This English version is a translation for information. The German version is the governing legal text.
Imprint
Information pursuant to § 5 DDG and § 18(2) MStV. The provider operating Quadralign is responsible for this website’s content.
Provider
kotesys UG (haftungsbeschränkt) i.G.
represented by Christian Kollar
Brigitte-Frauendorf-Str. 38
60486 Frankfurt am Main
Germany
Not yet entered in the Commercial Register.
Contact
Email: hello@kotesys.com
Register and tax information
No Commercial Register, tax, or VAT information is published. It will only be supplied once confirmed.
Person responsible for content pursuant to § 18(2) MStV
kotesys UG (haftungsbeschränkt) i.G., represented by Christian Kollar, address as above.
Consumer dispute resolution
The European Commission discontinued the EU online dispute-resolution platform on 20 July 2025, so no link to that platform is provided.
We are neither willing nor obliged to participate in consumer dispute-resolution proceedings before a consumer arbitration board.
Liability for content
As a service provider, we are responsible for our own content on these pages under the general laws pursuant to § 7(1) DDG. Under §§ 8 to 10 DDG, however, we are not obliged to monitor transmitted or stored third-party information or investigate circumstances indicating unlawful activity.
Obligations to remove or block the use of information under general laws remain unaffected. Liability in this respect is only possible from the time of knowledge of a specific infringement. Upon becoming aware of corresponding infringements, we will remove the content without delay.
Liability for links
Our site contains links to external third-party websites over whose content we have no influence. We therefore cannot assume any guarantee for this third-party content. The respective provider or operator of the linked pages is always responsible for their content.
Copyright
Content and works created by the site operators are subject to German copyright law. Reproduction, editing, distribution and any kind of exploitation beyond the limits of copyright law require the written consent of the respective author or creator.
This notice applies to quadralign.com as a public information website and to invited test access to Quadralign, including the practice app at app.quadralign.com, the owner app at my.quadralign.com, and the Tent Suite ID sign-in used for that access.
Controller
kotesys UG (haftungsbeschränkt) i.G., represented by Christian Kollar, Brigitte-Frauendorf-Str. 38, 60486 Frankfurt am Main, Germany · privacy@kotesys.com
Public website
Cloudflare Workers and Cloudflare Assets provide the public pages. This may process, in particular, the IP address, time, requested address, transmission status, and browser and device information. The purposes are delivery, stability, and protection; the legal basis is Article 6(1)(f) GDPR. The operator does not use its own analytics, advertising, or tracking services on the marketing sites.
Test access and sign-in
For invited test access, the operator processes in particular email address, user identifier, invitation and authorisation data, sign-in and security events, and test data entered by test users in the application. This serves the setup, operation, protection, and support of test access. Legal bases are Article 6(1)(b) GDPR where access is based on the test-access terms, and Article 6(1)(f) GDPR for abuse prevention and system security.
Supabase
The operator uses Supabase, including Supabase Auth, for authentication, database, and storage functions. Supabase processes the data required for this as a processor. The service and its subprocessors may process data outside the EEA; where required, transfers take place under appropriate safeguards such as adequacy decisions or EU Standard Contractual Clauses.
Cloudflare and Turnstile
Cloudflare, Inc., and the affiliated companies or subprocessors used receive technical connection and security data for hosting and delivery. Cloudflare Turnstile is used on sign-in forms to prevent automated and abusive sign-in attempts; Cloudflare processes technical browser, device, connection, and interaction data and the verification result for this purpose. Processing outside the EEA cannot be ruled out; where required, appropriate safeguards such as adequacy decisions or EU Standard Contractual Clauses apply.
B2B sign-in and cookies
For B2B sign-in via Tent Suite ID, technically necessary authentication cookies are used for the .tentsuite.com domain so that sign-in can continue between Tent Suite ID and connected B2B surfaces. The cookie storage provided in the code is limited to a maximum of seven days; access ends when the user signs out or the session expires. Legal bases are Article 6(1)(b) GDPR where access is based on the test-access terms, and Article 6(1)(f) GDPR for abuse prevention and system security. The cookies do not serve advertising, analytics, or profiling.
Web storage and PKCE cookie
The B2C web app at my.quadralign.com stores its session separately per web address in local browser storage (localStorage); it does not use cross-domain authentication cookies for this. The practice portal session at app.quadralign.com is also separate and stored locally. When B2B sign-in starts, app.quadralign.com additionally sets a PKCE verifier cookie that applies only to that host. It is HttpOnly, Secure, SameSite=Lax, limited to five minutes, serves exclusively to complete sign-in securely through Tent Suite ID, and is deleted after success or failure. Local entries serve sign-in and usability and remain until sign-out, session expiry, or deletion of browser data. Language and appearance are also stored locally. With future registration, validated return intents may temporarily reside in sessionStorage; this storage ends with the browser tab.
