Privacy Policy
QuintaDB Sp. z o.o. — for QuintaDB and Quinta SI
Last updated: 7 October 2026
This is the privacy policy of QuintaDB Sp. z o.o. (“the company”, “we”). It covers both of our brands and every site they run on:
- QuintaDB — quintadb.com, quintadb.ru and quintadb.com.ua;
- Quinta SI — quinta.si.
Where a brand differs, this policy says so. The policy is designed to meet the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applies to all users of our services, wherever they live.
We are committed to protecting your privacy and to handling your personal information with care. We will never sell your information to third parties for advertising purposes, and we will not profit from showing you ads from other companies. This policy says what we collect, how we use it, who has access to it and what you can do about it.
1. Who is responsible for your data
The data controller is:
QuintaDB Sp. z o.o.
ul. Karmelicka 27/301, 31-131 Kraków, Poland
registered under Polish law, KRS 0000954863, NIP 6762587272.
For anything about your personal data, write to our data protection contact at kari@quinta.si.
We keep a record of processing activities in accordance with Article 30 GDPR.
Two brands, one company. Both brands are run by the same company on the same servers. Accounts and databases are separate. An account on QuintaDB is not an account on Quinta SI. We do not move your data from one brand to the other unless you ask us to.
Two roles. For the data described in sections 2 and 3 we are the controller. For the data that our customers store in the systems they build with us, we are a processor; section 4 explains this.
2. Personal information we collect and control
We collect only the information we need to provide the products and services you ask for. This may include your name, your contact information and other details you give us when you create an account, ask for support or buy something from us.
2.1 Account sign-up
To create an account we ask for your e-mail address and a password. Depending on the brand and the form, we may also ask for your name, a contact telephone number, your company name and your country, and you may choose a user name. A photo, a time zone and a language are optional.
You need an e-mail address and a password, or a sign-in provider, to have an account. Without them we cannot provide the service.
2.2 Sign-in with Google
You can sign up or sign in with your Google account (accounts.google.com). Google then confirms who you are and gives us the identifier and the e-mail address of your Google account. We do not receive your Google password. When the sign-up or sign-in page opens, Google’s sign-in button sets a cookie of its own (section 9). What Google does with the data is governed by Google’s privacy policy.
2.3 Payment
To buy something from us we need your name and your billing details. With each payment we store the amount, the date, the payment method, and the billing name, company, address, country, telephone number and VAT number that you give. Your card details go straight to our payment provider (section 6), which processes the payment in accordance with PCI DSS standards. We do not receive or store your card number.
2.4 Interactions with us
To improve how we work with you and other customers, we may record, analyse and use your interactions with us, including e-mail, telephone and chat conversations with our sales and support teams. We do this with your consent or on the basis of our legitimate interest in the quality of customer service.
2.5 Information from browsers
When you visit our sites, we collect information that your browser, device and server make available: the internet protocol (IP) address, browser type, language preference, time zone, referring address, date and time of access, operating system, mobile device manufacturer and mobile network information. It is recorded in our log files so that we understand who visits our sites and can keep them secure.
2.6 Our own record of a first visit
When a new visitor opens one of our sites for the first time, we keep our own record of that visit:
- the address of the page;
- the address the visitor came from (the referrer);
- the campaign tags in the link (
utm_source,utm_medium,utm_campaign); - a random visitor identifier, stored in a cookie called
visitor_id.
The record holds no name and no e-mail address. If you later sign up, the record is attached to your account, so that we know which page or link brought you. With the same identifier we count a click on a link that leads from one of our brands’ sites to the other. We keep these records on our own servers.
On quinta.si this is the only measurement of visitors. On QuintaDB’s domains the tools in section 10 are used as well.
2.7 How you use the service
When you use our sites and services, we record on our own servers which areas you open and which features and settings you use. We use this to improve our products and services.
