Legal
Quottum — Privacy Policy
Last updated: June 24, 2026
This Privacy Policy explains how Gaviso Digital Marketing, LLC ("Quottum," "we," "us," "our") collects, uses, shares, and protects personal data in connection with the Quottum application at app.quottum.io (the "Service"), a multi-tenant B2B platform for quote, contract, and renewal management.
It is written to address the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended ("CCPA/CPRA"). Terms not defined here have the meaning given in our Terms of Service.
1. Our Two Roles: Controller vs. Processor
(a) Account Data — we are the controller. For personal data about Account Users and Workspaces (sign-in, profile, membership, security logs), Quottum is the controller and decides how that data is used to operate, secure, and support the Service.
(b) Customer Data — we are the processor. For personal data a Customer enters about its Clients/Recipients, and for the content of Quotes and Contracts, Quottum acts as a processor on the Customer's behalf; the Customer is the controller and is responsible for the lawful basis and any notice or consent. This processing is governed by our Data Processing Agreement (DPA), available at https://quottum.io/dpa or on request to help@gaviso.agency.
If you are a Client/Recipient with questions about data a business entered into Quottum, contact that business; we will assist them as their processor.
2. Data We Collect
2.1 Account and authentication data (we are controller)
- email address; password (stored hashed by our auth provider — we don't see plaintext); optional display name and avatar;
- optional TOTP 2FA secret; and
- sign-in method details (email/password, magic link).
2.2 Workspace and membership data (we are controller)
- company/workspace info, slug, timezone, branding assets (logo, slogan, footer);
- members and their roles (owner/member); and
- assigned plan tier and plan status.
2.3 Activity and security logs (we are controller)
- quote/contract events and
attachment_downloadedevents, which for some event types include IP-anonymized actor metadata; and - our internal admin audit log (which platform administrator did what, and when — see Section 5).
2.4 Customer-entered data (Customer is controller; we are processor)
- CRM data: client company name, contacts, emails, role, lifecycle stage, and related fields;
- Documents: Quotes, Contracts, line items, totals, currency, and T&C text; and
- Files: user-uploaded attachments (size-capped per plan), with an optional client-visibility flag.
2.5 Beta signup metadata
- email, company, role, how you heard about us, and an optional free-text note.
We do not collect payment-card data (no payment processor is integrated today), and we do not use analytics, advertising, or third-party tracking in the app.
3. How We Use Data and Legal Bases (GDPR/UK GDPR)
For Account Data (where we are controller), we process personal data for these purposes and legal bases:
| Purpose | Legal basis |
|---|---|
| Create accounts/Workspaces, authenticate users, provide the Service | Performance of a contract |
| Send transactional/service emails (incl. auth emails) | Performance of a contract |
| Secure the Service; detect and prevent fraud and abuse; audit logging | Legitimate interests |
| Improve features and respond to support and voluntary beta feedback | Legitimate interests |
| Comply with legal obligations and enforce our Terms | Legal obligation / legitimate interests |
Where we rely on legitimate interests, we balance them against your rights. For Customer Data, we process only on the Customer's documented instructions as their processor, under the DPA.
4. Sub-Processors and Recipients
We do not sell personal data and do not share it for cross-context behavioral advertising. We use the following sub-processors, each receiving only the data needed for its function:
| Sub-processor | Function | Notes |
|---|---|---|
| Supabase | Postgres database, authentication, row-level security | Core; US region |
| Backblaze B2 | File attachment storage | United States (us-west-001) |
| Resend | All outbound email (app + auth, on quottum.io) | Recipient addresses + content |
| Kinetic Cloud / Coolify | Application hosting | |
| n8n (self-hosted) | Internal workflow runner (changelog publish, redeploy) | Does not touch Customer Data today |
| GitHub | Source control and release infrastructure | No Customer Data |
We may also disclose data to comply with law or legal process, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (subject to this Policy). We will give notice of new sub-processors per Section 13.
5. Operator Support Access
Our platform administrators are a separate role and are never members of your Workspace. To provide support, an administrator may view or act within your Workspace through impersonation. This is off by default: an operator must request access, and a Workspace owner must enable the per-Workspace "Support access" toggle. All administrator actions are recorded in our admin audit log. You can disable Support access at any time.
6. International Data Transfers
Our core infrastructure (Supabase) is hosted in the United States. If you or your Clients are in the EEA, the UK, or other regions, your data may be transferred to and processed in the US and other locations where our sub-processors operate. For such transfers we rely on appropriate safeguards — including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — as set out in our DPA and sub-processor agreements.
7. Data Retention
We keep personal data only as long as needed for the purposes above, then delete or de-identify it:
| Data class | Retention period |
|---|---|
| Account & profile data | Life of the account; purged within 90 days of verified deletion |
| Workspace / Customer Data (processor) | Per Customer instruction; on Workspace deletion, purged within 30 days |
| Attachment files (Backblaze B2) | Deleted within 30 days of record/Workspace deletion; backups expire within 35 days |
| Activity logs (quote/contract events) | 18 months |
| Admin audit log | 24 months (security/compliance) |
| Beta signup metadata | Until program end or 12 months, then deleted or anonymized |
Backups are retained on a rolling basis and expire on their own cycle, after which deleted data is no longer recoverable.
8. Cookies and Tracking
We use only first-party, essential session cookies:
- our auth cookies (access/refresh tokens) to keep Account Users signed in; and
- a
quottum_workspacecookie storing the active Workspace ID.
We use no analytics, advertising, or third-party tracking cookies in the app, so no tracking-consent banner is required. You can control cookies in your browser, but disabling essential cookies will prevent sign-in.
9. Your Privacy Rights
Subject to verification and legal exceptions, you may have the right to access, correct/rectify, delete/erase, restrict or object to processing, port your data, and withdraw consent where processing is based on consent. Under CCPA/CPRA, California residents may request to know, delete, and correct personal information, and to opt out of sale/sharing — note that we do not sell or share personal information. We do not discriminate against you for exercising your rights.
How to exercise rights. Email help@gaviso.agency. We verify requests using account-associated information and respond within the time required by law. Self-service export and account deletion are not yet available in-app; deletion is handled manually by our team (account/Workspace export options described in the Terms remain available by plan). If you are a Client/Recipient, direct requests to the business that entered your data; we assist them as their processor.
You may also lodge a complaint with your supervisory authority (EEA/UK) or applicable regulator.
10. Children
The Service is for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a minor provided data, contact help@gaviso.agency and we will delete it.
11. Security
We use measures appropriate to the data, including encrypted transmission, hashed password storage, optional 2FA, row-level security, token-gated access to public records, default-off operator support access, and audit logging. No system is completely secure; you are responsible for safeguarding credentials and for how you distribute tokenized links.
12. Transactional Emails and Non-User Recipients
We send transactional email only (e.g., quote sent/accepted/declined, renewal reminders, invites, beta welcome, and operational notices) — no marketing email. Some emails are delivered to non-users (your Clients/Recipients) using addresses you supplied. You are responsible for being permitted to provide those addresses.
13. Changes to This Policy
We may update this Policy. For material changes — including new sub-processors — we will update the "Last updated" date and provide notice (for example, an in-app banner and/or email) with reasonable lead time before the change takes effect. Continued use after the effective date constitutes acceptance.
14. Contact
Contact: help@gaviso.agency
Gaviso Digital Marketing, LLC, 10250 Constellation Blvd., Ste. 2300, Los Angeles, CA 90067.