Quantheo AI SaaS ("we", "us", "our") is the Data Controller responsible for your personal data under the General Data Protection Regulation (EU) 2016/679 ("GDPR").
If you have any questions about this Privacy Policy or your personal data, you can contact us at:
This Privacy Policy applies to all visitors and users of www.quantheo.ai and its associated subdomains (saas.quantheo.ai, demo.quantheo.ai, contact.quantheo.ai, sub.quantheo.ai, stats.quantheo.ai).
This policy is provided in accordance with Articles 13 and 14 of the GDPR and applies to all individuals located in the European Economic Area (EEA), the United Kingdom, and Switzerland, as well as any visitor whose personal data is processed by us.
3. Personal Data We Collect
We collect the following categories of personal data:
Contact & Account Data: Your name, email address, business/activity name, website links, and any information you voluntarily submit through our contact or setup forms.
Business Content: Text files (up to 50,000 characters), logo images, background images, and suggested questions you upload for AI training.
Usage Data: IP address, browser type, device information, pages visited, timestamps, and referral URLs. This data is derived from HTTP request metadata (including Cloudflare's request.cf fields such as country code).
Geolocation Data (Country-level): We detect your country from Cloudflare's edge network to determine whether GDPR applies to your visit. We do not collect precise geolocation data.
Communication Data: The contents of emails and form submissions you send to us.
4. How We Collect Your Data
We collect personal data through the following methods:
Information you provide directly: When you fill out our setup form, contact form, or subscribe to a plan.
Automatic collection: When you visit our website, our hosting provider (Cloudflare) automatically processes technical data such as IP address and request metadata at the edge.
5. Purposes & Legal Bases
We process your personal data for the following purposes, each with a corresponding legal basis under Article 6 of the GDPR:
5.1 Performance of a Contract (Art. 6(1)(b))
Setting up, configuring, and maintaining your AI SaaS assistant.
Processing your subscription payments and managing your account.
Training the AI model on the content you provide.
5.2 Consent (Art. 6(1)(a))
Storing non-essential cookies or local storage entries beyond what is strictly necessary for the site to function.
Any optional advertising or cross-site tracking, if and when implemented.
You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5.3 Legitimate Interests (Art. 6(1)(f))
Ensuring the security and integrity of our platform (e.g., detecting abuse, fraud, or malicious traffic).
Measuring aggregate website performance and traffic via privacy-preserving, cookieless analytics (see Section 6.2).
Improving our website performance and user experience.
Communicating with you about your subscription or service updates.
5.4 Legal Obligation (Art. 6(1)(c))
Complying with applicable tax laws (e.g., processing billing location data for VAT/tax determination).
Responding to lawful requests from authorities where required.
6. Cookies & Local Storage
We use the following types of storage and measurement tools on your device:
6.1 Strictly Necessary (No consent required)
Theme preference (localStorage: theme) — Stores your day/night theme choice. This is strictly necessary for the functionality you requested and does not require consent under the ePrivacy Directive.
Cookie consent record (localStorage: cookieConsent) — Remembers your consent choices so we don't ask you again.
6.2 Analytics
Cloudflare Web Analytics — We use Cloudflare's privacy-first analytics beacon to measure aggregate site traffic (page views, load performance). It does not use cookies, does not track you across other websites, and does not build an individual profile of you. We rely on legitimate interest (Art. 6(1)(f)) for this processing, as it is limited to aggregate, non-invasive measurement. See Cloudflare Web Analytics for details.
We do not currently deploy any advertising or cross-site tracking cookies. If we add any in the future, they will only be activated after you give explicit consent via Cookie Settings below.
6.3 Third-Party Embeds
YouTube (privacy-enhanced mode): We embed videos using youtube-nocookie.com, which is YouTube's privacy-enhanced mode. This means YouTube will not set cookies until you press play. When you interact with the embedded video, YouTube may set cookies on your device. Please refer to Google's Privacy Policy for details.
6.4 Managing Cookies
You can manage or withdraw your cookie/local storage consent at any time via , also available in the footer, or by clearing your browser's local storage.
