Acceptable Use Policy

Acceptable Use Policy

The rules for using the Quot service: what you can do, what is prohibited and what happens if someone crosses the line. Plainly stated, to keep the service reliable for everyone.

Last updated: 6 July 2026 · version v2026-07-06

Purpose and scope

This Acceptable Use Policy (hereinafter the "Policy" or "AUP") sets out the rules for using the Quot service, comprising the website quotlab.com and the application app.quotlab.com (hereinafter the "Service"). Quot is a Lyreth product, provided by Donzella di Thomas Donzella, with registered office at Via S. Francesco D'Assisi 47E, 20073 Opera (MI), P.IVA IT02865930180 (hereinafter the "Owner").

The Policy applies to anyone who accesses or uses the Service: the Customer holding the subscription (a business with a VAT number) and every user authorised by it. By accepting the General Terms and Conditions and using the Service, you agree to comply with this Policy. The Policy is an integral part of the General Terms and Conditions of Service: in the event of conflict, the General Terms and Conditions prevail.

Prohibited uses

By using the Service, you undertake not to carry out, and not to allow third parties to carry out, the following conduct:

  • Unlawful activities. Using the Service for illegal, fraudulent or deceptive purposes, or to infringe the rights of third parties, including rules on intellectual property, competition and the protection of personal data.
  • Introduction of malicious code. Uploading, transmitting or spreading malware, viruses, worms, trojans or any code designed to damage, interfere with or compromise the Service, its infrastructure or other users' data.
  • Scraping and unauthorised access. Extracting data in a massive or automated way without authorisation, by means of crawlers, bots, scrapers or similar techniques, beyond what is permitted by the export functions and any APIs made available.
  • Reverse engineering. Decompiling, disassembling, decoding or otherwise attempting to derive the source code, logic or structure of the Service, except within the mandatory limits provided by law.
  • Resale or account sharing. Reselling, sublicensing, renting or making the Service or the access credentials available to third parties, or sharing a single account among several businesses or unauthorised parties.
  • Overloading and circumventing limits. Attempting to overload, degrade or make the Service unavailable (for example through denial of service attacks), or bypassing, disabling or circumventing technical limits, quotas, security measures or access controls.
  • Non-compliant use. Using the Service in a manner inconsistent with its intended purpose of managing electroplating quotes, or in a way that impairs the integrity, availability or confidentiality of other Customers' data.

Constraints on uploaded content

The Customer is responsible for the data and content entered into the Service (the customer records of its own clients, quotes, part and treatment data). In particular, the Customer undertakes to:

  • Upload only personal data for which it has a valid legal basis under the GDPR and has informed its own data subjects about the processing, including the purposes connected with the use of the Service.
  • As a rule, not to upload special categories of data under Article 9 of the GDPR (for example data concerning health, opinions, beliefs or orientations), unless this is genuinely necessary and supported by an appropriate legal basis and suitable measures. The Service is designed for commercial and technical data, not for special categories.
  • Not to enter unlawful or defamatory content, or content that infringes the rights of others or confidentiality obligations.
  • Keep the data accurate and up to date and delete or update it when the legal basis for the processing ceases to apply.

The Service does not use artificial intelligence, does not perform automated decision-making or profiling and is not intended to process special categories of data.

Responsibilities of the Customer as Controller

With regard to the personal data of third parties that it enters into the Service (primarily the customer records of its own clients), the Customer acts as the Controller of the processing under the GDPR, while Quot acts as the Processor on its behalf (Article 28 GDPR). It is therefore for the Customer to identify the legal basis, provide the privacy notice, collect any consents and respond to the requests of its own data subjects. Quot provides the functions required to enable the Customer to fulfil those obligations, including the export and deletion of the data.

Technical limits and quotas

To ensure the stability and performance of the Service for all Customers, use may be subject to technical limits and quotas, including:

  • Limits on the number of calls to the functions and to any APIs, including requests to update metal prices.
  • Limits on storage space, on the number of users and records linked to the subscription, according to the plan taken out (Prima, Opus or Magnum).
  • Limits on the frequency and volume of operations, to prevent anomalous or automated use.

Any specific thresholds are indicated on the Pricing page or in the conditions of the plan. Attempting to exceed or circumvent these limits is not permitted.

Account security

The security of access also depends on the Customer. In particular, you undertake to:

  • Safeguard the access credentials with the utmost care, not share them and not leave them accessible to unauthorised third parties.
  • Use strong passwords that differ from those used for other services, and enable two-factor authentication (2FA) where available.
  • Manage authorised users carefully, promptly revoking access that is no longer needed.
  • Notify the Controller without delay, writing to info@quotlab.com, in the event of loss of credentials, unauthorized access or a suspected security breach.

Reporting abuse

If you find improper use of the Service, a breach of this Policy or a possible security issue, we ask you to report it by writing to info@quotlab.com, providing as precisely as possible the details useful to understand and address the matter. We will review every report and take the appropriate measures.

Consequences of breaches

In the event of a breach of this Policy, the Controller may adopt, depending on the seriousness and urgency, one or more of the following measures: sending a formal notice, restricting or temporarily suspending access, removing non-compliant content and, in the most serious or repeated cases, terminating the contractual relationship. In situations that entail an immediate risk to the security, integrity or availability of the Service, or to the data of other Customers, suspension may be ordered without prior notice, with subsequent communication to the Customer.

The consequences of breaches, the effects on data retention and export, and further provisions on the matter are governed by the General terms of service, to which this Policy refers. The Controller retains the right to protect itself in the competent forums and to report to the authorities any conduct constituting an offence.

Changes to this Policy

We may update this Policy to bring it into line with regulatory, technical or service changes. The version published on this page, with the last updated date at the top, is the one in force.