Who We Are
Quotent Ltd (“Quotent”, “we”, “us”, or “our”) is the data controller responsible for the personal data described in this Privacy Policy. We operate the quoting platform at quotent.net. We are a company registered in Croatia.
This policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have in relation to it. It applies to all users of our Service worldwide, whether on a free or paid plan.
As a Croatian company operating within the European Union, we process personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679). Users located outside the EU are also protected by this policy and may have additional rights under local law.
Data We Collect
Account data
When you register, we collect your email address, company name, and engineer or contact name. If you set optional profile details (trade type, country, hourly rate, logo), those are also stored.
Quote and job data
We store the quotes you generate through the Service, including the job descriptions you provide, the AI-generated line items, final totals, and any edits you make. This data is linked to your account and retained for as long as your account is active.
Voice recordings
If you use the Voice-to-Quote feature, your audio recording is captured in your browser and transmitted over an encrypted connection to our transcription API. We do not permanently store raw audio files; only the resulting text transcript is retained as part of your quote data.
Photos
If you use the Photo-to-Quote feature, images you upload are processed by our AI provider and may be stored in our cloud storage bucket (“quote-photos”) to generate a job scope draft. Images are associated with your quote record. You may delete individual quotes, which removes associated image references.
Payment data
Subscription payments are handled by Stripe. We receive confirmation of payment and your subscription status from Stripe but do not store your full card number, CVV, or bank details on our servers. Stripe acts as an independent data controller for payment processing.
Usage and technical data
We collect standard server logs, including your IP address, browser type, pages visited, and timestamps. This data is used to monitor system health, investigate issues, and ensure the security of the Service. We do not use third-party analytics scripts that place tracking cookies.
Communications
If you contact us by email, we retain the correspondence to respond to you and to keep a record of support history.
How We Use Your Data
We use your personal data for the following purposes and on the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Providing and operating the Service | Contract performance |
| Processing payments and managing subscriptions | Contract performance |
| Sending transactional emails (quotes, receipts) | Contract performance |
| Sending service notices (downtime, term changes) | Legitimate interest |
| Generating AI quotes via job description processing | Contract performance |
| Transcribing voice recordings into job descriptions | Contract performance / consent |
| Analysing photos to produce job scope drafts | Contract performance / consent |
| Fraud prevention and security monitoring | Legitimate interest / legal obligation |
| Improving and developing the Service | Legitimate interest |
| Responding to support requests | Legitimate interest / contract performance |
| Complying with legal obligations | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, other than enforcing plan usage limits (free quota enforcement) which is a non-discriminatory, contractual function of the Service.
We do not sell your personal data to third parties.
Third-Party Processors
We share data with the following sub-processors who help us operate the Service. Each is bound by a data processing agreement and adequate safeguards.
Our primary database and file storage provider. Account data, quote data, and uploaded photos are stored in Supabase infrastructure hosted in the EU (AWS eu-west-1).
We use OpenAI’s GPT-4o model to generate quote line items and analyse photos, and the Whisper model to transcribe voice recordings. Your job descriptions, photos, and audio are transmitted to OpenAI for this purpose. OpenAI does not use API inputs to train its models by default. Data may be processed in the United States — see the International Transfers section.
Payment processing for Pro and Business subscriptions and Stripe Connect for payment links sent to your clients. Stripe is an independent data controller for payment card data. For Stripe Connect, your clients’ payment details are handled directly by Stripe.
Transactional email delivery — used to send quotes to your clients, payment receipts, and account notifications. Emails contain your quote content and your client’s email address.
We will notify you of material changes to our sub-processor list where required by law or where we believe you would reasonably expect notification.
Data Retention
We retain personal data for the following periods:
- Account data — retained for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes.
- Quote data — retained for the life of your account and deleted with it.
- Voice recordings — raw audio is discarded after transcription. The resulting transcript is stored as part of the quote record.
- Photos — stored for the life of the associated quote record.
- Payment records — billing and invoicing records are retained for a minimum of 7 years to comply with Croatian accounting law (Zakon o računovodstvu) and applicable EU financial regulations.
- Server logs — retained for up to 90 days for security and operational purposes.
- Support emails — retained for up to 3 years after the last communication.
Your Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate data. Much of your data is editable directly in your account settings.
- Right to erasure (“right to be forgotten”) — you may request deletion of your personal data where there is no overriding legal reason for us to retain it.
- Right to restriction — you may ask us to restrict processing of your data in certain circumstances.
- Right to portability — you may request a machine-readable export of the personal data you have provided to us.
- Right to object — you may object to processing based on our legitimate interests. We will stop unless we have compelling grounds to continue.
- Right to withdraw consent — where we rely on your consent (e.g. voice and photo processing), you may withdraw it at any time, which will not affect the lawfulness of prior processing.
To exercise any of these rights, email us at privacy@quotent.net. We will respond within one calendar month. We may ask you to verify your identity before acting on a request.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr. If you are located in another EU member state, you may also lodge a complaint with your local supervisory authority.
International Transfers
Some of our sub-processors (notably OpenAI and Stripe) are based in the United States. Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
Our primary data storage through Supabase is hosted in the EU (AWS eu-west-1) and does not involve a transfer outside the EEA. Users located outside the EU are subject to the same data protection standards described in this policy.
Security
We take reasonable technical and organisational measures to protect your personal data, including:
- All data in transit is encrypted via TLS 1.2 or higher
- Database access is restricted to authenticated services using row-level security (RLS)
- API keys and secrets are stored as environment variables, not in source code
- File storage (photos) is access-controlled via Supabase Storage policies
- Passwords are never stored — authentication is handled via magic link or OAuth
No method of transmission over the internet or electronic storage is 100% secure. If you discover a security vulnerability, please disclose it responsibly to security@quotent.net.
Children
The Service is not directed at or intended for use by children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in how we process data, new legal requirements, or feedback from users. We will notify you of material changes by email and by posting the updated policy on this page with a revised effective date. We encourage you to review this page periodically.
Contact & DPO
For privacy-related questions, data subject requests, or to report a concern, contact us at:
Quotent Ltd — Data PrivacyCroatia
Email: privacy@quotent.net
Website: quotent.net
We aim to respond to all enquiries within 5 business days and to fulfil data subject requests within one calendar month.