Quotien Application — Privacy Notice
Quotien is operated by Quotien Switzerland, 1950 Sion, Switzerland ("Quotien", "we"). As a Swiss company offering the service to customers in Switzerland and the EU/EEA, we comply with both the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).
1. Scope
This notice covers the Quotien application — the signed-in product where organizations run AI process interviews, build maps, generate reports, upload documents, and (optionally) connect cloud storage, connect an operational system such as Zendesk, Jira or ServiceNow, or use voice. It is distinct from and supplements the quotien.com website privacy policy, which covers only the marketing site. Where they conflict for application data, this notice governs.
2. Controller and processor
Quotien's role differs by data type:
- Customer content — interview transcripts, captured process data, maps, uploaded documents and their extracts, connected-drive files, and the records we read from a connected operational system. These belong to and are controlled by the customer organization (the controller). Quotien acts as a processor, handling this content only on the customer's documented instructions to provide the service, under a Data Processing Agreement (§13).
- Account & operational data — a user's name, work email, company, role, authentication data, and technical/usage logs. For this, Quotien is the controller.
Customer content may include personal data about the customer's own employees or third parties (e.g. named in an SOP or interview). The customer is responsible for having a lawful basis to provide it; Quotien processes it as instructed.
3. Information we process
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, company, role, password hash, locale | You / your admin at signup or invite |
| Workspace content | Interview transcripts & captured slots, maps/graphs, reports | Generated as you use the product |
| Documents | Files you upload; the structured text extract we derive; chunks + embeddings | You / your admin |
| Connected storage | Files an admin or a member selects via a cloud picker (see §7); their extracts | Google Drive (opt-in) |
| Operational system records | Tickets, issues and incidents from a connected system: each record’s own summary line, the sequence of actions on it, and an identifier for the person who acted (see §7) | Zendesk / Jira / ServiceNow (opt-in) |
| Voice audio | Live interview/dictation audio (see §6) | You, when voice is used |
| Technical data | Cookieless usage analytics, hosting/security logs, IP (transient) | Automatically, via our host |
| Audit records | A record of significant actions in a workspace: what was done, when, by which user, and to what | Written by Quotien as the product is used |
We do not use tracking cookies and do not sell personal data.
4. Why we process it, and legal bases
We process personal data on the following bases (GDPR Art. 6; the equivalent grounds apply under the Swiss FADP):
- To provide the service (run interviews, generate maps/reports, retrieval, account management) — performance of a contract, Art. 6(1)(b); for customer content, on the controller's instructions under the DPA.
- Optional features you switch on (voice, cloud storage and operational-system connectors) — consent, Art. 6(1)(a). Voice is used only when you start a voice session or dictate, so withdrawing means not using it. A connector can be disconnected by an administrator in the product, and anyone who authorised one can also revoke Quotien's access directly with the provider.
- Security, abuse prevention, and service reliability (logs, rate limiting) — legitimate interests, Art. 6(1)(f).
- Transactional email (verification, invites, resets) — contract necessity.
5. AI processing and model training
Quotien uses AI models to conduct interviews, generate maps and reports, extract the text of documents you upload, and create embeddings for retrieval. Document extraction sends the file itself to the model, so a PDF or image you upload is processed by the AI provider configured for your workspace. Where an operational system is connected, each record’s own summary line is also sent to our embedding provider (§8) so that related work can be matched. Neither Quotien nor its AI subprocessors use your content to train their models — each approved provider's API terms contractually exclude API inputs and outputs from model training. Content is sent to these providers only to produce your results, then discarded by them per those terms.
Product lookup. When an administrator adds a tool to the register, Quotien searches the public web for that product and asks the model to summarise what it does, so that reports can be specific about the software you already own. Only the product name leaves the workspace; the pages that come back are public vendor documentation. A tool marked as built in house is never searched, because the name of an internal system is itself sensitive.
6. Voice (audio) processing
Voice is an optional feature, used only when you start a voice session or dictate. When used:
- Realtime path (primary): audio streams directly between your browser and OpenAI's Realtime API over a peer-to-peer connection. Quotien's servers broker only the connection setup — we do not receive or store your audio.
- Dictation fallback: if the direct connection can't be established, your recording is sent to Quotien's EU servers and immediately forwarded to OpenAI for transcription. It is processed transiently to return text and is not stored.
In both cases OpenAI processes the audio as a subprocessor (§8) and only the resulting transcript is retained as workspace content.
7. Connected systems
Cloud storage (Google Drive). An administrator can connect a drive for the whole organization, and a member can connect their own. In both cases Quotien accesses only the specific files that person explicitly selects through Google's file picker (the drive.file permission) — never the full drive. We read selected files solely to extract their text (§10) to ground your workspace.
What disconnecting does, and does not do. Disconnecting revokes our access to the source and destroys the stored credential, so nothing further is read. It does not delete text already extracted from the files that were selected: that extract is your organization's own content and stays in the workspace until the document is deleted, or the workspace is. Removing or unsharing a file inside Google Drive likewise does not delete an extract already taken from it. To remove the content, delete the document in Quotien (§10).
Operational systems (Zendesk, Jira, ServiceNow). An administrator can connect a service desk or issue tracker so that Quotien can measure how work actually flows. We read records and their history only; we do not create, modify or close records in your systems. From each record we store its own summary line, the sequence of actions taken on it, and an identifier for the person who acted. That identifier is stored once per person so it can be found and erased on request; on the individual event records the actor is held only as a pseudonym. These records commonly describe people who are not Quotien users — your staff and the people who contacted them — and they are customer content, controlled by your organization (§2). Where Jira is connected, Atlassian requires us to report the account identifiers we hold back to Atlassian periodically so that deletions on their side reach us; we do this on a weekly cycle and it carries no other content.
