Policies
Privacy Policy
Accurate to the real architecture as of 2026-07-13. Two things must be true when this goes live: (a) the retention-deletion jobs in §8 are actually running, and (b) the Data Processing Agreement referenced in §12 is published. Set the effective date on publication.
Last updated: 2026-07-13
Data controller: Quadrant Sunshine Unipessoal LDA · Avenida 5 de Outubro 72, R/C Loja B, 1050-063 Lisboa, Portugal
Contact: privacy@quadrantsunshine.com
1. This policy and our two roles
Quadrant Sunshine ("QS", "we", "us") builds AI employees — voice, WhatsApp and email agents — for businesses. We handle personal data in two distinct roles:
As a controller — for personal data whose purposes we decide: visitors to this website, people who contact us or book a meeting or demo, and business contacts we reach out to.
As a processor — for the personal data of our clients' own customers, which our AI agents handle on behalf of, and on the documented instructions of, each client. There, the client is the controller and we act under a written Data Processing Agreement (Article 28 GDPR). This policy explains our processor role and our sub-processors; each client's own privacy notice governs its customers.
We process personal data in line with the EU General Data Protection Regulation (GDPR) and the EU AI Act (Regulation (EU) 2024/1689).
2. The personal data we handle
As a controller (our website, prospects and client accounts):
Identity and contact details: name, business name, email, phone number.
Meeting/demo bookings: the details you submit and the related calendar information.
Communications: emails, messages and call notes you exchange with us.
Website and technical data: IP address and basic device/usage data needed to serve and secure the site.
Business-contact data used for B2B outreach: name, role, business email/phone, company, and the public source it came from.
As a processor (on behalf of our clients):
Caller and contact details (name, phone number).
Call recordings and transcripts; WhatsApp and chat message content; voice-note audio.
Booking details (name, time, contact); order details; CRM records.
We do not seek to collect special-category data. Voice recordings are treated as sensitive.
3. Why we process it, and our legal basis
Purpose Legal basis (Article 6 GDPR) Provide the service — answer calls and messages, book appointments, take orders Performance of a contract — 6(1)(b) Reminders, follow-ups, retention outreach, securing and improving the service Legitimate interests — 6(1)(f) B2B outreach to business contacts Legitimate interests — 6(1)(f); business-to-business only, never consumers Invoicing and legally required records Legal obligation — 6(1)(c) Anything we ask your consent for (e.g. optional marketing) Consent — 6(1)(a), withdrawable at any time
Where we act as a processor, the lawful basis for an end-customer's data is set by our client (the controller); we process only on its instructions.
4. AI transparency and automated decisions
You always know it's an AI. Our voice and messaging agents identify themselves as an artificial-intelligence assistant, in line with Article 50 of the EU AI Act.
No manipulation. Our agents inform and assist. They surface relevant options honestly and never use deceptive or high-pressure techniques, never fabricate urgency, and never invent facts or prices.
No solely-automated decisions. We do not make decisions producing legal or similarly significant effects about a person by automated means alone (Article 22 GDPR). Bookings, quotes and reminders are administrative and reversible, and a person remains responsible.
5. AI models and training
We do not use your data — or your customers' data — to train AI models, and we require our AI sub-processors not to train on it. We configure our language-model providers to disable training and data retention on the data we send them, and we keep the systems that store your records within the EU (see §6–7). We use AI providers only to operate the service for you.
6. Where your data is stored
Our systems of record — the databases, CRM and call/booking records — are self-hosted on infrastructure located in Germany (EU), with a disaster-recovery copy in Switzerland (recognised by the European Commission as providing an adequate level of protection). Keeping your records within the EU/adequacy area is a core part of our design.
7. Who we share it with, and international transfers
We do not sell your personal data. We share it only with the service providers needed to run the service — each bound by appropriate data-protection terms and permitted to use it solely to provide their service to us. These providers fall into the following categories:
Cloud hosting and infrastructure — where our systems run and are backed up (EU and adequacy regions).
AI language- and voice-processing providers — to power the agents; configured not to train on the data (see §5).
Messaging and telephony providers — to deliver calls and messages.
Email delivery providers — to send transactional and, where permitted, outreach email.
Scheduling and calendar providers — to manage appointments.
Security and content-delivery providers — to protect and serve our website and services.
Where a provider is located outside the EU/EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision. We maintain an up-to-date list of the specific providers we use; we make that list available to our business clients under our Data Processing Agreement, and we inform them before we add or change a provider so they may object.
8. How long we keep it
We keep personal data only as long as necessary for the purposes above:
Conversation logs (call/chat transcripts, message history): up to 12 months.
Voice recordings: up to 30 days, then deleted.
Email content and delivery logs: up to 90 days.
B2B outreach contact data: up to 24 months.
Opt-out / do-not-contact records: kept indefinitely, solely to honour your request.
Records we must keep by law (e.g. invoices): for the period the law requires.
After these periods we delete or anonymise the data. Where we act as a processor, retention follows the client's instructions and the Data Processing Agreement.
9. How we protect it
We apply appropriate technical and organisational measures: encryption in transit (TLS) across all services; encryption at rest for sensitive credentials; strict access controls with per-client data isolation, so one client's data is never exposed to another; least-privilege access; and regular backups held within the EU/adequacy area. No system is perfectly secure, but we work continuously to keep your data safe, and we will notify the relevant parties of a personal-data breach without undue delay, as required by Articles 33–34 GDPR.
10. Your rights
Under the GDPR you have the right to: access your data; have it corrected; ask us to delete it; restrict or object to its use; data portability; and, where we rely on consent, to withdraw that consent at any time. To exercise any of these, contact privacy@quadrantsunshine.com. If we handle your data on behalf of one of our clients, we will forward your request to that client (the controller) or help them respond. You also have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt.
11. Cookies
Our website uses only the cookies necessary to operate and secure it; we do not use advertising or cross-site tracking cookies. Where any non-essential cookie is used, we ask your consent first. Our AI messaging and voice services do not use browser cookies.
12. Data Processing Agreement (for business clients)
Business clients are the controllers of their end-customers' data and enter into our Data Processing Agreement (Article 28 GDPR), which forms part of their contract and sets out our processor obligations, security measures, the specific list of sub-processors, and retention periods. It is available on request and at dpa.quadrantsunshine.com.
13. Changes to this policy
We may update this policy from time to time. The current version, with its "last updated" date, is always available on this page.
14. Contact
Quadrant Sunshine Unipessoal LDA · Avenida 5 de Outubro 72, R/C Loja B, 1050-063 Lisboa, Portugal · privacy@quadrantsunshine.com · Supervisory authority: CNPD (www.cnpd.pt).
