EU, EEA & UK Privacy Policy

Additional privacy information for residents of the European Union, EEA, UK, and Switzerland

Last updated: April 2026

Who We Are and How to Contact Us

Quintech LLC operates as an AI R&D lab for organizations. Through the lab, Quintech delivers product development, research, software factory platform, and managed services to enterprise and mid-market clients across the United Kingdom, the United States, Australia, and India.

FieldDetails
Data ControllerQuintech LLC
Registered addressCalifornia, USA
Emailquin@quin-tech.ai
Websitequin-tech.ai

Quintech LLC acts as the data controller for personal data collected through the quin-tech.ai website and platform. Where Quintech processes personal data on behalf of an enterprise client, Quintech acts as a data processor and the client is the data controller. In those cases, please direct data subject requests to the relevant client.

As Quintech is registered in Wyoming and does not have an establishment in the EU or UK, we have appointed a representative to handle data protection enquiries from EU and UK residents. Representative contact details are available on request at quin@quin-tech.ai.

Personal Data We Collect

We collect personal data in the following categories. Full details of collection methods are set out in our Global Privacy Policy.

CategoryExamplesSource
Identity dataName, job title, employer, professional credentialsDirectly from you
Contact dataEmail address, phone number, business addressDirectly from you
Account dataUsername, password hash, access role, login historyDirectly from you / automated
Usage dataFeature interaction logs, session duration, navigation pathsAutomated collection
Technical dataIP address, browser type, device type, time zoneAutomated collection
AI interaction dataPrompts, documents, and outputs processed through AI featuresDirectly from you
Communications dataSupport tickets, email correspondence, meeting notesDirectly from you
Financial dataBilling contact and subscription records, not card numbersDirectly from you / payment processor
Third-party dataProfile data from SSO or directory integrations you authoriseThird-party providers

We do not knowingly collect special category personal data (including health data, biometric data, racial or ethnic origin, religious beliefs, or political opinions) unless explicitly required by and agreed in a specific client engagement, in which case a separate Data Processing Agreement governs its handling.

Your Rights Under EU GDPR and UK GDPR

As a data subject located in the EU, EEA, UK, or Switzerland, you have the following rights in relation to your personal data. These rights apply subject to applicable exemptions and the specific circumstances of each request.

4.1 Right of Access (Article 15): You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data together with information about how it is processed. We will respond within one calendar month.

4.2 Right to Rectification (Article 16): You have the right to request correction of inaccurate personal data and completion of incomplete personal data. We will action valid rectification requests without undue delay and within one month.

4.3 Right to Erasure -- 'Right to Be Forgotten' (Article 17): You have the right to request deletion of your personal data where: the data is no longer necessary for the purpose for which it was collected; you withdraw consent and there is no other lawful basis; you object to processing based on legitimate interests and there are no overriding grounds; the data has been unlawfully processed; erasure is required to comply with a legal obligation. This right is not absolute. We may retain data where required by law, for legal claims, or for archiving purposes in the public interest.

4.4 Right to Restriction of Processing (Article 18): You have the right to request that we restrict processing in the following circumstances: you contest accuracy, pending verification; processing is unlawful but you prefer restriction to erasure; we no longer need the data but you require it for legal claims; you have objected to processing and we are assessing whether our legitimate grounds override your interests.

4.5 Right to Data Portability (Article 20): Where processing is based on consent or contractual necessity and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) and to transmit it to another controller.

4.6 Right to Object (Article 21): You have the right to object at any time to processing based on legitimate interests, including profiling. You have an unconditional right to object to processing for direct marketing purposes.

4.7 Rights in Relation to Automated Decision-Making (Article 22): You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Quintech's AI features are designed with human-in-the-loop controls for high-stakes decisions. Where automated decisions may have significant effects, you have the right to request human review, express your point of view, and contest the decision.

4.8 Right to Withdraw Consent (Article 7(3)): Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

4.9 Right to Lodge a Complaint (Article 77): You have the right to lodge a complaint with a supervisory authority. Key authorities include: United Kingdom -- Information Commissioner's Office (ICO) at ico.org.uk; Ireland -- Data Protection Commission (DPC) at dataprotection.ie; Germany -- Bundesdatenschutzbeauftragter (BfDI) at bfdi.bund.de; France -- CNIL at cnil.fr; Netherlands -- Autoriteit Persoonsgegevens (AP) at autoriteitpersoonsgegevens.nl; Switzerland -- FDPIC at edoeb.admin.ch; All EU member states -- full list at edpb.europa.eu/about-edpb/about-edpb/members_en.

4.10 How to Exercise Your Rights: Contact us by email at quin@quin-tech.ai with the subject line 'Data Subject Request'. Include your full name, the email address associated with your account, the specific right(s) you wish to exercise, and sufficient detail to identify the data concerned. We will respond within one calendar month.

International Data Transfers

Quintech LLC is registered in Wyoming and operates with infrastructure and personnel across India, the United Kingdom, the United States, and Australia. Processing personal data of EU, EEA, and UK residents may therefore involve transfers to countries outside those jurisdictions.

India does not currently have an EU adequacy decision.