7. Data Sharing & Recipients
We do not sell your personal data. We share it only with the following categories of recipients:
Cloudflare, Inc. — Our CDN, edge computing, and analytics provider. Cloudflare processes IP addresses and request metadata at the edge. See Cloudflare's Privacy Policy.
Google LLC (YouTube) — Video embedding via privacy-enhanced mode. See Google's Privacy Policy.
Resend Email service provider — Used to deliver form submissions and communications to our team via Resend
We may also disclose data if required by law or to protect our legal rights.
8. International Data Transfers
Your personal data may be transferred to and processed in countries outside the EEA, UK, or Switzerland, including the United States (where Cloudflare, Dodopayments, and Google are located).
We ensure appropriate safeguards are in place for such transfers:
Cloudflare is certified under the EU-U.S. Data Privacy Framework and the UK Extension.
Dodopayments complies with applicable data transfer frameworks.
Google relies on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs).
Where no adequacy decision or certification applies, we use Standard Contractual Clauses (Art. 46 GDPR) or rely on a derogation under Art. 49 GDPR.
9. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
Active subscriptions: Data is retained for the duration of your subscription plus 30 days after cancellation to allow for account recovery.
AI training content: Retained for the duration of your subscription. Deleted within 30 days of cancellation.
Contact form submissions: Retained for up to 24 months for communication and support purposes.
Usage/technical data: Retained for up to 30 days, except where longer retention is required for security or legal compliance.
Billing records: Retained as required by applicable tax law (typically 7–10 years).
After the retention period, data is permanently deleted or anonymized.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
TLS/SSL encryption for all data in transit.
Access controls limiting data access to authorized personnel only.
Regular security reviews of submitted content before AI deployment.
Secure storage of API keys and credentials.
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR, and affected individuals where required under Article 34.
11. Your Rights Under GDPR
As a data subject located in the EEA, UK, or Switzerland, you have the following rights:
Right of Access (Art. 15): You can request a copy of the personal data we hold about you.
Right to Rectification (Art. 16): You can ask us to correct inaccurate or incomplete data.
Right to Erasure / "Right to be Forgotten" (Art. 17): You can ask us to delete your personal data in certain circumstances.
Right to Restriction of Processing (Art. 18): You can ask us to restrict processing of your data in certain situations.
Right to Data Portability (Art. 20): You can receive your data in a structured, machine-readable format and transmit it to another controller.
Right to Object (Art. 21): You can object to processing based on legitimate interests or for direct marketing.
Rights Related to Automated Decision-Making (Art. 22): You have the right not to be subject to solely automated decisions with legal or significant effects.
To exercise any of these rights, contact us at info@quantheo.ai. We will respond within one month (Art. 12(3)).
12. Withdrawal of Consent
If we are processing your personal data based on your consent (e.g., non-essential cookies), you have the right to withdraw that consent at any time.
Withdrawing consent does not affect the lawfulness of any processing we carried out before the withdrawal. It also does not affect processing that is based on other legal bases (e.g., contract performance or legal obligation).
You can withdraw consent by:
Clicking in the footer and updating your preferences.
Our AI SaaS assistant is trained on the content you provide and generates responses based on that content. This is a tool you control and configure — it does not make solely automated decisions about you that produce legal or similarly significant effects.
We do not use automated profiling that produces legal effects or significantly affects you. Any AI processing is done for the purpose of providing the service you subscribed to, based on the contract between us (Art. 6(1)(b)).
14. Children's Data
Our services are not directed at individuals under the age of 16 (or the age of digital consent in your country of residence). We do not knowingly collect personal data from children.
If you believe a child has provided us with personal data, please contact us at info@quantheo.ai and we will promptly delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will update the "Last updated" date at the top of this page whenever we make changes.
If we make material changes, we will notify you via a prominent notice on our website or by email (if we have your contact details).
16. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority in the EU member state, the UK (Information Commissioner's Office), or Switzerland (Federal Data Protection and Information Commissioner) where you live, work, or where an alleged infringement of GDPR occurred.
We encourage you to contact us first at info@quantheo.ai so we can address your concerns directly.