Status: Pre-launch draft for professional review. This is not a final privacy notice or legal advice.
1. Scope
This draft covers personal information handled through the Queux public website, account administration, customer support and subscription kitchen-operations service. A customer may also have its own notices and obligations for information it controls in a Queux workspace.
2. Information Queux may handle
Public website and enquiries
- Contact details and the contents of an enquiry.
- Basic technical and security information needed to operate and protect the website.
Accounts and subscriptions
- Name, work contact details, authentication records, role and organisation or site memberships.
- Subscription status, invoices and payment-provider references. Queux is not intended to store payment-card details.
Kitchen operations
- Aggregate room, meal, dietary and texture counts used for kitchen calculations by default.
- Operational entries, task completions, approvals, amendments, training records, support messages and audit events.
- Documents and attachments the customer chooses and is authorised to upload.
3. Data minimisation
Queux is designed so ordinary kitchen calculations do not require names of children or care recipients. Customers should provide only the minimum information needed for the authorised purpose. Complete enrolment, medical or attendance files should not be copied into Queux merely because they exist elsewhere.
4. Purposes
Information may be used to provide, secure, support and improve the service; authenticate users; apply roles and tenant boundaries; process subscriptions; communicate service messages; maintain records and backups; investigate misuse; and meet applicable obligations.
Queux should not use identifiable operational information for unrelated advertising. Optional AI features, if enabled by the customer, are intended to use minimum necessary data and no personal information by default.
5. Sources
Information may come from the person, their organisation, authorised users, uploaded CSV files, configured providers, payment providers and technical operation of the service. Provider access depends on permission and supported documentation.
6. Sharing and service providers
Queux may use contracted infrastructure, email, payment, support, monitoring, security and optional integration providers. The final policy must identify material subprocessors or provide a maintained subprocessor list, including relevant locations and change notices.
Information may also be disclosed where authorised by the customer, required by law, needed to protect people or systems, or involved in a properly managed business transaction. The final wording requires legal review.
7. Hosting and overseas disclosure
The production hosting region and any overseas disclosure pathways must be confirmed in deployment and customer documentation before launch. Queux should not imply Australian-only storage unless the configured infrastructure and all relevant subprocessors support that statement.
8. Security
The intended controls include tenant-scoped access, role-based authorisation, private file storage, encryption for recoverable credentials, hashing for one-way secrets, audit events, rate limiting, signed-webhook verification, backups and vulnerability maintenance.
No online service can guarantee absolute security. Customers must maintain appropriate user access, devices, local procedures and prompt offboarding.
9. Retention and deletion
Retention should reflect the purpose, the customer’s documented instructions, contractual commitments, backup cycles and applicable recordkeeping obligations. Critical operational history may need to remain append-only during the agreed retention period. Final schedules and post-termination export and deletion periods must be approved before launch.
10. Access, correction and complaints
People may contact Queux about access, correction or a privacy concern. Where the relevant information is controlled by a customer, Queux may direct the request to that customer and assist under the data-processing arrangement.
The final policy must state the verified identity process, response pathway, privacy contact and any regulator escalation rights that apply.
11. Cookies and analytics
The public site should use only technical storage required for security, sessions and requested functionality unless a documented consent and notice mechanism is introduced. Any analytics or marketing technology must be accurately listed before use.
12. Contact
Privacy questions about this draft can be sent to support@queux.com.au. The final policy must identify the responsible legal entity and privacy contact.