Queuey Privacy Notice
Last updated: 14 August 2026 · Effective: 31 August 2026
This Privacy Notice (the "Notice") explains how Queuey AS processes Personal Data for which it is the Controller, and describes the rights available to the individuals whose Personal Data we process. It is provided in accordance with Articles 13 and 14 of the GDPR.
In this Notice, "Queuey", "we", "us" and "our" mean Queuey AS. "You" and "your" mean the individual whose Personal Data we process as Controller — for example an Authorised User, an account administrator, a billing or business contact, or a visitor to our website. Where you use the Service on behalf of a business or organisation, that business or organisation is the "Customer" under our Agreement; this Notice concerns you as an individual and does not vary the Agreement.
Capitalised terms used but not defined in this Notice have the meanings given to them in the Cloud Service Agreement and the Data Processing Agreement ("DPA"). References to "Personal Data", "Controller", "Processor", "Sub-processor", "Data Subject", "processing" and "Supervisory Authority" have the meanings given to them in the Data Protection Laws.
1. Who we are (Controller identity)
1.1. The Controller responsible for the Personal Data described in this Notice is:
- Queuey AS (organisation number 937 342 977; registered business address: c/o Sverre Senneset, Skjermvegen 66, 7023 Trondheim, Norway), operating the website queuey.ai.
- Data-protection contact: privacy@queuey.ai No Data Protection Officer has been appointed (not required under GDPR Article 37). Queuey is established in Norway (EEA), so no Article 27 representative is required..
1.2. If you have any question about this Notice or about how we process your Personal Data, please contact us at privacy@queuey.ai.
2. Scope of this Notice — Controller data only, not Customer/Event data
2.1. What this Notice covers. This Notice covers only the Personal Data that Queuey processes as a Controller in order to operate its business and provide the Service, namely: account and Authorised-User data; billing data; website and product usage, diagnostics and telemetry; security and audit logs; support communications; and marketing-contact data. This corresponds to the Controller processing referred to in clause 2.3 of the DPA.
2.2. What this Notice does not cover. This Notice does not apply to the Personal Data contained in Events, Endpoint configuration or other Customer Data that Queuey processes as a Processor (or Sub-processor) on behalf of, and on the documented instructions of, a Customer (together, "Customer Personal Data"). Queuey does not determine the purposes and means of processing Customer Personal Data. That processing is governed by the DPA and by the privacy notices of the relevant Customer, who is the Controller (or Processor) for that data. If you are a Data Subject whose Personal Data is contained in a Customer's Events and you wish to exercise your rights in respect of that data, please contact the relevant Customer; on request we will assist that Customer as described in the DPA.
3. Categories of Personal Data we process, and their sources
3.1. Depending on how you interact with Queuey, we process the following categories of Personal Data as Controller:
- (a) Account and Authorised-User data — such as your name, work email address, job title or role, the Customer/organisation you are associated with, your account and user identifiers, your preferences and settings, and metadata relating to your credentials (for example the fact and timing of sign-in, authentication and API-key events, and password/credential status). We do not store your password in plain text. Source: provided by you or by the Customer that authorises you as an Authorised User, and generated by your use of the Service.
- (b) Billing and payment data — such as billing contact name and email, billing address, organisation and tax/VAT identifiers, Subscription Plan and transaction history, and payment-status information. Card and payment-instrument details are collected and processed by our payment processor, Stripe, and are not stored by Queuey. Source: provided by you or the Customer, and returned to us by Stripe (see clause 5).
- (c) Website and product usage, diagnostics and telemetry — such as pages viewed, features used, actions taken in the console, device and browser information, approximate location derived from IP address, log and diagnostic data, and error/performance telemetry. Source: generated automatically when you visit our website or use the Service; see also clause 10 (Cookies).
- (d) Security and audit logs — such as IP addresses, timestamps, request and access metadata, and records of security-relevant and administrative events, processed to secure and monitor the Service, prevent and investigate abuse, and maintain accountability. Source: generated automatically by your use of the Service.
- (e) Support and other communications — such as the content of messages, tickets and correspondence you send to us (for example to privacy@queuey.ai, abuse@queuey.ai, legal@queuey.ai or a support channel), and our records of those interactions. Source: provided by you.
- (f) Marketing-contact data — such as your name, work email and marketing preferences, where you have subscribed to updates or where we contact you about the Service in reliance on legitimate interests. Source: provided by you or generated from your interactions with us (Queuey does not currently send marketing communications; this category applies only if marketing is introduced.).
3.2. We do not seek to collect special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) in the course of the Controller processing described in this Notice, and ask that you do not provide such data to us other than where strictly necessary.