5.1 Safeguards for Transfers to India and Other Non-Adequate Countries: Standard Contractual Clauses (SCCs) -- We use the European Commission's SCCs (2021) as the primary transfer mechanism for transfers from the EU/EEA to India. UK International Data Transfer Agreement (IDTA) -- For transfers from the UK, we use the UK IDTA or UK Addendum to the EU SCCs. Transfer Impact Assessments (TIAs) -- We conduct TIAs for transfers to India and other high-risk jurisdictions. Technical safeguards -- All data transferred internationally is encrypted in transit using TLS and at rest. PII is obfuscated at the LLM gateway before processing by any third-party AI model provider.

5.2 Transfers to Third-Party Sub-processors: Some sub-processors are located in the United States. Key sub-processors and transfer mechanisms: Anthropic (LLM API, United States, SCCs/IDTA, PII obfuscated before transmission); Google Cloud / Google Analytics (United States, SCCs/IDTA, EU data stored in EU regions where configured); Datadog (United States, SCCs/IDTA, observability data only); HubSpot (United States, SCCs/IDTA, marketing contact data for opted-in prospects only); OpenAI (optional LLM API, United States, SCCs/IDTA, PII obfuscated before transmission).

5.3 UK Sovereign Cloud Option: For enterprise clients with UK data residency requirements, Quintech offers deployment on UK sovereign cloud infrastructure. Where this option is selected, personal data does not leave UK jurisdiction and all processing occurs within UK-based data centers. This option is available at no additional platform fee.

Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, in accordance with our legal obligations and contractual commitments.

Data TypeRetention Period
Active client account dataDuration of the engagement plus any mandatory legal retention period (minimum 6 years for financial records under UK law)
Platform usage and access logs12 months from collection
AI decision and audit logsMinimum 12 months, may be retained longer for regulatory compliance
Security and incident logsMinimum 12 months, or longer as required by applicable law or certification frameworks (SOC 2, ISO 27001)
Marketing contact dataUntil opt-out, removed from active systems within 30 days; suppression records retained indefinitely
Data subject request records6 years from the date of the request
Closed account dataDeleted or anonymised within 90 days of account closure, subject to legal hold obligations

At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data deletion procedures.

AI Processing and Automated Decision-Making

Quintech processes personal data through AI-powered features within the Software Factory platform. The following disclosures are required under Articles 13-14 and 22 of the GDPR.

7.1 How AI Features Process Personal Data: Where you use AI features, your inputs (prompts, documents, queries) are processed by large language models (LLMs) to generate outputs. Before data is transmitted to any third-party LLM provider: PII is automatically detected and obfuscated at the Quintech LLM gateway layer; Data is transmitted only to models within the client-approved model catalogue; All transmissions are encrypted in transit. Interaction data (prompts and outputs) is not used to train AI models operated by Quintech or its LLM providers, unless you have provided separate written consent.

7.2 Automated Decision-Making: Quintech does not make decisions about individuals that produce legal or similarly significant effects based solely on automated processing, without human involvement. Where AI features generate recommendations or classifications that could affect individuals: human-in-the-loop checkpoints are implemented at the platform architecture level; a human review step is required before any high-stakes action is executed; all decisions are logged with full context, enabling audit and challenge.

7.3 Profiling: Quintech uses usage analytics to understand how the platform is used in aggregate and to improve features. This does not constitute profiling for the purposes of Article 22 GDPR as it does not produce legal or similarly significant effects on individuals. If you object to any analytics processing, you may do so under Article 21 GDPR by contacting quin@quin-tech.ai.

Personal Data Breaches

Quintech maintains a documented incident response process aligned to Article 33 (EU GDPR) and equivalent UK GDPR provisions.

Supervisory authority notification: Where a breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR.

Data subject notification: Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay, as required by Article 34 GDPR, unless an exemption applies.

Breach register: All personal data breaches are recorded in our internal breach register, regardless of whether they require notification, in accordance with Article 33(5) GDPR.

Post-incident review: A root cause analysis is completed for all significant incidents within 48 hours of closure, with corrective actions tracked to completion.

Data Protection Officer and EU/UK Representative

Quintech LLC does not currently meet the thresholds under Article 37 GDPR that require mandatory appointment of a Data Protection Officer. However, all privacy and data protection enquiries are handled by our designated privacy lead, who can be reached at quin@quin-tech.ai.

As Quintech is not established in the EU or UK, we are required under Article 27 GDPR and equivalent UK GDPR provisions to appoint a representative in the EU and UK for data subjects and supervisory authorities to contact. Details of our appointed representatives are available on request at quin@quin-tech.ai.

Changes to This Policy

We may update this Policy to reflect changes in applicable law, regulatory guidance, or our data processing practices. Material changes will be notified to you by email or by a prominent notice on the platform at least 14 days before they take effect.

For significant changes to how we process your personal data (such as a new legal basis or a new category of data), we will seek fresh consent where consent is the applicable legal basis.

Contact and Escalation

For all data protection enquiries, subject access requests, or complaints, please contact us:

FieldDetails
CompanyQuintech LLC
Emailquin@quin-tech.ai
Response timeWithin one calendar month
Websitequin-tech.ai

If you are not satisfied with our response, you have the right to escalate your complaint to the supervisory authority in your country of residence. Contact details for all EU/EEA supervisory authorities are available at edpb.europa.eu. UK residents may contact the ICO at ico.org.uk.