Quotely / studioOpen quote desk
Menu
WorkspaceFormatsPricingSupportAccountContact

Quotely / policy register

Privacy Policy

How Quotely handles account, support, job-brief, document and subscription data.

Important boundary
Your job briefs, client names, amounts and generated documents can contain commercially sensitive information. We use them to provide the requested document workflow, not to train models.

Last updated 21 July 2026

1. Who is responsible

QCODE SOFTWARE LIMITED is the data controller for Quotely. QCODE SOFTWARE LIMITED, 8 Church Street, Inverness, Scotland, IV1 1EA, United Kingdom. Email support@qcodesoftl.shop; telephone +44 7103115594.

Our service is operated from United Kingdom. Questions and rights requests may be sent to support@qcodesoftl.shop.

2. What we collect

We collect account identifiers, name, email, authentication records, subscription status, support messages, device and security logs, cookie choices, and the job briefs, client details, amounts, uploaded files and instructions you choose to submit. Generated quotes, scopes, invoices, layouts and video task records are also processed.

  • Order and account data: plan, renewal state, invoice reference and customer reference.
  • Tool data: prompts, project details, client fields marked for verification, generated results and export requests.
  • Support data: contact form, quote-process enquiry and correspondence.
  • Technical data: IP address, browser, timestamps, security events and cookie preference.

3. Collection sources

We receive information directly from you when you create an account, complete a contact or workflow form, type a job brief, upload a file, request a generation or contact support. We collect technical and usage information automatically from service requests, essential cookies, security controls and hosting logs.

Our subscription payment providers send us customer, transaction, renewal, refund and fraud-status records, but not your complete card number or card security code. AI providers return generated content and operational task metadata after we submit the inputs needed for your requested generation.

4. Why we use it and legal bases

We process account, tool and export data to perform our contract; subscription and transaction records to perform the contract and meet legal obligations; security logs to pursue our legitimate interest in protecting the service; optional analytics with consent; and support or product communications with consent or our legitimate interest where permitted.

If information is needed to create an account, fulfil an export, support a subscription or secure the service, not providing it may prevent that function from working.

5. AI inputs, uploads and generated data

When you request a document, layout or video, we transmit your user input, job brief, instructions, selected document context and any file you choose to upload to an AI provider acting as our processor. The provider processes that content to return the requested generated result and related task metadata. Do not include passwords, complete payment-card details, government identity documents or personal data that is not needed for the task.

We do not claim ownership of your input or generated result. We do not use customer inputs, uploads or outputs to train our own general-purpose models, and our processor terms and configuration prohibit provider use for general-purpose model training. Working inputs, uploads and results may be cached for up to 30 days for retrieval, abuse prevention and support, then deleted from active working storage.

Account-linked documents remain available while your account is active unless you delete them. Deleting a hosted document removes the active copy; account deletion requests remove associated hosted content subject to legal retention duties. Security backups expire on a rolling schedule within 90 days. Copies you export to your own device are controlled by you. Deletion requests may be sent to support.

6. Who we share it with

We use service providers under contractual controls: hosting and storage, authentication and database services, payment providers for our own subscriptions, transactional email and support delivery, security/analytics services selected under your cookie choice, and AI generation providers when you request generation. Processors receive only the data required for their function.

Stripe or PayPal may independently process subscription payment and fraud-prevention data under their own privacy notices. Quotely does not see or store your full payment card number. Quotely never processes payments between you and your client.

7. International transfers

Because we serve users globally, processors may handle data outside the UK or EEA. Where required, we rely on adequacy regulations, the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses and supplementary safeguards.

8. How long we keep it

Account and active document data is kept while your account is open. AI working inputs, uploads and results are cached for no longer than 30 days; deleted content may remain in protected backups for up to 90 days. Support records are normally kept for 24 months; security logs for up to 12 months; subscription, invoice and tax records for up to 7 years where required; cookie consent records for up to 24 months. A legal hold may extend the relevant period.

9. Security

We use access controls, encrypted transport, restricted service credentials, logging and provider security reviews. No internet service can guarantee absolute security. Do not submit full card details, passwords, government identity documents or unnecessary sensitive personal data in a job brief.

10. UK GDPR, EU GDPR and CCPA rights

Depending on your location, you may request access, correction, deletion, restriction, portability or objection, or withdraw consent. You may complain to the UK Information Commissioner's Office or the competent supervisory authority. We may verify identity before responding.

California residents may request to know, correct or delete covered personal information and may not be discriminated against for exercising rights. Quotely does not sell personal information and does not share it for cross-context behavioural advertising. To make a request or submit a Do Not Sell or Share request, email our support address with the subject Privacy Request.

11. Cookies and analytics

Essential cookies support security, session continuity and cookie preferences. Optional analytics is used only after consent where required. Details and controls are in the Cookie Policy.

12. Automated decisions and children

Quotely generates editable documents but does not make decisions producing legal or similarly significant effects about individuals. Users must review outputs. The service is not for children under 13; users aged 13–17 require a parent or guardian's consent.

13. Contact and complaints

Contact us at support@qcodesoftl.shop or using the company details above. If you are unhappy with our response, you also have the right to complain to the UK Information Commissioner's Office or your competent supervisory authority.