Privacy
These notes describe the current processing for the website and Quinn application. Customer-specific processing, legal bases, retention periods and transfer assessments are additionally defined for the applicable contract and use case.
Last updated: July 2026
Controller
Can Yilmaz, trading as Quinn Health; The serviceable business address is currently being determined and will be added before business operations begin. Contact: can@quinnhealth.de
Privacy contact
can@quinnhealth.de
Hosting and auth
Supabase, server-side application, protected organisation areas
AI processing
OpenAI API for transcription, structuring and draft support
Required information
The controller for this website and the Quinn application is Can Yilmaz, trading as Quinn Health. The serviceable business address is currently being determined and will be added before business operations begin. Contact: can@quinnhealth.de, +49 176 81748167.
For privacy questions, contact Can Yilmaz at can@quinnhealth.de. A separate data protection officer has not currently been appointed.
We process account data, organisation data, roles and permissions, team memberships, logging, security data, billing information and content entered in consultation, care or healthcare workflows. This can include audio, transcripts, free text, documentation drafts, SIS-related content and export data.
In customer use, Quinn may process health data and care-related information. This requires an appropriate legal basis, clear role allocation and contractual rules between customer and provider.
Data is processed to authenticate users, manage organisations, provide documentation workflows, turn audio and text into reviewable drafts, log approvals and exports, provide support, monitor security and enable billing.
Depending on the use case, processing is based on contract performance, legitimate interests, legal obligations, consent or, for health data, a separately reviewed basis under Art. 9 GDPR. Customers remain responsible for their professional and legal use.
We use Vercel for website hosting and consent-based Web Analytics, Supabase for authentication, database and private storage, and OpenAI for transcription and AI-assisted draft creation. Sentry for error analysis and Upstash for technical safeguards and rate limiting are used only where activated for the relevant operational path. Roles, regions, sub-processors and transfer safeguards are specified in the applicable DPA and provider assessment.
Where providers outside the EU/EEA are used or remote access from third countries is possible, suitable safeguards such as EU standard contractual clauses, adequacy decisions or additional protective measures are reviewed and documented.
Data is stored only as long as required for contract, operation, evidence, security, billing or legal obligations. The deletion concept covers user deletion, organisation deletion and customer-specific export or retention periods.
Quinn uses technically necessary cookies and comparable technologies, especially for login sessions and protected areas. Further details are provided in the cookie notice.
Quinn uses technical and organisational safeguards such as protected areas, role-based access, logging, separated organisation data and controlled storage paths. AI outputs remain drafts; professional responsibility stays with the user.
Data subjects have rights under GDPR including access, rectification, erasure, restriction, portability, objection and complaint to a supervisory authority.
This privacy information may be updated if the product, providers, law or processing operations change.