Noted is a product of QuickReply.ai. It is built, operated and supported by QuickReply Private Limited and its affiliates. This privacy policy is QuickReply's policy and it applies to Noted, the Noted website and the Noted app in full.

Legal

Privacy Policy

Last updated: Aug 16, 2026

QuickReply respects your privacy and is committed to protecting personal data in accordance with applicable data protection and privacy laws.

This Privacy Policy explains how QuickReply Private Limited, Singapore, and its affiliates, including QuickReply Technologies India Private Limited (collectively, "QuickReply", "we", "us" or "our"), collect, use, disclose, retain and protect personal data.

This Privacy Policy applies to:

  • our website at QuickReply.ai, including its webpages, landing pages and forms;
  • our web application at app.quickreply.ai;
  • other websites, applications and digital properties operated by QuickReply;
  • communications with QuickReply through email, phone, WhatsApp, RCS, SMS, LinkedIn or other channels; and
  • other interactions where this Privacy Policy is referenced.

The QuickReply entity responsible for personal data may depend on the context of your interaction with us, including the QuickReply entity with which you contract or interact.

Section 1

Our Role: Controller and Processor

QuickReply processes personal data in different capacities depending on the context.

When QuickReply acts as a controller

When you interact directly with QuickReply — for example, when you:

  • visit our website;
  • request a demo;
  • contact our sales or support teams;
  • subscribe to communications;
  • create or administer a QuickReply account;
  • use the QuickReply application as an employee or authorised user of a customer; or
  • otherwise interact directly with QuickReply,

QuickReply generally determines why and how your personal data is processed and acts as a controller, business, data fiduciary or equivalent under applicable privacy law.

When QuickReply acts on behalf of our customers

Businesses use QuickReply to communicate with and process information relating to their customers, prospects, website visitors and other individuals.

For such Customer Data, the QuickReply customer generally determines the purposes and means of processing and acts as the controller or equivalent, while QuickReply acts as its processor, service provider or equivalent.

Our processing of Customer Data is governed by the applicable Customer Agreement, Data Processing Agreement ("DPA"), the customer's instructions and applicable law.

If your personal data has been processed through QuickReply by one of our customers, you should ordinarily contact that customer directly regarding your privacy rights. We provide reasonable assistance to our customers in responding to such requests as required under our contractual and legal obligations.

Section 2

Personal Data We Collect Directly

Depending on how you interact with QuickReply, we may collect the following categories of information.

Contact and business information

This may include:

  • name;
  • work email address;
  • telephone or WhatsApp number;
  • company, organisation or brand name;
  • designation or role;
  • website URL;
  • country or location;
  • information included in a demo or contact request; and
  • any other information you choose to provide when communicating with us.

Account information

If you create or use a QuickReply account, we may process information such as:

  • name and email address;
  • telephone number;
  • organisation;
  • role and permissions;
  • workspace and account information;
  • authentication information;
  • login history;
  • IP address;
  • browser and device information;
  • audit and security logs; and
  • account configuration information.

Integration and configuration information

Customers may connect QuickReply with third-party systems such as ecommerce platforms, order management systems, CRM platforms, ecommerce stores and other applications.

To provide these integrations, we may process information such as:

  • API keys;
  • authentication or access tokens;
  • integration credentials;
  • account identifiers;
  • configuration information; and
  • other access details supplied or authorised by the customer.

We use this information to establish, operate, maintain and secure the integrations requested by the customer.

Communications and support information

When you communicate with QuickReply, we may retain information such as:

  • emails;
  • chats;
  • support requests;
  • call details;
  • meeting information;
  • feedback;
  • correspondence; and
  • other information you provide to us.

Where communications are recorded, we will handle such recordings in accordance with applicable law.

Billing and transaction information

We may process information relating to:

  • subscriptions;
  • invoices;
  • purchases;
  • payment status;
  • transaction references;
  • billing contacts; and
  • related accounting information.

Payment cards and similar payment credentials are handled by third-party PCI-DSS compliant payment processors. QuickReply does not directly store complete payment card details.

Section 3

Information We Obtain From Other Sources

We may receive personal data about business contacts and prospective customers from sources including:

  • professional networks;
  • advertising and lead-generation platforms;
  • events, conferences and webinars;
  • referrals;
  • business partners;
  • publicly available sources;
  • permitted third-party data providers; and
  • customers or users who refer or introduce you to us.

We may combine such information with information we already hold about our business contacts where permitted by applicable law.

