SoWerate Privacy Policy
Last updated: 7 July 2026
This Privacy Policy explains how Quotech Pte. Ltd. (âQuotechâ, âweâ, âusâ, or âourâ) collects, uses, protects, and retains personal data and workspace information when you use SoWerate.
SoWerate is a structured source-of-wealth write-up workspace for relationship managers. The current product is designed around manual, human-reviewed inputs and generated reports. It is not intended to replace the relationship managerâs own review, judgement, or compliance obligations.
1. Scope and Roles
This Policy applies to SoWerate public pages, account registration, workspace use, billing, support, and generated write-up/report features. Where a firm, team, or other organisation creates a workspace, that organisation is normally responsible for deciding what client or business information its authorised users submit to SoWerate.
Users must ensure they have the authority, consent, and internal approval required to enter personal data, source-of-wealth facts, case notes, evidence references, and related business information into SoWerate.
2. Personal Data and Workspace Data We Collect
- Account and identity data, such as name, business email address, password hash, activation status, workspace membership, role, invitation status, and authentication/session records.
- Workspace and team data, such as workspace name, authorised users, permissions, settings, billing status, credit balances, credit lots, credit expiry dates, and audit records.
- Case data manually entered by users, such as client particulars, nationality, tax residence, date of birth where provided, additional background, source-of-wealth experiences, calculation settings, evidence/corroboration references, listing notes, and draft/report snapshots.
- Generated output data, such as structured write-up runs, report versions, Word document outputs, side-note/attention-note outputs, prompt version/checksum, calculation snapshots, model/provider metadata, and generation status.
- Billing and payment data, such as selected credit pack, Stripe checkout identifiers, payment status, transaction references, promotion/coupon application where provided by Stripe, credit usage, credit expiry, and ledger/audit history. We do not collect or store full payment card numbers directly.
- Security and operational data, such as IP address, browser/device signals, request metadata, form-verification status, error logs, audit events, and support correspondence.
For this version of SoWerate, the ordinary user flow does not require uploading original client documents for OCR or document summarisation. The product may store generated reports and structured references to evidence supplied by the user. If document-upload features are enabled in a future version or by separate arrangement, additional storage and security terms may apply.
3. How We Use Data
- To create and manage user accounts, workspaces, roles, sessions, invitations, and access controls.
- To save draft cases, calculation settings, evidence references, structured source-of-wealth information, generated write-ups, Word documents, attention notes, and audit history.
- To perform local calculations such as foreign-exchange conversion, growth adjustment, valuation-month calculations, and credit usage reconciliation.
- To generate structured source-of-wealth write-ups and related review notes using the saved case snapshot, workspace settings, published Quotech operations prompt, and configured AI provider flow.
- To process credit purchases and top-ups through Stripe, record credit lots and ledger entries, apply expiry rules, and support billing/accounting records.
- To send operational emails, such as activation, password reset, invitation, ticket/support, generation-completed, and case-link notifications.
- To prevent abuse, verify public/auth-sensitive form submissions, investigate errors, protect accounts, maintain tenant/workspace isolation, and improve reliability and security.
4. AI Processing and Privacy Masking
SoWerate may use configured AI providers to draft structured source-of-wealth write-ups and related review notes. AI output is assistive only. It must be reviewed, corrected, and approved by the relationship manager and the relevant firm before any external submission or compliance use.
Before sending case content to an external AI provider, SoWerate applies privacy-masking controls intended to replace direct identifiers and sensitive values with stable placeholders. This masking is designed to reduce unnecessary exposure to external providers. It does not mean the internal SoWerate workspace database stores only masked data: authorised workspace data, saved case snapshots, generated reports, and audit records may be stored in unmasked form where needed for the service.
SoWerate does not use AI output to make an automated onboarding, credit, AML, suitability, compliance, approval, rejection, or regulatory decision. Users remain responsible for the truth, completeness, and appropriateness of all information and outputs.
5. Security, Isolation, and Access Controls
We use technical and organisational safeguards intended to protect SoWerate data, including account authentication, server-side authorisation checks, workspace-level access controls, tenant/workspace scoping in data access, audit logs, mutation-origin checks, public-form anti-abuse verification, and controlled administrative access.
Cloudflare Turnstile or similar security services may be used on public and authentication-sensitive forms to help distinguish legitimate users from automated abuse. These checks may process limited request, browser, device, and security-challenge data.
No internet service can guarantee absolute security. Users should not enter information they are not authorised to process and should promptly notify us of suspected unauthorised access or security incidents.
6. Disclosure and Third-Party Providers
We may disclose or make data available to service providers that help operate SoWerate, including hosting, database, storage, email, logging, monitoring, security, payment, AI, and support providers. These providers may process data in Singapore or other jurisdictions.
Stripe processes payment details through its own checkout and payment systems. SoWerate records payment and credit status needed for billing, but does not directly store full card numbers.
We may also disclose data where required by law, regulation, legal process, security investigation, dispute handling, enforcement of our terms, or protection of our rights, users, or the public.
7. Cross-Border Transfers
SoWerate and its service providers may process, store, or access data from Singapore and other jurisdictions. Where required, we take steps intended to provide appropriate protection for personal data transferred across borders.
8. Retention
We retain data for as long as reasonably required to provide SoWerate, maintain workspaces, preserve case/report/audit history, support billing and accounting records, comply with legal obligations, resolve disputes, prevent fraud or abuse, and maintain security.
Credit expiry does not automatically delete case data, generated reports, billing records, or audit records. Backup copies, logs, and records required for legal, security, accounting, or dispute purposes may be retained for a further period.
9. Access, Correction, Deletion, and Workspace Closure
Authorised workspace users may update certain account, team, case, and workspace information through the product. For access, correction, export, deletion, or workspace-closure requests that are not available through the interface, contact us at info@sowerate.com.
We may decline, delay, or limit a deletion or export request where we are required or permitted to retain records for legal, accounting, audit, security, fraud-prevention, dispute, contractual, or operational reasons.
10. Cookies and Similar Technologies
SoWerate may use cookies or similar technologies for authentication, session management, security, preferences, diagnostics, and product reliability. Public-form verification and payment providers may also use cookies or similar technologies under their own policies.
11. Changes
We may update this Privacy Policy from time to time. The updated version will be posted on SoWerate with a new effective date. Continued use of SoWerate after an update means the updated Policy applies.
12. Contact
For privacy questions or requests, contact Quotech Pte. Ltd. at info@sowerate.com.