PRIVACY POLICY

PRIVACY POLICY

Quantalis

Company

SALAZAR & Co. d.o.o.

Brand / Service

Quantalis

Registered office

Radnička cesta 80, 10000 Zagreb, Croatia

OIB / VAT ID

87140852001

Company registration number (MBS)

081409536

Registration court

Commercial Court in Zagreb

Support and written complaints

support@quantissoftwaresolution.com

Website

https://www.quantissoftwaresolution.com

 

 

 

1. Purpose and Scope

This Privacy Policy explains how SALAZAR & Co. d.o.o. (the “Company”, “we”, “us” or “our”), operator of Quantalis, collects, uses, stores, shares and protects personal data in connection with the Quantalis website, account registration, free trials, Subscriptions, payment-related functions, support communications and delivery of the Service.

This Policy is intended to satisfy applicable data-protection and privacy transparency requirements, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) where it applies, the Croatian data-protection framework, and applicable privacy laws in other jurisdictions.

2. Data Controller

The controller responsible for personal data processed for the operation of Quantalis is SALAZAR & Co. d.o.o., Radnička cesta 80, 10000 Zagreb, Croatia.

Privacy questions and requests may be sent to support@quantissoftwaresolution.com.

3. Personal Data We Process

3.1 Account and Contact Data

  • · name and surname, where provided
  • · email address
  • · mobile telephone number
  • · username, account ID or other User identifier
  • · selected product, Subscription status, billing frequency and relevant activation, trial, cancellation and billing dates
  • · transaction IDs, payment status and related accounting or invoicing records
  • · limited payment-method identifiers received from the payment service provider, such as a token, card fingerprint, masked card data, card brand or expiry information where made available
  • · records showing the User’s acceptance of legal documents and affirmative payment or Subscription consents, including date and time and the material terms accepted

3.2 Subscription, Payment and Consent Data

The Company does not store the User’s full payment-card number or CVV on its own systems. Full card data are processed in the secure environment of the authorized payment service provider.

3.3 Technical, Security and Usage Data

  • · IP address
  • · device, operating system and browser information
  • · date and time of access
  • · security, authentication, error and system logs
  • · cookie and similar-technology data where applicable
  • · emails and other communications with the Company
  • · support requests, complaints and payment-related inquiries
  • · information voluntarily provided by the User when requesting assistance

3.4 Communications and Support Data

3.5 Telegram and Delivery-Channel Data

Where the Service is delivered through Telegram or another third-party platform, the Company may process the User’s platform identifier, username or alias, group/channel access status and information necessary to activate, maintain or remove access.

The Company does not receive access to private communications between Users merely because the Service is delivered through Telegram. Telegram and other third-party platforms process data under their own terms and privacy notices.

3.6 Sources of Personal Data

Personal data are obtained directly from the User, generated through the User’s use of the Service, or received from authorized payment providers, communication platforms, security providers or other service providers to the extent necessary for the purposes described in this Policy.

4. Purposes of Processing

  • · creating and administering User accounts
  • · activating and delivering free trials and paid Subscriptions
  • · providing and controlling access to Quantalis products and delivery channels
  • · processing payments, billing, invoices, refunds and payment-related support
  • · maintaining records of Subscription and payment authorization
  • · preventing fraud, repeated free-trial abuse, unauthorized access and other misuse
  • · providing customer support and handling complaints
  • · maintaining security, system stability, logging and technical troubleshooting
  • · complying with accounting, tax, legal, regulatory and dispute-resolution obligations
  • · protecting the Company’s legal rights and establishing, exercising or defending legal claims
  • · using non-essential analytics or similar technologies where valid consent has been obtained and where such technologies are used

5. Legal Bases Where the GDPR Applies

Where the GDPR applies, the Company relies on one or more of the following legal bases:

  • · performance of a contract or steps taken at the User’s request before entering into a contract, including account, Subscription and Service delivery processing
  • · compliance with legal obligations, including accounting, tax, consumer-protection and regulatory obligations
  • · legitimate interests, including security, fraud prevention, free-trial abuse prevention, service integrity, technical maintenance and protection of legal claims, provided those interests are not overridden by the User’s rights and freedoms
  • · consent, where processing legally requires consent, including non-essential cookies or similar technologies where applicable

6. Automated Decision-Making and Profiling

Quantalis does not use personal data to make automated decisions about the User that produce legal effects or similarly significant effects within the meaning of applicable data-protection law.

Analytical Outputs are market-focused and are not personalized on the basis of a User’s financial situation, portfolio, risk profile or investment objectives.

