Snapshot 57811
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Policy | The Quantic Factory
THE QUANTIC FACTORY - PRIVACY POLICY
Document control Value
Organization THE QUANTIC FACTORY SAS
Version 4.0
Effective date 25 September 2026
Review cycle At least every 12 months, and after any material change to processing
Contact dpo [at] quanticfy. io
This policy replaces the version dated December 2021.
1. Who we are
The Quantic Factory ("TQF", "we", "us") is a société par actions simplifiée incorporated in France, registered with the Paris Trade and Companies Register under number 900 795 766.
TQF publishes software-as-a-service products for e-commerce merchants: QTrack QSide, and Qfy. These products collect, structure and analyse a merchant's own first-party data, and synchronise signals to the third-party tools that the merchant has chosen, including Klaviyo, Shopify, advertising platforms and analytics tools.
For any question about this policy or about personal information, write to dpo [at] quanticfy. io.
2. Scope of this policy
This policy explains how TQF handles personal information:
in its products and integrations, including the Klaviyo integration, where TQF acts for a merchant;
on its website and in its own business relationships, where TQF acts for itself.
It applies worldwide. Section 11 sets out the additional rights of California residents, and section 12 the rights granted by other United States state privacy laws.
3. Our two roles
TQF processes personal information in two distinct capacities. The rights you can exercise, and the party you exercise them against, depend on which one applies.
Capacity What it covers Legal characterisation
Processor and service provider Personal information belonging to a merchant's customers and site visitors, processed through our products and their integrations Processor under Article 4(8) GDPR; service provider under California Civil Code section 1798.140(ag)
Controller and business Personal information of our own prospects, clients, their staff, our website visitors and our applicants Controller under Article 4(7) GDPR; business under California Civil Code section 1798.140(d)
Where we act as a processor and service provider, the merchant is the controller and the business. The merchant decides what is collected, on what legal basis, and for how long. We act only on that merchant's documented instructions, under a data processing agreement concluded pursuant to Article 28 GDPR. If you are a customer of a merchant and you wish to exercise your rights, address the merchant first; if you contact us, we will forward your request to the merchant without undue delay and support the merchant in answering it.
4. Personal information we process for a merchant
4.1 Categories of information
Category Examples
Customer identifiers Email address, merchant-assigned customer identifier, internal pseudonymous identifiers, first-party cookie identifier
Contact details Email address, and where the merchant transmits them, name and postal locality
Consent and preference status Subscription status, opt-in and opt-out signals, suppression status
Event data Page views, product views, add-to-cart, checkout steps, purchases, email opens and clicks reported by the merchant's messaging tools
Order metadata Order identifier, order value, currency, order date, product references
Indicators computed by our services Results computed from the categories above and returned to the merchant
This information comes from the merchant's e-commerce platform, from the merchant's website and from the tools the merchant has connected.
4.2 What we never process through these integrations
We do not process, through customer or partner integrations, special-category data within the meaning of Article 9 GDPR, health data, non-public government identifiers, financial account data, payment card data, or data known to relate to children below the age at which the applicable law permits processing. Merchants must not transmit such data to us.
4.3 Purposes
We process this information only to deliver the services the merchant has subscribed to, as described in the merchant's contract and product documentation, and to provide support, security, fault diagnosis and service continuity.
4.4 What we do not do with it
We do not sell this information and we do not share it for cross-context behavioural advertising. We do not use it for advertising of our own. Each merchant's data is logically isolated from every other merchant's data: we do not enrich one merchant's data with another merchant's data, we do not create new contacts, and we do not send messages to a merchant's customers.
We use aggregated and anonymised statistics, from which neither a merchant nor an individual can be identified, to measure and improve the technical quality of our services. Where a merchant's data processing agreement restricts that use further, the data processing agreement prevails.
