Skip to content
QAIYU

Legal

Privacy statement

What QAIYU does with your data, why, and how long it is kept.

Last updated on August 14, 2026.

Who processes your data

Goldstar-Capital Holding Ltd is the controller for the processing described on this page. You can reach us at info@qaiyu.com.

  • Company name: Goldstar-Capital Holding Ltd
  • Address: Unit 3, Office A, 1st Floor, 6-7 St Mary At Hill, EC3R 8EE London
  • Company number (Companies House): 17347660

We have not appointed a data protection officer. For a company of this size that is not required. Privacy questions reach us at the address above.

What we process and why

We collect no more than we need in order to help you. Per situation it looks like this.

When you contact us

When you email us or use the contact form, we process your name, your email address, your company website and whatever you write to us, in order to answer your question. The legal basis is our legitimate interest in ordinary business correspondence, and where a quote is involved, taking steps at your request prior to entering into a contract.

When you become a client

To carry out an engagement we process your company details, contact details, invoicing details and the data that arises from the work itself. The legal basis is performance of the contract we enter into with you; what applies within it is set out in our terms and conditions. A statutory obligation applies in addition for our accounting records.

Data an agent processes on your behalf

Where an agent handles work inside your systems, it processes the data in those systems. For that processing you are the controller and we are the processor, which means it is governed by a separate data processing agreement rather than by this page. What an agent may access is limited to what the agreed process requires, and it is set out in writing before anything is built.

Access to your systems

Building and running an agent usually requires access to one or more of your systems. We request only the access the work requires, we keep those credentials in a password manager, and we remove them within fourteen days of the engagement ending. Never share a password with us by email.

When you visit this website

Our web server keeps technical logs containing your IP address, the time of your visit and the page requested. That is needed to run the site and to recognise abuse. The legal basis is our legitimate interest in the security and availability of the site. These logs are not used to track visitors or build profiles.

Cookies

This website places no tracking cookies and sends no data to advertising networks. Fonts load from our own server, so no request goes to Google either. That is why there is no cookie banner here. The details are in our cookie statement.

How long we keep your data

We keep your data no longer than is necessary for the purpose it was given for.

  • Enquiries that do not lead to an engagement: 12 months after the last contact
  • Client data and engagement records: 7 years after completion, due to the statutory retention obligation
  • Invoices and the accounting around them: 7 years, statutory retention obligation of the Dutch tax authorities
  • Credentials to client systems: Deleted within 14 days of the engagement ending
  • Logs of actions carried out by an agent: Retention agreed per engagement in the data processing agreement

Who we share your data with

We do not sell your data and we do not pass it to third parties for their own purposes. We do engage a number of parties that process data on our behalf. We have a data processing agreement with each of them.

  • Mijndomein: Hosting this website, keeping server log files, and sending and receiving business email. Data is held in the Netherlands, within the EEA.
  • SEOwebsitehelper: Receiving and forwarding the messages sent through the forms on this site. Data is held in France, within the EEA.

We also share data where the law requires it, for example with the tax authorities.

Automated decision-making

We make no decisions about you on the basis of automated processing, and we build no profiles of visitors or clients. Agents built for a client act inside that client's own processes and within limits agreed in writing.

Your rights

The GDPR gives you a number of rights. You can exercise all of them with us.

  • Access: request which data we hold about you.
  • Rectification: have incorrect data corrected.
  • Erasure: have your data deleted, unless we are legally required to keep it.
  • Restriction: have the processing temporarily suspended.
  • Objection: object to processing based on legitimate interest.
  • Portability: receive your data in a common file format.
  • Withdrawal of consent: where we asked for consent, you may withdraw it at any time.

Send your request to info@qaiyu.com. We respond within one month. To avoid handing data to the wrong person, we may ask you to identify yourself.

Security

We take appropriate technical and organisational measures to protect your data: encrypted connections, access limited to those who need it, and credentials in a password manager rather than in documents or email. If you notice something wrong with our security, tell us at the address above.

Filing a complaint

If we cannot resolve it together, you can file a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl. We would appreciate it if you tried us first.

Changes

If the way we handle data changes, we update this statement. The date at the top of this page shows when that last happened.