Privacy Policy
This policy describes the personal data IMSQ LLC ("IMSQ") processes, why, who it is shared with, and the rights you have. IMSQ LLC is the data controller for the platform. It is written in plain language on purpose — the practices described here are the ones the platform actually implements.
Data we process
Account and profile data (name, work email, role, organisation); learning and engagement records (module progress, session attendance, assessment scores, advisory artefacts); security telemetry (sign-in events, device and IP metadata, MFA changes); billing records (invoices and subscription state — card details are held by Stripe, not by IMSQ); and, for Experts, registry data (CV, certifications, expertise, rates).
Public forms collect what they state inline: the fit assessment collects your name, work email, company, optional phone, and your responses (plus an optional marketing opt-in you control); the Expert application collects professional details you submit.
Why we process it (legal bases)
To deliver the service and produce governance records (performance of contract); to authenticate users and secure accounts, preserve audit-record integrity, and improve the service using cookieless analytics (legitimate interests); to meet legal obligations; and, for optional marketing updates, your consent — which you can withdraw at any time.
Audit-relevant records are part of the product’s value: their integrity is preserved so they remain retrievable for your QMS and supplier files.
Sharing & sub-processors
We share data with independent Experts only as needed to deliver an engagement, with your own account administrators, and with the sub-processors below under their published data-protection terms. IMSQ does not sell personal data and is not an open freelance marketplace.
Supabase — Database, authentication, file storage. Region: United States (us-east-1, AWS).
Stripe — Payment processing. Region: United States (primary), per Stripe's published sub-processor list.
Resend — Transactional email delivery. Region: United States.
Vercel — Hosting, edge network, cookieless analytics. Region: United States (primary).
Microsoft (Teams / Microsoft 365) — Operational notifications, corporate email tenant. Region: United Kingdom (tenant data location).
Sentry — Error monitoring. Region: European Union (Frankfurt).
International transfers
Platform data is hosted primarily in the United States (Supabase, us-east-1). Error monitoring is processed in the European Union (Sentry, Frankfurt) and operational notifications ride our Microsoft 365 tenant located in the United Kingdom. Where personal data moves between regions, it does so under each named provider’s published data-protection framework (each maintains its own DPA and standard contractual protections).
Cookies
IMSQ uses strictly-necessary cookies only: session and authentication cookies that make sign-in work, and a security cookie for trusted-device MFA where you enable it. Our analytics (Vercel Analytics) is cookieless. Because no non-essential cookies are set, no cookie-consent banner is shown. If that ever changes, this policy and the site’s consent posture will change with it.
Retention
Account and engagement data is retained while your account is active. When an account closes, data is deleted or de-identified on verified request through the rights process below; audit-relevant records whose integrity is part of the service (for example signed advisory records) may be preserved or placed under documented retention before deletion completes.
Provider backups age out on the providers’ published schedules after deletion from the live system.
Security
Accounts are isolated with role-scoped, row-level access control enforced in the database; privileged roles use multi-factor authentication; traffic is encrypted in transit and data encrypted at rest by our hosting providers; rate limiting protects abuse-prone endpoints; and errors are continuously monitored. Security research contact and disclosure instructions are published at /.well-known/security.txt.
Your rights
Subject to applicable law, you can access, correct, export, or request deletion of your personal data, object to certain processing, and complain to your supervisory authority. Send requests to privacy@imsq.org — we verify the requester’s identity before acting and respond without undue delay, at most within one month.
Where your data lives inside an organisation’s account, we may coordinate with your account administrators to preserve audit-trail integrity while honouring your request.
Marketing choices
Marketing updates are strictly opt-in: the checkbox is never pre-ticked, and leaving it unticked never affects the service. Withdraw at any time by emailing privacy@imsq.org.
Changes & contact
This policy carries a version and effective date; material changes are versioned and announced through the service. Privacy questions and rights requests: privacy@imsq.org. Security reports: security@imsq.org.
Questions about the fine print?
Procurement and legal reviews are welcome. Book a programme review and we’ll walk your team through the terms, the SLA, and the Supplier Qualification Pack.