Privacy Policy
Last updated: 2026-06-27
This Privacy Policy explains how Fluidlabs OÜ (“Quittance”, “we”, “us”) collects, uses, and shares personal data when you visit quittance.ai, contact us, or use the Quittance application (the “Service”). We are the controller of the personal data described here, except for the customer content you process through the Service, where we act as a processor on your behalf (see our DPA).
Who we are & how to contact us
- Controller: Fluidlabs OÜ, Vesivärava tn 50-201, Kesklinna linnaosa, Tallinn, Harju maakond, 10152, Estonia (registry code 16534086; VAT EE102514753).
- Privacy contact: privacy@quittance.ai.
- Data Protection Officer / EU representative: we have not appointed a Data Protection Officer (the Art. 37 GDPR criteria do not apply to our processing) and, as a controller established in the EU, we are not required to designate an Art. 27 EU representative.
The personal data we collect
- Account & identity - name, work email, employer, role, password/SSO identifiers.
- Contact & demo requests - the details you submit through our forms (name, email, company, message).
- Customer content - invoices, agreements, purchase orders, rate cards and related documents you (or your connected systems, e.g. Docusign Agreement Manager and your accounting system) provide to the Service, which may contain personal data such as names of vendor contacts and approvers. We process this as your processor under the DPA.
- Usage & device - log data, IP address, browser/device type, pages viewed, and actions taken, used to operate and secure the Service.
- Cookies - see our Cookie Policy.
Where we get data. Most data comes from you directly. Some personal data - for example vendor, approver and signatory contact details - is obtained indirectly, from your connected systems (Docusign Agreement Manager, your accounting system) and the documents you upload. We process this on your behalf as a processor under the DPA.
Providing certain data (for example your account details) is necessary to enter into and use the Service; without it we cannot provide the Service.
Why we use it, and our legal bases (GDPR)
- To provide the Service and our website - legal basis: performance of a contract.
- To respond to demo/contact requests - legal basis: our legitimate interest in responding to enquiries, or steps prior to a contract.
- To secure, maintain and improve the Service - legal basis: legitimate interests (kept proportionate and balanced against your rights).
- To send service and, where permitted, marketing communications - legal basis: legitimate interests or consent, with an opt-out in every marketing message.
- To comply with legal obligations - legal basis: legal obligation.
We do not use your customer content or documents to train shared or public AI models.
Who we share it with
We share personal data with vetted service providers (sub-processors) that help us run the Service - hosting, authentication, email delivery and similar - under contracts that require appropriate protection. Our current list is on the Subprocessors page. We may also disclose data where required by law, or in connection with a corporate transaction. We do not sell personal data.
International transfers
Personal data may be processed in the United States. Where personal data is transferred out of the EEA/UK, we rely on the EU Standard Contractual Clauses (Module 2, controller-to-processor)as accepted in each sub-processor’s data processing agreement, supplemented by encryption in transit and at rest as additional safeguards. Where a sub-processor is certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), we rely on that framework additionally. We do not offer EU-only data residency.
How long we keep it
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. As a baseline we retain account and contractual records for 6 years from your last contact with us, and operational logs for approximately 12 months; specific periods vary by data category. Customer content is retained and deleted per your instructions and the DPA.
How we protect it
Quittance is operated by an ISO/IEC 27001:2022-certified organisation (Fluidlabs OÜ). Data is encrypted in transit and at rest, access is role-based and least-privilege, and we maintain organisational and technical security measures appropriate to the risk.
Your rights
Subject to applicable law, you have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent at any time. Where we rely on consent, you can withdraw it at any time - use the unsubscribe link in our emails, or contact privacy@quittance.ai - without affecting the lawfulness of processing before withdrawal. To exercise these rights, contact privacy@quittance.ai.
If you are in the EEA/UK and believe we have not handled your data properly, you may lodge a complaint with your supervisory authority - our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
Automated decision-making
Quittance does not make decisions producing legal or similarly significant effects about you that are based solely on automated processing. Our flags, scores and drafts are decision-support: a person on your team reviews them and decides what to do.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know the categories and specific pieces of personal information we collect, the purposes for collection, and the categories of recipients; to delete and to correct your personal information; to opt out of any sale or sharing of personal information; and to limit the use and disclosure of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information beyond the purposes permitted by the CPRA. We will not discriminate against you for exercising your rights. We retain each category of personal information for as long as needed for the purposes for which it was collected, in line with the retention periods described in “How long we keep it” above. You may submit a request yourself or through an authorized agent acting on your behalf. To make a request, contact privacy@quittance.ai.
Children
The Service is for business use and is not directed to children; we do not knowingly collect personal data from children.
Changes
We may update this policy; we will post the new version here and update the date above, and notify you of material changes where required.
Contact
Questions about this policy or your data: privacy@quittance.ai.