Section 4

Information Collected Automatically

When you visit our websites or use our applications, we may automatically collect information such as:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • referring URLs;
  • pages or features viewed;
  • interactions with our website or application;
  • session information;
  • approximate location derived from IP address;
  • timestamps;
  • diagnostic information;
  • application activity; and
  • security and audit information.

We may collect this information through server logs, cookies, pixels, scripts, analytics tools and similar technologies.

Section 5

Cookies, Analytics and Advertising Technologies

We use cookies, browser storage and similar technologies for purposes including the following.

Necessary and security technologies

These technologies help provide essential website or application functionality, authentication, security, fraud prevention and account operation.

Analytics and performance technologies

We may use first-party and third-party analytics, performance and measurement technologies to understand how visitors and users interact with our websites and Services and to improve their performance and usability.

Advertising and marketing technologies

We may use third-party advertising, conversion-measurement and retargeting technologies to understand the effectiveness of our marketing and, where permitted, deliver advertising based on previous interactions with QuickReply.

Where required by applicable law, we obtain consent before using non-essential cookies, pixels or similar technologies and provide users with options to reject or manage them.

You may also be able to control certain technologies using our cookie preference controls and through your browser or device settings.

Further information regarding the technologies currently used on our websites may be provided through our cookie consent or preference interface.

Section 6

How We Use Personal Data

When QuickReply acts as a controller, we may use personal data to:

  • provide and operate our websites, application and Services;
  • create and administer accounts;
  • authenticate users and maintain platform security;
  • provide customer support;
  • respond to enquiries and demo requests;
  • establish and maintain integrations;
  • process subscriptions, billing and payments;
  • communicate about accounts, subscriptions or Services;
  • send service announcements and operational communications;
  • send product updates, educational content and promotional communications;
  • understand website and product usage;
  • measure advertising and marketing performance;
  • improve our products, Services and user experience;
  • perform internal analytics, quality assurance and troubleshooting;
  • detect fraud, abuse or security incidents;
  • enforce our agreements and policies;
  • comply with legal and regulatory requirements;
  • establish, exercise or defend legal claims; and
  • carry out other purposes disclosed at the time information is collected.

Where required by law, you may opt out of marketing communications. Opting out of marketing communications will not prevent us from sending necessary transactional, security, account or service-related communications.

Section 7

Customer Data Processed Through QuickReply

Our customers may submit, collect, integrate or otherwise process Customer Data through QuickReply. Depending on the customer's use of the Services, this may include contact information, communications and message content, customer and prospect information, ecommerce and transaction information, website and engagement activity, consent records, CRM or OMS information, media, voice interactions and other information submitted by the customer.

The customer determines what Customer Data is processed and is responsible for having the rights, notices, permissions, consents and lawful bases required for such processing. QuickReply processes Customer Data on the customer's behalf in accordance with the applicable Customer Agreement, DPA and customer instructions. Further details regarding the categories and nature of Customer Data processed are available in our DPA.

Section 8

Sensitive Personal Data

QuickReply does not generally require customers to provide sensitive or special-category personal data in order to use the Services.

However, depending on a customer's business or use case, customers may choose to process sensitive personal data through QuickReply.

Customers are responsible for determining whether such processing is permitted under applicable law and for implementing any additional notices, consents, security measures or other safeguards required for such information.

We recommend that customers minimise the collection and processing of sensitive personal data and only process information that is necessary for their legitimate business purposes.

Section 9

Artificial Intelligence and AI-Enabled Features

QuickReply provides features that may use artificial intelligence, machine learning, large language models, AI chatbots, voice bots or similar technologies.

Depending on the functionality selected or configured by a customer, these features may use one or more third-party AI service providers.

When a customer enables an AI-enabled feature, relevant Customer Data may be transmitted to an AI service provider as necessary to generate responses, perform the requested function or provide the feature.

QuickReply does not use Customer Data to train QuickReply's own AI models and does not intentionally enable third-party AI service providers to use Customer Data for the purpose of training their general-purpose or foundation models.

We may use aggregated or de-identified information, operational metrics and other information that does not identify an individual or a particular customer to measure, secure and improve our Services.

Section 10

Aggregated and De-identified Information

We may generate statistical, aggregated or de-identified information from the use of our Services.

We may use such information for purposes including:

  • service analytics;
  • product improvement;
  • performance measurement;
  • delivery optimisation;
  • fraud and abuse prevention;
  • capacity planning;
  • benchmarking; and
  • research and development.

Where we treat information as de-identified, we take reasonable measures designed to prevent it from being used to identify an individual or a particular customer's data.

