Legal
Privacy policy
Last updated 2026-09-25 · CS Cloud Ltd
This policy explains how CS Cloud Ltd collects and uses personal data when you visit our website or use QueuePower. It covers the data we hold as a controller. Data your customers submit through support tickets is processed on your instructions as a processor, and that is governed by our Data processing agreement.
1. Who we are
CS Cloud Ltd, company number 12922625, registered at 1 Thegn Walk, Fleet, Hampshire, GU51 1GQ, United Kingdom. Our data protection contact is reachable at privacy@queuepower.com.
2. Data we collect as a controller
Account data. When you create a workspace or are invited to one: your name, email address, role, sign-in metadata (timestamps, IP address, device information), and the company name and support address you enter during onboarding. Authentication is operated by Clerk on our behalf.
Billing data. When you subscribe: billing contact, company name, VAT number if you give one, and invoice history. Payment card details are collected and held by Stripe; we never see the full card number.
Usage and audit data.Actions taken in the product are recorded in your workspace’s audit log (who did what, when), which is visible to your administrators and to us for support and security purposes. We also collect server logs with personal data redacted, and error reports.
Correspondence. Emails you send us and our replies.
Website visitors. Our public pages set no analytics or advertising cookies. To see how many people visit and which pages they read, we keep a cookieless, aggregate visit log: the page, the referring site, country, device type, and a visitor identifier that is a one-way hash of your IP address and browser details with a key that changes every day, so it cannot identify you or follow you across days. Visit logs are deleted after 90 days. We also receive standard server logs (IP address, user agent, pages requested) from our hosting provider, retained briefly for security and capacity planning.
3. How and why we use it
- To provide the Service — creating and securing your account, running your workspace, sending operational emails such as invitations, usage alerts, and billing notices. Lawful basis: performance of our contract with you.
- To bill you — processing payments, issuing invoices, handling tax. Lawful basis: contract and legal obligation.
- To keep the Service secure and reliable — detecting abuse, investigating incidents, maintaining audit trails. Lawful basis: legitimate interests in operating a secure multi-tenant platform.
- To support you — answering your questions and diagnosing problems, which may involve our staff viewing data in your workspace with your permission. Lawful basis: contract and legitimate interests.
- To tell you about the product — occasional emails about material changes or new capabilities. Lawful basis: legitimate interests; you can opt out of non-operational email at any time.
4. Artificial intelligence
The Service sends support-ticket content to Anthropic, our AI provider, to classify requests and draft replies. Before any content is sent, customer names and email addresses are replaced with placeholders; the original values never leave our systems and are re-inserted into the draft only after it returns. Our contract with Anthropic prohibits the use of your content to train models.
Where you enable unattended AI resolution for a category, the AI may send a reply or close a ticket without a person reviewing it first. This is a configuration choice made by your administrators; every such action is recorded in the audit log and can be reversed. We do not make decisions with legal or similarly significant effects about individuals on your behalf.
6. International transfers
Some of our providers are located in the United States. Where personal data is transferred outside the United Kingdom or European Economic Area we rely on the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses, together with the providers’ own security commitments, or on an adequacy decision where one applies.
7. How long we keep it
- Account and workspace data: for the life of your subscription plus 30 days in a recoverable state, after which it is deleted from live systems.
- Billing records: seven years, to meet UK tax and accounting obligations.
- Audit logs: for at least the retention period of your plan, and for as long as needed to investigate a security incident.
- Server logs: up to 30 days.
- Correspondence: up to two years after our last exchange.
8. Security
Each customer’s workspace is isolated at the database using row-level security enforced by a non-bypass database role. Customer email addresses and stored credentials are encrypted at the application layer before being written to disk. All traffic is encrypted in transit. A fuller description is published on our security page.
9. Your rights
Under UK and EU data protection law you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to certain processing, to data portability, and to withdraw consent where processing is based on it. Write to privacy@queuepower.com and we will respond within one month.
If your request concerns data that one of our customers holds about you in their support workspace, we will pass it to them, because they, not we, decide how that data is used.
You may complain to the UK Information Commissioner’s Office (ico.org.uk) or, in the EU, to your local supervisory authority. We would appreciate the chance to address your concern first.
11. Changes to this policy
We will post any changes here and update the date at the top. For material changes affecting how we use your data we will also email your workspace administrators.