Client Portal
Privacy Policy
Version 1.4 · 26 September 2026
This policy covers the H‑Queex client portal: the signed-in area where a client reaches the documents for their own engagement. The H‑Queex website at h-queex.com has its own separate privacy policy covering the enquiry form and anything else collected there.
Who is responsible
The controller for the personal data described here is Hevandro Martire, trading as H‑Queex, a business name registered with the Companies Registration Office under number 790968. Questions and requests go to info@h-queex.com.
Where H‑Queex handles a client's own records as part of a paid engagement, the terms agreed for that engagement govern how that material is treated, not this policy.
What the portal holds
The email address used to sign in, and a password. The password is never stored as typed: only a bcrypt hash of it is kept, which cannot be read back.
The documents belonging to that client's own engagement.
When a document is confirmed in the portal, the confirmation keeps the name typed into the confirmation box, the date and time in UTC, and the network address the confirmation came from. The document is marked accepted, and a separate confirmation file holding those same details is saved alongside the engagement documents so the confirmation can still be read years later.
Records of portal sign-ins. Each sign-in, and each failed attempt, is recorded with the date and time and the network address it came from; a failed attempt also keeps the email address that was typed. The account itself keeps the time it last signed in. These records exist so repeated failed attempts against an account can be seen and acted on.
Why this information is held
Each piece of information above is held for one of three reasons.
To carry out the engagement. The portal account, the engagement documents and the confirmation records exist so the agreed work can be delivered and so both sides have a record of what was agreed. Holding them is part of performing the contract for that engagement.
To keep client accounts secure. The sign-in records and the network addresses they carry are kept because H‑Queex has a legitimate interest in keeping client accounts secure, and in being able to show who confirmed which document and when.
Because the law requires it. Some records have to be kept to meet H‑Queex's obligations under company and tax law, and are held for that reason.
How long it is kept
Portal sign-in details. The account is closed when the engagement ends, and the account and its sign-in details are deleted 12 months after that.
Engagement documents and confirmation records. Kept for 6 years after the engagement ends, which is what company and tax law and the ordinary time limits for legal claims require.
Sign-in and security records. Kept for 6 years, alongside the records they relate to, so it stays possible to show who confirmed what.
Nightly backups. Kept for 30 days. A backup copy is replaced as it ages out, so when something is deleted, that deletion reaches every backup copy within 30 days.
Who can see it
A portal account reaches its own engagement and nothing else. One client never sees another client's documents or confirmations, and a portal account cannot reach the rest of the H‑Queex Hub.
H‑Queex staff reach engagement material in order to deliver the engagement. Access is limited by role, and changes are recorded.
Where it is held
The portal and its database run on a server hosted by Hetzner in Falkenstein, Germany, inside the European Union.
Document and receipt files themselves are stored on Microsoft OneDrive for Business under the H‑Queex account.
Copies are taken each night to a Google Drive account belonging to H‑Queex, so there is a second copy if the server is lost. Every one of those copies is encrypted before it leaves the server, the database backup and the copies of the document and receipt files alike, contents and file names both, with the key held by H‑Queex. Google therefore holds only encrypted data, and can read neither the files nor their names.
Others who process this data
These providers process data on H‑Queex's instructions, for the purposes named and no other.
Hetzner hosts the server the portal runs on. Microsoft stores document and receipt files, and carries email sent by the Hub. Google stores the encrypted nightly backups.
Anthropic is used for two things. First, reading an uploaded receipt so its details can be recorded rather than typed by hand, which sends the receipt image. Second, drafting sections of engagement documents, which sends the engagement scope text, including the business context recorded for that engagement, and which can include the names of the people named as stakeholders. Anthropic processes that material for those two purposes only.
Anthropic is based in the United States, so this is a transfer of personal data outside the European Economic Area. It is made under Anthropic's Data Processing Addendum, which includes the European Commission's Standard Contractual Clauses.
Keeping it safe
The portal is served over HTTPS only. Sign-in sessions expire, and their cookies are restricted so they cannot be read by scripts or sent to other sites. Passwords are hashed with bcrypt, must be at least twelve characters, and are checked against known breached passwords when they are set. Repeated failed sign-ins are rate limited, per account and per network.
Your rights
You can ask what personal data is held about you, ask for it to be corrected, ask for it to be deleted, ask for its use to be restricted, ask for a copy in a portable format you can reuse elsewhere, and object to how it is handled. Requests are answered within one month.
Some records are kept because company and tax law requires it, and where that applies the reason will be explained rather than the request simply refused.
To make a request, or to ask anything about this policy, contact your H‑Queex point of contact or write to info@h-queex.com. You can also complain to the Irish Data Protection Commission.
Changes to this policy
This policy may be updated. The version and date at the top of the page show when it last changed.