Who is responsible
The controller within the meaning of Article 4(7) GDPR is:
- Controller
- SNS Software Solutions GmbH
- Address
- Schrötlgasse 8a, 1220 Vienna, Austria
- Phone
- +43 670 1922538
We are not required to appoint a data protection officer under Article 37 GDPR. Data protection questions go to the address above and are answered by the managing directors.
The two roles, and why the difference matters
QFUtool is a controller for the data about you and your company: the email address you sign in with, your company settings, your billing details. We decide what that data is for.
QFUtool is a processor for the data in the spreadsheets you upload — your customers, the people you quoted. You are the controller of that data. We only do what your use of the product tells us to do with it: read it, render it into an email, send it, and record what happened. We never use it for our own purposes, never sell it, and never use it to train anything.
The terms of that processing are set out in our Data Processing Agreement, which forms part of the contract with every customer.
Because your customers never sign in, they cannot exercise their rights against us directly. Requests about them are passed to you, and we help you answer them.
What we collect, and on what legal basis
- Account
- Your email address, your name if you give one, the company you belong to and your role in it. Collected because you cannot use the service without an account — Art. 6(1)(b) GDPR, performance of a contract.
- Sign-in
- A one-time link is emailed to you; we store the session token in a cookie. No password is ever stored, because none is ever set. Art. 6(1)(b) GDPR.
- Company settings
- Sending domain, sender name, reply address, send window, daily cap, currency, quote ceiling. Art. 6(1)(b) GDPR.
- Uploaded quotes
- Whatever your spreadsheet contains — typically customer name, email address, phone, address, the quoted amount, what was quoted, and which of your people quoted it. Processed on your instructions under Art. 28 GDPR; the legal basis for the underlying processing is yours to hold.
- Email events
- Whether a message was delivered, opened, clicked, bounced, or reported as spam, and whether a reply came back. Used to stop chasing people who have replied and to suppress addresses that bounce. Art. 6(1)(b) and, for deliverability and abuse prevention, Art. 6(1)(f).
- Billing
- Company name, billing address, VAT identification number, subscription status and invoices. Card numbers are entered on Stripe and never reach our servers. Art. 6(1)(b), and Art. 6(1)(c) for the records tax law requires us to keep.
- Server logs
- IP address, time, requested URL and user agent, kept briefly by our hosting provider for operation, security and troubleshooting. Art. 6(1)(f) GDPR, our legitimate interest in a service that stays up and is not abused.
There is no analytics on this site. We do not run Google Analytics, advertising pixels, session recording, heat maps or cross-site tracking of any kind, and there is nothing here that profiles you.
Fonts are served from our own servers
The typefaces used here are downloaded when the site is built and delivered from qfutool.com. Your browser never contacts Google Fonts, so your IP address is never disclosed to Google by visiting this site — the practice German courts have held to be an unlawful transfer.
Who else processes the data
We use a small number of providers, each under a data processing agreement, each doing one job. The full list, what each one gets and where it sits, is published at Subprocessors and is part of our contractual commitment to you.
Where a provider is outside the EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. The database holding your uploaded customers is in Ireland and does not leave the EU.
How long we keep it
- Account and company data
- For as long as the account exists, then deleted within 30 days of the account being closed.
- Uploaded quotes and messages
- Until you delete them, or within 30 days of the account being closed.
- Suppression list
- Kept indefinitely, on purpose. It is the record of every address that unsubscribed, bounced or complained. Deleting it would let a future import email those people again, which is exactly what it exists to prevent. It holds nothing but the address and the reason.
- Invoices and accounting records
- Seven years, as §132 of the Federal Fiscal Code (BAO) requires.
- Server logs
- Days, not months. Retained by our hosting provider under their own schedule.
Your rights
Under the GDPR you may ask us for a copy of your data (Art. 15), to correct it (Art. 16), to delete it (Art. 17), to restrict what we do with it (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on legitimate interest (Art. 21). Where processing rests on consent, you may withdraw it at any time without affecting what was lawful before.
Write to office@sns-austria.com. We answer within one month.
If you think we have handled your data unlawfully you may complain to the supervisory authority. In Austria that is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria — dsb@dsb.gv.at.
If you were emailed by someone using QFUtool
You received that email because a business you asked for a quote from uses QFUtool to follow up. That business decides who is emailed and what is said; we only deliver it. Every message carries a one-click unsubscribe link that works without an account and takes effect immediately — it cancels every message still queued for you, not just the next one.
For access to or deletion of your data, contact the business that emailed you: they hold it and they decide. If you cannot reach them, write to us and we will pass it on and help them act.
Security
Traffic is encrypted with TLS and data is encrypted at rest. Access between customers is separated in the database itself by row-level security, so a request can only ever return rows belonging to the requester’s own company — the boundary does not depend on application code remembering to check. The elevated database key is used only by the background sender and the inbound webhooks, never by anything a browser can reach. Sign-in is by one-time link, so there is no password to leak.
Changes
When this policy changes materially, we tell account holders by email before the change takes effect. The date at the top of this page is always the date of the current version.