2.8 Blogs and social media
Some of our sites have public blogs, forums and social media pages. Anything you post there is public and may be used by others to contact you. Please be careful when you disclose personal information there. We are not responsible for personal information that you choose to make public. Some of your comments and some profile information may remain after you close your account. To have your information removed from our blogs and forums, write to [support address].
QuintaDB’s sites feature social media widgets, such as those of Facebook and Twitter, that let you share articles. Your interactions with these widgets are governed by the privacy policies of the companies that provide them. If you interact with our brands on social media (liking, commenting, mentioning or following us), we can see those interactions and your profile information.
2.9 Information we receive indirectly
If you ask about our products through a service provider such as Google or Meta (Facebook), they may give us your contact information. We use it to answer your request.
3. How we use your information, and the legal basis for each use
We use your information to provide the services you asked for, to maintain your accounts and to detect unauthorised activity on them. We also use it to communicate with you about the products you use, to answer your support requests, to suggest new products that may interest you, to gather feedback and to tell you about changes to our policies. We analyse the information we collect to understand what users need and to improve our sites and services.
The GDPR requires a legal basis for each use. Ours are these:
| What we do | Legal basis (GDPR Article 6) |
|---|---|
| Create and maintain your account; provide the service you asked for; answer your support requests | Performance of our contract with you — Art. 6(1)(b) |
| Take payment and issue invoices | Contract — Art. 6(1)(b). Keeping tax and accounting records is a legal obligation — Art. 6(1)(c) |
| Send service messages: about the products you use, your plan and capacity, payment reminders, notices before an inactive account is deleted, changes to this policy or to the Terms of Service | Contract — Art. 6(1)(b); our legitimate interest in keeping you informed — Art. 6(1)(f) |
| Send news of new products and services (including our other brand), events, offers and promotions; invite you to surveys or ask for feedback | Your consent where the law requires it — Art. 6(1)(a); otherwise our legitimate interest in telling our customers about our own services — Art. 6(1)(f). You can switch this off at any time |
| Detect unauthorised activity; prevent fraud, spam, phishing and abuse; keep server logs; recognise your device | Our legitimate interest in a safe service — Art. 6(1)(f) |
| Keep our own record of a first visit; analyse how visitors move through our sites; monitor and prevent problems; improve our products, services and marketing campaigns | Our legitimate interest in knowing how our services are found and used — Art. 6(1)(f) |
| Analytics, advertising measurement and session recording by other companies (QuintaDB’s domains only, section 10) | Our legitimate interest in understanding how our sites are used and whether our advertising works — Art. 6(1)(f). These tools load when a page opens; section 9.4 says how to refuse them |
| Record and analyse your conversations with our sales and support teams | Your consent — Art. 6(1)(a), or our legitimate interest in the quality of customer service — Art. 6(1)(f) |
| Comply with the law and answer lawful requests of authorities | Legal obligation — Art. 6(1)(c) |
| Establish, exercise or defend legal claims; enforce our agreements | Our legitimate interest — Art. 6(1)(f) |
| Protect someone’s life or safety, in rare cases | Vital interests — Art. 6(1)(d) |
You can decline some uses of your information by not providing it or by opting out later. Where we rely on your consent, you can withdraw it at any time: by contacting us, by changing the cookie settings of your browser or by deleting your account. Withdrawal does not affect what was done before it. Where we rely on legitimate interests, you can object (section 13).
Only employees and contractors who have a legitimate need for your personal information have access to it. If we share your information with other parties, such as developers, service providers, domain registrars and reselling partners, they must have appropriate security measures in place and a valid reason for using it, usually to serve you.
4. Service data: when we are your processor
If you use our services to store or process data about other people — your customers, leads or employees, for example — you entrust that data to us. We call it service data. You own it. Under the GDPR you are the controller of that data and we are your processor (Article 28).
We protect your service data, limit access to it and process it only on your instructions. You give those instructions through the service: by what you build, what you write and what you ask the service to do. For example, when a system of yours produces an invoice, we use the name and address of your customer to produce it. When you send e-mail to a mailing list, we use the addresses on that list to send it.