Native app and device storage
The native Quadralign app stores the Supabase authentication session and preference settings in AsyncStorage. It uses Expo SecureStore on iOS and Android for local account storage, activity status, and a device-specific identifier. These entries are necessary for sign-in, account switching, session management, and use of the app. On sign-out, the app removes the active local account storage; other local settings remain until they are changed or app data is deleted.
Push notifications in the native app
Only where the operating-system permission is granted, the native app retrieves an Expo push token and stores it with a device-specific identifier, platform, and associated user identifier at Supabase. This serves delivery of requested notices, such as messages, tasks, appointments, or care events. The legal basis is consent under Article 6(1)(a) GDPR. Operating-system settings control or suppress notification display but do not remove the token stored at Supabase. Remote-push processing can be withdrawn for the current account and device through the remote-push switch in the app notification settings or by signing out. Recipients are Supabase for token management and Expo for delivery, together with Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM). Expo receives the push token, title, text, and technically necessary event data; for delivery, the platform services process device-related delivery and message data. Processing outside the EEA cannot be ruled out; where required, transfers take place under appropriate safeguards such as adequacy decisions or EU Standard Contractual Clauses. On sign-out or deactivation of remote-push delivery, the app requests deletion of the token for the current account and device immediately. If deletion is temporarily unavailable, it stores the deletion request protected with the necessary account session and retries on the next app start and when returning to the foreground. If no account remains on the device after sign-out and server-side deletion is unavailable, the app additionally invalidates the native push transport for that device. If Expo reports a token as DeviceNotRegistered, immediately or after processing a delivery receipt, it is also removed. A token therefore remains stored until a deletion request is successfully processed or an invalid token is automatically cleaned up.
Contact and email
Data from an email is processed to handle the request. The legal basis is Article 6(1)(b) GDPR where it concerns pre-contractual measures; otherwise Article 6(1)(f) GDPR, based on the interest in answering requests. The operator uses Microsoft 365 for email; the contracting party and processor for EEA customers is Microsoft Ireland Operations Limited. Processing outside the EEA cannot be ruled out; where required, appropriate safeguards such as adequacy decisions or EU Standard Contractual Clauses apply.
Recipients are the processors and their subprocessors named above and, where push notifications are enabled, Expo and the platform services Apple APNs or Google FCM used for delivery, in each case where necessary for the described service. Test-account and test data are retained only as long as test access, test evaluation, security, or statutory obligations require; they are then deleted or anonymised. Technical log data and contact data are likewise retained only as long as needed for operation, security, handling the request, or statutory obligations. The deletion criteria described above additionally apply to push tokens.
Your rights
Subject to the GDPR, you may request access, rectification, erasure, restriction, data portability, and objection. Where processing is based on consent, consent may be withdrawn with effect for the future. You also have the right to lodge a complaint with a data-protection supervisory authority, in particular the Hessian Commissioner for Data Protection and Freedom of Information. For data-protection matters, contact the controller at privacy@kotesys.com.
Status 07/2026. The existing German version is retained as legal reference material for the intended later operation.
Show historical reference version for the intended later operation
§ 1 · Subject matter
The historical terms describe the time-limited provision of the Quadralign software-as-a-service application via the internet and the storage of data entered by customers.
The provider named in that reference version is kotesys UG (haftungsbeschränkt) i.G., represented by Christian Kollar, Brigitte-Frauendorf-Str. 38, 60486 Frankfurt am Main. The UG i.G. is not yet entered in the Commercial Register.
§ 1a · Consumers and businesses
These terms apply to consumers and businesses; individual provisions expressly distinguish the customer group.
Consumer (§ 13 BGB) means a person who uses Quadralign for purposes that predominantly cannot be attributed to their commercial or self-employed professional activity. This concerns the free Owner Access and Owner Plus (B2C). Consumer prices are final prices including VAT; the withdrawal right under § 4a and statutory venues apply.
Business (§ 14 BGB) means a person acting on conclusion of a contract in the exercise of a commercial or self-employed professional activity. This concerns the Pro subscription for therapists and practices (B2B). Prices for businesses are plus statutory VAT; there is no withdrawal right and the venue under § 9 applies.
§ 2 · Scope of service
The scope of functions follows the description at quadralign.com and may change as the application develops. The reference terms promise 95% monthly availability of core functions. Maintenance windows are announced in advance and do not count as downtime.
