Privacy Policy

Last updated: 11 August 2026

1. Who we are

Quantilence is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS]. For anything in this policy, contact us at privacy@quantilence.com.

Where this policy uses “you”, it means the person or company holding a Quantilence account. Where it refers to data subjects, it means the people whose faces or documents you upload — who are usually not our customers.

2. Information we collect

Account information. Your name, email address, and the company, role and country you give us during onboarding.

Billing information. Your billing address, legal company name and tax identifier, and a record of each payment (amount, date, card brand and last four digits). We never see or store full card numbers — card details go directly to our payment provider.

Files you upload. Images and documents you submit to the tools. These are processed and returned; we do not keep the original upload once the result has been produced.

Biometric data. When you enrol a face in Face Store, we generate and store indefinitely: a mathematical representation of the face (a 512-dimension embedding vector) and a cropped image of the face, along with any name or metadata you attach. This is what makes the collection searchable later. See section 4.

Usage records. For each operation: which tool was used, when, whether it succeeded, and how long it took. We use this to meter your plan and to show you your own usage.

3. Why we process it, and on what basis

For account, billing and usage data we rely on performance of a contract — we cannot provide or bill for the service without it — and, for security and fraud prevention, on our legitimate interests.

For biometric data we rely on the explicit consent of the data subject, obtained by you. See the next section: this is the most important obligation in this document.

We do not sell personal data, and we do not use your uploads to train models.

4. Biometric data

Face embeddings and face crops are biometric identifiers. They are treated as special category data under the UK and EU GDPR, and are separately regulated in several other places, including Illinois (BIPA), Texas and Washington in the United States, and under India’s DPDP Act.

Your responsibility.You are the controller of any face data you enrol. Before uploading a person’s face you must have obtained their informed, explicit and documented consent, told them how long it will be kept, and given them a way to withdraw it. We act as your processor. If you cannot evidence that consent, do not upload the face.

How it is stored. Embeddings are held in a database partitioned by account. Face crops are held in private object storage — they are not publicly accessible, and every image is served through a link that expires after ten minutes. Data from one account is never searchable from another.

How long we keep it. Until you delete it. Deleting a face removes both the embedding and the stored image; deleting a collection removes all of them; deleting your account removes everything. There is no separate retention period — if you want a face gone, delete it and it is gone.

What we do not do. We do not use enrolled faces to train or improve any model, we do not share them with other customers, and we do not enrich them from any outside source.

5. Who we share it with

We use these subprocessors. We do not sell or rent data to anyone.

  • Dodo Payments — Merchant of Record. Handles checkout, card storage, tax and invoicing. Receives your name, email and billing address.
  • [HOSTING PROVIDER] — hosts the application and databases in [REGION].
  • [EMAIL PROVIDER] — delivers transactional email (verification, billing notices). Receives your email address.

We will also disclose data where we are legally compelled to, and will tell you first unless we are prohibited from doing so.

6. How long we keep things

  • Uploaded files — not retained after processing.
  • Face embeddings and crops — until you delete them.
  • Usage records — [12] months, then deleted.
  • Account and billing records — deleted when you delete your account, except where tax law requires us to keep transaction records; our payment provider retains its own copies independently.

7. Your rights

Depending on where you live you may have the right to access, correct, delete, export, or restrict our processing of your personal data, to object to it, and to withdraw consent. To exercise any of these, email privacy@quantilence.com. We respond within one month.

Deletion is self-service. Settings → Danger zone deletes your account, cancels your subscription, and erases your face collections, the stored images, and your usage history. You do not need to ask us.

If a data subject contacts us directly about face data you enrolled, we will refer them to you, since you are the controller of it.

In the EEA or UK you may also complain to your local supervisory authority.

8. Security

Data is encrypted in transit. Each account’s data is isolated at the database level by row-level security, so one customer’s records are not reachable from another’s session. Face images sit in private storage behind expiring links. Passwords are hashed and never stored in readable form.

We do not currently hold SOC 2, ISO 27001, or any other third-party security certification. If you need one for procurement, tell us — we would rather you knew that now than found out during a review.

9. Cookies

We use a session cookie to keep you signed in and a preference cookie to remember your light or dark theme. Google Analytics sets a third cookie, holding a random identifier, so that repeat visits to these pages can be counted as one visitor rather than several. There is no advertising cookie and no session recording, and nothing you do inside the dashboard — the files you upload, the results you get — is sent to it.

10. International transfers

Our infrastructure is hosted in [REGION]. Where data moves outside the UK or EEA, we rely on Standard Contractual Clauses or an adequacy decision. Ask us and we will tell you exactly where your data sits.

11. Children

The service is not for anyone under 16, and we do not knowingly collect their data. If you believe a child’s data has been uploaded, contact us and we will remove it.

12. Changes

If we make a material change we will email you before it takes effect. The date at the top always reflects the current version.