Privacy Policy

Last updated September 28, 2026

This policy explains what personal data front/q collects, why, who else handles it, and your rights. We never sell your data.

Data controller

The controller for the processing described in this policy is the provider named in our Impressum. For privacy questions, write to [email protected].

Controller or processor

front/q is software that companies ("customers") use to find, evaluate and onboard their suppliers. This policy covers the people we deal with directly: visitors to our websites, prospective customers, and the people who use a customer's front/q account, in relation to that account and our relationship with the customer.

It does not cover the data a customer puts into front/q or collects through it, such as supplier contacts, questionnaire answers, bank details or documents. For that data the customer is the controller and we are its processor under Art. 28 GDPR. We process it only on the customer's instructions, as set out in the data processing agreement between us.

If a company invited you to answer a questionnaire or an RFP through front/q, that company decides what happens to your answers. Please contact them with any questions or requests.

What we collect and why

Our rule is to collect only what we need.

Visiting frontq.app

Our website sets no cookies, has no forms and uses no analytics or advertising tools. To deliver a page, our hosting provider and our network provider see your IP address, browser type and the page you requested. We use this only to deliver the site and keep it secure. Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).

Emailing us

When you email us, for example to book a demo, we use your name, email address and message to answer you, and we keep the correspondence so we have the history if you write again. Legal basis: steps before a contract (Art. 6(1)(b)) or our legitimate interest in answering enquiries (Art. 6(1)(f)).

Customer accounts

When a customer gives you access to front/q, we store your name, work email address, role and the settings you choose. We log each sign-in and sensitive action with the time and your IP address, for security and for the customer's audit trail. If your company signs in through its own identity provider (single sign-on), we receive your name and email address from it.

The apps use a single cookie to keep you signed in. It is strictly necessary and is not used for tracking. The sign-in, password reset and invitation forms use Cloudflare Turnstile to tell people from bots; it assesses your IP address and browser signals and returns only a pass or fail to us.

Legal basis: performance of our contract with the customer (Art. 6(1)(b)) and our legitimate interest in keeping accounts secure (Art. 6(1)(f)).

Email from front/q

front/q sends notifications and supplier invitations by email through Resend. The message holds the recipient's name and address and the content of the notification. Links in these messages are not tracked.

AI-assisted features

Some features use AI models, for example to draft questions or summarise answers. When you use them, the content needed for that task is sent through the Vercel AI Gateway to Anthropic models that run in the EU, with zero data retention. Neither provider may use it to train models. Supplier research sends search queries to Exa. We build those queries from what the customer wants to buy, not from personal data. AI output is a suggestion and should be reviewed before use.

Integrations you turn on

A customer can connect front/q to other services, for example Slack or its own systems. Data then flows to that service at the customer's direction and under the customer's agreement with that service.

Sub-processors

These providers process personal data for us:

  • Hetzner Online GmbH (Germany): servers and database, in German data centres only
  • Cloudflare, Inc. (USA): network delivery and attack protection, the Turnstile bot check, and file storage in a bucket restricted to the EU
  • Resend, Inc. (USA): sending email
  • Vercel Inc. (USA): AI Gateway, which routes AI requests to Anthropic models in the EU with zero data retention
  • Anthropic PBC (USA): AI models, run in the EU through the AI Gateway
  • Exa Labs, Inc. (USA): web search for supplier research; receives search queries only

We will update this list before a new sub-processor starts handling personal data. To be told of changes, write to [email protected].

International transfers

Our own servers and databases are in Germany, and uploaded files are stored in the EU. Some of the providers above are based in the USA, or have parent companies there. Where personal data may reach the USA, the transfer relies on the EU-US Data Privacy Framework for certified providers, and otherwise on the European Commission's Standard Contractual Clauses (Art. 46 GDPR).

How we secure your data

  • All traffic is encrypted with TLS.
  • Bank and tax details are encrypted in the application, with a separate key for each customer.
  • Each customer's data is kept apart by row-level security in the database.
  • Backups are encrypted before they leave the server.
  • Access to sensitive data is recorded in an audit log.

To report a security issue, write to [email protected].

Data retention

We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires, for example under German commercial and tax law.

  • Server logs: deleted once they are no longer needed for security.
  • Correspondence: kept for as long as the conversation needs, and longer only where the law requires.
  • Account data: kept while the customer's contract runs. After it ends, we delete the customer's data within 60 days, including from backups, unless the law requires us to keep it or the customer asks for an export first.

Customer data held as a processor follows the customer's retention settings and our data processing agreement.

When we access or disclose your data

No one at front/q looks at customer content except to help with a support case the customer raises, to fix an error that stops an automated process, to investigate abuse, or where the law requires it. For a support case we ask first.

Requests from authorities. We disclose data only when a legally binding order from a competent German or EU authority compels us to. We notify affected customers before we disclose, unless the law forbids it.

If front/q changes owner, we will tell you before your personal data moves to another company or becomes subject to a different policy.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15)
  • correct it (Art. 16)
  • have it deleted (Art. 17), unless we must keep it by law
  • restrict how we process it (Art. 18)
  • receive it in a portable format (Art. 20)
  • object to processing based on our legitimate interest (Art. 21)
  • withdraw consent at any time, where processing is based on consent

Write to [email protected]. We may need to confirm your identity before we act on a request.

You can also complain to a data protection authority. Ours is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Postfach 3163, 65021 Wiesbaden, Germany, datenschutz.hessen.de.

Changes and questions

We may update this policy when our services or the law change. We will change the date at the top of this page, and tell customers by email about significant changes.

Questions about this policy or your data: [email protected].