Google API Limited Use. Quotien's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except as necessary for security, to comply with law, or with your explicit consent.
8. Subprocessors
We engage the following processors to run the service. The current list is also published at quotien.com/subprocessors.
| Subprocessor | Purpose | Primary location | Content it may process |
|---|---|---|---|
| Neon | Application database | Frankfurt, EU (eu-central-1) | All stored data |
| Vercel | App hosting & compute; cookieless analytics; logs | EU (fra1) | Data in transit, logs |
| Anthropic | Default LLM inference (interviews, maps, reports) | United States | Content sent for generation |
| OpenAI | Optional LLM inference; voice audio | United States | Content / audio when used |
| OVHcloud | Embedding inference for semantic retrieval (AI Endpoints, bge-m3); background application compute | France, EU (Gravelines); Frankfurt, EU (compute) | Document/interview text; summary lines of records from connected operational systems |
| Tavily | Web search for the product lookup in the tool register | United States | Only the product name an administrator types when adding a tool. No workspace content, and no organization or user identifier |
| Resend | Transactional email; notification digests | EU (eu-west-1) | Name, email; in digest emails, the organization and map names and short summaries of what changed |
| Cloud-storage connector (opt-in) | US / EU | Only the files the connecting person selects | |
| Customer-configured endpoint | If a customer arranges their own AI endpoint with us (for example Azure OpenAI in the EU, or an OpenAI-compatible endpoint they host). We must review and approve the host first, so this is arranged with us rather than self-served | Customer's choice (e.g. EU) | Content, per their config |
9. International transfers and EU data residency
Stored data and application compute are EU-domiciled (Neon Frankfurt; Vercel fra1; a background worker on OVHcloud in Frankfurt). As a Swiss controller, transfers between the EU/EEA and Switzerland are covered by the European Commission's adequacy decision for Switzerland.
Our LLM subprocessors (Anthropic and optional OpenAI), and the web-search subprocessor used for the product lookup (Tavily), process in the United States; those transfers rely on appropriate safeguards — the EU Standard Contractual Clauses (with the Swiss addendum recognized by the FDPIC) and, where a provider is certified, the Data Privacy Framework. Customers requiring EU-only inference can ask us to approve an EU AI endpoint for their organization (§8, last row) — for example Azure OpenAI in the EU. We review and allowlist the host before it can be used, so this is arranged with us rather than self-served. Two limits matter: this covers text generation, and voice and dictation always run against our own OpenAI endpoint in the United States, so an organization that needs EU-only processing should not use them. Email (Resend) is processed in the EU.
10. Retention and deletion
- Uploaded/connected files: we keep only the derived extract — the original file content is discarded after extraction (extract-then-discard). An uploaded original is held in our EU database only until extraction runs, normally seconds to minutes. If extraction cannot run yet — for example the workspace has used its monthly AI allowance — the file is kept until it can be processed, which may be until the allowance renews; deleting the document removes it immediately. Files read from a connected drive are never stored in original form.
- Voice audio: not stored (§6); only transcripts are retained.
- Workspace content: retained while the workspace is active, and deleted (or returned) on request. Deleting a document deletes it; deleting the organization deletes the workspace and everything in it, including maps, documents and their extracts, reports, and records imported from connected systems. Disconnecting a connector does not delete content already imported (§7).
- Account data: deleted or pseudonymised on request. Erasing an individual removes their sign-in credentials, sessions, connector tokens and workspace memberships, and replaces their name and email with a pseudonym. It does not delete the work they authored: maps, interviews, documents and reports belong to the customer organization that controls them (§2), and are removed by that organization or when its workspace is deleted. A minimal placeholder record is kept so that the organization's own history stays intelligible.
- Audit records — who did what, and when — are kept as evidence for about twelve months and are then purged. They cannot be edited.
- Deleting a document removes its chunks and embeddings. If that document was used to prepare an interview, short excerpts copied into that map before the interview began stay with the map, and go when the map, or the workspace, is deleted.
- Deletion is subject to short backup-rotation windows.
11. Security
We protect data with encryption in transit (TLS) and at rest, logical isolation of each organization's data enforced at the data-access layer, and least- privilege access to AI providers through platform-held credentials that are never exposed to other tenants. Where cloud-storage connectors are enabled, third-party access tokens are encrypted at rest. We restrict internal access to production data to authorized personnel and will notify affected customers of a personal- data breach without undue delay, as required by the GDPR and the Swiss FADP.
12. Your rights
Under the GDPR and the Swiss FADP you may request access, rectification, erasure, restriction, portability, and objection. Because Quotien is a processor for workspace content, end-users (e.g. a customer's employees) should exercise these rights through the customer organization that controls that data; we assist the customer in responding. For account data (where Quotien is controller), contact us directly at hello@quotien.com; §10 sets out exactly what an erasure removes and what stays with the customer organization. You may also lodge a complaint with your data protection authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, your national supervisory authority.
13. Data Processing Agreement (DPA)
For customer content, Quotien acts under a DPA that incorporates the GDPR Art. 28 processor terms, this subprocessor list (with a mechanism to object to new subprocessors), and the EU Standard Contractual Clauses (with the Swiss addendum) for onward transfers. A DPA is available to customers on request at hello@quotien.com.
14. Changes and contact
We will post changes here with an updated version and date, and notify customers of material changes (including new subprocessors) in advance where required.
Controller: Quotien Switzerland, 1950 Sion, Switzerland
Contact: hello@quotien.com
