Legal · Privacy

Privacy Policy

Plain-language explanation of what data we collect, what we don't, and what you can do about it. Written to be read, not skimmed past.

Last updated: 2026-05-20 Applies worldwide; written under EU/Austrian law

1. Who we are

This privacy policy is issued by:

pagu.at EDV Management GmbH

Spaunstraße 128, 4020 Linz, Austria

Executive director: Mag. Paul Gutenbrunner

VAT ID: ATU 51053201 · Commercial register: FN 205640m (Landesgericht Linz)

Privacy: privacy@webqsee.com · Support: support@webqsee.com

We have appointed a Data Protection Officer. You can reach them directly at data-protection@pagu.at for any question about how we handle your personal data.

2. What this policy covers

This policy applies to every surface where we may process personal data on behalf of pagu.at EDV Management GmbH:

  • The marketing site at webqsee.com.
  • The web-mode viewer at view.webqsee.com.
  • The webQsee browser extension for Chrome and Microsoft Edge (Manifest V3).
  • The backend API at app.webqsee.com.
  • The checkout flow that handles billing.

Different surfaces process different data, we'll be explicit about which is which throughout.

3. The data we collect

3.1 Account registration

If you create a webQsee account, we store:

  • Your email address (required, used as login).
  • Your name (optional, used in greetings and invoices if filled in).
  • A bcrypt hash of your password, never the password itself.
  • An OAuth identifier if you sign in via Google or GitHub (so we recognise you next time without storing the provider's password).

3.2 Settings & configuration

So your extension can sync between devices, we store on our servers:

  • Your rule definitions for error detection.
  • Gallery metadata: capture titles, descriptions, status flags, tags.
  • Your team membership and team-shared settings.
  • The connection parameters for your S3 bucket, endpoint, region, bucket name and access key ID. The matching AWS secret access key never leaves your extension; we have no way to retrieve it.

3.3 Server logs

Like every web service, our infrastructure writes operational logs for security and abuse detection: IP address, user agent, timestamp, request URL and HTTP status. These logs are kept for up to 30 days and then deleted.

3.4 Payment

Payments are handled by Braintree, a PayPal Inc. service. We do not see, store or have any access to your card numbers, Braintree passes us a token. We do keep invoice records (subscription tier, amount, country, VAT data) for seven years, as required by §132 of the Austrian Bundesabgabenordnung (federal fiscal code).

3.5 The marketing website

This website runs no analytics, no tracking pixels and no advertising scripts, and it sets no cookies. There is no contact form to protect either, you reach us by email.

The one request that leaves our server is the web font stylesheet, delivered by Google Fonts (Google LLC), which necessarily discloses your IP address to Google. Everything else, stylesheets, scripts, images and icon fonts, is served from webqsee.com itself. Beyond that, the only record of your visit is the server log described in 3.3.

4. What we don't collect

The actual recordings, what most products would call "the data", never reach our servers in their default configuration. Concretely, we do not collect or process:

  • Behavior Reports.
  • Event Snapshots.
  • Screenshots and screencast/video files.
  • HTTP request and response bodies.
  • Console logs, WebSocket frames, Server-Sent Event streams.

All of the above are written to your browser's IndexedDB and stay there. If you connect Cloud Gallery, the extension uploads them directly from your browser to your own Amazon S3 bucket (or any S3-compatible target you configure, such as a self-hosted min.io). The bytes flow browser-to-bucket and never pass through any webQsee server. webQsee servers only ever see the metadata index you choose to maintain.

5. How we use your data

  • Service provision, running the extension, sync, gallery, team features.
  • Billing, issuing invoices, processing subscription payments, complying with tax law.
  • Support, answering your emails and resolving the issues you report.
  • Security, detecting and blocking abuse, brute-force attempts, scraping.
  • Product improvement, aggregate, anonymised usage trends to decide what to build next.

We do not sell your data. We do not share it for marketing purposes. We do not train AI models on your captures.

