Privacy Policy
Last updated: 30 August 2026
Who We Are
SPEQ ("SPEQ", "we", "us") operates the GxP resource hub at speqgx.com. For the personal data described here, SPEQ is the data controller. SPEQ is operated from the United States and serves practitioners worldwide. You can reach us about any privacy matter at isaiah@speqgx.com.
The Data We Collect
We collect only the data needed to run the resource hub and the services you ask for. We do not collect special-category (sensitive) personal data. Payment-card details are entered directly into Stripe and are not stored by SPEQ.
- Newsletter & briefing sign-up — your email address, first name (optional), and the page you subscribed from.
- Framework overview download — your name, work email, and organization, recorded when you request the PDF.
- Maturity assessment — the answers you select and the resulting scores. The Quick Scan needs no account; emailing your results adds your name, email, and organization.
- Account & sign-in — if you create an account, we store your email and authentication details needed for email-and-password sign-in, or the basic profile (such as email and name) returned by Google or Microsoft if you choose OAuth. Signed-in features such as saved items, personal watchlists, role and industry preferences, collections, and private notes are stored against your account only.
- Recently viewed — reading history is off by default. If you explicitly enable it, we store the internal SPEQ page, title, view count, and first and latest view times so you can return to recently viewed material. You can clear it or disable it at any time.
- Professional previews — when you open a limited Explorer preview, we record the change-report identifier, month, and account identifier to enforce the monthly allowance. The event does not contain the report content.
- Professional billing — Stripe returns a customer identifier, subscription and invoice status, selected plan and billing interval, trial dates, renewal dates, and limited billing metadata. SPEQ does not receive or store your full card number or security code.
- Personal watchlist delivery — if you explicitly enable a digest, we store its cadence, processing cursor, matched reviewed-feed identifiers, delivery status, and provider message identifier. We do not retain rendered email bodies in the delivery ledger.
- Professional report alerts — if you opt in while eligible, we store the preference and a delivery record containing your account identifier, report identifier and version, delivery status, and provider message identifier. We do not store rendered email bodies in the delivery ledger.
- Browser notifications — if you explicitly enable them, we store your selected streams plus the browser push endpoint and encryption key material needed to reach that browser. Notification content excludes sensitive account or regulated-record details, and no permission prompt appears until you choose to enable a stream.
- Usage data — aggregate, privacy-preserving analytics about which pages and features are used, including bounded Intelligence Companion visits, content-category selections, return buckets, and installation outcomes. These events exclude account identifiers, search text, saved records, assessment answers, scenario choices, and content text (see "Cookies & Analytics").
We do not buy personal data about you, and we do not build advertising profiles.
How & Why We Use It (Legal Bases)
Under the GDPR and UK GDPR we rely on a specific legal basis for each use:
- To deliver what you request — the framework PDF, your assessment results, account features, and paid Professional access. Basis: performance of a contract / steps taken at your request.
- To send the Weekly GxP Briefing and any alert streams you opt into. Basis: your consent, withdrawable at any time via the unsubscribe link in every email or on your profile.
- To deliver browser notifications for the specific streams you select. Basis: your consent, withdrawable at any time from the Intelligence Companion or your browser settings.
- To understand aggregate usage and improve the hub. Basis: your consent for analytics cookies (see below); privacy-preserving, cookieless measurement runs on our legitimate interest in a reliable service.
- To follow up with relevant GxP resources after you download the framework or request results, and to secure the platform and prevent abuse. Basis: our legitimate interests, balanced against your rights.
- To meet legal obligations where they apply. Basis: legal obligation.
We never sell your personal data, and we do not use it for automated decisions that produce legal or similarly significant effects.
Service Providers We Share Data With
We share personal data only with the vetted providers ("processors") that run the platform on our behalf, under contracts that require them to protect it and use it only for our instructions:
- Supabase — database and authentication (hosted on Amazon Web Services). Stores subscriber, lead, assessment, and account records.
- Resend — delivery of transactional emails (e.g. your assessment results), the Weekly GxP Briefing, opted-in personal watchlist digests, and opted-in Professional report alerts, including managing delivery and subscriber/unsubscribe status.
- Vercel — website hosting and content delivery, plus Vercel Analytics and Speed Insights, which measure performance and traffic in aggregate without cookies and without identifying you.
- Stripe — hosted Checkout, subscription billing, fraud prevention, invoices, and the customer billing portal. Stripe processes payment details under its own privacy terms; SPEQ stores only the resulting customer and subscription references needed to provide access.
- Google — Google Analytics for aggregate usage statistics. The Google tag loads on every page, but under Google Consent Mode it stores nothing and sets no cookies unless you accept analytics; if you decline, measurement is cookieless and nothing identifying you persists between visits. Also Google Sign-In, used only if you choose to sign in with Google.
- Microsoft — Microsoft Clarity (product analytics: aggregate usage, heatmaps, and session replay of on-page interactions), loaded only after you accept analytics cookies; and Microsoft Sign-In, used only if you choose to sign in with Microsoft. Microsoft processes this data under the Microsoft Privacy Statement.