4.5 Partner integrations
Where a merchant connects a partner platform such as Klaviyo, the integration is authorised through OAuth 2.0 Authorization Code flow with PKCE, with the least-permissive scope set required for the features the merchant has enabled. Access and refresh tokens are held in an encrypted secret store and are never exposed in browsers, logs or repositories. When the merchant uninstalls or disables the integration, we revoke the tokens with the partner platform and delete the associated integration data in accordance with section 7. Data obtained through a partner platform is used solely to deliver the merchant's subscribed services and is never used for any unrelated purpose.
5. Personal information we process for ourselves
This section covers our website, our commercial relationships and our administrative operations.
Purpose Categories processed Legal basis, Article 6(1) GDPR
Managing contracts and client accounts Identity, professional contact details, account and subscription data, correspondence Article 6(1)(b), performance of a contract or pre-contractual steps
Billing, payment and accounting Identity, billing details, invoices, payment status, VAT identifiers Article 6(1)(c), compliance with a legal obligation
Providing support Identity, professional contact details, ticket content, technical logs Article 6(1)(b), performance of a contract
Business-to-business prospecting Professional contact details, company information, interaction history Article 6(1)(f), our legitimate interest in developing our client base; you may object at any time
Satisfaction surveys and client research Professional contact details, survey answers, usage statistics Article 6(1)(f), our legitimate interest in improving our services
Website audience measurement and site security Connection data, pseudonymous identifiers, operation logs Article 6(1)(f) for strictly necessary measurement and security; consent under Article 6(1)(a) for any non-essential cookie
Managing disputes and claims All of the above, as relevant Article 6(1)(f), our legitimate interest in establishing or defending a legal claim
Recruitment Application data provided by the candidate Article 6(1)(b), pre-contractual steps, and Article 6(1)(a) for a talent pool
Providing the information needed to subscribe to our services is a contractual requirement: without it we cannot enter into the contract.
6. Recipients and disclosures
6.1 Categories of recipients
Category Role
Hosting and infrastructure providers located in the European Union Hosting, storage and processing of the data we handle for a merchant
Business software providers Our own email, office and administrative tools
Payment and billing providers Collection of our own subscription payments
Professional advisers Accounting, tax and legal advice
Each provider is bound by written obligations of confidentiality, security, incident cooperation and return or deletion of data, at least equivalent to those we owe our clients. The current list of our subprocessors, with their identity, role and location, is provided to clients under the data processing agreement and to any person with a legitimate interest on request to dpo [at] quanticfy. io.
6.2 Disclosures on the merchant's instruction
Where we act as a processor, we transmit signals to the third-party tools that the merchant has connected, such as Klaviyo, advertising platforms and analytics tools. Those tools are the merchant's own providers; the merchant's agreements with them govern their use of the data. Those transmissions are encrypted in transit.
6.3 Other disclosures
We disclose personal information where we are required to do so by law, by a court order or by a competent authority, and to a successor entity in the context of a merger, acquisition or reorganisation, subject to equivalent protection.
We do not sell personal information and we do not disclose it to data brokers.
7. Retention
Data Retention
Data processed for a merchant For the duration of the merchant's subscription, then deleted in accordance with the merchant's instructions and the data processing agreement
Production data approved for deletion Deleted within 30 days
Residual encrypted backup copies Expire through normal rotation within 90 days, unless a longer period is legally required
Client data under an active contract For the duration of the contractual relationship, then in intermediate archive for the 5-year limitation period
Prospect data, where no contract follows 3 years from collection or from the prospect's last contact
Operation logs, including IP addresses 6 months, rolling
Security logs At least 365 days
Cookie lifetime and information collected through cookies 13 months and 25 months respectively
Accounting records 10 years, as required by the French Commercial Code
Retention periods are documented by data category and reviewed with this policy.
8. International transfers
The data we process for a merchant is stored and processed exclusively within the European Union. We make no transfer of that data outside the European Economic Area.