You can access, share, export and delete your service data yourself, including through the integrations you connect.
When a person who is not signed in submits one of your public web forms, the service can record that person’s IP address with the submission.
As your processor we:
- process service data only on your documented instructions, including where data leaves the EEA, unless the law requires otherwise;
- make sure that the people who can access it are bound by confidentiality;
- apply the security measures in section 12;
- use other processors (“sub-processors”) only as listed below, under contracts that give the data the same protection;
- help you, as far as the nature of the service allows, to answer requests from the people whose data it is, and to meet your own duties on security, breach notification and impact assessments;
- tell you of a personal data breach that affects your data within 72 hours of becoming aware of it;
- delete your service data when the account is deleted (sections 8 and 14); until then you can export it;
- give you the information you need to show that these duties are met.
Sub-processors for service data:
- Hetzner Online GmbH, Germany — the data centre that houses our servers;
- Google (Gemini models) and Groq — only where a service builds or changes a project from your description (section 5);
- our mail provider (section 6) — for the e-mail that your systems send;
- Clickatell — for the SMS that your systems send;
- Google (Maps Platform) — where a system of yours places addresses on a map: the address is sent to find its position, and a page that shows the map loads it from Google.
We announce a new sub-processor by changing this policy as described in section 20. If you object, you can export your data and close your account.
The terms of data processing are set by this policy and by the Terms of Service, and they form an integral part of your agreement with us. If you want a signed Data Processing Agreement that meets Article 28 GDPR, write to [support address].
If you are a person whose data was entrusted to us by one of our customers, please contact that customer to use your rights. We will work with them to fulfil your request.
5. Building from your description: model providers
Where a service builds or changes a project from a description you write, it uses language models run by other companies (“model providers”). The building is done by automated systems, not by a person.
What is sent. The text of your request and the structure of your project: the names and types of your tables, forms and fields. The contents of your records are sent only when carrying out your request requires reading them — for example, when you ask a question about your data, or ask for a record to be created or changed. Otherwise the contents of your records are not sent.
If you ask for a search of the internet or for a page to be opened, the words or the address you give are sent to the service that carries it out.
Who receives it.
- Google (Gemini models) — building and changing projects;
- Groq (open models that it hosts) — short, fast decisions about what you asked for.
What they may do with it. Both act as our processors. Under their API terms, what we send is not used to train their models. We do not use your data to train models either.
Both are companies in the United States. Section 7 describes the safeguards for that transfer.
When nothing is sent. Building by hand — creating projects, forms, portals and reports yourself — never sends your data to a model provider. Data from projects in which you have not used building by description is not sent for this processing at all. On Quinta SI, building from your description is how the service works, so this section applies to every project there.
This processing is covered by the data processing terms in section 4.
6. Who receives your data
We will never sell, rent or share your personal information with any third party for marketing purposes without your express permission.
We share personal information only with service providers who perform services on our behalf, and only as far as that is necessary to provide our services. These providers are contractually required to protect the data and may not use it for purposes of their own. All providers that process data on our behalf have signed data processing agreements that meet the GDPR. We regularly review their security measures and limit what we share to the minimum needed.
