QueryCue is a brand of ucepts UG (haftungsbeschränkt). Contact for all privacy matters: info@querycue.io.
We are not required to appoint a data protection officer under § 38 BDSG. Your enquiry reaches us directly at the address above.
querycue.io runs on a dedicated server that we rent from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in a data centre in Frankfurt am Main, Germany. We administer the server ourselves; Hetzner provides the infrastructure and has no access to the content of our databases in the ordinary course of operations.
We have concluded a data processing agreement (Art. 28 GDPR) with Hetzner. No personal data is transferred outside the European Union through hosting.
Our web server automatically records information that your browser transmits when you visit the site:
Purpose and legal basis: operating the website securely and reliably, detecting and tracing attacks and abuse. Legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in a secure, functioning website. This data is not merged with other data sources and is not used to identify you.
Retention: log files are deleted after [[LOG_TAGE]] days.
We do not use tracking, analytics or advertising cookies, and we do not run a cookie banner, because we set no cookies that would require your consent.
The only cookies that occur are strictly necessary ones:
| Cookie | Purpose | Duration |
|---|---|---|
wordpress_logged_in_*, wordpress_sec_* | Keeps you signed in to your customer account after you click your sign-in link. Set only once you sign in — never for visitors who just browse the site. | 14 days, or until you sign out |
wp-settings-* | Stores interface preferences for signed-in users. | up to 1 year |
These cookies are strictly necessary to provide the service you explicitly requested (signing in). Legal basis: § 25 (2) no. 2 TDDDG and Art. 6 (1) (b) GDPR. They require no consent, and you cannot switch them off without losing the ability to sign in.
You can create an account to buy and manage a licence. We deliberately use no passwords. Instead, we send you a one-time sign-in link (“magic link”) by email.
Purpose: providing and securing your account. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures) and Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse of the sign-in form).
Retention: expired sign-in links are deleted automatically every day. Your account data is kept for as long as your account exists. You can ask us to delete your account at any time — see section 9. Statutory retention obligations under commercial and tax law (see section 8) remain unaffected.
Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (“Stripe”).
We never see or store your payment details. When you buy, you are redirected to Stripe’s own checkout page. Card numbers, bank details and similar payment data are entered there and processed exclusively by Stripe.
Stripe collects your billing address and payment details directly from you and reports the outcome of the payment back to us. From Stripe we store a customer ID and the status and expiry date of your plan — nothing else.
Legal basis: Art. 6 (1) (b) GDPR (performance of the contract). Stripe processes data in part on servers of its affiliate Stripe, Inc. in the USA. For such transfers, Stripe relies on the EU Standard Contractual Clauses and is certified under the EU–U.S. Data Privacy Framework. Details: stripe.com/privacy.
Retention: invoices and the associated data are retained for 10 years under statutory commercial and tax law obligations (§ 147 AO, § 257 HGB).
Customers with an active Pro plan can open support requests in their dashboard.
Please do not send us passwords, payment details or personal data of your own website visitors in a support request. If we need such information to help you, we will tell you how to transmit it safely.
Legal basis: Art. 6 (1) (b) GDPR (performance of the contract, including support).
Retention: support requests are retained for as long as they are needed to handle your enquiry and to answer follow-up questions, and are deleted afterwards on request. A request that has been closed is not automatically deleted. You can ask us to delete your support history at any time — see section 9.
We send transactional emails only: your sign-in link, a welcome message after a purchase, and support notifications. These emails are sent from our own mail server in the data centre in Frankfurt am Main — no external mail provider receives your address for this purpose.
Legal basis: Art. 6 (1) (b) GDPR. We do not send marketing emails without your separate, explicit consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time.
Outside our own infrastructure, personal data reaches only the following recipients:
| Recipient | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting (processor, Art. 28 GDPR) | Germany |
| Stripe Payments Europe, Ltd. | Payment processing | Ireland / USA (SCCs, Data Privacy Framework) |
| Tax advisor, auditors, authorities | Statutory accounting and tax obligations | Germany |
There is no one else. We use no analytics service, no advertising network, no CDN for fonts or scripts, and no customer relationship platform. We do not sell personal data.
Under the GDPR you have the right to:
One email to info@querycue.io is enough. We will respond within one month.
You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)You can browse querycue.io without providing any personal data. To create an account or buy a licence, we need your email address and, for a purchase, the billing information required by law. Without it, we cannot conclude or perform the contract.
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
This privacy policy covers querycue.io — our website and store. It does not describe what happens on your website when you install QueryCue Forms.
That distinction matters, and it is in your favour: the plugin sends no data to us. Form submissions collected with QueryCue Forms stay in the database of your own WordPress installation. There is no QueryCue cloud, no telemetry, no “phone home” with your visitors’ data. We never see the submissions your forms collect.
For those submissions, you are the controller under the GDPR — not us. Because no personal data flows to us, we do not act as your processor and a data processing agreement (Art. 28 GDPR) is not required for the operation of the plugin.
Optional features of the Pro edition can transmit data to third parties if you switch them on — for example a captcha provider (which receives your visitor’s IP address), an outbound webhook to a URL you choose, or a Calendly integration. These are off by default, you activate them deliberately, and you are responsible for reflecting them in your own privacy policy. The plugin tells you so in the settings screen.