Privacy Policy
Version 2.2 · 28.09.2026
This policy explains what personal data we process and on what terms. We act in two different roles. For the quanty.ai website, the waitlist, user accounts and billing we are the controller. For the content our customers put into Quanty, including call data handled by the AI Secretary, we are a processor and the customer is the controller. Sections 2 to 4 cover the first role, sections 5 to 8 the second. The Polish version of this document governs.
1. Who is responsible
Quanty is operated by Pluscode Sp. z o.o. (PLUSCODE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ), registered office: ul. Kosowska 12/3, 60-464 Poznań, Polska, entered in the register of entrepreneurs of the Polish National Court Register kept by Sąd Rejonowy Poznań - Nowe Miasto i Wilda w Poznaniu, VIII Wydział Gospodarczy Krajowego Rejestru Sądowego (District Court Poznań - Nowe Miasto i Wilda in Poznań, 8th Commercial Division), under KRS number 0000811470, NIP (VAT) 7812002984, REGON 384741150, share capital 5 000,00 PLN.
For anything related to personal data write to dawid@pluscode.io. The contact person is Dawid Kubicki (CEO).
We have not designated a data protection officer. The assessment under art. 37(1)(c) GDPR is under way and we repeat it with every new customer that processes health data. If we designate an officer, we will publish the contact here and notify the Polish supervisory authority.
2. Data we process as controller
Waitlist: your email address, and optionally your name, phone number and industry if you choose to provide them.
Demo requests: your name, work email, and optionally company and a note about what to look at.
Contact form: your name, email, optional subject, and your message.
Quanty account: email address, name, a hash of your password, second-factor data, account settings, IP address and sign-in time, and a record of security events.
Second factor by SMS, if you switch it on: the mobile phone number you register yourself, the one-time code sent to it, and delivery metadata, that is a timestamp and a delivery status. We keep the number so that you can receive later codes, and we show it back to you only masked. Codes are stored hashed; they expire after 5 minutes, work once, and are limited by a cooldown between sends and a daily cap.
Billing: company name and address, tax number, the plan you chose, payment history and invoices. We never see or store your card details; Stripe handles them.
Support tickets and correspondence with us.
Website usage statistics: only if you accept analytics cookies in the banner, Google Analytics sets its cookies (_ga and _ga_S5GL271GPC) and records the pages you visit, how you reached the site, your device and browser, and your approximate location. If you decline, no analytics cookie is set and Google Analytics receives only cookieless signals without identifiers. You can change your choice at any time under "Cookie settings" in the footer.
Your theme, language and cookie choice are stored only in your browser (localStorage) and never leave it.
3. Why and on what legal basis (controller role)
To run the waitlist and contact you when your seat opens: our legitimate interest (art. 6(1)(f) GDPR) and, once a contract exists, its performance (art. 6(1)(b)).
To schedule and hold a demo you requested: steps taken at your request before entering an agreement (art. 6(1)(b)).
To run your account and provide the service: performance of the agreement (art. 6(1)(b)).
Billing, invoicing and accounting: legal obligation (art. 6(1)(c)) and tax law.
Security of the service, abuse prevention, and establishing or defending legal claims: our legitimate interest (art. 6(1)(f)).
Sending a one-time code by SMS as a second factor: securing the account, which is our legitimate interest (art. 6(1)(f)) and, for business customers, performance of the agreement (art. 6(1)(b)). We do not use the number for marketing and we do not contact you on it for anything other than authentication codes.
Answering your messages and handling support: our legitimate interest (art. 6(1)(f)).
Measuring how the site is used with analytics cookies: your consent (art. 6(1)(a)), which you can withdraw at any time.
4. How long we keep it (controller role)
Waitlist data: until the purpose of the list ends, or until you ask us to remove you. Leaving the waitlist takes one email.
Demo and contact messages: as long as needed to handle the conversation, then up to 3 years for accountability, unless you request deletion earlier.
Account: for the term of the agreement. After you delete an account we move it to an archived state for 180 days so it can be restored after a mistake, then delete it permanently.