| Category | Who | Brand | What they receive |
|---|---|---|---|
| Data centre | Hetzner Online GmbH, Germany | Both | It houses the dedicated servers that we run and that hold all data and backups |
| Model providers | Google (Gemini models); Groq | Where a service builds from a description | See section 5 |
| Payment provider | Stripe | Both | Your card details and the billing details of the payment |
| Protection of forms against automated programs | Google reCAPTCHA | Both | When you open a sign-up, password-recovery or account-activation page, the support form, or a public form whose owner has switched the check on: your IP address, data about your browser and device, and a cookie of Google’s own |
| E-mail delivery | Mailgun, EU service | Both | Your e-mail address and the messages we send you |
| SMS delivery | Clickatell | Where a system sends SMS | The telephone number and the text of the message |
| Maps | Google (Maps Platform) | On pages that show a map, and where an address is placed on a map | Your IP address when the map loads; the address that is looked up |
| Sign-in | Google (accounts.google.com) | Both, if you choose it | See section 2.2 |
| Analytics, advertising measurement, session recording | Google Analytics 4, Google Ads conversion tag, Microsoft Clarity; Yandex Metrika on quintadb.ru and quintadb.com.ua | QuintaDB only | See section 10 |
| Hosts of script libraries and fonts on some pages | cdn.jsdelivr.net, unpkg.com, cdnjs.cloudflare.com, Google Fonts | See section 11 | Your IP address |
| Other providers | Developers, domain registrars and reselling partners; for QuintaDB also marketing and advertising partners and event organisers | As needed | Only what the task needs |
The payment provider also handles payment data under its own responsibility and its own privacy notice.
We may also disclose data to authorities and other third parties in the cases described in section 17.
7. Transfers outside the EEA
All user data and all backups are stored in the European Union, in Germany.
Some of the providers in section 6 are outside the European Economic Area or belong to groups based outside it, mainly in the United States: the model providers, Google, Microsoft, and the payment, mail and SMS providers. When personal data goes to them, we rely on a safeguard allowed by Chapter V of the GDPR:
- an adequacy decision of the European Commission — for the United States, the EU–US Data Privacy Framework, where the provider is certified under it; or
- the Standard Contractual Clauses approved by the European Commission.
Yandex Metrika, used on quintadb.ru and quintadb.com.ua only, is provided by the Yandex group, and the data it collects may be processed in Russia, for which there is no adequacy decision.
For users outside the EU, data transfers are carried out under GDPR-compliant safeguards, so that the protection is equivalent. You can ask for a copy of the safeguards at kari@quinta.si.
8. Retention
We keep personal data only for as long as it is needed to provide our services, comply with legal obligations, resolve disputes and enforce our agreements.
- Account data and service data — for as long as you have the account.
- After an account is deleted — all data, including backups, is permanently erased within 30 days, except where the law requires us to keep it.
- Backups — daily, encrypted, stored in the EU. They are kept for up to 30 days for disaster recovery and then deleted automatically.
- Inactive accounts — an account that nobody has signed in to and whose projects have not changed for six months gets two e-mail notices, at least two weeks apart. If nobody signs in, the account and all its data are deleted about a month after the first notice.
- Invoices and payment records — for the time that tax and accounting law requires.
- Server logs, and the first-visit record of a visitor who never signs up — for as long as we need them to keep the service secure and to understand how our sites are found. They carry no name. Once you sign up, the first-visit record is kept with your account.
- Longer, where the law allows or requires it — to maintain suppression lists, to prevent abuse, in connection with legal claims or proceedings, to enforce our agreements, or for tax and accounting.
When we no longer have a legitimate need to process your information, we delete it or make it anonymous.
9. Cookies and similar technologies
Cookies are small text files stored on your computer or other device. They identify your browser and remember information such as your sign-in or your language. We use temporary cookies, which are removed when you close your browser, and permanent cookies, which stay until they expire or you delete them.
9.1 Kinds of cookies
- Required cookies are necessary for our sites to work and cannot be switched off in our systems. If you remove or block them, we cannot guarantee that you will be able to use our sites.
- Selection cookies remember choices you make (sign-in, language, region), so that you do not have to set them again.
- Analytics cookies record information about visits to our sites, so that we can improve them and report on how they perform.
