// LEGAL
Privacy Policy
Last updated: June 26, 2026
1. Legal Entity
This Privacy Policy applies to services provided by QUANTACODES SOLUTIONS (“we”, “us”, or “our”), a business registered in Ahmedabad, India, through Descovo. For the purposes of GDPR, QUANTACODES SOLUTIONS is the data controller for both customer account data and the business-contact dataset described below.
2. Information We Collect
We collect the minimal data necessary to provide our service:
- Account information: Email address and authentication data (via Clerk)
- API usage: Tool calls, timestamps, and response metadata for billing and rate limiting
- Payment information: Processed securely by Paddle (we never store credit card numbers)
3. What We Don't Collect
Your privacy is important to us. We explicitly do not:
- Store the content of the search queries or results you run, beyond the metadata (call count, timestamp) needed for billing
- Store your credit card numbers — payment information is handled entirely by Paddle
- Track your browsing activity outside our service
- Sell or share your customer account data with third parties for marketing
4. The B2B Contact Database We Provide
Descovo provides business-to-business contact and company information (such as professional names, job titles, business email addresses, phone numbers, and company details) to help our customers with sales, recruiting, and research. This information relates to individuals in their professional capacity.
Source of this data. We did not collect this information directly from the individuals it describes. It is obtained from publicly available sources and licensed third-party data providers, and compiled into our database.
Lawful basis (GDPR). Where GDPR applies, we process this professional contact data on the basis of our legitimate interests (and those of our customers) in providing B2B sales-intelligence and prospecting services. We have assessed that this processing is limited to professional, business-context information and is balanced against the rights and freedoms of the individuals concerned. Categories of recipients are our customers, who agree to use the data only for lawful B2B outreach in compliance with applicable law.
5. Your Choices About the Contact Database
If you are an individual whose information appears in our database, you have the right to access, correct, object to the processing of, or request deletion of your personal data, regardless of whether you are a Descovo customer. To exercise these rights, email team@descovo.com from the email address in question or with enough detail for us to locate your record. We will action verified requests in accordance with applicable law (including GDPR and CCPA/CPRA), free of charge, within the timeframes those laws require.
6. Do Not Sell or Share My Personal Information (U.S. State Privacy Rights)
Under the California Consumer Privacy Act (CCPA), as amended by the CPRA, and similar U.S. state laws, our provision of business-contact data to customers may be considered a “sale” or “sharing” of personal information. You have the right to opt out.
- Right to opt out of the sale or sharing of your personal information
- Right to know what personal information we hold about you
- Right to request deletion of your personal information
- Right to correct inaccurate personal information
- Right not to be discriminated against for exercising these rights
To submit a “Do Not Sell or Share My Personal Information” request, or any other state-privacy request, email team@descovo.com. We do not sell or share the personal information of known minors.
7. How We Use Your Data
- To provide and maintain the Descovo service
- To track API usage for billing and rate limiting
- To send service-related notifications (billing, security alerts)
- To improve our service based on aggregated usage patterns
- To comply with legal obligations
8. Data Security
We rely on infrastructure providers (AWS and Supabase) that provide encryption of data in transit and at rest, and we apply the following measures:
- API keys are SHA-256 hashed (we only store the hash)
- All data transmission uses TLS
- Access to production systems is restricted on a least-privilege basis
9. Third-Party Services (Subprocessors)
We use trusted third-party subprocessors:
- Clerk — Authentication services
- Paddle — Payment processing and Merchant of Record
- Amazon Web Services (AWS) — Infrastructure hosting
- Supabase — Managed database hosting
10. International Data Transfers
Our subprocessors may process data in countries outside your own, including the United States. Where personal data is transferred out of the European Economic Area, the United Kingdom, or other regulated regions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) and the data protection commitments offered by our subprocessors.
11. Data Retention
We retain your account data as long as your account is active. You can delete your account at any time from the dashboard. Upon deletion, we remove all personal account data within 30 days, except where legal obligations require longer retention (e.g., billing records for 7 years). Records in the B2B contact database are retained while they remain accurate and relevant for business-prospecting purposes, are periodically refreshed, and are removed upon a verified deletion or opt-out request.
12. Data Breach Notification
We maintain procedures to detect and respond to security incidents. In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals without undue delay, as required by applicable law.
13. Your Rights
As an account holder, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data
- Opt out of non-essential communications
14. Cookies
We use minimal cookies: essential session cookies for authentication and optional analytics cookies (with your consent). You can manage cookie preferences via your browser settings.
15. Children's Privacy
Our service is intended for business users aged 18 and over. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, please contact us immediately.
16. Changes to This Policy
We may update this Privacy Policy periodically. We will notify users of significant changes via email or dashboard notification. Continued use of the service after changes constitutes acceptance of the updated policy.
17. Contact Us
For privacy-related questions or requests, contact us at team@descovo.com.