The phone number registered as a second factor: for as long as that factor stays enrolled. We delete it when you remove SMS as a factor or when you delete the account. The codes themselves are discarded on use or after 5 minutes; the security log keeps only the fact that a code was sent and whether it was entered correctly.
Billing records and invoices: 5 years from the end of the tax year, as the law requires.
Security logs and the record of platform admin actions: up to 12 months, unless they relate to an incident under investigation.
Analytics data: for the retention period set in our Google Analytics property, at most 14 months.
5. Customer data we process as a processor
Everything you put into Quanty, or that Quanty fetches on your instruction, we process only to provide the service: tables and records, files, AI chat content, data from connected mailboxes, spreadsheets and file stores such as SharePoint and OneDrive, and call data handled by the AI Secretary.
We do not use that data for our own purposes, we do not sell it and we do not use it to train models. We do not profile the people it describes.
You are the controller of that data. Our processing rests on a data processing agreement (art. 28 GDPR). The template is published at /dpa and we sign it with every customer who asks.
If a data subject contacts us directly, we pass the request to the controller and tell the person we have done so, unless the controller instructs otherwise.
6. Where the data is, and when it leaves the EEA
The Quanty application and database run in Amazon Web Services in the eu-central-1 Region (Frankfurt, Germany) since 13.09.2026. Customer files are stored in the same Region.
Earlier versions of this policy said that data stays in the European Economic Area. That sentence is not true for every feature and has been removed. Every case in which data leaves the EEA is described below.
AI features in the application run on Amazon Bedrock. The default configuration allows a request to be routed to AWS Regions outside the EEA. The basis is the AWS data processing addendum, which incorporates the Standard Contractual Clauses. For customers for whom we enable EU-only routing, requests do not leave the EU.
Web search that you start yourself, in columns and in chat, is run by Exa Labs, Inc. in the United States. Exa receives the text of your query.
AI Secretary: calls are handled by Eleven Labs, Inc. Call data is stored in the United States by default, and processing may take place in the US, the EU or Singapore. The transfer rests on the European Commission adequacy decision (EU-US Data Privacy Framework), with the Standard Contractual Clauses as a fallback. Claiming that call data never leaves the EU would be false.
AI Secretary, the carriage layer: where a customer connects a number through AWS, the inbound call arrives over an Amazon Chime SDK Voice Connector SIP trunk in the eu-central-1 Region (Frankfurt, Germany). AWS then receives the call signalling: the calling and the called number, the start and end time, the duration, and the audio in transit. That layer does not leave the EU. The conversation itself is still handled by Eleven Labs as described above.
One-time SMS codes are sent through Amazon Web Services, using AWS End User Messaging SMS (the service formerly branded Amazon Pinpoint SMS), in the eu-central-1 Region (Frankfurt, Germany). That processing does not leave the EU. The message itself is then delivered by your mobile network operator, which is an independent controller for the delivery and works under its own contract with you. We have no control over what the operator records about the delivery, or for how long.
Google Analytics: data may be processed by Google LLC in the United States, certified under the EU-US Data Privacy Framework.
The full list of providers, processing locations and transfer safeguards is published at /subprocessors.
7. Who processes data for us
Amazon Web Services EMEA SARL: hosting for the application and database, file storage, outgoing and incoming email (Amazon SES), sign-in (Amazon Cognito), sending one-time SMS codes (AWS End User Messaging SMS), the SIP trunk for AI Secretary numbers connected through AWS (Amazon Chime SDK Voice Connector) and AI models (Amazon Bedrock).
Stripe Payments Europe, Limited with Stripe, Inc.: payments and invoicing. Stripe processes payer data as a separate controller to the extent payment services law requires.
Exa Labs, Inc.: web search started by a user.
Eleven Labs, Inc.: speech recognition, conversation and speech synthesis in the AI Secretary, together with the language model providers it engages (Google Cloud for Gemini and Claude models, OpenAI for GPT models).