9.2 Cookies on quinta.si
| Cookie | Set by | What it is for | Kind |
|---|---|---|---|
| Session cookie | quinta.si | Keeps you signed in and keeps the state of the page between requests | Required |
qdb_device |
quinta.si | A random identifier of your device. It recognises the device at sign-in and helps prevent abuse of free capacity | Required |
visitor_id |
quinta.si | A random identifier for our own record of a first visit (section 2.6) | Analytics, our own |
g_state |
Google’s sign-in button, when the sign-up or sign-in page is opened | Remembers the state of Google’s sign-in prompt | Set by Google |
| A cookie of Google reCAPTCHA | Google, when the check runs on a page named in section 6 | Tells a person from an automated program | Set by Google |
The session cookie ends when you close your browser. visitor_id and qdb_device are kept for up to 20 years,
unless you delete them earlier.
quinta.si sets no advertising cookies and no cookies of analytics companies.
9.3 Cookies on QuintaDB’s domains
The same cookies as in section 9.2, and in addition:
- a permanent cookie when you choose “Remember me”, so that you do not have to sign in on each visit;
- selection cookies for language and region;
- the cookies of the analytics, advertising and session-recording tools in section 10;
- cookies set by social media widgets, under the policies of the companies that provide them.
9.4 The cookie notice and your choice
Our sites show a cookie notice until you close it. That you have closed it is remembered in your browser’s local
storage, not in a cookie. The notice informs; it does not ask. Required cookies and our own visitor_id cookie are
set as soon as you open a page. On
QuintaDB’s domains the analytics and advertising cookies of section 10 are also set when a page loads; quinta.si
sets none of those. You can refuse or remove cookies at any time in your browser settings.
In your browser settings you can accept all cookies, be told when a cookie is set, or reject all cookies. If you block all cookies, you may not be able to use the signed-in areas of our sites, and settings such as your sign-in may not be saved.
10. Analytics, advertising tags and session recording, by brand
Quinta SI (quinta.si). The site loads no advertising tags, no analytics of other companies and no session recording. The only measurement is our own record of a first visit (section 2.6).
QuintaDB (quintadb.com, quintadb.ru, quintadb.com.ua). These sites also use:
- Google Analytics 4 — statistics about visits;
- a Google Ads conversion tag — tells us whether a visit that came from one of our advertisements led to a sign-up;
- Microsoft Clarity — to understand how visitors use our marketing pages and the account owner’s workspace. Clarity records interactions with the page: clicks, scrolling and mouse movement. The contents of form fields are masked. Recordings are not made on client portals or public forms. The data is processed by Microsoft in accordance with the Microsoft Privacy Statement;
- Yandex Metrika — statistics about visits, on quintadb.ru and quintadb.com.ua only.
These tools load when a page of those sites opens. Section 9.4 says how to refuse their cookies.
A customer of ours may add analytics code of their own to their own public forms. That is the customer’s processing, and the customer’s privacy policy applies to it.
11. Fonts and script libraries
Our pages take their fonts and script libraries from our own servers, so that no other company learns that you opened a page. The public pages of quinta.si load nothing of this kind from another host.
A few pages inside the product still load one library or font from the host of another company:
- the workspace of a project — cdn.jsdelivr.net and unpkg.com;
- the chat page — cdnjs.cloudflare.com;
- the editor of a portal’s colours — cdn.jsdelivr.net;
- an embedded calendar — cdn.jsdelivr.net;
- the page of a single record — cdnjs.cloudflare.com and Google Fonts;
- a portal or site whose owner chose a brand font — Google Fonts.
On QuintaDB’s domains other pages may load files from the same hosts.
When your browser fetches such a file, the host receives your IP address and the usual technical details of the request, such as your browser type and the page that asked for the file. We send these hosts nothing else. We use them to display those pages correctly, on the basis of our legitimate interest (Art. 6(1)(f)). Some of these hosts are operated from outside the EEA; section 7 applies.
12. Security
We have administrative, technical and physical safeguards in place to prevent unauthorised access to, and unauthorised use, modification, disclosure or destruction of, the information you entrust to us.
- All accounts use SSL/TLS encryption by default, with strong ciphers.
- Data is stored on dedicated servers that we run, in a data centre in Germany operated by Hetzner Online GmbH, a GDPR-compliant provider certified under ISO/IEC 27001.