4. Purposes and legal bases (Article 6)
4.1. We process your Personal Data for the following purposes and on the following legal bases under Article 6(1) of the GDPR:
| Purpose | Categories (clause 3) | Legal basis |
|---|---|---|
| Providing, administering and securing your account and the Service; authenticating Authorised Users; providing support | (a), (c), (d), (e) | Performance of a contract, Article 6(1)(b), where you are the contracting party; and our legitimate interests, Article 6(1)(f), in administering and supporting the account relationship where you are an Authorised User of a Customer that is the contracting party (see clause 4.2) |
| Billing, invoicing, collection of Fees and management of the customer relationship | (a), (b) | Performance of a contract, Article 6(1)(b); and compliance with a legal obligation, Article 6(1)(c), including Norwegian bookkeeping and tax law |
| Ensuring the security, integrity, availability and proper operation of the Service; preventing, detecting and investigating fraud, abuse and misuse; diagnostics and improving the Service | (c), (d), (e) | Our legitimate interests, Article 6(1)(f), in operating a secure, reliable and improving service, and in protecting Queuey, our Customers and Data Subjects (see clause 4.2) |
| Complying with our legal obligations and responding to lawful requests from authorities, and establishing, exercising or defending legal claims | (a)–(e) | Compliance with a legal obligation, Article 6(1)(c); and our legitimate interests, Article 6(1)(f), in the establishment, exercise or defence of legal claims |
| Sending you marketing or product communications about the Service | (f) | Your consent, Article 6(1)(a), where consent is required; or our legitimate interests, Article 6(1)(f), in promoting the Service to business contacts, in each case subject to your right to opt out at any time No marketing e-mail is currently sent. If introduced, Queuey will rely on consent, or on the existing-customer exception in the Norwegian Marketing Control Act (markedsføringsloven § 15) with opt-out. |
4.2. Legitimate interests. Where we rely on legitimate interests (Article 6(1)(f)), we have assessed that those interests are not overridden by your interests or fundamental rights and freedoms, taking into account your reasonable expectations and the safeguards we apply. You may ask us for more information about that assessment, and you have the right to object as described in clause 8.
5. Recipients and Sub-processors
5.1. We share your Personal Data only as necessary for the purposes described in clause 4, and only with the following categories of recipients:
- (a) Service providers acting on our behalf (Sub-processors), who process Personal Data under written contracts requiring appropriate security and confidentiality and permitting processing only on our instructions. Our principal Sub-processors for the Controller processing described in this Notice are:
| Recipient (legal entity) | Purpose | Location |
|---|---|---|
| Microsoft Azure — Microsoft Ireland Operations Limited | Cloud hosting and managed database for the Service and our systems | Norway East (EEA) (administration and support are performed from Norway, within the EEA) |
| Stripe — Stripe Payments Europe, Limited | Payment and billing processing | EEA (Stripe Payments Europe, Limited, Ireland); transfers to Stripe, Inc. (United States) occur under Stripe's intra-group Standard Contractual Clauses |
| Resend — Resend, Inc. | Transactional and notification email delivery | United States — Resend, Inc. is certified under the EU-US Data Privacy Framework (including the UK Extension), and its Data Processing Addendum additionally incorporates the EU Standard Contractual Clauses |
- (b) Stripe as an independent controller. In addition to acting as our processor for the billing we instruct, Stripe processes certain payment, fraud-prevention and compliance data as an independent controller for its own regulatory and risk purposes. That processing is governed by Stripe's own privacy policy (https://stripe.com/privacy).
- (c) Professional advisers — such as our lawyers, accountants, auditors and insurers, where necessary and under duties of confidentiality.
- (d) Authorities, courts and other third parties — where we are required or permitted to disclose Personal Data to comply with a legal obligation, respond to a lawful request, or establish, exercise or defend legal claims.
- (e) Successors in a corporate transaction — where Queuey is involved in a merger, acquisition, financing, reorganisation or sale of assets, Personal Data may be disclosed to a counterparty and its advisers, subject to appropriate confidentiality protections.
5.2. We do not sell your Personal Data, and we do not share it for third parties' own independent marketing purposes.
5.3. A current list of the Sub-processors that process Customer Personal Data is maintained under the DPA; this clause 5 concerns the recipients of the Controller data described in this Notice.
6. International transfers
6.1. Our primary processing takes place within the EEA. The Service and its managed databases are hosted on Microsoft Azure in the Norway East region, which is within the EEA.
6.2. Where a recipient (for example Stripe or Resend) processes Personal Data outside the EEA in a country not covered by an adequacy decision, we ensure that the transfer is protected by an appropriate safeguard under the Data Protection Laws — in particular the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with any supplementary technical, organisational and contractual measures reasonably necessary to ensure an essentially equivalent level of protection For United States recipients Queuey relies on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on Standard Contractual Clauses with supplementary measures. Specifically: Resend, Inc. is certified under the EU-US Data Privacy Framework (including the UK Extension); OpenAI is engaged via OpenAI Ireland Limited (EEA), with onward transfers to the United States covered by the Standard Contractual Clauses incorporated in OpenAI's Data Processing Addendum..
