Policies

Europe Privacy Policy

QuoteIt Europe Privacy Policy (EEA, UK, Switzerland)

Effective Date: September 12, 2026

Platform: QuoteIt

Website: https://quoteit.me

Company: QuoteIt Automation Private Limited ("QuoteIt", "we", "our", "us")

Contact: privacy@quoteit.me | legal@quoteit.me

This Europe Privacy Policy applies to individuals in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland. It explains how we collect and use Personal Data when you use QuoteIt's websites, applications, APIs, CLI-based agents, extensions, and related tools and documentation (collectively, the "Services").

If you are outside the EEA/UK/Switzerland, please refer to our non-Europe Privacy Policy available on quoteit.me.

1) Data controller and contacts

1.1 Controller

For processing described in this policy where QuoteIt determines the purposes and means of processing, the controller is:

QuoteIt Automation Private Limited
Registered office (general location): Palampur, Himachal Pradesh, India
Email: privacy@quoteit.me

(We intentionally provide a general location publicly. If you require a full registered office address for formal notice or regulatory correspondence, contact us at privacy@quoteit.me.)

1.2 EU/UK representative

We do not currently have an appointed EU or UK representative. If we are required to appoint a representative under applicable law and do so, we will update this policy with their details. (GDPR Article 27 addresses representative obligations for certain non-EU controllers/processors.)

1.3 Data Protection Officer (DPO)

We do not currently have an appointed DPO. If we appoint one, we will publish the contact details here.

2) Scope: controller processing vs business workspace processing

2.1 When QuoteIt is a controller

This policy primarily covers processing where QuoteIt acts as a controller, including:

  • account creation and authentication (including SSO where enabled),
  • billing and procurement contacts,
  • customer support communications,
  • security logs and abuse/fraud prevention,
  • product analytics and service improvement for QuoteIt-controlled systems,
  • legal compliance and enforcement.

2.2 When QuoteIt is a processor/service provider (business workspaces)

When an organization (the "Customer") uses QuoteIt workspaces to process documents, prompts, persona materials, drafts, approvals, and related content ("Customer Content"), QuoteIt typically processes that content on the Customer's behalf as a processor/service provider. In those cases, processing is governed by the Customer agreement and any Data Processing Addendum (DPA).

If you use QuoteIt through your employer, agency, or other organization, your organization may control workspace settings and content access. Requests relating to workspace content may need to be handled through your workspace administrator.

3) Personal Data we collect

3.1 Personal Data you provide

  • Account information: name, business email, organization, role/title, authentication credentials (including SSO identifiers), workspace settings.
  • Billing/procurement information (business): billing contact details, invoices, transaction history, tax-related information where applicable.
  • Communications: information you provide in support tickets, emails, surveys, or other communications.
  • Marketing access and waitlist: a work email submitted to check access is logged as an unverified access attempt even if you do not join the waitlist. A separate waitlist opt-in records the submitted name, company, role, notes, source, and consent evidence. Email confirmation is separate from opt-in; a saved request or sent message does not mean the address is verified.

3.2 Personal Data we receive from your use of the Services (Technical Information)

  • Log data: IP address, browser type/settings, timestamps, diagnostic logs.
  • Usage data: interactions with the Services, features used, actions taken, time zone, approximate country/region, access dates/times.
  • Device information: device type, OS, browser details, device identifiers.
  • Location information: approximate location inferred from IP for security/abuse prevention; precise location only if you choose to provide it where a feature supports it.
  • Cookies and similar technologies: used for authentication, preferences, security, and (where enabled) analytics.

3.3 Information we receive from other sources

  • Identity providers (SSO provisioning/authentication),
  • Security partners (fraud/abuse signals),
  • Integrations/connectors enabled by Customers (depending on configuration),
  • Business/marketing sources where permitted by law.

3.4 Workspace content (Customer Content)

Customers may upload or submit Customer Content that can include Personal Data (e.g., documents, prompts, persona materials, drafts, edits, approvals). This is usually processed under the Customer agreement/DPA.

4) How we use Personal Data

We use Personal Data to:

  • provide, operate, and maintain the Services,
  • authenticate users and manage accounts and workspaces,
  • provide customer support and respond to requests,
  • secure the Services (detect/prevent fraud, abuse, and security incidents),
  • manage billing and contract administration,
  • record access interest and respond to access checks,
  • send waitlist updates only after separate affirmative opt-in and email verification,
  • improve reliability, performance, and safety of the Services,
  • comply with legal obligations and enforce our terms and policies.

5) AI processing, Personas, and improvement/training

QuoteIt helps customers generate persona-based communications grounded in verified information and supported by approvals. To provide these capabilities:

5.1 Personas and Persona Artifacts (core service processing)

Customers may create Personas (e.g., CEO, CTO, spokesperson voice profiles). To implement Personas, QuoteIt may derive and store Persona Artifacts inside the relevant workspace - such as style profiles/guides, embeddings/vector representations, prompt representations, rules/configurations, adapters (including LoRA), fine-tuned weights, soft prompts, and related metadata.

Default posture: Persona Artifacts are workspace-specific and used only to provide the Services for that Customer/workspace unless generalized improvement is enabled as described below.

5.2 Standard Mode vs Early Access Mode (alpha/beta)

Depending on the Customer plan and workspace settings:

  • Standard Mode (default for many business customers): We do not use Customer Content, Outputs, or Persona Artifacts from that workspace to improve generalized models/services for other customers unless the Customer explicitly opts in.
  • Early Access Mode (alpha/beta): Customers may enroll in Early Access Mode. Within Early Access Mode, generalized improvement may be enabled by default for eligible data described below, and can be turned off by the Customer at any time.

