At FQ Central, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our AI-powered services and platforms. We comply with the General Data Protection Regulation (GDPR) and applicable Greek and European Union data protection laws.
Last Updated: January 7, 2026
Version: 2.0
Effective Date: January 7, 2026
FQ Central ("FQ," "we," "us," or "our") is an AI solutions provider established in 2025, with its registered office in Athens, Greece. We provide artificial intelligence solutions through our platforms including Reveal, AI Demonstration Hub, AI Real Estate Agents, and QA Monitoring Agents, as well as consulting services in AI strategy, implementation, and quality assurance.
This Privacy Policy applies to:
By using our services, you acknowledge that you have read this Privacy Policy. Your use of our services is subject to your agreement with our Terms of Service and your rights under applicable data protection law, including GDPR.
We collect information necessary to provide and improve our services. We adhere to the principles of data minimization and purpose limitation under GDPR. The categories of personal data we may collect include:
We only collect personal data that is necessary for the specific purposes outlined in this policy. We regularly review our data collection practices to ensure compliance with this principle.
We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activities. For detailed information, please see Section 10 (Cookies & Tracking Technologies) and our separate Cookies Policy.
We process your personal data only for lawful purposes and in accordance with the legal bases provided under GDPR Article 6. We use your information for the following purposes:
As an AI solutions provider, we utilize artificial intelligence and machine learning technologies to process data and provide insights. This section provides transparency about our AI processing activities in compliance with GDPR and the EU AI Act.
Our AI systems may perform the following types of processing, depending on the services you use:
We employ privacy-preserving techniques in our AI systems, including data minimization, pseudonymization, and aggregation. When training or improving AI models, we use only aggregated and anonymized data that cannot reasonably identify individuals.
You have specific rights related to AI processing of your data under GDPR:
We do not sell your personal information to third parties. We may share your data only in the following limited and specific circumstances:
We may engage carefully selected third-party service providers to support our operations. These processors are contractually obligated to protect your data and use it only for the specific purposes we authorize. Examples may include:
In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website at least 30 days prior to any such change in ownership or control of your personal information, and you will have the opportunity to delete your account before the transfer.
We may disclose personal data when required by law or when we believe in good faith that disclosure is necessary to:
We may share aggregated, anonymized data that cannot reasonably be used to identify you with research institutions, business partners, or the public through reports and case studies. Such data does not constitute personal data under GDPR.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, as a startup company, we acknowledge that we do not currently hold formal security certifications.
We employ industry-standard security practices including:
In the event of a personal data breach, we will notify affected individuals and the Hellenic Data Protection Authority (HDPA) within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Notifications will include the nature of the breach, likely consequences, and measures taken or proposed to address it.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
When retention periods expire or upon valid deletion requests:
We may retain data beyond standard periods when:
As we operate in the European Union (Greece), you have comprehensive rights under the General Data Protection Regulation (GDPR). These rights include:
You have the right to request confirmation of whether we process your personal data and to obtain a copy of your personal data. We will also provide information about the processing, including purposes, categories of data, recipients, and retention periods.
You have the right to request correction of inaccurate personal data and to have incomplete personal data completed.
You have the right to request deletion of your personal data when:
This right is not absolute. We may need to retain certain data to comply with legal obligations (e.g., tax records) or for the establishment, exercise, or defense of legal claims.
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as CSV or JSON) and to transmit that data to another controller, where technically feasible.
You have the right to object to:
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. You have the right to obtain human intervention, express your point of view, and contest such decisions.
To exercise any of these rights, please contact us at:
You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) if you believe we have violated your data protection rights:
Hellenic Data Protection Authority
1-3 Kifissias Ave., Athens 115 23, Greece
Phone: +30 210 6475 600
Email: contact@dpa.gr
Website: www.dpa.gr
FQ Central operates from Greece (European Union). However, we may transfer, store, and process your personal data with service providers located outside the European Economic Area (EEA), including in the United States.
For transfers to countries without an adequacy decision from the European Commission, we rely on:
You have the right to:
We use cookies and similar tracking technologies to collect information about your browsing activities and improve your experience on our website and platforms.
You can control cookies through:
Blocking strictly necessary cookies may affect platform functionality and prevent you from using certain features. For detailed information, please see our separate Cookies Policy.
Our services are not directed to individuals under the age of 16 (or the applicable age of consent in your jurisdiction), and we do not knowingly collect personal information from children.
Age Restriction: You must be at least 18 years old (or the age of consent in your country) to use our services. If you are under this age, you may not provide any personal information through our platforms.
If we become aware that we have collected personal information from a child without appropriate parental consent, we will take immediate steps to delete that information from our systems. If you believe we have collected information from a child, please contact us immediately at corporate@fq-central.com.
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations.
Your continued use of our services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you may:
We encourage you to review this Privacy Policy regularly to stay informed about how we protect your information. The most current version is always available at https://fq-central.com/privacy-policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
This Privacy Policy and all matters relating to your privacy rights shall be governed by and construed in accordance with the laws of the Hellenic Republic (Greece), without regard to its conflict of law provisions.
Any disputes arising out of or relating to this Privacy Policy, including but not limited to the interpretation, validity, or enforcement of data protection rights, shall be subject to the exclusive jurisdiction of the courts of Athens, Greece.
EU Residents: Nothing in this clause affects your rights under GDPR or your right to lodge a complaint with your local supervisory authority or the Hellenic Data Protection Authority.
This Privacy Policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 and Greek Law 4624/2019 on the protection of personal data. FQ Central does not currently hold ISO 27001, ISO 42001, SOC 2, or other formal security certifications. We implement security measures appropriate to our size and resources as a startup company. While we strive to protect your personal data using reasonable security measures, we cannot guarantee absolute security. As with any internet-based service, there are inherent risks associated with data transmission and storage. As our company grows and our services evolve, we will continue to enhance our data protection practices and may pursue relevant security certifications in the future.