Section 11

How We Disclose Personal Data

We may disclose personal data to the following categories of recipients where reasonably necessary.

Service providers and subprocessors

We may use third-party providers for services including:

  • cloud infrastructure and hosting;
  • communications;
  • analytics;
  • CRM and customer support;
  • artificial intelligence and machine-learning functionality;
  • payment processing;
  • security and monitoring;
  • productivity and collaboration tools;
  • data processing; and
  • other services necessary to operate QuickReply.

When such providers process Customer Data on our behalf, they are engaged subject to the applicable DPA and contractual requirements.

The current list of subprocessors used in connection with Customer Data is maintained in our Data Processing Agreement, which may be updated from time to time in accordance with the DPA.

Customer-directed integrations

Where a customer connects QuickReply to an ecommerce platform, CRM, OMS, advertising platform, messaging provider or other third-party service, we may exchange information with that provider as directed or authorised by the customer.

Advertising and analytics partners

For our own websites and marketing activities, we may disclose certain device identifiers, online activity and similar information to analytics, measurement and advertising providers.

QuickReply does not sell personal data for monetary consideration.

However, depending on the jurisdiction, certain disclosures associated with online advertising or retargeting may be legally characterised as "sharing", "targeted advertising", "cross-context behavioural advertising" or similar processing.

Where applicable law provides a right to opt out of such processing, we will provide or honour the applicable choice mechanisms.

Affiliates

We may disclose information between QuickReply group entities where reasonably necessary to operate our business and provide the Services.

Legal and regulatory disclosures

We may disclose personal data where reasonably necessary to:

  • comply with applicable law;
  • respond to lawful requests from courts, regulators or governmental authorities;
  • protect QuickReply, our customers, users or others;
  • investigate fraud, abuse or security incidents; or
  • establish, exercise or defend legal rights.

Corporate transactions

Personal data may be disclosed as part of a merger, acquisition, financing, restructuring, sale of assets or similar corporate transaction, subject to applicable legal requirements and appropriate safeguards.

Section 12

We Do Not Sell Customer Data

QuickReply does not sell Customer Data.

We also do not sell personal data collected directly from our website visitors, users or business contacts for monetary consideration.

As explained above, certain advertising technologies used on QuickReply's own digital properties may nevertheless fall within definitions such as "sharing" or "targeted advertising" under some privacy laws.

Where such laws apply to QuickReply, we will provide the choices required by applicable law.

Section 13

International Processing and Data Transfers

QuickReply operates internationally, and our customers, affiliates and service providers may be located in different countries.

Our primary production infrastructure and databases are hosted using Amazon Web Services in the Mumbai, India region.

Certain service providers and subprocessors may process or store Customer Data or other personal data in other jurisdictions depending on the services being provided.

Our current Customer Data subprocessors and relevant processing locations are identified in our DPA.

Where required by applicable law, we use appropriate mechanisms designed to protect personal data transferred internationally, including applicable contractual safeguards, recognised adequacy mechanisms or other legally permitted transfer arrangements.

Section 14

Data Retention

We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide our Services, maintain business and financial records, comply with legal requirements, resolve disputes and enforce agreements.

Retention periods may depend on:

  • the nature of the information;
  • the purpose for which it was collected;
  • the duration of our relationship;
  • applicable contractual commitments;
  • security requirements;
  • legal, accounting and regulatory obligations; and
  • whether a valid deletion request has been received.

Customer Data

Customer Data is retained and deleted in accordance with the applicable Customer Agreement and DPA. Termination does not automatically result in immediate deletion. Unless earlier deletion is requested or required, inactive Customer Data may generally be retained for up to approximately three years. Further information regarding deletion, backups and data export is available in our DPA.

Other personal data

We do not apply one fixed retention period to all website, sales, account, support or business-contact information.

We retain such information for as long as reasonably necessary for the purposes for which it was collected and according to applicable legal, contractual and legitimate business requirements.

Section 15

Security

QuickReply maintains administrative, organisational and technical measures designed to protect personal data against unauthorised access, use, alteration, disclosure, loss or destruction.

Our security programme includes measures such as:

  • role-based access controls;
  • least-privilege access principles;
  • multi-factor authentication for privileged access;
  • security monitoring; and
  • information-security governance.

QuickReply maintains ISO 27001 certification and undergoes SOC 2 Type II assessment.

No method of transmission, processing or storage is completely secure, and we cannot guarantee absolute security.

If a qualifying security incident affects personal data, we notify affected customers or other parties in accordance with applicable law and our contractual commitments.

