This version applies to United States.
Privacy Policy
This policy explains which personal data is processed when you visit https://quotrail.com, contact us, or use the Quotrail application. In short: no advertising or analytics cookies, no tracking, no sharing for advertising purposes, and customer data from the application is never used to train AI models.
Last updated: 10/02/2026
1. Controller
Neithra Technologies – Fabian Lorenz, Thaler Weg 2a, 51647 Gummersbach, Germany. Email: [email protected]. Phone: +49 2266 4889976 (Germany), +1 332 287 9966 (USA). No data protection officer is required under Art. 37 GDPR; please direct requests to the address above.
2. Hosting and server logs
When you visit the website, our server and the upstream service Cloudflare automatically process your IP address, the date and time, the requested URL, the status code returned, the browser used and the referring page. This serves to deliver the page, defend against attacks and troubleshoot errors (Art. 6 (1) (f) GDPR — legitimate interest in secure operation). Logs on our server are deleted after 14 days at the latest unless a security incident requires them to be retained.
The website and the application run on servers of netcup GmbH in Karlsruhe (registered office), data centre in Nuremberg, Germany, which acts as our processor under Art. 28 GDPR.
All requests reach our server through the Cloudflare network (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Cloudflare accepts the connection, fends off attacks and forwards it to our server through an encrypted tunnel; the server cannot be reached directly from outside. Cloudflare acts as our processor under Art. 28 GDPR. For transfers to the USA Cloudflare is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) apply in addition.
3. Cookies
This website only sets strictly necessary cookies, which is why there is no cookie banner.
- qx_locale and qx_market: store your choice of language and country once you make it in the selector. Lifetime: twelve months.
- Application session cookie: keeps you signed in. Deleted on sign-out or when the session expires.
- Cloudflare may set a strictly necessary security cookie to fend off automated attacks (e.g. __cf_bm, lifetime 30 minutes).
- No analytics, marketing or third-party cookies. No external fonts, scripts or tracking pixels are embedded.
4. Contact form and email
When you contact us through the contact form or by email, we process your name, company, email address, optionally a phone number, and the content of your message in order to answer your inquiry and prepare a proposal (Art. 6 (1) (b) GDPR — pre-contractual measures; otherwise Art. 6 (1) (f)). Stating a request volume is optional. To prevent abuse, the number of submissions per sender is limited; a hash of the email address is stored briefly for that purpose. To keep out automated submissions, the contact form and the appointment request also check a small computation that your browser solves when you send the form, a field that is invisible to people, and the time taken to fill in the form — without third-party services and without cookies.
Inquiries are deleted twelve months after the correspondence ends unless a contract is concluded or statutory retention obligations apply.
To send emails — account confirmation, password, invitations and forwarding your contact request to us — we use Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as our processor under Art. 28 GDPR. Emails are sent via Resend’s EU region (Ireland); where data is transferred to the USA in the process, Resend is certified under the EU-US Data Privacy Framework (Art. 45 GDPR), and the EU Standard Contractual Clauses apply in addition (Art. 46 (2) (c) GDPR).
5. Customer account and use of the application
To use the application, you create an account. We process your name, work email address, company, company location, team role and a hashed password, as well as sign-in timestamps and security-relevant events (Art. 6 (1) (b) GDPR). Failed sign-in attempts are counted for a short period to defend against attacks (Art. 6 (1) (f) GDPR).
We retain legally required evidence for its specific purpose with restricted access: commercial and business correspondence generally for six years, invoices and accounting vouchers generally for eight years, from the end of the relevant calendar year. Statutory extensions and documented legal disputes remain reserved; other account data is removed under the deletion process described below.
Accounts without an order, payment or ongoing checkout are deleted no earlier than 30 days after registration and seven days after sending the deletion notice by email. You can delete your account yourself in the account area at any time and download your data as a ZIP archive first.