Two activities carried out for our own account may involve a transfer to the United States: the business email and office suite we use, and the audience measurement of our website described in section 10, which operates only after you have consented. Those transfers are governed by the European Commission's standard contractual clauses and, where the provider is certified, by the EU-US Data Privacy Framework. A copy of the transfer safeguards is available on request to dpo [at] quanticfy. io.
9. Security
TQF maintains a written information security programme covering administrative, technical and physical safeguards. It requires, among other controls: encryption in transit using TLS 1.2 or higher and encryption at rest; multi-factor authentication on every system that processes customer data; least-privilege role-based access with regular review; secrets held in a dedicated encrypted store with periodic rotation; mandatory security controls on company-managed devices, including full-disk encryption, automatic locking, security updates, endpoint protection and a host-based firewall; centralised logging and real-time alerting; a documented incident response process; and risk-based review of suppliers before any confidential data is shared, repeated at least every 12 months for critical suppliers.
A copy of our information security policy is available on request to dpo [at] quanticfy. io.
10. Cookies and similar technologies
On our own website, we use cookies that are strictly necessary to provide the site and to keep it secure, and audience-measurement cookies provided by Google Analytics 4. Non-essential cookies, including those of Google Analytics 4, are set only after you have consented through our consent banner, and you may withdraw your consent at any time through the same banner or through your browser settings. Cookie lifetime is limited to 13 months and the information collected through them is retained for no more than 25 months.
In our products, we set a first-party cookie on the merchant's own domain. That cookie does not allow tracking across other websites or applications. The merchant remains responsible for the information notice and for collecting consent where the applicable law requires it, and for offering an objection mechanism in its own privacy policy.
11. California privacy rights
This section applies to California residents and is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"). Terms used here have the meaning given to them by the CCPA.
11.1 Our role under the CCPA
For personal information we process through our products and integrations on a merchant's behalf, TQF is a service provider within the meaning of section 1798.140(ag). We process that personal information only to perform the services specified in our written contract with the merchant. We do not sell it, we do not share it for cross-context behavioural advertising, we do not retain, use or disclose it for any purpose other than performing those services, we do not retain, use or disclose it outside the direct business relationship with the merchant, and we do not combine it with personal information received from another source, except where the CCPA expressly permits a service provider to do so. If you are a California resident whose personal information we process for a merchant, exercise your rights with that merchant; we will assist the merchant in responding.
For personal information we collect for our own purposes, described in section 5, TQF is a business within the meaning of section 1798.140(d). The remainder of this section concerns that information.
11.2 Categories of personal information collected in the preceding 12 months
CCPA category, section 1798.140(v) Collected Examples
A. Identifiers Yes Name, professional email address, telephone number, account identifier, IP address
B. Personal information under Civil Code section 1798.80(e) Yes Name, professional contact details, billing details
C. Protected classification characteristics No Not collected
D. Commercial information Yes Subscription purchased, invoices, payment status, interaction history
E. Biometric information No Not collected
F. Internet or other electronic network activity Yes Browsing on our own website, pages viewed, interaction with our communications
G. Geolocation data No We do not collect precise geolocation; an IP address may indicate an approximate city
H. Sensory data No Not collected
I. Professional or employment-related information Yes Employer, job title, professional role; application data for candidates
J. Non-public education information No Not collected
K. Inferences drawn from the above Yes Commercial interest in our products, segment of our client base
L. Sensitive personal information, section 1798.140(ae) No Not collected. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit under section 1798.121
11.3 Sources
We collect this personal information directly from you when you contact us, subscribe to our services or apply for a role; from your employer or from the company you represent; automatically from your device when you visit our website; and from publicly available professional sources and business-information providers in the course of business-to-business prospecting.
11.4 Business and commercial purposes
We use this personal information to enter into and perform our contracts, to invoice and collect payment, to provide support, to secure and maintain our systems, to carry out business-to-business prospecting, to conduct satisfaction surveys and client research, to comply with our legal and accounting obligations, and to establish or defend legal claims. These are business purposes within the meaning of section 1798.140(e).
