Privacy Policy

Last updated: September 2026

1. Introduction

This Privacy Policy explains how JAMMZ Limited ("QuotaMark", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you use the QuotaMark sales intelligence and customer relationship management platform (the "Service").

We are a company registered in England and Wales (company number 14754949), with our registered office at 2 Crossways Business Centre, Bicester Road, Kingswood, Aylesbury, HP18 0RA, England.

We are committed to protecting your privacy and complying with our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy should be read alongside our Terms of Service, which are incorporated by reference.

2. Data We Collect

We collect and process the following categories of personal data:

Account data: your name, email address, password (hashed), job title, and organisation role when you register or are invited to the Service.

Usage data: information about how you interact with the Service, including login times, pages viewed, features used, and device/browser information collected automatically via cookies and similar technologies.

Customer data you upload: contact details, company information, sales notes, activity records, and other data you or your organisation choose to store in the Service. This may include personal data relating to your prospects, customers, and other contacts.

Email and calendar data: when you connect an email or calendar account (e.g. Gmail, Google Calendar, or Outlook), we process email metadata, message content, and calendar events as needed to provide synchronisation and activity tracking features, in accordance with the permissions you grant.

Billing data: payment method details processed by our payment provider (Stripe). We do not store full card numbers on our servers.

Communications data: records of your support requests, feedback, and other correspondence with us.

3. How We Use Your Data

We process your personal data for the following purposes:

Providing the Service: operating your account, displaying your data, synchronising email and calendar activities, and delivering AI-powered insights and research.

Account administration: managing user access, authentication, organisation membership, and role assignment.

Billing and subscriptions: processing payments, managing subscription plans, and issuing invoices.

Improvement and development: analysing usage patterns to improve features, fix issues, and develop new capabilities. We may use aggregated, de-identified data that does not identify you or your contacts.

Security and fraud prevention: monitoring for suspicious activity, protecting accounts from unauthorised access, and investigating potential violations of our Terms.

Communication: sending service notifications, security alerts, and responding to your support requests.

Compliance: meeting our legal, regulatory, and accounting obligations.

4. Legal Basis for Processing

Under the UK GDPR, we rely on the following lawful bases for processing your personal data:

Performance of a contract (Article 6(1)(b)): processing necessary to provide the Service you have subscribed to, including account management, data storage, and synchronisation features.

Legitimate interests (Article 6(1)(f)): improving our Service, ensuring security, and communicating with you about your account, where these interests are not overridden by your rights.

Consent (Article 6(1)(a)): where you have given explicit consent, for example when you connect an email or calendar account, or when you opt in to receive marketing communications. You may withdraw consent at any time.

Legal obligation (Article 6(1)(c)): where we are required to process data to comply with a legal obligation, such as tax and accounting requirements.

5. AI Features and Data Processing

The Service includes AI features that generate insights, summaries, scores, and messages based on your inputs and publicly available data.

When you use AI features, the data you submit (including company and contact information) may be processed by us and our AI sub-processors to generate the requested output. We do not use your Customer Data to train AI models for the benefit of third parties.

AI-generated outputs may contain personal data derived from public sources. You are responsible for ensuring your use of such outputs complies with the UK GDPR, including having a lawful basis for any processing of personal data.

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with the following categories of recipients:

Sub-processors: third-party service providers who help us deliver the Service, including cloud hosting, email delivery, payment processing (Stripe), and AI/LLM providers. Our sub-processors are bound by written agreements requiring appropriate data protection measures.

Organisation members: within the Service, data you upload is visible to other members of your organisation according to the access controls your organisation administrator has configured.

Legal authorities: where required by law, court order, or to protect our rights, safety, or the safety of others.

Business transfers: in connection with a merger, acquisition, or asset sale, we may transfer data as permitted by law and subject to confidentiality obligations.

7. International Data Transfers

Your personal data may be processed and stored in countries outside the UK, including the United States and the European Economic Area. Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements, adequacy decisions, or other legally recognised transfer mechanisms.

Our cloud hosting and AI sub-processors may process data in their respective regions. We require all sub-processors to provide a level of data protection consistent with the UK GDPR.

8. Data Retention

We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.

Customer Data is retained for the duration of your subscription. Upon account termination, you should export any data you need. We may delete Customer Data after a reasonable period following termination, in accordance with the UK GDPR.

Usage data and logs are retained for a shorter period determined by our data retention schedule and legal requirements.

9. Your Rights Under the UK GDPR

You have the following rights regarding your personal data:

Right of access: you may request a copy of the personal data we hold about you.

Right to rectification: you may ask us to correct inaccurate or incomplete data.

Right to erasure: in certain circumstances, you may ask us to delete your personal data.

Right to restriction: you may ask us to limit how we process your data in certain situations.

Right to data portability: you may request a machine-readable copy of data you provided to us.

Right to object: you may object to processing based on legitimate interests or for direct marketing.

Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.

Right to lodge a complaint: you may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data properly.

To exercise any of these rights, please contact us using the details in Section 12.

10. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Service, remember your preferences, and analyse usage. We use essential cookies for authentication and security, and analytics cookies to understand how the Service is used.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, regular security reviews, and staff training.

While we strive to protect your data, no method of transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to meeting our obligations under the UK GDPR.

In the event of a personal data breach, we will notify affected individuals and the ICO where required by law.

12. Contact and Data Protection Officer

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at support@quotamark.ai.

You may also write to us at: JAMMZ Limited, 2 Crossways Business Centre, Bicester Road, Kingswood, Aylesbury, HP18 0RA, England.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the features of the Service. We will notify you of material changes by email or through the Service.

Your continued use of the Service after a change takes effect constitutes acceptance of the updated Privacy Policy.

This Privacy Policy is a template provided for convenience and does not constitute legal advice. Have it reviewed by a solicitor qualified in England & Wales before relying on it.