QueBids (operated by Quecorex LLC) is fully committed to compliance with the General Data Protection Regulation (EU) 2016/679 and the UK GDPR. This page explains who we are as a data controller, the legal basis on which we process your personal data, your rights as a data subject, and how to exercise them. For any GDPR-related inquiry, contact our Data Protection Officer at [email protected].
01

Who We Are - Data Controller Details

FieldDetails
Data ControllerQuecorex LLC
Trading NameQueBids
Legal FormLimited Liability Company (LLC), Delaware, USA
Registered AddressDelaware, United States
Data Protection Officer QueBids DPO - [email protected]
EU Representative Contact [email protected] to request EU representative details
Platform URLquebids.com
๐Ÿ‡ช๐Ÿ‡บ GDPR Article 27 - EU Representative
As a non-EU establishment offering services to EEA data subjects, QueBids is in the process of designating an EU representative as required by GDPR Article 27. Contact our DPO for current representative details.
02

Lawful Basis for Processing

GDPR requires that every processing activity has a lawful basis. We rely on four lawful bases across our different processing activities:

Art. 6(1)(b)
Contract Performance
Processing necessary to deliver the services you subscribed to.
e.g. Account creation, tender alerts, billing
Art. 6(1)(f)
Legitimate Interests
Processing for fraud prevention, security, and platform improvement - balanced against your rights.
e.g. Security monitoring, usage analytics
Art. 6(1)(c)
Legal Obligation
Processing required to comply with law - tax records, court orders, regulatory requirements.
e.g. Invoice retention, law enforcement requests
Art. 6(1)(a)
Consent
Processing only where you have given clear, specific, freely given, and withdrawable consent.
e.g. Marketing emails, non-essential cookies
Processing Activities Mapped to Legal Basis
Processing ActivityLegal BasisCan You Object?
Account registration & managementContractNo (core service)
Subscription billing & invoicingContractLegal ObligationNo (legal requirement)
Tender alerts & notificationsContractVia account settings
Platform security & fraud preventionLegitimate InterestYes - contact DPO
Usage analytics & improvementLegitimate InterestYes - contact DPO
Marketing communicationsConsentYes - unsubscribe anytime
Non-essential cookiesConsentYes - cookie settings
Tax & financial recordsLegal ObligationNo (legal requirement)
03

Personal Data We Process

CategoryData PointsPurposeRetention
IdentityName, email, job title, companyAccount management, communicationsAccount lifetime + 90 days
AuthenticationHashed password, MFA tokens, session tokensSecurity, access controlActive sessions only
Financial Billing address, last 4 digits of card (via payment processor), invoices Payment processing, tax compliance7 years (legal obligation)
Usage DataPages visited, searches, tenders saved, feature usageService improvement, personalisation12 months rolling
TechnicalIP address, browser, device type, OSSecurity, fraud prevention, analytics12 months rolling
CommunicationsSupport tickets, feedback, emailsCustomer service, dispute resolution3 years from last contact
PreferencesNotification settings, saved searches, alert configurationsPersonalised service deliveryAccount lifetime
โœ… No Special Category Data
QueBids does not intentionally collect or process special category data (GDPR Article 9) such as health data, racial or ethnic origin, political opinions, religious beliefs, biometric data, or sexual orientation. Please do not submit such data through our platform.
04

Your 8 Rights Under GDPR

GDPR grants you eight enforceable rights over your personal data:

๐Ÿ‘
Article 15
Right of Access
Request a copy of all personal data we hold about you, including how we use it and who we share it with.
โœ๏ธ
Article 16
Right to Rectification
Correct inaccurate or incomplete personal data.
๐Ÿ—‘
Article 17
Right to Erasure
Request deletion of your data ("right to be forgotten") under certain conditions.
โธ
Article 18
Right to Restriction
Restrict how we process your data in certain circumstances.
๐Ÿ“ฆ
Article 20
Right to Portability
Receive your data in a structured, machine-readable format (JSON export).
๐Ÿšซ
Article 21
Right to Object
Object to processing based on legitimate interests or direct marketing.
๐Ÿค–
Article 22
Automated Decision-Making
Not be subject to decisions based solely on automated processing with legal effects.
โ†ฉ๏ธ
Article 7(3)
Withdraw Consent
Withdraw consent at any time without affecting prior processing.
05