5.3 Improvement Data (minimized and de-identified)

Where generalized improvement is enabled, we use Improvement Data: minimized, de-identified excerpts derived from eligible sources (typically: approved outputs, user edits, and de-identified quality signals).

We apply reasonable measures intended to reduce identifiability and do not attempt to re-identify Improvement Data except as required by law. Note that pseudonymised data can still be Personal Data under EU guidance.

5.4 Customer controls: opt-in and opt-out

  • Standard Mode: generalized improvement is off by default; Customer must opt in (e.g., Order Form or admin setting).
  • Early Access Mode: generalized improvement may be on by default for eligible Improvement Data; Customer can opt out via admin settings or by contacting privacy@quoteit.me.

Changes apply going forward. Opting out does not require us to retrain or remove learning already incorporated into generalized models, except where required by law or expressly agreed.

6) Disclosure of Personal Data

We may disclose Personal Data as follows:

6.1 Vendors and service providers (subprocessors)

We may share Personal Data with vendors providing hosting, storage, monitoring, analytics, security, customer support tooling, email delivery, payment processing, OCR/layout processing, and other IT services, under contractual confidentiality and security obligations.

6.2 Third-party services and model providers

If a Customer enables third-party services (including third-party model APIs), relevant prompts/context may be transmitted to those providers to generate outputs. Processing by those providers is governed by their terms and policies.

6.3 Business transfers

If QuoteIt is involved in a merger, acquisition, restructuring, bankruptcy, or sale of assets, Personal Data may be shared during diligence and transferred as part of the transaction.

6.4 Legal, compliance, and safety

We may disclose Personal Data if necessary to comply with law/legal process, enforce our terms/policies, prevent fraud/abuse, or protect rights, safety, and security.

6.5 Affiliates

We may share Personal Data with affiliates for purposes consistent with this policy.

7) Retention

We retain Personal Data only as long as necessary to:

  • provide the Services,
  • maintain security and prevent abuse,
  • resolve disputes,
  • comply with legal obligations.

Retention depends on the type of data, sensitivity, legal requirements, and Customer settings. Backups may persist for limited periods. For business workspaces, retention and deletion of workspace content is typically governed by the Customer agreement and configuration.

For the marketing access and waitlist service, our current operational defaults are 48 hours for expired abuse-control windows, 30 days for unverified access attempts and unconfirmed waitlist personal fields, no more than 180 days for cookie receipts and unnecessary user-agent values, and no more than 365 days for command and consent evidence.

A confirmed waitlist profile is retained while subscribed. On unsubscribe, we clear nonessential name, company, role, and notes, while retaining the minimum email, suppression, and proof needed to honor that choice while the marketing service can send updates. For correction or removal requests, contact support@quoteit.me.

8) Security

We maintain commercially reasonable technical, administrative, and organizational measures designed to protect Personal Data. No system is completely secure; please use appropriate safeguards (SSO where available, strong passwords, least-privilege access).

9) Legal bases for processing (EEA/UK/CH)

We rely on the following legal bases as applicable:

PurposePersonal DataLegal basis
Provide, operate, and maintain Services (account/workspace access)Account + technical infoContract necessity; legitimate interests for operational necessities
Support and communicationsContact + message contentContract necessity and/or legitimate interests
Billing and contract administrationBilling/procurement dataContract necessity; legal obligation where applicable
Security, abuse prevention, incident responseLogs, security signalsLegitimate interests and/or legal obligation
Cookies/analytics (where required)Cookie identifiersConsent (for non-essential cookies where required)
Generalized improvement using Improvement DataMinimized/de-identified excerptsIn Standard Mode: consent/contract via explicit Customer opt-in; in Early Access Mode: contract/legitimate interests consistent with Customer enrollment and settings, subject to applicable law

Where we rely on legitimate interests, you may have a right to object (see Section 10).

10) Your rights (EEA/UK/CH)

Subject to applicable law and exceptions, you may have the right to:

  • access, rectify, delete,
  • restrict processing,
  • data portability (in certain cases),
  • object to processing (especially where based on legitimate interests),
  • withdraw consent (where processing is based on consent),
  • lodge a complaint with a supervisory authority.

10.1 How to exercise rights

Email: privacy@quoteit.me. We may request verification to protect your data.

10.2 Business workspace users

If you use QuoteIt through an organization, that organization may control workspace content and settings. Requests about workspace content may need to be handled through your workspace administrator; we will assist Customers as required by contract and law.

10.3 Complaints

You may lodge a complaint with your local supervisory authority. UK: ICO. Switzerland: FDPIC.

11) International data transfers (EEA/UK/CH)

QuoteIt is based in India and may process Personal Data in India and other jurisdictions where QuoteIt and its service providers operate. Where required, we implement appropriate safeguards such as EU SCCs and the UK transfer mechanisms. To request information about safeguards, contact privacy@quoteit.me.

12) Cookies and similar technologies

We use cookies and similar technologies for authentication, preferences, security, and (where enabled) analytics. Where required by law, we obtain consent for non-essential cookies and provide controls. See our Cookie Notice.

13) Children

The Services are not intended for children under 13 (or older where required). We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data, contact privacy@quoteit.me.

14) Changes to this policy

We may update this policy from time to time. We will post updates with a revised Effective Date and provide additional notice if required.

15) Contact

Privacy: privacy@quoteit.me

Legal: legal@quoteit.me

Registered office (general location): Palampur, Himachal Pradesh, India