at any time by emailing support@kustiq.com. Verification details on the Trust & Security page.

§ 13 · Children & CCPA

Children, California, and other regional notes.

Kustiq is a B2B research tool intended for users 16 years of age or older. We do not knowingly collect personal data from children. If you become aware that a child has provided personal data, contact support@kustiq.com and we will erase it.

California residents have the rights described in § 5, plus the additional CCPA right to opt out of any “sharing” for cross-context behavioral advertising. Because Kustiq does no such sharing (see § 4), there is nothing to opt out of, but we honor Global Privacy Control headers as a courtesy.

Automated decision-making: Kustiq generates company profiles, churn risk assessments, and qualification assessments using automated processing. These outputs are informational tools designed to assist your team’s decision-making, not to produce legal effects or similarly significant effects on any data subject. If you believe automated processing has produced such an effect, contact support@kustiq.com and we will provide meaningful human review.

§ 14 · Changes

Changes to this policy.

We update this policy when our practices, our sub-processors, or applicable law change. Substantive changes are announced by email to all account holders at least 30 days before they take effect; the effective date in the header chip is updated at the same time. The full diff for every version lives in § 16.

Cosmetic, structural, or pure-clarification edits are made without notice but always recorded in the version log. See our Terms of Service for the full agreement governing use of Kustiq.

§ 15 · Contact

How to contact us.

Three routes, in order of speed.

  • For most things · /support. Ticketed, time-stamped, with SLAs.
  • For data-protection questions · support@kustiq.com. Use this for breach notifications, complex Article 15 to 22 questions, or anything where the ticket flow is the wrong shape.
  • For paper mail · Analytics Lab S.R.L., Int. Gheorghe Simionescu 19, 014155 Sector 1, Bucharest, Romania.
§ 16 · Version history

Version history.

The current version is v2.2 (effective ).

v2.22026-05-16
Legal cluster lock: canonical Organization entity-graph shared across /trust /privacy /terms /dpa, Cloudflare Turnstile and Browserless added to the sub-processor register (10 → 12), “anonymised” / “rendering” terminology canonicalised, breadcrumb mesh aligned to /trust, FAQ extended to GDPR SAR + CCPA opt-out questions.
v2.12026-03-24
Fresh layout: glance card hyperlinks, 5-column sub-processor table, inline deletion runbook, rights matrix, keep/drop analytics callout. Saleshandy and Google Workspace named in the sub-processor register. First-party analytics disclosure expanded.
v2.02026-03-23
Added children’s privacy, automated decision-making, Do Not Track, AI model training opt-out, supervisory authority, intermediate data retention, data minimization, Art 14 public data, right to restrict, CPRA right to correct, encryption at rest, breach-notification details, 30-day email notice for changes.
v1.02026-03-14
Initial publication.
FAQ

Quick answers.

Does Kustiq sell data?
Kustiq does not sell, rent, or syndicate personal data. The contents of your workspace are visible only to you and the teammates you invite. Aggregated, anonymised usage statistics may inform product improvement; nothing in those statistics can be tied back to an individual. Under CCPA / CPRA, this means Kustiq has not 'sold' or 'shared' personal information of California residents in the previous 12 months. Full text in §4.
Does Kustiq train AI on my data?
No model training, no fine-tuning, no distillation on your inputs. Inference calls go to Anthropic under contractual no-training flags, with stateless inference: the model sees the input, returns an answer, and forgets. Kustiq itself does not maintain a customer-data corpus. Full text in §6.
Where is my data stored?
API-server processing runs on Hetzner in Germany (EU). Database hosting is on Supabase in the US, encrypted at rest under SCCs + DPF. The full sub-processor list, with region and legal basis per vendor, is in §11. We give 30 days' notice before adding new sub-processors.
How do I delete my account?
Three steps. Open account settings, click Delete account, confirm with your password. The account is locked immediately, removed from production, and rolled off backups within 30 days. If you cannot sign in, write to support@kustiq.com from the email on file with subject 'Account deletion request'. Full runbook with SLA in §10.
How do I file a GDPR subject access request?
Email support@kustiq.com from the address on file with subject 'SAR' and the rights you are exercising (access, rectification, erasure, portability, restriction, or objection). First response within one business day; substantive response within the GDPR Art 12 30-day window. No fee for normal requests. Full rights detail in §5.
How do California residents opt out under CCPA / CPRA?
Kustiq does not sell or share personal information, so the CCPA opt-out is automatically in effect for all California residents — no action required on your part. To submit a 'right to know' or 'right to delete' request, email support@kustiq.com with subject 'CCPA request'. Verification mirrors the GDPR SAR flow. Full text in §13.
Your data · v2.2 · GDPR + CCPA

Your data, your settings.

Privacy is not a banner. Open account settings to export everything, delete everything, or file a request through the ticketed path.