Quotien Application — Privacy Notice
Quotien is operated by Quotien Switzerland, 1950 Sion, Switzerland ("Quotien", "we"). As a Swiss company offering the service to customers in Switzerland and the EU/EEA, we comply with both the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).
1. Scope
This notice covers the Quotien application — the signed-in product where organizations run AI process interviews, build maps, generate reports, upload documents, and (optionally) connect cloud storage or use voice. It is distinct from and supplements the quotien.com website privacy policy, which covers only the marketing site. Where they conflict for application data, this notice governs.
2. Controller and processor
Quotien's role differs by data type:
- Customer content — interview transcripts, captured process data, maps, uploaded documents and their extracts, and connected-drive files. These belong to and are controlled by the customer organization (the controller). Quotien acts as a processor, handling this content only on the customer's documented instructions to provide the service, under a Data Processing Agreement (§13).
- Account & operational data — a user's name, work email, company, role, authentication data, and technical/usage logs. For this, Quotien is the controller.
Customer content may include personal data about the customer's own employees or third parties (e.g. named in an SOP or interview). The customer is responsible for having a lawful basis to provide it; Quotien processes it as instructed.
3. Information we process
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, company, role, password hash, locale | You / your admin at signup or invite |
| Workspace content | Interview transcripts & captured slots, maps/graphs, reports | Generated as you use the product |
| Documents | Files you upload; the structured text extract we derive; chunks + embeddings | You / your admin |
| Connected storage | Files an admin selects via a cloud picker (see §7); their extracts | Google Drive / Microsoft (opt-in) |
| Voice audio | Live interview/dictation audio (see §6) | You, when voice is used (currently unavailable) |
| Technical data | Cookieless usage analytics, hosting/security logs, IP (transient) | Automatically, via our host |
We do not use tracking cookies and do not sell personal data.
4. Why we process it, and legal bases
We process personal data on the following bases (GDPR Art. 6; the equivalent grounds apply under the Swiss FADP):
- To provide the service (run interviews, generate maps/reports, retrieval, account management) — performance of a contract, Art. 6(1)(b); for customer content, on the controller's instructions under the DPA.
- Optional features you switch on (voice, cloud connectors) — consent, Art. 6(1)(a); withdrawable by disabling the feature.
- Security, abuse prevention, and service reliability (logs, rate limiting) — legitimate interests, Art. 6(1)(f).
- Transactional email (verification, invites, resets) — contract necessity.
5. AI processing and model training
Quotien uses AI models to conduct interviews, generate maps and reports, and create embeddings for retrieval. Neither Quotien nor its AI subprocessors use your content to train their models — each provider's API terms (Anthropic, OpenAI, Voyage) contractually exclude API inputs and outputs from model training. Content is sent to these providers only to produce your results, then discarded by them per those terms.
6. Voice (audio) processing
Voice is an optional feature (currently not enabled in production). When used:
- Realtime path (primary): audio streams directly between your browser and OpenAI's Realtime API over a peer-to-peer connection. Quotien's servers broker only the connection setup — we do not receive or store your audio.
- Dictation fallback: if the direct connection can't be established, your recording is sent to Quotien's EU servers and immediately forwarded to OpenAI for transcription. It is processed transiently to return text and is not stored.
In both cases OpenAI processes the audio as a subprocessor (§8) and only the resulting transcript is retained as workspace content.
7. Connected cloud storage (Google Drive / Microsoft)
If an admin connects a cloud drive, Quotien accesses only the specific files and folders the admin explicitly selects through the provider's file picker (Google drive.file permission) — never the full drive. We read selected files solely to extract their text (§10 extract-then-discard) to ground your workspace. Extracts are deleted when the admin removes the file, disconnects the integration, or deletes the account.
Google API Limited Use. Quotien's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except as necessary for security, to comply with law, or with your explicit consent.
8. Subprocessors
We engage the following processors to run the service. The current list is also published at quotien.com/subprocessors.
| Subprocessor | Purpose | Primary location | Content it may process |
|---|---|---|---|
| Neon | Application database | Frankfurt, EU (eu-central-1) | All stored data |
| Vercel | App hosting & compute; cookieless analytics; logs | EU (fra1) | Data in transit, logs |
| Anthropic | Default LLM inference (interviews, maps, reports) | United States | Content sent for generation |
| OpenAI | Optional LLM inference; voice audio; optional embeddings | United States | Content / audio when used |
| Voyage AI | Default text embeddings for retrieval | United States | Document/interview text |
| Resend | Transactional email | EU (eu-west-1) | Name, email |
| Google / Microsoft | Cloud-storage connector (opt-in) | US / EU | Admin-selected files |
| Customer-configured endpoint | If a customer sets their own AI endpoint (Azure OpenAI EU, AWS Bedrock Frankfurt, Mistral, self-hosted) | Customer's choice (e.g. EU) | Content, per their config |
9. International transfers and EU data residency
Stored data and application compute are EU-domiciled (Neon Frankfurt, Vercel fra1). As a Swiss controller, transfers between the EU/EEA and Switzerland are covered by the European Commission's adequacy decision for Switzerland.
Our default AI subprocessors (Anthropic, OpenAI, Voyage) process in the United States; those transfers rely on appropriate safeguards — the EU Standard Contractual Clauses (with the Swiss addendum recognized by the FDPIC) and, where a provider is certified, the Data Privacy Framework. Customers requiring EU-only inference can configure their own EU AI endpoint (§8, last row) — e.g. Azure OpenAI in the EU or Claude on AWS Bedrock Frankfurt — so no content leaves the EU for inference. Email (Resend) is processed in the EU.
10. Retention and deletion
- Uploaded/connected files: we keep only the derived extract — the original file content is discarded after extraction (extract-then-discard).
- Voice audio: not stored (§6); only transcripts are retained.
- Workspace content & account data: retained while the account is active; deleted (or returned) on request, on document/connector removal, or on account deletion, subject to short backup-rotation and legal-retention windows.
- Deleting a document removes its chunks and embeddings.
11. Security
We protect data with encryption in transit (TLS) and at rest, logical isolation of each organization's data enforced at the data-access layer, and least- privilege access to AI providers through platform-held credentials that are never exposed to other tenants. Where cloud-storage connectors are enabled, third-party access tokens are encrypted at rest. We restrict internal access to production data to authorized personnel and will notify affected customers of a personal- data breach without undue delay, as required by the GDPR and the Swiss FADP.
12. Your rights
Under the GDPR and the Swiss FADP you may request access, rectification, erasure, restriction, portability, and objection. Because Quotien is a processor for workspace content, end-users (e.g. a customer's employees) should exercise these rights through the customer organization that controls that data; we assist the customer in responding. For account data (where Quotien is controller), contact us directly at hello@quotien.com. You may also lodge a complaint with your data protection authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, your national supervisory authority.
13. Data Processing Agreement (DPA)
For customer content, Quotien acts under a DPA that incorporates the GDPR Art. 28 processor terms, this subprocessor list (with a mechanism to object to new subprocessors), and the EU Standard Contractual Clauses (with the Swiss addendum) for onward transfers. A DPA is available to customers on request at hello@quotien.com.
14. Changes and contact
We will post changes here with an updated version and date, and notify customers of material changes (including new subprocessors) in advance where required.
Controller: Quotien Switzerland, 1950 Sion, Switzerland
Contact: hello@quotien.com