6. Your customers’ data in the application — data processing on your behalf
Within the application, you process data about your own customers: requests, contacts, catalogs, terms and quotes. For this data, you are the controller; Neithra Technologies acts as processor under Art. 28 GDPR solely on your instructions, based on a data processing agreement that we provide with the proposal.
Access is strictly limited to your own tenant (workspace). You can export your tenant data as a ZIP archive in account management. After the contract ends, your data is deleted within 30 days unless you request earlier deletion.
If you connect a shared mailbox, the application retrieves unread messages from it and creates requests from them. It stores the server, username and password — the password encrypted (AES-256-GCM) and decrypted only for retrieval. Retrieved messages are marked as read and, if you choose, moved to a folder; nothing is deleted from the mailbox.
7. Payment processing
Companies on individually agreed invoice plans pay by invoice and bank transfer. For the invoice we process the company name, billing address, VAT identification number and billing email address and record them in our accounts (Art. 6 (1) (b) and (c) GDPR; retained for the statutory periods). We keep invoices and accounts with Lexware (Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany), which acts as our processor under Art. 28 GDPR in Germany.
Companies that order online pay through Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland; parent Stripe, Inc., USA). Stripe processes payment data as an independent controller; payment details never reach our systems. For the invoice we pass Stripe the company name, billing address, billing email and VAT ID; Stripe checks an EU VAT ID against the EU database (VIES) (Art. 6(1)(b) and (c) GDPR). For transfers to the USA Stripe is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
8. Automated decisions and use of AI
Quotrail prepares and proposes: it reads requests, matches lines against the customer’s catalogue and applies stored pricing rules. Every match carries its reasoning, every price its rule. A person always makes the approval decision. No automated decision with legal effect within the meaning of Art. 22 GDPR takes place.
Matching currently runs inside the application and is rule-based and statistical. No customer data is transmitted to external AI services, and no customer data is used to train models. If external models are integrated in the future, we will inform you here in advance about the provider, processing location and purpose.
9. Recipients and international transfers
Recipients of personal data are exclusively the processors named in this policy. We do not share data for advertising and we do not sell data. Where data is transferred outside the European Economic Area this relies on an adequacy decision or the EU Standard Contractual Clauses; copies of the safeguards are available on request.
10. Retention
Server logs: 14 days. Contact inquiries: twelve months after completion. Account data: contract term plus statutory retention periods. Application data of your tenant: up to 30 days after the contract ends. Accounts without an order, payment or ongoing checkout: no earlier than 30 days after registration and seven days after sending the deletion notice. Notices of termination as business correspondence: six years from the end of the year in which they were received, unless a longer statutory retention period applies (e.g. Section 147 of the German Fiscal Code, Section 257 of the German Commercial Code); they are then deleted or anonymised. Termination and contract-end information is restricted and retained for longer only where it is a necessary part of a statutory record category. Security counters for sign-in attempts and form submissions: 48 hours at most. Backups: deleted data may remain in encrypted backup copies for up to 14 days and is then overwritten as backups rotate.
11. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You can withdraw any consent you have given at any time, with effect for the future. To exercise these rights, please contact us at the address above.
If you are located in the European Economic Area you may lodge a complaint with a supervisory authority; the authority competent for the controller is the Data Protection Commissioner of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
12. California residents
Under the California Consumer Privacy Act (as amended by the CPRA) you may have the right to know which categories of personal information we collect and the purposes for which we use them, to request deletion or correction, and not to be discriminated against for exercising these rights. The data categories, purposes, recipients and retention periods are described throughout this notice, including account and contact identifiers, professional and billing details, technical logs and customer-provided workspace content. We do not sell personal information, and we do not share it for cross-context behavioral advertising. Rights requests may be sent through the contact channels below.
To exercise your rights, email [email protected] or use the contact form on our home page. We verify requests proportionately as described in the international-rights section below. An authorized agent may submit a request on your behalf with your written permission.
12a. Residents of other US states
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others) may have rights to access, correct, delete and obtain a copy of their personal data, and to opt out of targeted advertising, sale or profiling. We do none of the latter. Send requests to the address above; if we decline a request you may appeal by replying to our decision, and we will respond within the period the applicable law requires.