- Your browser push provider — Apple, Google, Microsoft, Mozilla, or another browser/platform provider routes an enabled browser notification using the endpoint issued by that provider. SPEQ does not use that endpoint for advertising.
We may also disclose data if required by law, to protect our rights, or in connection with a business transfer — in which case this policy continues to govern your data.
International Data Transfers
SPEQ is operated from the United States, and our providers may process data in the US and other countries. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and our providers’ certifications under the EU–US Data Privacy Framework where applicable. You can contact us for more detail on the safeguards that apply to a specific transfer.
How Long We Keep Data
We keep personal data only as long as it serves the purpose it was collected for:
- Newsletter subscriptions — until you unsubscribe, after which we remove or suppress the subscription address so it is not contacted through that list.
- Watchlist email preferences — until you disable delivery or delete the watchlist. Your account email remains part of the account until the account is deleted.
- Watchlist delivery history — retained with your account for delivery deduplication and operational auditing, and deleted when the watchlist or account is deleted.
- Professional report alert preferences and delivery history — retained with your account for opt-in delivery, deduplication, and operational auditing, and deleted when the account is deleted.
- Browser-notification subscriptions and preferences — retained while enabled; turning them off removes browser delivery credentials, and account deletion removes both credentials and preferences.
- Download and results leads — for a limited follow-up period, then reviewed and deleted or anonymised when no longer needed.
- Assessment responses — retained to provide and improve the assessment; you may ask us to delete yours.
- Account data — for as long as your account is active, and deleted on request.
- Collections, private notes, and role or industry preferences — until you remove them or delete your account.
- Recently viewed history — for up to 90 days while the feature is enabled. Clearing history or turning it off deletes the stored history immediately.
- Explorer preview usage — retained as an account usage and security record so allowances can be enforced and abuse investigated; it is deleted with the account subject to any legally required security-record retention.
- Billing records — subscription and transaction records are retained for the account lifecycle and for the period required by tax, accounting, fraud-prevention, and legal obligations. Stripe may retain payment records under its own legal obligations.
Cookies & Analytics
We use strictly necessary cookies to operate the site (sign-in and session management); these are always active and are not used for tracking. With your consent, we also use two analytics tools to understand how the hub is used so we can improve it: Google Analytics (aggregate, anonymised usage statistics) and Microsoft Clarity (which captures aggregate usage, heatmaps, and session replay of on-page interactions using first- and third-party cookies and similar technologies, to show how visitors navigate our pages). The two are treated differently, because only one of them can run without storing anything. The Google Analytics tag loads on every page under Google Consent Mode with all analytics and advertising storage denied by default — so before you choose, and if you decline, it sets no cookies and no identifier persists between your visits; choosing "Accept" is what permits that storage. Microsoft Clarity has no equivalent cookieless mode, so its tag is not injected at all unless you opt in, and session replay never runs for a visitor who has not accepted. You can grant or withdraw this consent at any time via "Cookie preferences" in the site footer. Vercel Analytics and Speed Insights measure traffic and performance in aggregate without cookies. We use no third-party advertising cookies and do not sell or share data for cross-context behavioural advertising. For how Microsoft collects and uses data gathered through Clarity, see the Microsoft Privacy Statement at https://www.microsoft.com/privacy/privacystatement.
Your Rights
Depending on where you live, you have some or all of the following rights over your personal data. To exercise any of them, email isaiah@speqgx.com — we will respond within the time required by applicable law and will not discriminate against you for asking.
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is inaccurate or incomplete.
- Erasure — ask us to delete your data ("right to be forgotten").
- Restriction & objection — limit or object to certain processing, including our legitimate-interests uses.
- Portability — receive your data in a portable, machine-readable format.
- Withdraw consent — unsubscribe from emails via any footer link, turn browser notifications off in the Intelligence Companion or browser settings, or withdraw analytics consent via "Cookie preferences", at any time and without affecting prior processing.
EU/EEA users may lodge a complaint with their local data protection authority; UK users with the Information Commissioner’s Office (ICO). California residents have the rights to know, delete, and correct their personal information and to opt out of its sale or sharing — we do not sell or share personal information, and honour Global Privacy Control signals for the limited analytics choice above.
Data Security
All connections are encrypted in transit via TLS, and data is encrypted at rest by our infrastructure providers. Per-user records are isolated with database row-level security, access is limited on a least-privilege basis, and we do not store card details. No system is perfectly secure, but we work to protect your data and to notify you and the relevant authorities of any breach as required by law.
Children's Privacy
SPEQ is a professional resource for GxP practitioners and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes to This Policy
We may update this policy as our services or the law evolve. When we do, we revise the "last updated" date above, and for material changes we notify registered users by email. Continued use of SPEQ after an update means you accept the revised policy.
Contact
For any privacy request or question, email isaiah@speqgx.com. SPEQ is the controller of the data described here and is operated from the United States.