Section 16

Your Privacy Rights

Depending on your jurisdiction, the nature of our relationship with you and whether QuickReply acts as a controller or processor, you may have rights relating to your personal data.

Where applicable, these may include the right to:

  • request access to personal data;
  • request correction of inaccurate information;
  • request deletion or erasure;
  • request restriction of certain processing;
  • object to certain processing;
  • withdraw consent where processing is based on consent;
  • request portability of information;
  • opt out of certain marketing;
  • opt out of certain targeted advertising or legally defined sharing;
  • lodge a complaint or grievance with an appropriate authority; and
  • exercise other rights provided under applicable law.

These rights are subject to the conditions, limitations and exceptions provided by applicable law.

To submit a request relating to information for which QuickReply acts as controller, contact: privacy@quickreply.ai

We may request information reasonably necessary to verify your identity and process your request.

We will not discriminate against an individual for exercising privacy rights available under applicable law.

Section 17

Requests Relating to Our Customers' Data

If you are a customer, prospect, website visitor or other individual of a business that uses QuickReply, that business generally controls your personal data.

For example, if you receive a communication from a business through QuickReply and want your information accessed, corrected or deleted, you should ordinarily submit the request directly to that business.

If QuickReply receives such a request directly, we may:

  • refer you to the relevant customer;
  • forward the request to the customer where appropriate; and
  • assist the customer in fulfilling the request in accordance with our DPA and applicable law.

QuickReply will not independently alter or delete Customer Data contrary to the instructions of the relevant customer unless permitted or required by applicable law.

Section 18

Legal Bases for EEA and UK Processing

Where the GDPR, UK GDPR or similar laws require us to identify a lawful basis, QuickReply may process personal data based on:

  • performance of a contract, where processing is necessary to provide Services or fulfil contractual obligations;
  • legitimate interests, including operating and securing our business, providing support, improving our Services, communicating with business contacts, measuring business performance and preventing fraud;
  • consent, where consent is required and obtained;
  • compliance with legal obligations; or
  • another lawful basis available under applicable law.

Where we rely on legitimate interests, we consider whether our interests are appropriately balanced against the rights and interests of the affected individual.

Section 19

U.S. State Privacy Rights

Certain U.S. state privacy laws may provide residents of those states with additional privacy rights.

Where such a law applies to QuickReply, we will provide and honour the rights and privacy choices required by that law.

These may include rights relating to:

  • access;
  • correction;
  • deletion;
  • portability;
  • targeted advertising;
  • the sale or sharing of personal information;
  • certain uses of sensitive personal information; and
  • appeals or other statutory privacy procedures.

Our use of certain online advertising and measurement technologies may fall within definitions such as targeted advertising or sharing under some U.S. state privacy laws even though QuickReply does not sell personal information for monetary consideration.

Where applicable law requires a specific privacy-choice or opt-out mechanism, we will make such a mechanism available or honour applicable recognised preference signals.

Section 20

Children

QuickReply's websites and Services are intended for businesses and professional users and are not directed to children or minors.

We do not knowingly solicit children to create QuickReply accounts.

A QuickReply customer may operate a business whose own customers or users include minors. In those circumstances, the QuickReply customer is responsible for determining whether such processing is lawful and for providing any notices, obtaining any consents or authorisations, and implementing any safeguards required by applicable law.

QuickReply processes such Customer Data on behalf of the customer in accordance with the applicable agreement, DPA and law.

Section 21

Third-Party Services and Integrations

Our websites and Services may contain links to or integrate with services operated by third parties.

Where a third party independently determines how and why it processes personal data, its own terms and privacy practices apply.

Customers should review the applicable privacy and security terms of third-party services they choose to connect to or use with QuickReply.

Section 22

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, practices, technologies, legal requirements or other circumstances.

When we make changes, we will update the "Last Updated" date at the beginning of this Privacy Policy.

Where required by applicable law, we will provide additional notice of material changes.

Section 23

Contact Us

For privacy questions, requests or complaints, please contact our Privacy / Data Protection Contact at:

Email: privacy@quickreply.ai

QuickReply Private Limited151 Chin Swee Road
#07-12 Manhattan House
Singapore 169876

QuickReply Technologies India Private LimitedPlot No. 17, Kh. No. 31/24, 17, 14 & 25
Second Floor, Sector-7, Palam Extension
Delhi, South West Delhi
Delhi 110045, India

If you are contacting us about personal data processed by one of our customers through QuickReply, please identify the relevant business or organisation so that we can route your request appropriately.

Back to top ↑