The service is intended for businesses and is not directed at children under 16. We do not knowingly collect personal information from children.
13. Data security
All transmission is encrypted (TLS). Passwords are stored only as hashes. Access to application data is tenant-bound and logged; quote approvals are logged with person and time, and log entries cannot be edited in the application.
14. Changes
We update this policy when processing changes — for example when a new provider is engaged. The version published here applies; the date of the last change is shown at the top of the page.
International privacy rights
Additional international rights: applicable US state law may give you rights to access, correction, deletion and a portable copy, and rights concerning sale, targeted advertising or certain profiling. Applicability depends on the law, its thresholds and the processing concerned; business contact data is not automatically excluded in California. We do not sell personal data or use it for cross-context behavioural advertising. Browser Do Not Track signals do not change the necessary processing described here; our service does not use cross-site advertising tracking. This is distinct from legally recognised opt-out preference signals such as Global Privacy Control. Send a rights request to the contact in this notice or the legal notice, without needing a paid account. An authorised agent may act with evidence of authority. We verify identity proportionately to the request, normally through the known account or contact address; we request additional evidence only where necessary and do not disclose another person’s data. We explain any refusal and applicable exceptions. You may request a review by replying to that decision; we handle requests and any statutory appeal within the applicable legal deadlines and explain any permitted extension. We do not discriminate for exercising privacy rights. Where UK GDPR or Swiss data protection law applies, their rights and safeguards also remain available; you may contact the UK Information Commissioner (ico.org.uk) or the Swiss FDPIC (edoeb.admin.ch), respectively. For data controlled by a customer, we forward or assist with the request as its processor. Changes to these practices are shown with the updated date of this notice; material changes affecting existing accounts are also communicated through the account or contact address before they take effect, with consent where required. If Canadian privacy law applies, you may also use the same contact to request access or correction, withdraw consent where applicable or complain about our handling; you may contact the competent federal or provincial privacy authority (priv.gc.ca). A professional email address alone does not exclude all related account or usage data from protection.
Quotrail Support / Neithra Office
The support dialogue processes questions using public product information (GDPR Article 6(1)(f): answering product questions). Without AI, the conversation stays in the open browser. With AI enabled, Neithra stores a limited conversation context and unresolved support cases under pseudonymous identifiers for follow-up and handling. Short-lived abuse counters contain a hashed client key. Only with your explicit selection and an enabled AI feature are the question and up to six previous messages sent to central Neithra support and from there to the providers named in the dialogue: OpenAI or OpenAI and Google Gemini for an answer, based on consent (Article 6(1)(a)), withdrawable for future questions by unchecking the option. Provider terms, data processing and possible international transfers must be reviewed and specified here before activation. Without activation no such transfer occurs. Preparing an enquiry copies only your last three questions and stated requirements into an editable form. A draft crossing pages uses browser session storage, is deleted after transfer and is no longer used after ten minutes. Submitting the form stores the contact request; existing contact retention periods apply. Contact and call requests may be transferred to the same controller’s Neithra Office for central processing. No automatic newsletter subscription. Limited central bot cases are cleaned up after 30 days without activity during regular operation. Separately submitted contact emails follow their own retention periods. With separate consent in authenticated administrator support, the stored plan and local access status from the authorized workspace are sent to the named AI services. The read time is not a payment verification; receipt of payment remains unknown without current evidence. Pseudonymous account and caller references bind the central request. The AI model receives only the limited facts without account, payment or email identifiers. Invoice files and customer records are not attached. Signed-in users can also save personal support requests. Subject, message, status and reply are linked to the user account and customer number and accessible to that user and the operator. A separately authenticated support system can retrieve these data and save replies. They are not automatically sent to the AI model. Requests are included in the account export and deleted with the tenant; completed requests are removed within twelve months of their last change. Limited central bot cases are cleaned up after 30 days without activity during regular operation. Separately submitted contact emails follow their own retention periods.