Privacy Policy

Effective Date: September 11, 2026

Your privacy and trust are important to us. This Privacy Policy explains how ICESTAT (“ICESTAT”, “we”, “us”, “our”) processes personal data when you visit our website or interact with us. It also clarifies how CQ — our anonymization and analytics module for banks — handles aggregated datasets.

This policy applies only to the ICESTAT website and marketing interactions. CQ bank integrations are governed by separate data‑processing agreements.

1. Who We Are

ICESTAT is the publisher of CQ, a data‑governance control layer used by European banks to transform aggregated ATH/CTH/CTF transaction datasets into anonymized, regulatory‑safe insights.

For website visitors, ICESTAT acts as data controller.

For bank‑provided aggregated datasets processed inside CQ, ICESTAT acts as data processor, and banks remain the data controllers of their transaction data.

2. What This Policy Covers

This policy applies only to:

  • the ICESTAT website

  • contact forms

  • newsletter interactions

  • marketing communications

It does not apply to bank integrations or CQ’s processing of aggregated datasets, which are governed by bank‑specific data‑processing agreements.

3. What Personal Data We Collect on the Website

We collect only the minimum data required to operate the website and respond to inquiries:

3.1. Data you provide
  • Name

  • Email address

  • Company / role

  • Message content (contact form)

3.2. Data collected automatically
  • IP address (for security + analytics)

  • Device type, browser, OS

  • Pages visited, time on page

  • Cookie preferences

3.3. Cookies

We use only:

  • Essential cookies (site functionality)

  • Analytics cookies (anonymous usage statistics)

We do not use advertising cookies, fingerprinting, or cross‑site tracking.

4. What Data We Do Not Collect

ICESTAT does not collect:

  • payment card numbers

  • bank account numbers

  • transaction‑level personal data

  • PAN, names, addresses, or cardholder identifiers

  • CCTV footage

  • location tracking

  • children’s data

  • app usage data (ICESTAT has no consumer apps)

CQ processes only aggregated datasets provided by banks.

5. CQ’s Data Model

CQ processes aggregated ATH/CTH/CTF datasets, such as:

  • merchant‑level aggregates

  • MCC‑level aggregates

  • postal‑code aggregates

  • demographic segment aggregates

CQ never receives:

  • identifiable cardholder data

  • PAN

  • names

  • addresses

  • transaction‑level personal identifiers

CQ applies:

  • anonymization

  • minimization

  • pseudonymization

  • regulatory‑safe transformation

  • GDPR, ePrivacy, PCI DSS, and DORA controls

Banks remain controllers of their transaction data. ICESTAT acts strictly as processor.

6. Legal Basis for Processing

We process personal data on the website under:

  • Legitimate interest (analytics, security, site operation)

  • Consent (newsletter signup)

  • Contract (responding to inquiries or requests)

7. How We Use Website Data

  • Respond to contact requests

  • Provide information about CQ

  • Improve website performance

  • Maintain security and prevent abuse

  • Send newsletters (only with consent)

We do not sell, rent, or share personal data with third‑party marketers.

8. Data Sharing

ICESTAT uses third‑party service providers for different parts of its operations:

Website Hosting (Marketing Site Only)

The public ICESTAT website is hosted on Bluehost, a US‑based provider. As a result, limited technical data (such as IP addresses and device metadata) may be transferred outside the EU. These transfers are protected using Standard Contractual Clauses (SCCs) and additional safeguards required under GDPR.

CQ Infrastructure (Bank Deployments)

CQ does not run on Bluehost. CQ operates exclusively on EU‑resident cloud infrastructure (AWS EU regions or Microsoft Azure EU regions), ensuring that no bank‑provided data ever leaves the EU. CQ processes only aggregated ATH/CTH/CTF datasets, never identifiable cardholder data.

We do not sell or share personal data with third‑party marketers. We only share data with service providers who support website operation, security, analytics, or communication.

9. International Transfers

Website hosting may involve transfers to the United States. These transfers are protected using:

  • Standard Contractual Clauses (SCCs)

  • Additional technical and organizational safeguards

CQ bank data remains fully within the EU.

10. Data Retention

  • Contact form data: 12–24 months

  • Newsletter data: until you unsubscribe

  • Analytics data: 12–26 months

CQ bank data retention is governed by bank contracts and is not part of this website policy.

11. Your Rights

You have the right to:

  • Access your data

  • Correct inaccuracies

  • Request deletion

  • Object to processing

  • Request portability

  • Withdraw consent

  • Lodge a complaint with your local Data Protection Authority

12. Contact

Controller (pre‑incorporation):

ICESTAT (forming entity)

Represented by: Snorri H. Gudmundsson

Email: info@icestat.com

Location: Sitges, Spain

LinkedIn: https://www.linkedin.com/company/icestat/

You may contact us for any questions regarding this Privacy Policy or to exercise your GDPR rights (access, correction, deletion, objection, portability, or withdrawal of consent).