7. Recipients and Service Providers

Personal data may be disclosed only where reasonably necessary to authorized recipients, including:

  • · IT infrastructure, hosting, cybersecurity and technical support providers
  • · email and communication service providers
  • · payment service providers, acquirers, card-related service providers and invoicing/accounting providers
  • · Telegram or other delivery platforms selected by the User or used to provide the Service
  • · analytics providers where analytics are actually used and legally permitted
  • · professional advisers, auditors or insurers where reasonably necessary
  • · courts, regulators, tax authorities, law-enforcement bodies or other public authorities where disclosure is legally required

Depending on the specific processing activity, a recipient may act as the Company’s processor, sub-processor or independent controller. Where required, the Company uses appropriate data-processing agreements and safeguards.

8. International Transfers

Personal data may be processed within the European Economic Area and, where necessary for the Service, in other countries in which authorized service providers operate.

Where the GDPR applies and personal data are transferred to a country that is not recognized as providing an adequate level of protection, the Company will use an applicable lawful transfer mechanism, such as European Commission Standard Contractual Clauses or another mechanism permitted by law, together with supplementary safeguards where required.

9. Data Retention

Personal data are retained only for as long as reasonably necessary for the purposes for which they were collected, taking into account the duration of the User relationship, accounting and tax requirements, payment and chargeback periods, security needs, limitation periods and the need to establish, exercise or defend legal claims.

When personal data are no longer required, they are deleted or anonymized unless further retention is required or permitted by applicable law.

10. Security

The Company applies appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration or disclosure. Measures may include access controls, encryption where appropriate, authentication, activity logging, security monitoring and restricted access based on operational need.

No internet-based system can guarantee absolute security. Where applicable law requires notification of a personal-data breach, the Company will make the required notifications within the applicable legal time limits.

11. Privacy Rights

11.1 Rights Where the GDPR Applies

Subject to the conditions and exceptions in applicable law, a data subject may have the right to:

  • · obtain access to personal data
  • · correct inaccurate or incomplete personal data
  • · request deletion
  • · request restriction of processing
  • · object to certain processing based on legitimate interests
  • · receive certain data in a portable format
  • · withdraw consent at any time where processing is based on consent, without affecting prior lawful processing
  • · lodge a complaint with a competent data-protection supervisory authority

11.2 Privacy Rights in Other Jurisdictions

Where applicable privacy law in the User’s country or U.S. state grants additional rights, the User may exercise those rights subject to the law’s scope, thresholds, exceptions and verification requirements. Depending on the applicable law, these rights may include rights to know or access, correct, delete, obtain a portable copy, opt out of certain sales, sharing, targeted advertising or qualifying profiling, appeal a rights-request decision, and receive equal service without unlawful discrimination for exercising privacy rights.

The Company does not currently sell personal data and does not currently use personal data for cross-context behavioral advertising. If the Company’s practices materially change, this Policy and any legally required privacy controls will be updated before the new processing is implemented.

12. Cookies and Similar Technologies

The website may use strictly necessary cookies and, where enabled, non-essential analytics or similar technologies. Non-essential technologies requiring consent will not be used before valid consent is obtained where applicable law requires consent.

More information is provided in the Quantalis Cookies Policy and the website’s cookie settings tool.

13. Children

The Service is intended for Users who are at least 18 years old. The Company does not knowingly offer the Service to children under 18 or intentionally collect their personal data for account or Subscription purposes.

14. Exercising Privacy Rights

Privacy requests may be submitted to support@quantissoftwaresolution.com. The Company may request information reasonably necessary to verify the identity and authority of the requester and will respond within the period required by applicable law.

Where applicable law permits an authorized agent to submit a request, the Company may require evidence of the agent’s authority and may verify the request directly with the User where permitted.

15. Complaints

Where the GDPR applies, the User may lodge a complaint with the competent supervisory authority, including the Croatian Personal Data Protection Agency (AZOP) where Croatia is the competent authority, or with another supervisory authority that has jurisdiction under applicable law.

Privacy complaints may also be sent directly to the Company using the contact details below.

16. Changes to this Privacy Policy

The Company may update this Privacy Policy when processing activities, legal requirements or the Service change. Where applicable law requires advance notice or consent for a material change, the Company will provide it.

17. Contact

For privacy questions, rights requests or complaints, contact SALAZAR & Co. d.o.o. at support@quantissoftwaresolution.com or by post at Radnička cesta 80, 10000 Zagreb, Croatia.