// LEGAL

Privacy policy

LAST UPDATED: 26 July 2026

This policy explains what personal data we process when you use qontexta.ai, why, and for how long. It starts with the part that rarely appears in one of these: where your data is not.

01

1. Where your data lives

Your semantic model is not here. It lives in the Git repository you designate, under your own GitHub account. qontexta reads from it and writes to it on your instruction, and keeps only a rebuildable index so it can list and search quickly. If you stop using the service, your model stays with you.
Your warehouse data is not copied either. There is no replication and no ingestion: qontexta reads the schema and runs read-only queries against your database when someone asks a question. Results go to whoever asked and are not stored.

What we do keep is in section 3, and it is what the service cannot run without: your account, your billing details, and the encrypted credentials we use to reach your warehouse and your repository.

02

2. Data controller

Company name: Mind Analytics SL
Tax ID: B86740743
Registered office: Ronda de Sant Pere 16, 08010 Barcelona, Spain
Data protection contact: lopd@wearemind.io
This policy applies to qontexta.ai and to the qontexta platform.

03

3. What data we process

  • Identifiers: name, surname and email of whoever creates the account or is invited to it.
  • Organisation: tenant name, associated domains, and who belongs to the team with which role.
  • Billing: company name, tax ID, address and tax details when you subscribe to a paid plan. Payment is processed by Stripe; we never see your card number.
  • Technical and usage: IP address, activity logs and product analytics.
  • Credentials: those of your data warehouse and the access to your repository, encrypted and never shown again by the interface.

Your warehouse metadata (table and column names, comments and a sample of rows) and your model definitions are processed on behalf of the customer, who is their controller; with regard to those, Mind Analytics SL acts as a processor.

04

4. Purposes and legal bases

  • Providing the service — creating and keeping your account, giving access, connecting your warehouse and your repository, support and billing. Basis: performance of the contract.
  • Answering enquiries — replying to what you write to us. Basis: consent.
  • Marketing communications — product news. Basis: consent, withdrawable at any time.
  • Legal compliance — accounting and tax obligations. Basis: legal obligation.
  • Improving the product — aggregated usage analytics. Basis: legitimate interest.
05

5. The AI assistant

The assistant runs on qontexta’s own account: you do not bring a key. To propose a model it needs to read your warehouse metadata and any definitions you already have, and that is sent to the provider we operate with — Anthropic, through Google Cloud Vertex AI — which processes it to produce the answer.

The provider does not train its models on it. For each call we record usage (tenant, user, feature and token count) so we can measure cost and apply plan limits; we do not store the content of the conversation.

06

6. How long we keep it

For as long as the contractual relationship lasts and, afterwards, blocked and access-restricted for the applicable limitation periods. Data processed on your consent, until you withdraw it. When you delete your account we delete your encrypted credentials and the model index; we do not touch your repository or your warehouse, because they are yours.

07

7. Who else is involved

We do not disclose your data to third parties except where legally required. We do rely on providers acting as processors:

  • Google Cloud — infrastructure and the AI provider (Vertex AI), in EU data centres.
  • Neon — managed database (EU).
  • GitHub — the repository is yours and sits in your account; qontexta accesses it with the permission you grant.
  • Stripe — payments and subscriptions.
  • Mailgun — transactional email. Mailchimp — marketing communications.

Where a transfer leaves the European Economic Area, it relies on an adequacy decision or on standard contractual clauses.

08

8. Your rights

You may request access, rectification, erasure, restriction, portability and objection by writing to lopd@wearemind.io, proving your identity. You may also complain to the Spanish Data Protection Agency (www.aepd.es).

09

9. Security

We apply appropriate technical and organisational measures: encryption in transit (HTTPS/TLS), encryption at rest of sensitive data — warehouse credentials and repository access tokens among them — and role-based access control. qontexta’s access to your warehouse is read-only.

10

10. Changes to this policy

We may update it to reflect regulatory or service changes. The current version will be published on this page with its date and, if the change is substantial, we will tell you through the usual channels.