Last updated: 2026-06-13

Privacy Policy

This Privacy Policy explains how HQ Visible ("we", "us", "our") collects, uses, stores and protects personal data when you use our website and services. We comply with the EU General Data Protection Regulation (GDPR).

1. Data controller and contact

HQ Visible is the data controller for the personal data processed through this website. You can reach us at hello@hqvisible.com for any privacy question or to exercise your rights.

2. What data we collect

When you request a Free AI Visibility Snapshot, we collect:

  • Website URL — the domain you want us to analyse.
  • Email address — so we can deliver your snapshot and communicate about your request.
  • Company name (optional) — only if you choose to provide it.
  • Language preference — the language you used the site in.
  • Submission metadata — date/time of submission, the user-agent of your browser and a one-way hash of your IP address. We do not store the raw IP address. The hash is used solely for spam / rate-limit protection.

We do not collect special-category data (health, political opinion, etc.) and we do not use behavioural advertising cookies or third-party analytics on this website at the time of this update. If we introduce analytics in the future, this policy will be updated and a cookie banner will be shown before any non-essential cookies are set.

Geo-based language and pricing

We may use your approximate country based on technical information provided by our hosting/CDN provider, such as IP-derived country code, to display the correct language, currency and regional pricing. We do not use this to determine your precise location, and we do not store exact geolocation data.

3. Why we collect it (purposes)

  • To deliver your AI Visibility Snapshot to the email you provided.
  • To contact you about your requested analysis (e.g. clarifying questions, or notifying you when your snapshot is ready).
  • To deliver the Full AI Visibility Report and related customer support if you choose to purchase it.
  • To provide customer support if you contact us by email.
  • To prevent abuse of the form (spam, duplicate / automated submissions) using the IP hash and basic rate limiting.

4. Legal basis (GDPR Art. 6)

  • Consent (Art. 6(1)(a)) — you submit the snapshot form voluntarily and can withdraw consent at any time.
  • Contract (Art. 6(1)(b)) — when you purchase the Full Report, processing is necessary to deliver it.
  • Legitimate interest (Art. 6(1)(f)) — to protect the form against spam/abuse and to keep accurate business records.
  • Legal obligation (Art. 6(1)(c)) — accounting/tax records for paid orders are kept for the period required by Danish law.

5. How long we keep it (retention)

  • Snapshot leads — kept for up to 12 months from submission, then deleted, unless you ask us to delete them sooner or you become a paying customer.
  • Paid customer records — kept for as long as required to meet accounting, tax and other legal obligations (at least 5 years under Danish accounting law).
  • Marketing opt-in records — kept until you unsubscribe or withdraw consent.
  • Consent audit trail (consent flag, timestamp, policy version) — kept for the life of the underlying record as evidence of GDPR compliance.
  • Submission metadata (IP hash, user-agent) — kept for up to 90 days for abuse prevention.

6. How we store and protect your data

Personal data is stored on encrypted servers inside the European Union, operated by our backend infrastructure provider. Access is restricted to authorised personnel and protected by strong authentication. We use TLS in transit and encryption at rest.

7. Sub-processors

We rely on the following sub-processors to operate the service. All have signed standard data-processing agreements:

  • Database & application hosting — EU-based managed backend (Lovable Cloud / Supabase, EU region).
  • Transactional email delivery — used to send the snapshot confirmation email and the snapshot itself.
  • Payments — when the Full Report becomes available, payment processing will be handled by Stripe. Your card details are never stored on our servers.

8. Cookies and analytics

We use two cookie categories and ask for your consent through a cookie banner the first time you visit the site:

  • Necessary cookies — always active. Required for core functionality such as remembering your language preference and storing your cookie choice. No consent required (GDPR Art. 6(1)(f) — strictly necessary).
  • Analytics cookies — optional. Aggregated usage statistics to help us improve the site. Off by default and never loaded until you opt in via the cookie banner. You can change or withdraw consent at any time by re-opening the banner from the footer.

We do not use advertising or cross-site tracking cookies.

9. Lead form processing & consent

The Free Snapshot form follows the GDPR principle of data minimisation. We collect only:

  • Required: Website URL and email address.
  • Optional: Company name.

Before you submit, you must tick a required consent checkbox confirming we may process the information to deliver your snapshot and contact you about your request. We log your consent status, the consent timestamp, a one-way hash of your IP address and the version of this Privacy Policy in effect at submission as part of our GDPR audit trail.

Submitting the form does not subscribe you to any marketing list. A separate, optional, unchecked-by-default checkbox lets you opt in to occasional marketing emails — you can unsubscribe with one click at any time.

Your submission is (1) validated in your browser, (2) sent to our server, (3) stored in our database, and (4) used to send (a) an internal notification to hello@hqvisible.com and (b) a confirmation email back to you. We do not share your submission with any third party for marketing.

10. Your rights

Under GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you, why we hold it, and when it was collected.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — restrict processing in certain circumstances.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — at any time, without affecting prior lawful processing.
  • Lodge a complaint with your supervisory authority (in Denmark: Datatilsynet, datatilsynet.dk).

How to request access

Email hello@hqvisible.com from the email address you used when submitting the form, with the subject line "GDPR access request". We will reply within 30 days with a copy of the personal data we hold about you, the purposes of processing, and the dates the data was collected.

How to request deletion

Email hello@hqvisible.com from the email address you used, with the subject line "GDPR deletion request". We will delete your data within 30 days and confirm by email. Records we are legally required to keep (e.g. paid invoices under Danish accounting law) may be retained for the legally mandated period and then deleted.

11. International transfers

Personal data is stored within the EU. If any sub-processor transfers data outside the EEA, that transfer is covered by EU Standard Contractual Clauses or an adequacy decision.

12. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated before they take effect where required.

13. Contact

Questions about this Privacy Policy or how we handle your data? Email hello@hqvisible.com.


Back to home