11.5 Disclosures for a business purpose
In the preceding 12 months, we disclosed categories A, B, D, F, I and K to the categories of recipients listed in section 6.1, for the business purposes stated above, and to professional advisers and competent authorities where required.
11.6 No sale and no sharing
In the preceding 12 months, TQF has not sold personal information and has not shared personal information for cross-context behavioural advertising, within the meaning of sections 1798.140(ad) and 1798.140(ah). Neither selling personal information nor sharing it for cross-context behavioural advertising forms part of our business model, and we do not intend to engage in either. We have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age; we do not knowingly collect personal information from minors.
11.7 Retention
We retain each category of personal information for the periods stated in section 7. We do not retain personal information for longer than is reasonably necessary for the purpose for which it was collected.
11.8 Your California rights
Subject to the conditions and exceptions of the CCPA, you have the right to:
know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes, and the categories of third parties to whom we disclose it;
delete the personal information we have collected from you;
correct inaccurate personal information we hold about you;
opt out of the sale or sharing of your personal information. We do not sell or share personal information, so there is nothing to opt out of; we honour Global Privacy Control signals received on our website as an opt-out request should that ever change;
limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information, so this right does not arise;
not be discriminated against for exercising any of these rights. We will not deny you goods or services, charge you a different price, or provide a different level of quality because you exercised a privacy right.
11.9 How to exercise them
Submit a request by email to dpo [at] quanticfy. io with the subject line "California privacy request". We will confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 calendar days where reasonably necessary, in which case we will notify you within the first 45 days.
We verify requests by matching the information you provide against the information we already hold, and we may ask for additional information where the request concerns specific pieces of personal information. We will not use verification information for any other purpose.
An authorised agent may submit a request on your behalf by providing written permission signed by you, together with proof of the agent's registration where applicable; we may still ask you to verify your own identity directly.
If we refuse your request, we will tell you why. You may appeal by replying to our decision with the subject line "California privacy appeal"; we will respond to the appeal within 45 calendar days.
12. Other United States state privacy rights
Residents of other United States states that have enacted comprehensive privacy legislation, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana, have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and certain profiling. TQF does not sell personal information, does not use it for targeted advertising, and does not carry out profiling producing legal or similarly significant effects. Requests are handled through the channel in section 11.9 and answered within the period set by the applicable state law. Where that law provides a right of appeal, our appeal procedure in section 11.9 applies.
13. Your rights under the GDPR
Where we act as a controller, you have the right to request access to your personal data, its rectification, its erasure, the restriction of its processing, and its portability, and the right to object to processing based on our legitimate interest, including profiling. Where processing rests on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal. You may also give instructions on the fate of your data after your death.
To exercise these rights, write to dpo [at] quanticfy. io. We answer within one month of receipt, extendable by two further months where the request is complex, in which case we will tell you within the first month. We may ask for proof of identity where we have reasonable doubt.
You may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés, www.cnil.fr, or with the supervisory authority of your habitual residence.
Where we act as a processor for a merchant, address your request to that merchant.
14. Children
Our services are sold to professionals and are not directed to children. We do not knowingly collect personal information from children. Merchants must not transmit to us data they know to relate to children below the age at which the applicable law permits processing. If you believe a child's personal information has reached us, write to dpo [at] quanticfy. io and we will delete it.
15. Changes to this policy
We may update this policy. The current version is published at this address, in English and in French, with its version number and effective date in the document control table. Where a change materially affects how we process personal information, we will inform affected clients through the usual contractual channels before it takes effect. We review this policy at least every 12 months.
16. Contact
Subject Contact
Privacy, data protection, exercise of rights, security and incident reporting dpo [at] quanticfy. io
French supervisory authority Commission Nationale de l'Informatique et des Libertés, www.cnil.fr