Twilio Ireland Limited with Twilio Inc.: phone numbers and call routing, only where Quanty provides the number. If you use your own operator, it works under your own contract.
Your mobile network operator: it delivers the SMS carrying a one-time code. It is not our processor. For the delivery itself it is an independent controller and works under the contract you have with it.
Google Ireland Limited: Gmail and Google Sheets, only if you connect your own Google account, and Google Analytics if you accept analytics cookies.
Microsoft Ireland Operations Limited: an Outlook mailbox, and files in SharePoint or OneDrive, only if you connect your own Microsoft account (section 11).
We do not sell personal data and we do not share it with advertisers. Each provider works under a processing agreement and only on our documented instruction, except in the cases described above where the provider acts as a separate controller.
8. AI Secretary
The AI Secretary answers phone calls on behalf of a customer and writes the request into that customer’s table. The controller of the caller’s data is the customer, that is the clinic or company that switched the feature on. We are the processor.
What is processed: the caller’s phone number, the voice during the call, a text transcript, an AI-written summary of the call, and whatever the caller says, for example a name, contact details and a description of the matter.
For how long: the transcript held by the voice provider is deleted after 30 days by default. The request record written into the customer’s table stays under the customer’s control and the customer decides when to delete it. Audio recording is off by default and the customer has to switch it on deliberately.
At the start of every call the caller is told that they are speaking with an assistant based on artificial intelligence, on whose behalf it acts, that the call is stored and processed including outside the European Union, and that in a life-threatening situation they should hang up and dial 112.
The AI Secretary is an administrative intake tool. It does not assess symptoms, does not decide urgency, does not determine eligibility and does not give advice. It is not a medical device and it is not an emergency line.
We do not create a voiceprint or any other biometric profile of a caller.
The number the AI Secretary answers on is brought by the customer. It can be a number from Twilio, a number at the customer’s own SIP operator, or a number pointed at an Amazon Chime SDK Voice Connector SIP trunk in Amazon Web Services, in the eu-central-1 Region (Frankfurt, Germany). The carriage layer sees the call signalling: the calling number, the called number, the start and end time, the duration and the audio in transit. It does not see the transcript or the request written into the customer’s table.
The providers behind this feature and the transfer safeguards are listed at /subprocessors.
Status at the date of publication: the AI Secretary is not yet cleared to process health data. That requires written permission from the voice provider, which we are seeking. Until then the feature may be used for organisational matters only.
9. Google user data (Quanty application)
The Quanty application lets signed-in users connect their Google account. Connecting is always optional and always initiated by you.
Gmail (read-only scope, gmail.readonly): Quanty reads the email address of the connected account and the incoming messages that match the automation filters you configured, and only messages that arrive after you switch that automation on. Matching messages, their text and their attachments become records in your own tables, in the places you mapped them to. Quanty does not synchronise, index or archive your mailbox and does not read historical mail. The processing copy of a message is kept for up to 14 days; what was written into your tables stays in your workspace, under your control.
Gmail (send scope, gmail.send): Quanty sends messages that your own automations compose, from the connected address, for example a reply in the same thread to a message an automation has just processed, or a message to a contact stored in your table. Recipients and content always come from your own automation. Quanty sends no marketing and no bulk mail, sends nothing on its own initiative, and limits sending to 100 messages per hour per connected mailbox. The send scope gives Quanty no permission to delete or modify mail.
Google Sheets: when you share a spreadsheet with Quanty’s service account, Quanty reads and writes that spreadsheet only to perform the imports and exports you request.
OAuth tokens are stored encrypted. Message content is processed only to run your automations; results are stored in your workspace, where you can review and delete them. Disconnecting the integration in Quanty deletes the stored tokens, and you can also revoke access at any time in your Google account (myaccount.google.com/permissions).
We do not use Google user data for advertising, we do not sell it, we do not use it to train machine-learning models, and no humans read it except with your explicit permission, where necessary for security or abuse investigation, or where required by law.
