Skip to main content

Last updated: 22 February 2026

Privacy Policy

1. Introduction

PriceX Ltd. ("we," "us," or "our") operates FleetQ (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service.

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.

2. Data Controller

3. Personal Data We Collect

3.1 Data You Provide Directly

CategoryData ElementsPurposeLegal Basis
Account DataName, email, password (hashed)Account creation and authenticationContract performance
Team DataTeam name, settings, member rolesMulti-user workspace managementContract performance
AI Provider CredentialsAPI keys (encrypted)BYOK AI processingContract performance
Billing DataBilling name, address, payment method (via Stripe)Subscription billingContract performance

3.2 Data Collected Automatically

CategoryData ElementsPurposeLegal Basis
Usage DataPages visited, features used, experiment runsService improvement and quota enforcementLegitimate interest
Device DataIP address, browser type, OSSecurity and compatibilityLegitimate interest
Session DataSession identifiers (Redis-backed)AuthenticationContract performance
Analytics DataAnonymized page views (Plausible Analytics)Aggregated statisticsLegitimate interest

4. How We Use Your Data

  1. Service Delivery: To provide, maintain, and improve the FleetQ platform
  2. Account Management: To create and manage your account, team, and subscriptions
  3. AI Processing: To execute AI agents, skills, and experiments using your configured LLM providers
  4. Billing: To process subscription payments and generate invoices via Stripe
  5. Security: To protect against unauthorized access, enforce rate limits, and maintain platform integrity
  6. Analytics: To understand aggregated usage patterns via privacy-respecting Plausible Analytics
  7. Legal Compliance: To comply with legal obligations including tax records and regulatory reporting
  8. Communication: To send service-related notifications (usage alerts, weekly digests, approval requests)

5. Legal Bases for Processing (GDPR)

Legal BasisProcessing Activities
Consent (Art. 6(1)(a))Marketing emails, optional analytics features
Contract (Art. 6(1)(b))Account creation, service delivery, AI agent execution, payment processing
Legal Obligation (Art. 6(1)(c))Tax records, regulatory reporting, audit logs
Legitimate Interest (Art. 6(1)(f))Security monitoring, fraud prevention, service improvement, anonymized analytics

6. Data Sharing and Disclosure

RecipientPurposeSafeguards
Stripe (USA)Payment processingPCI DSS Level 1, DPA, SCCs
Anthropic (USA)AI model inference (Claude)DPA, SCCs
OpenAI (USA)AI model inference (GPT-4o)DPA, SCCs
Google (USA)AI model inference (Gemini)DPA, SCCs
Plausible Analytics (EU)Privacy-respecting analyticsEU-hosted, no personal data

We do NOT sell your personal data.

Important: When you configure AI providers via BYOK (Bring Your Own Key), your prompts and data are sent directly to the LLM provider you choose. The data processing relationship for AI inference is between you and your chosen provider.

7. International Data Transfers

We transfer personal data outside the EEA to the United States (Stripe, Anthropic, OpenAI, Google), protected by Standard Contractual Clauses (SCCs) and supplementary measures.

8. Data Retention

Data CategoryRetention PeriodBasis
Account DataDuration of account + 6 monthsContract + legal obligations
AI Execution Logs90 days (configurable per plan)Legitimate interest
Audit Trail30-365 days (per subscription plan)Legal obligation
Billing Data7 yearsTax/legal requirements
Usage Metrics12 months aggregated, 30 days rawLegitimate interest

9. Your Rights

9.1 GDPR Rights (EU/EEA Residents)

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data ("right to be forgotten") (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability — receive your data in a machine-readable format (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time (Art. 7(3))
  • Lodge a complaint with the Bulgarian CPDP or your local supervisory authority

9.2 CCPA/CPRA Rights (California Residents)

  • Know what personal information we collect
  • Delete your personal information
  • Correct inaccurate personal information
  • Opt-out of the sale or sharing of personal information
  • Non-discrimination for exercising your rights

To exercise your rights, contact us at privacy@pricex.app. We respond within 30 days (GDPR) or 45 days (CCPA).

10. Data Security

  • Encryption of data at rest and in transit (TLS 1.2+)
  • Encrypted storage of sensitive fields (2FA secrets, API keys)
  • Password hashing using bcrypt
  • CSRF protection on all forms
  • Security headers (X-Content-Type-Options, X-Frame-Options, HSTS)
  • Role-based access controls (owner, admin, member, viewer)
  • Rate limiting on API endpoints and AI calls
  • Audit trail of all sensitive operations

11. Automated Decision-Making

Our Service uses AI/LLM processing for experiment execution, agent tasks, and skill execution. These are configured and initiated by users, do not produce decisions with legal effects on data subjects, and include human-in-the-loop approval workflows for high-risk operations.

12. Children's Privacy

Our Service is not directed to individuals under 16 years of age. We do not knowingly collect personal data from children.

13. Changes to This Policy

We will notify you of material changes via email at least 30 days before they take effect.

14. Contact Us