PowerQuant

Trust Center

Data Types

What customer data PowerQuant processes. Each row maps to lawful basis under GDPR Article 6, retention period, and storage location.

Data categorySourceLawful basis (Art. 6)RetentionStorage
Customer email + name + companyOnboarding formContract performance + legitimate interestLength of relationship + 3 yearsSupabase EU
Stripe customer-IDStripe webhookContract performance7 years (DK Bogføringslov)Stripe EU + Supabase EU
AI inventory content (customer-provided)Customer uploadContract performanceLength of relationship + 1 yearSupabase EU (encrypted)
Article 4 register entriesCustomer questionnaireContract performanceLength of relationship + 7 years (audit)Supabase EU
Annex IV documentationGenerated by PowerQuant + customerContract performance + audit-trail obligation7 years post-deliverySupabase EU + customer copy
Council-vote audit-logPowerQuant internalLegitimate interest (audit-trail)Permanent (Ed25519 chain)Supabase EU
LLM-prompt + LLM-outputPowerQuant pipelineContract performance90 days for debugging; redacted afterSupabase EU
Email transactionalResend webhookContract performance12 monthsResend EU
IP address (web visit)Cloudflare WAFLegitimate interest (security)7 daysCloudflare aggregated
Stripe payment metadataStripe webhookContract performance + legal obligation7 years (DK Bogføringslov)Stripe EU

Special categories (Article 9 GDPR)

PowerQuant does NOT process special categories of personal data (racial/ethnic origin, political opinions, religious beliefs, trade union, genetic, biometric, health, sex life). If a customer's AI system processes such data, PowerQuant stores only the categorical reference (e.g. "system processes biometric data per Article 9(2)(g)") in the AI inventory, not the actual special-category data.

Children's data

PowerQuant does not process children's data.

Customer-controlled data export (GDPR Article 20)

Customers can request export of their data in machine-readable JSON format within 30 days of request to dpo@powerquant.dk.