QuotentQuotent
How it worksFeaturesPricing
LoginStart Free
Back to Quotent

Legal

Privacy Policy

Effective date: 1 September 2026

On this page

Terms of Service →

Who We Are

Quotent Ltd (“Quotent”, “we”, “us”, or “our”) is the data controller responsible for the personal data described in this Privacy Policy. We operate the quoting platform at quotent.net. We are a company registered in Croatia.

This policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have in relation to it. It applies to all users of our Service worldwide, whether on a free or paid plan.

As a Croatian company operating within the European Union, we process personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679). Users located outside the EU are also protected by this policy and may have additional rights under local law.

Data We Collect

Account data

When you register, we collect your email address, company name, and engineer or contact name. If you set optional profile details (trade type, country, hourly rate, logo), those are also stored.

Quote and job data

We store the quotes you generate through the Service, including the job descriptions you provide, the AI-generated line items, final totals, and any edits you make. This data is linked to your account and retained for as long as your account is active.

Voice recordings

If you use the Voice-to-Quote feature, your audio recording is captured in your browser and transmitted over an encrypted connection to our transcription API. We do not permanently store raw audio files; only the resulting text transcript is retained as part of your quote data.

Photos

If you use the Photo-to-Quote feature, images you upload are processed by our AI provider and may be stored in our cloud storage bucket (“quote-photos”) to generate a job scope draft. Images are associated with your quote record. You may delete individual quotes, which removes associated image references.

Payment data

Subscription payments are handled by Stripe. We receive confirmation of payment and your subscription status from Stripe but do not store your full card number, CVV, or bank details on our servers. Stripe acts as an independent data controller for payment processing.

Usage and technical data

We collect standard server logs, including your IP address, browser type, pages visited, and timestamps. This data is used to monitor system health, investigate issues, and ensure the security of the Service. We do not use third-party analytics scripts that place tracking cookies.

Communications

If you contact us by email, we retain the correspondence to respond to you and to keep a record of support history.

How We Use Your Data

We use your personal data for the following purposes and on the following lawful bases:

PurposeLawful basis
Providing and operating the ServiceContract performance
Processing payments and managing subscriptionsContract performance
Sending transactional emails (quotes, receipts)Contract performance
Sending service notices (downtime, term changes)Legitimate interest
Generating AI quotes via job description processingContract performance
Transcribing voice recordings into job descriptionsContract performance / consent
Analysing photos to produce job scope draftsContract performance / consent
Fraud prevention and security monitoringLegitimate interest / legal obligation
Improving and developing the ServiceLegitimate interest
Responding to support requestsLegitimate interest / contract performance
Complying with legal obligationsLegal obligation

We do not use your personal data for automated decision-making that produces legal or similarly significant effects, other than enforcing plan usage limits (free quota enforcement) which is a non-discriminatory, contractual function of the Service.

We do not sell your personal data to third parties.

Third-Party Processors

We share data with the following sub-processors who help us operate the Service. Each is bound by a data processing agreement and adequate safeguards.

Supabase

Our primary database and file storage provider. Account data, quote data, and uploaded photos are stored in Supabase infrastructure hosted in the EU (AWS eu-west-1).

OpenAI

We use OpenAI’s GPT-4o model to generate quote line items and analyse photos, and the Whisper model to transcribe voice recordings. Your job descriptions, photos, and audio are transmitted to OpenAI for this purpose. OpenAI does not use API inputs to train its models by default. Data may be processed in the United States — see the International Transfers section.

Stripe

Payment processing for Pro and Business subscriptions and Stripe Connect for payment links sent to your clients. Stripe is an independent data controller for payment card data. For Stripe Connect, your clients’ payment details are handled directly by Stripe.

Resend

Transactional email delivery — used to send quotes to your clients, payment receipts, and account notifications. Emails contain your quote content and your client’s email address.

We will notify you of material changes to our sub-processor list where required by law or where we believe you would reasonably expect notification.

Data Retention

We retain personal data for the following periods:

  • Account data — retained for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes.
  • Quote data — retained for the life of your account and deleted with it.
  • Voice recordings — raw audio is discarded after transcription. The resulting transcript is stored as part of the quote record.
  • Photos — stored for the life of the associated quote record.
  • Payment records — billing and invoicing records are retained for a minimum of 7 years to comply with Croatian accounting law (Zakon o računovodstvu) and applicable EU financial regulations.
  • Server logs — retained for up to 90 days for security and operational purposes.
  • Support emails — retained for up to 3 years after the last communication.

Your Rights

Under the GDPR, you have the following rights in relation to your personal data:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may ask us to correct inaccurate data. Much of your data is editable directly in your account settings.
  • Right to erasure (“right to be forgotten”) — you may request deletion of your personal data where there is no overriding legal reason for us to retain it.
  • Right to restriction — you may ask us to restrict processing of your data in certain circumstances.
  • Right to portability — you may request a machine-readable export of the personal data you have provided to us.
  • Right to object — you may object to processing based on our legitimate interests. We will stop unless we have compelling grounds to continue.
  • Right to withdraw consent — where we rely on your consent (e.g. voice and photo processing), you may withdraw it at any time, which will not affect the lawfulness of prior processing.

To exercise any of these rights, email us at privacy@quotent.net. We will respond within one calendar month. We may ask you to verify your identity before acting on a request.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr. If you are located in another EU member state, you may also lodge a complaint with your local supervisory authority.

International Transfers

Some of our sub-processors (notably OpenAI and Stripe) are based in the United States. Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

Our primary data storage through Supabase is hosted in the EU (AWS eu-west-1) and does not involve a transfer outside the EEA. Users located outside the EU are subject to the same data protection standards described in this policy.

Cookies

We use a small number of cookies that are strictly necessary to operate the Service:

  • Authentication cookies — set by Supabase Auth to maintain your login session. These are session cookies that expire when you close your browser, or persistent cookies with a short expiry used for “stay logged in” functionality.
  • CSRF tokens — short-lived cookies used to prevent cross-site request forgery.

We do not use advertising cookies, third-party tracking cookies, or analytics platforms that set cookies (such as Google Analytics). You cannot opt out of strictly necessary cookies without disabling the Service entirely.

Security

We take reasonable technical and organisational measures to protect your personal data, including:

  • All data in transit is encrypted via TLS 1.2 or higher
  • Database access is restricted to authenticated services using row-level security (RLS)
  • API keys and secrets are stored as environment variables, not in source code
  • File storage (photos) is access-controlled via Supabase Storage policies
  • Passwords are never stored — authentication is handled via magic link or OAuth

No method of transmission over the internet or electronic storage is 100% secure. If you discover a security vulnerability, please disclose it responsibly to security@quotent.net.

Children

The Service is not directed at or intended for use by children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in how we process data, new legal requirements, or feedback from users. We will notify you of material changes by email and by posting the updated policy on this page with a revised effective date. We encourage you to review this page periodically.

Contact & DPO

For privacy-related questions, data subject requests, or to report a concern, contact us at:

Quotent Ltd — Data Privacy
Croatia
Email: privacy@quotent.net
Website: quotent.net

We aim to respond to all enquiries within 5 business days and to fulfil data subject requests within one calendar month.

Last updated: 1 September 2026 — Quotent Ltd