6. Lawful basis (GDPR Art. 6)

  • Contract (Art. 6(1)(b)), processing necessary to deliver the service you signed up for, including paid subscriptions.
  • Legitimate interest (Art. 6(1)(f)), server logs for security and abuse detection; pseudonymised analytics to improve the product.
  • Consent (Art. 6(1)(a)), non-essential cookies, marketing emails. You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)), keeping invoice records for tax purposes.

7. Cookies

This marketing site sets no cookies at all. The app at app.webqsee.com uses the small number listed below. The browser extension itself does not set third-party cookies on the pages you visit.

CookieSet byPurposeRetention
sessionwebQseeKeep you signed into app.webqsee.com.Session / 30 days "remember me"
XSRF-TOKENwebQseeCSRF protection for form submissions.Session
cookie-consentwebQseeRemember your cookie preferences.12 months

8. Storage location and retention

All webQsee infrastructure runs in the European Union, Frankfurt and Austrian datacenters. Retention timetable:

  • Account data, kept until you delete your account. You can do that any time in your account settings, and we'll purge personal data within 30 days.
  • Server logs, 30 days, then deleted.
  • Invoices, 7 years, mandated by §132 of the Austrian Bundesabgabenordnung.
  • Captures, n/a, we don't store them. They live in your browser or your S3 bucket; you control retention there.

9. Sharing with third parties (subprocessors)

We share data with the following processors strictly to deliver the service. Each is covered by a Data Processing Agreement (Art. 28 GDPR).

ProcessorPurposeData shared
Amazon Web Services (your bucket)Cloud Gallery object storage.You configure it; we have no access to its contents.
Braintree / PayPal Inc.Payment processing.Card data, billing details.
Google LLCWeb fonts on webqsee.com (Google Fonts), and OAuth sign-in if you choose "Sign in with Google".IP address and user agent when a font is fetched; your Google account identifier if you use Google sign-in.
Anthropic PBCListed for completeness. No current in-product use. If AI assistance is ever introduced, this policy will be updated before any user data is sent.None today.
Transactional email provider (EU)Sending invoices, password resets, system notifications.Email address, message content.
EU hosting providerServer infrastructure, backups.All hosted data (encrypted at rest).

10. Your rights under GDPR

If you are in the EU/EEA you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure, the "right to be forgotten" (Art. 17).
  • Restriction of processing (Art. 18).
  • Data portability in a machine-readable format (Art. 20).
  • Object to processing based on legitimate interest (Art. 21).
  • Withdraw consent at any time without affecting prior processing (Art. 7).

To exercise any of these rights, write to privacy@webqsee.com. We respond within 30 days.

11. Security

  • TLS 1.2+ on every connection, to webqsee.com, view.webqsee.com, app.webqsee.com and the checkout.
  • AES-256 at rest where the underlying storage supports it.
  • bcrypt password hashes, your password is never stored in any form we can read.
  • Multi-factor authentication required for all staff access to production systems.
  • Principle of least privilege for internal access, audit logs for sensitive operations.

12. International transfers

Under normal operation, your data stays inside the European Union. The exception is if you choose to point Cloud Gallery to an S3 bucket outside the EU, say, us-east-1, in which case your captures travel to that region by your own configuration. That transfer is between your browser and your bucket; we are not a party to it. We recommend EU-region buckets for users handling EU personal data.

13. Children

webQsee is a developer/QA tool and is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@webqsee.com and we'll delete it.

14. Changes to this policy

For material changes, anything that changes what data we process, who receives it, or what your rights are, we'll email registered users at least 30 days before the change takes effect. For minor edits (typo fixes, restructuring, link updates) we'll simply update the "Last updated" date at the top of this page.

15. Contact us

pagu.at EDV Management GmbH

Spaunstraße 128, 4020 Linz, Austria

Privacy questions: privacy@webqsee.com

Data Protection Officer: data-protection@pagu.at

Product support: support@webqsee.com

Supervisory authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, Austria, dsb.gv.at