Privacy
These notes describe the intended data processing for the website and Quinn application. Before go-live, controller, providers, transfer bases and retention periods must be finally reviewed and completed.
Last updated: May 2026
Controller
[Enter Quinn legal entity, address and contact before go-live]
Privacy contact
[Enter privacy@quinn.example or data protection officer contact]
Hosting and auth
Supabase, server-side application, protected organisation areas
AI processing
OpenAI API for transcription, structuring and draft support
Required information
The controller for this website and the Quinn application is [enter full company name, legal form, address, authorised representatives and contact].
For privacy questions, contact us at [enter email]. If a data protection officer is appointed, the name or contact route must be added here.
We process account data, organisation data, roles and permissions, team memberships, logging, security data, billing information and content entered in consultation, care or healthcare workflows. This can include audio, transcripts, free text, documentation drafts, SIS-related content and export data.
In customer use, Quinn may process health data and care-related information. This requires an appropriate legal basis, clear role allocation and contractual rules between customer and provider.
Data is processed to authenticate users, manage organisations, provide documentation workflows, turn audio and text into reviewable drafts, log approvals and exports, provide support, monitor security and enable billing.
Depending on the use case, processing is based on contract performance, legitimate interests, legal obligations, consent or, for health data, a separately reviewed basis under Art. 9 GDPR. Customers remain responsible for their professional and legal use.
We use technical service providers, especially for hosting, authentication, storage, error analysis, AI processing and, where applicable, billing. The concrete processor list must be completed before go-live.
Where providers outside the EU/EEA are used or remote access from third countries is possible, suitable safeguards such as EU standard contractual clauses, adequacy decisions or additional protective measures are reviewed and documented.
Data is stored only as long as required for contract, operation, evidence, security, billing or legal obligations. The deletion concept covers user deletion, organisation deletion and customer-specific export or retention periods.
Quinn uses technically necessary cookies and comparable technologies, especially for login sessions and protected areas. Further details are provided in the cookie notice.
Quinn uses technical and organisational safeguards such as protected areas, role-based access, logging, separated organisation data and controlled storage paths. AI outputs remain drafts; professional responsibility stays with the user.
Data subjects have rights under GDPR including access, rectification, erasure, restriction, portability, objection and complaint to a supervisory authority.
This privacy information may be updated if the product, providers, law or processing operations change.