6.3. You may request a copy of the safeguards we rely on for a given transfer by contacting us at privacy@queuey.ai.
7. Retention
7.1. We retain your Personal Data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting, tax or reporting requirements, and to establish, exercise or defend legal claims. Our retention approach is, in summary:
- (a) Account and Authorised-User data — retained for the life of the account and for a limited period after the account is closed or your authorisation ends deletion or anonymisation within ninety (90) days of account closure.
- (b) Billing and transaction records — retained for the period required by applicable accounting and tax law, including the Norwegian Bookkeeping Act (bokføringsloven) five (5) years for primary accounting records, per the Norwegian Bookkeeping Act.
- (c) Website and product usage, diagnostics and telemetry — retained for ninety (90) days, after which it is deleted or aggregated/anonymised.
- (d) Security and audit logs — retained for thirty (30) days to support security, investigation and accountability.
- (e) Support and other communications — retained for twenty-four (24) months after the matter is closed.
- (f) Marketing-contact data — retained until you unsubscribe or withdraw consent, and thereafter only as needed to honour your opt-out.
7.2. When Personal Data is no longer required, we delete it or irreversibly anonymise it. Deletion from encrypted backups occurs in accordance with our backup rotation cycle seven (7) days — the point-in-time-recovery window, after which the data is overwritten or destroyed.
8. Your rights
8.1. Subject to the conditions and exceptions in the Data Protection Laws, you have the right to:
- (a) access your Personal Data and obtain information about how we process it;
- (b) request rectification of inaccurate or incomplete Personal Data;
- (c) request erasure of your Personal Data ("right to be forgotten");
- (d) request restriction of processing in certain circumstances;
- (e) receive your Personal Data, where processing is based on consent or contract and carried out by automated means, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller (data portability);
- (f) object to processing based on our legitimate interests (Article 6(1)(f)), on grounds relating to your particular situation, and to object to direct marketing at any time, after which we will stop processing your Personal Data for that purpose; and
- (g) withdraw consent at any time, where we rely on your consent, without affecting the lawfulness of processing carried out before withdrawal.
8.2. How to exercise your rights. You may exercise your rights by contacting us at privacy@queuey.ai. We may need to verify your identity before acting on a request. We will respond without undue delay and in any event within one month of receipt, which we may extend by up to two further months for complex or numerous requests, in which case we will inform you. Exercising these rights is generally free of charge, although we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by the Data Protection Laws.
8.3. Automated decision-making. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Queuey does not carry out such processing today; if introduced, this notice will be updated first with its logic, significance and safeguards).
9. Complaints to the Supervisory Authority
9.1. If you have a concern about how we process your Personal Data, we encourage you to contact us first at privacy@queuey.ai so that we can try to resolve it. You also have the right to lodge a complaint with a Supervisory Authority, in particular in the EEA Member State of your habitual residence, place of work, or the place of the alleged infringement.
9.2. Queuey's lead Supervisory Authority is the Norwegian Data Protection Authority (Datatilsynet) (Postboks 458 Sentrum, 0105 Oslo, tel. +47 22 39 69 00, www.datatilsynet.no).
10. Cookies and analytics
10.1. Our website and console use cookies and similar technologies that are strictly necessary for the site to function, and, subject to your choices where consent is required, cookies for preferences and for measuring and improving usage The website currently sets no analytics or third-party cookies — only strictly necessary items are used. If analytics are introduced, a consent mechanism will be deployed first..
10.2. Where a separate cookie notice or cookie-consent tool is provided, it sets out further detail about the cookies we use and how you can manage them No consent tool is currently needed: only strictly necessary cookies are set..
11. Security
11.1. We implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, consistent with the measures described in Schedule 2 to the DPA. No system can be guaranteed to be completely secure; where required by law, we will notify you and/or the Supervisory Authority of a Personal Data Breach affecting your Personal Data.
12. Changes to this Notice
12.1. We may update this Notice from time to time to reflect changes in our processing, in the Service, or in legal requirements. We will post the updated Notice at queuey.ai with a revised "Last updated" date and, where the changes are material, provide additional notice by appropriate means (for example by email to your registered contact address or through the Service). Your continued use of the Service after an update takes effect is subject to the then-current Notice.
13. How to contact us
13.1. For any matter relating to this Notice or your Personal Data, contact us at privacy@queuey.ai. Abuse may be reported to abuse@queuey.ai, and other legal matters to legal@queuey.ai Written enquiries: Queuey AS, c/o Sverre Senneset, Skjermvegen 66, 7023 Trondheim, Norway..