- Data is encrypted in transit (SSL/TLS).
- We make daily encrypted backups, stored in the EU. You can also back up your data yourself with the export options of the service.
- Passwords are not stored as you type them: we keep only a salted hash of each password. We do not give your password to third parties.
- Only employees and contractors who have a legitimate need have access to personal information. On Quinta SI our staff do not open customer data except when you ask us to look at something, and support can see what you show us.
- If a personal data breach affects your data, we notify you within 72 hours of becoming aware of it, and we notify the supervisory authority as Article 33 GDPR requires.
13. Your rights and how to use them
People in the European Economic Area have the rights below. We give the same rights to everyone, wherever they live.
- Access — to ask whether we process your data and to receive a copy of it.
- Rectification — to have inaccurate or incomplete data corrected. Most of it you can change yourself in your account.
- Erasure — to have your data deleted (section 14).
- Restriction — to ask us to limit the processing of your data in the cases the GDPR names.
- Portability — to receive the data you gave us in a structured, commonly used, machine-readable format, or to have it sent to another controller. You can export the data in your projects yourself at any time.
- Objection — to object to processing that is based on legitimate interests and, at any time, to direct marketing.
- Withdrawal of consent — at any time, where processing is based on consent. It does not affect what was done before.
- Complaint — to a supervisory authority (section 19).
To use a right, write to kari@quinta.si or use the settings of your account. We may ask you to confirm who you are. We answer within one month. For complex or numerous requests the GDPR allows two further months; we will tell you if we need them. Using your rights is free, unless a request is manifestly unfounded or excessive.
If your data was entrusted to us by one of our customers, see the last paragraph of section 4.
14. Deleting your account and personal data
You have the right to ask us to delete your personal information.
- On QuintaDB: go to the “Account” menu, the “Other” tab, and click “Delete my account” at the bottom of the page. This deletes all of your personal data and the data of your applications.
- On either brand: write to kari@quinta.si and ask us to delete your account and everything in it.
We keep the data in your account for as long as you use the service. After deletion, all data, including backups, is permanently erased within 30 days, except where the law requires us to keep it.
15. Automated decisions
We do not make decisions about you that are based solely on automated processing and that have legal effects for you or affect you in a similarly significant way, with one exception: automated checks for spam, phishing and abuse can block an account. If your account was blocked and you object, write to kari@quinta.si and ask for a person to review the decision.
Building a project from your description (section 5) is automated, but it makes no decision about you.
16. Children
We do not knowingly collect or process personal information from children under the age of 16. If we become aware of such data, we delete it promptly. If you believe we have collected personal data from a minor, please tell us at kari@quinta.si.
17. Legal disclosures and protection of rights
There are limits to the privacy we can provide. We may be required by law to keep or disclose your personal information and service data in order to comply with applicable laws, regulations, legal processes or government requests, including national security requirements.
We may share personal information and service data with a third party if we believe it is necessary to prevent fraud, filter spam, investigate suspected illegal activity, enforce our agreements or policies, or protect the safety of our users.
18. Links to other sites
Our sites contain links to external sites whose privacy and security policies differ from ours. This policy does not cover them. We make no representations or warranties about the policies and practices of sites that our services or our users link to. If you give your personal information to such a site, its own privacy policy applies. We recommend that you read that policy first.
19. Supervisory authority
If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with your local supervisory authority, or directly with:
President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland.
20. Changes to this policy
We may change this policy. We will notify users by e-mail or by a notice on our sites before changes take effect. Only the online version of this policy is valid, so please review it from time to time.
21. Language and contact
If there is any inconsistency between translations, the English version of this policy prevails.
You can contact us at any time at kari@quinta.si, or by post at the address in section 1, to:
- get more information about our privacy practices;
- use any of the rights in section 13;
- ask for a signed Data Processing Agreement;
- tell us that you believe we have collected personal data from a minor;
- ask that your personal information be removed from our blogs or social media.