Quanty’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
10. Other connected mailboxes
Besides Gmail, the Quanty application can connect a Microsoft 365 or Outlook mailbox over Microsoft Graph (section 11 describes the permissions), a mailbox at any other provider over IMAP and SMTP, and a Quanty forwarding address, which is an address on a Quanty subdomain that you forward your mail to. Connecting is always optional and always initiated by you.
OAuth tokens and mailbox passwords are stored encrypted and are never shown again after you enter them. Incoming messages are processed the same way as Gmail: only the messages that match the filters you set, the processing copy kept for up to 14 days, and the data you mapped written into your own tables. Messages sent from a connected mailbox are composed by your own automations.
A connected mailbox is private to the member who connected it until that member shares it with the workspace. Disconnecting a mailbox deletes the stored credentials.
Mail sent to a Quanty forwarding address is received through Amazon Web Services EMEA SARL (Amazon SES) in the EU (Frankfurt) Region, and the raw message is deleted after 14 days.
11. Microsoft user data (Quanty application)
The Quanty application lets signed-in users connect a Microsoft work, school or personal account through Microsoft’s own sign-in. There are two separate connections, each optional and each initiated by you: an Outlook mailbox, and files in SharePoint and OneDrive. Before you agree, Microsoft shows the exact permissions requested; in some organisations an administrator has to approve them first.
Both connections use the permissions User.Read, openid, email, profile and offline_access, so that Quanty can identify the connected account and keep the connection working without asking you to sign in again.
Outlook mailbox (Mail.Read and Mail.Send): Quanty reads new messages in the Inbox that match the automation filters you configured, and only messages that arrive after you switch that automation on, and sends the messages your own automations compose from the connected address. Section 10 describes how those messages are processed and how long they are kept. These permissions do not allow Quanty to delete, move or change your mail.
SharePoint and OneDrive (Files.Read.All and Sites.Read.All, both read-only): Quanty lists the sites, document libraries, folders and files that your own Microsoft account can already open, so that you can browse them in the application; browsing shows names, sizes, dates and locations, not contents. Quanty downloads the contents of a file only when you import it, or when it sits in a folder you chose to keep in sync. A synced folder is checked periodically, and new or changed files are copied again. The copy lands in your Quanty file library and is processed like any file you upload yourself (section 5), including text extraction and indexing for AI features. Quanty never creates, changes, moves or deletes anything in SharePoint or OneDrive, and deleting a file there does not delete the copy in Quanty.
OAuth tokens are stored encrypted and are never shown to anyone. A connection is private to the member who made it until that member shares it with the workspace. Disconnecting in Quanty deletes the stored tokens and pauses every folder sync that used the connection; files already copied stay in your library until you delete them. You can also revoke Quanty’s access at any time: for a personal account at account.live.com/consent/Manage, for a work or school account at myapps.microsoft.com, where your organisation’s administrator can also remove the application.
We do not use data received from Microsoft for advertising, we do not sell it, we do not use it to train machine-learning models, and no humans read it except with your explicit permission, where necessary for security or abuse investigation, or where required by law.
Microsoft Ireland Operations Limited provides the account under your own agreement with Microsoft and is not our processor for this data. Where the account belongs to an organisation’s Microsoft 365, that organisation controls the mail and files, and connecting them to Quanty should follow its rules.
12. Your rights
You can request access to your data, a copy of it, correction, deletion, restriction of processing and portability, and you can object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time; that does not affect processing carried out before the withdrawal.
To exercise a right against us as controller, email dawid@pluscode.io. We answer without undue delay and at the latest within one month.
For data that one of our customers put into Quanty, address your request to that customer as controller. We help them carry it out.
You also have the right to lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl) or your local authority.
13. Changes
Changes appear at this address with a new version number and date. We tell customers about material changes by email at least 30 days in advance.
Version 2.2 of 28.09.2026 adds section 11 on Microsoft accounts, including SharePoint and OneDrive files, and renumbers the sections after it.
The Polish version is the binding one. Translations are for convenience.