Privacy Policy
Last updated: May 8, 2026
1. Who we are
Strat-IQ ("we", "us") operates the Strat-IQ Strategy IQ Assessment available at stratiq.live. For any privacy-related question you can reach us at contact@stratiq.live. This policy describes how we process your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the UK GDPR.
2. What we collect
- Account data: name, work email, password (hashed), and authentication identifiers when you sign in via Google.
- Assessment data: company name, industry, team and operational context you provide, your answers and the answers of respondents you invite.
- Contact data: information you submit through the discovery-call form.
- Technical data: IP address, device and browser information, and basic usage logs needed to operate and secure the service.
3. Why we process it (legal bases)
- Performance of a contract — to provide the assessment, generate your report and manage your account.
- Consent — when you tick a consent box (e.g. to send your results by email or to be contacted about a discovery call). You may withdraw consent at any time.
- Legitimate interests — to keep the service secure, prevent abuse and improve the product, balanced against your rights.
- Legal obligation — to retain records where required by law.
4. Sharing and processors
We do not sell your data. We share it only with vetted processors that help us run the service: cloud hosting, database and authentication infrastructure, and transactional email delivery. Where data leaves the EEA/UK we rely on Standard Contractual Clauses or equivalent safeguards.
5. Retention
Account data is kept for as long as your account is active. Assessment sessions are retained for up to 24 months after the last activity, then deleted or anonymised. Discovery-call enquiries are kept for up to 12 months. You can request earlier deletion at any time.
6. Your rights
Under GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- request erasure ("right to be forgotten");
- restrict or object to processing;
- data portability;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact contact@stratiq.live. We respond within 30 days.
7. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted to authorised personnel and protected by strong authentication.
8. Cookies
We use only the strictly necessary cookies required to keep you signed in and to maintain your session. We do not use advertising or third-party tracking cookies.
See also our Terms of Service.