How to Exercise Your Rights

To exercise any of your GDPR rights, you can:

  • Email: Send your request to [email protected] with the subject line "GDPR Rights Request - [Type of Request]"
  • Account Settings: Some rights (rectification, erasure, data export) can be exercised directly from your account dashboard
  • Identity Verification: We may need to verify your identity before processing your request to protect your data
  • Response Time: We will respond within 30 days (extendable to 60 days for complex requests)
  • No Fee: Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive
๐Ÿ“‹ What to Include in Your Request
Please provide: (1) Your full name and email address, (2) The specific right you wish to exercise, (3) Any relevant details to help us locate your data, (4) Proof of identity if requested.
06

International Data Transfers

QueBids is operated by Quecorex LLC, a company incorporated in Delaware, USA. Your data may be processed in the United States and the European Union.

For transfers of personal data from the EEA or UK to countries without an adequacy decision (such as the USA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.

Transfer Safeguards by Service Provider
Provider TypeServiceLocationSafeguard
Payment ProcessingPayment gatewayUSASCCs + DPA
Cloud InfrastructureHosting & computeUSA / EUSCCs + DPA
Email DeliveryTransactional emailUSASCCs + DPA
CDN & SecurityContent delivery & protectionUSASCCs + DPA
Database HostingManaged databaseEU / USASCCs + DPA

You may request a copy of the Standard Contractual Clauses in place with any of our sub-processors by contacting [email protected].

07

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements.

Data TypeRetention PeriodLegal Basis
Account dataDuration of account + 90 days after deletion requestContract / Legitimate Interest
Billing & invoices7 yearsLegal Obligation (tax law)
Support communications3 years from last interactionLegitimate Interest
Usage logs12 months (rolling)Legitimate Interest
Marketing consent recordsUntil consent withdrawn + 3 yearsLegal Obligation (proof of consent)
Fraud / security logs5 yearsLegitimate Interest
08

Data Processing Addendum (DPA)

If you are a business customer using QueBids to process personal data on behalf of your organisation, you may require a Data Processing Addendum (DPA) to comply with GDPR Article 28.

Request a DPA

Our standard DPA includes Standard Contractual Clauses (SCCs), sub-processor lists, security measures, and data subject rights assistance.

1
Email [email protected] with your company name and use case
2
Review and sign the DPA (typically within 5 business days)
3
Receive executed copy for your records
๐Ÿ“‹ Request DPA
09

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33)
  • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights (GDPR Article 34)
  • Provide clear information about the nature of the breach, likely consequences, and measures taken to address it
  • Document all breaches internally, regardless of whether notification is required
โš ๏ธ Security Incident Reporting
If you suspect a security incident or unauthorised access to your account, contact us immediately at [email protected].
10

Supervisory Authorities & Complaints

If you believe we have not handled your personal data in compliance with GDPR, you have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first at [email protected], but you are always entitled to go directly to the authority.

Key EU/EEA Supervisory Authorities
CountryAuthorityWebsite
๐Ÿ‡ฎ๐Ÿ‡ช IrelandData Protection Commission (DPC)dataprotection.ie
๐Ÿ‡ฌ๐Ÿ‡ง United KingdomInformation Commissioner's Office (ICO)ico.org.uk
๐Ÿ‡ฉ๐Ÿ‡ช GermanyFederal Commissioner for Data Protectionbfdi.bund.de
๐Ÿ‡ซ๐Ÿ‡ท France Commission Nationale de l'Informatique et des Libertรฉs (CNIL) cnil.fr
๐Ÿ‡ช๐Ÿ‡ธ SpainAgencia Espaรฑola de Protecciรณn de Datos (AEPD)aepd.es
11

Contact Our Data Protection Officer

For any questions, concerns, or requests regarding this GDPR Compliance page or our data practices, please contact our Data Protection Officer:

Get in Touch

Our DPO is here to help with all GDPR-related inquiries. We respond to all requests within 30 days.

โœ‰๏ธ
๐Ÿข
Registered Entity
Quecorex LLC, Delaware, United States