Privacy Policy
Effective Date: September 11, 2026
Your privacy and trust are important to us. This Privacy Policy explains how ICESTAT (“ICESTAT”, “we”, “us”, “our”) processes personal data when you visit our website or interact with us. It also clarifies how CQ — our anonymization and analytics module for banks — handles aggregated datasets.
This policy applies only to the ICESTAT website and marketing interactions. CQ bank integrations are governed by separate data‑processing agreements.
1. Who We Are
ICESTAT is the publisher of CQ, a data‑governance control layer used by European banks to transform aggregated ATH/CTH/CTF transaction datasets into anonymized, regulatory‑safe insights.
For website visitors, ICESTAT acts as data controller.
For bank‑provided aggregated datasets processed inside CQ, ICESTAT acts as data processor, and banks remain the data controllers of their transaction data.
2. What This Policy Covers
This policy applies only to:
-
the ICESTAT website
-
contact forms
-
newsletter interactions
-
marketing communications
It does not apply to bank integrations or CQ’s processing of aggregated datasets, which are governed by bank‑specific data‑processing agreements.
3. What Personal Data We Collect on the Website
We collect only the minimum data required to operate the website and respond to inquiries:
3.1. Data you provide
-
Name
-
Email address
-
Company / role
-
Message content (contact form)
3.2. Data collected automatically
-
IP address (for security + analytics)
-
Device type, browser, OS
-
Pages visited, time on page
-
Cookie preferences
3.3. Cookies
We use only:
-
Essential cookies (site functionality)
-
Analytics cookies (anonymous usage statistics)
We do not use advertising cookies, fingerprinting, or cross‑site tracking.
4. What Data We Do Not Collect
ICESTAT does not collect:
-
payment card numbers
-
bank account numbers
-
transaction‑level personal data
-
PAN, names, addresses, or cardholder identifiers
-
CCTV footage
-
location tracking
-
children’s data
-
app usage data (ICESTAT has no consumer apps)
CQ processes only aggregated datasets provided by banks.
5. CQ’s Data Model
CQ processes aggregated ATH/CTH/CTF datasets, such as:
-
merchant‑level aggregates
-
MCC‑level aggregates
-
postal‑code aggregates
-
demographic segment aggregates
CQ never receives:
-
identifiable cardholder data
-
PAN
-
names
-
addresses
-
transaction‑level personal identifiers
CQ applies:
-
anonymization
-
minimization
-
pseudonymization
-
regulatory‑safe transformation
-
GDPR, ePrivacy, PCI DSS, and DORA controls
Banks remain controllers of their transaction data. ICESTAT acts strictly as processor.
6. Legal Basis for Processing
We process personal data on the website under:
-
Legitimate interest (analytics, security, site operation)
-
Consent (newsletter signup)
-
Contract (responding to inquiries or requests)
7. How We Use Website Data
-
Respond to contact requests
-
Provide information about CQ
-
Improve website performance
-
Maintain security and prevent abuse
-
Send newsletters (only with consent)
We do not sell, rent, or share personal data with third‑party marketers.
8. Data Sharing
ICESTAT uses third‑party service providers for different parts of its operations:
Website Hosting (Marketing Site Only)
The public ICESTAT website is hosted on Bluehost, a US‑based provider. As a result, limited technical data (such as IP addresses and device metadata) may be transferred outside the EU. These transfers are protected using Standard Contractual Clauses (SCCs) and additional safeguards required under GDPR.
CQ Infrastructure (Bank Deployments)
CQ does not run on Bluehost. CQ operates exclusively on EU‑resident cloud infrastructure (AWS EU regions or Microsoft Azure EU regions), ensuring that no bank‑provided data ever leaves the EU. CQ processes only aggregated ATH/CTH/CTF datasets, never identifiable cardholder data.
We do not sell or share personal data with third‑party marketers. We only share data with service providers who support website operation, security, analytics, or communication.
9. International Transfers
Website hosting may involve transfers to the United States. These transfers are protected using:
-
Standard Contractual Clauses (SCCs)
-
Additional technical and organizational safeguards
CQ bank data remains fully within the EU.
10. Data Retention
-
Contact form data: 12–24 months
-
Newsletter data: until you unsubscribe
-
Analytics data: 12–26 months
CQ bank data retention is governed by bank contracts and is not part of this website policy.
11. Your Rights
You have the right to:
-
Access your data
-
Correct inaccuracies
-
Request deletion
-
Object to processing
-
Request portability
-
Withdraw consent
-
Lodge a complaint with your local Data Protection Authority
12. Contact
Controller (pre‑incorporation):
ICESTAT (forming entity)
Represented by: Snorri H. Gudmundsson
Email: info@icestat.com
Location: Sitges, Spain
LinkedIn: https://www.linkedin.com/company/icestat/
You may contact us for any questions regarding this Privacy Policy or to exercise your GDPR rights (access, correction, deletion, objection, portability, or withdrawal of consent).
