Legal

Quottum — Privacy Policy

Last updated: June 24, 2026

This Privacy Policy explains how Gaviso Digital Marketing, LLC ("Quottum," "we," "us," "our") collects, uses, shares, and protects personal data in connection with the Quottum application at app.quottum.io (the "Service"), a multi-tenant B2B platform for quote, contract, and renewal management.

It is written to address the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended ("CCPA/CPRA"). Terms not defined here have the meaning given in our Terms of Service.

1. Our Two Roles: Controller vs. Processor

(a) Account Data — we are the controller. For personal data about Account Users and Workspaces (sign-in, profile, membership, security logs), Quottum is the controller and decides how that data is used to operate, secure, and support the Service.

(b) Customer Data — we are the processor. For personal data a Customer enters about its Clients/Recipients, and for the content of Quotes and Contracts, Quottum acts as a processor on the Customer's behalf; the Customer is the controller and is responsible for the lawful basis and any notice or consent. This processing is governed by our Data Processing Agreement (DPA), available at https://quottum.io/dpa or on request to help@gaviso.agency.

If you are a Client/Recipient with questions about data a business entered into Quottum, contact that business; we will assist them as their processor.

2. Data We Collect

2.1 Account and authentication data (we are controller)

2.2 Workspace and membership data (we are controller)

2.3 Activity and security logs (we are controller)

2.4 Customer-entered data (Customer is controller; we are processor)

2.5 Beta signup metadata

We do not collect payment-card data (no payment processor is integrated today), and we do not use analytics, advertising, or third-party tracking in the app.

3. How We Use Data and Legal Bases (GDPR/UK GDPR)

For Account Data (where we are controller), we process personal data for these purposes and legal bases:

PurposeLegal basis
Create accounts/Workspaces, authenticate users, provide the ServicePerformance of a contract
Send transactional/service emails (incl. auth emails)Performance of a contract
Secure the Service; detect and prevent fraud and abuse; audit loggingLegitimate interests
Improve features and respond to support and voluntary beta feedbackLegitimate interests
Comply with legal obligations and enforce our TermsLegal obligation / legitimate interests

Where we rely on legitimate interests, we balance them against your rights. For Customer Data, we process only on the Customer's documented instructions as their processor, under the DPA.

4. Sub-Processors and Recipients

We do not sell personal data and do not share it for cross-context behavioral advertising. We use the following sub-processors, each receiving only the data needed for its function:

Sub-processorFunctionNotes
SupabasePostgres database, authentication, row-level securityCore; US region
Backblaze B2File attachment storageUnited States (us-west-001)
ResendAll outbound email (app + auth, on quottum.io)Recipient addresses + content
Kinetic Cloud / CoolifyApplication hosting
n8n (self-hosted)Internal workflow runner (changelog publish, redeploy)Does not touch Customer Data today
GitHubSource control and release infrastructureNo Customer Data

We may also disclose data to comply with law or legal process, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (subject to this Policy). We will give notice of new sub-processors per Section 13.

5. Operator Support Access

Our platform administrators are a separate role and are never members of your Workspace. To provide support, an administrator may view or act within your Workspace through impersonation. This is off by default: an operator must request access, and a Workspace owner must enable the per-Workspace "Support access" toggle. All administrator actions are recorded in our admin audit log. You can disable Support access at any time.

6. International Data Transfers

Our core infrastructure (Supabase) is hosted in the United States. If you or your Clients are in the EEA, the UK, or other regions, your data may be transferred to and processed in the US and other locations where our sub-processors operate. For such transfers we rely on appropriate safeguards — including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — as set out in our DPA and sub-processor agreements.

7. Data Retention

We keep personal data only as long as needed for the purposes above, then delete or de-identify it:

Data classRetention period
Account & profile dataLife of the account; purged within 90 days of verified deletion
Workspace / Customer Data (processor)Per Customer instruction; on Workspace deletion, purged within 30 days
Attachment files (Backblaze B2)Deleted within 30 days of record/Workspace deletion; backups expire within 35 days
Activity logs (quote/contract events)18 months
Admin audit log24 months (security/compliance)
Beta signup metadataUntil program end or 12 months, then deleted or anonymized

Backups are retained on a rolling basis and expire on their own cycle, after which deleted data is no longer recoverable.

8. Cookies and Tracking

We use only first-party, essential session cookies:

We use no analytics, advertising, or third-party tracking cookies in the app, so no tracking-consent banner is required. You can control cookies in your browser, but disabling essential cookies will prevent sign-in.

9. Your Privacy Rights

Subject to verification and legal exceptions, you may have the right to access, correct/rectify, delete/erase, restrict or object to processing, port your data, and withdraw consent where processing is based on consent. Under CCPA/CPRA, California residents may request to know, delete, and correct personal information, and to opt out of sale/sharing — note that we do not sell or share personal information. We do not discriminate against you for exercising your rights.

How to exercise rights. Email help@gaviso.agency. We verify requests using account-associated information and respond within the time required by law. Self-service export and account deletion are not yet available in-app; deletion is handled manually by our team (account/Workspace export options described in the Terms remain available by plan). If you are a Client/Recipient, direct requests to the business that entered your data; we assist them as their processor.

You may also lodge a complaint with your supervisory authority (EEA/UK) or applicable regulator.

10. Children

The Service is for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a minor provided data, contact help@gaviso.agency and we will delete it.

11. Security

We use measures appropriate to the data, including encrypted transmission, hashed password storage, optional 2FA, row-level security, token-gated access to public records, default-off operator support access, and audit logging. No system is completely secure; you are responsible for safeguarding credentials and for how you distribute tokenized links.

12. Transactional Emails and Non-User Recipients

We send transactional email only (e.g., quote sent/accepted/declined, renewal reminders, invites, beta welcome, and operational notices) — no marketing email. Some emails are delivered to non-users (your Clients/Recipients) using addresses you supplied. You are responsible for being permitted to provide those addresses.

13. Changes to This Policy

We may update this Policy. For material changes — including new sub-processors — we will update the "Last updated" date and provide notice (for example, an in-app banner and/or email) with reasonable lead time before the change takes effect. Continued use after the effective date constitutes acceptance.

14. Contact

Contact: help@gaviso.agency
Gaviso Digital Marketing, LLC, 10250 Constellation Blvd., Ste. 2300, Los Angeles, CA 90067.