Owner Access
Access for owners is permanently free. The scope of functions expands automatically once a treating therapist with an active Pro subscription is linked.
Owner Plus
Owner Plus expands free Owner Access with additional functions, including multiple animals and caregivers, health record, activity and condition history, and document storage. The exact scope follows the pricing page.
Pro subscription
The Pro subscription includes the services shown on the pricing page. A 30-day trial without providing a payment method is possible.
§ 3 · Contract conclusion
The contract is concluded by creation of a user account and confirmation by the provider. For paid plans, confirmation is made by booking through Stripe Checkout. If Owner Plus is purchased in the app, the contract is concluded through the relevant app store (Apple App Store or Google Play); its terms additionally apply. These are historical clauses only: no public account creation, checkout, payment or contract conclusion is enabled in the current pre-release phase.
§ 4 · Prices and payment
The prices shown at the time of booking apply. The standard tax regime applies and statutory VAT is shown. Consumer prices for Owner Plus are final prices including VAT; prices for business customers are plus statutory VAT.
No paid subscription is publicly offered during the current pre-release phase. For any later contract, only the prices and services displayed in the relevant booking flow immediately before the order is submitted apply. Price changes for existing contracts are announced under the terms agreed at that time.
Payment processing is carried out through Stripe (SEPA direct debit or credit card). Invoices are provided electronically through Stripe. For in-app purchases of Owner Plus, payment is processed through the relevant app store (Apple App Store or Google Play) at the final prices including VAT shown there. These are historical reference clauses only: no payment provider or payment route is active in the current pre-release phase.
§ 4a · Withdrawal
Consumers within the meaning of § 13 BGB generally have the right to withdraw from a distance contract within 14 days without giving reasons. The withdrawal period begins when the contract is concluded. Businesses (§ 14 BGB), especially under the Pro subscription, have no withdrawal right.
For contracts concerning digital content and digital services, for example the SaaS subscription, the withdrawal right expires early under § 356(5) BGB if (1) the consumer expressly agrees before performance begins that the provider begins performance before the withdrawal period expires, (2) confirms awareness that this agreement causes the withdrawal right to be lost, and (3) receives contract confirmation on a durable medium under § 312f BGB. Agreement and confirmation of awareness are obtained in the order process.
During the free trial period (30 days), termination without form is possible at any time without exercising the withdrawal right.
To exercise the withdrawal right, an unequivocal declaration by email to hello@kotesys.com is sufficient. The following model withdrawal form may be used but is not mandatory.
Model withdrawal form — If you wish to withdraw from the contract, complete this form and return it to kotesys UG (haftungsbeschränkt) i.G., represented by Christian Kollar, Brigitte-Frauendorf-Str. 38, 60486 Frankfurt am Main, or hello@kotesys.com: “I/we (*) hereby withdraw from the contract concluded by me/us (*) for the provision of the following service: Quadralign subscription — ordered on (*)/received on (*) — name of consumer(s) — address of consumer(s) — date — signature of consumer(s) (only if notified on paper). Delete as appropriate.”
§ 5 · Term and termination
Pro subscriptions are concluded for one month (monthly subscription) or one year (annual subscription). They renew for the same period unless terminated no later than the end of the respective term.
Termination may be made without form, for example by email to hello@kotesys.com, or through the Stripe customer portal. After contract end, data remains accessible in read-only mode for 30 days and is then deleted unless statutory retention obligations prevent this.
Owner Plus subscriptions run monthly or annually according to the selected option and renew automatically for the selected period unless terminated in time. Owner Plus subscriptions concluded through the website may be terminated as above. Subscriptions concluded in-app through an app store are managed and terminated exclusively through the subscription settings of the respective Apple or Google account; termination through the provider is technically not possible in that respect.
§ 6 · Duties of users
The reference version requires users to protect access credentials and comply with applicable data-protection requirements when processing owner contact data.
§ 7 · Liability
The provider is liable without limitation for intent and gross negligence, injury to life, body or health, and assumption of a guarantee. For ordinary negligence, the provider is liable only for breach of essential contractual obligations (Kardinalpflichten) and is limited in amount to the foreseeable damage typical for the contract.
Liability for indirect damage, lost profit or loss of data is excluded to the extent permitted by law. The provider recommends additionally securing important data.
§ 8 · Data protection
The processing of personal data is governed in the Privacy tab.
§ 9 · Final provisions
The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. If the customer is a business under § 14 BGB, merchant, legal entity under public law or special fund under public law, the exclusive venue for all disputes arising from the contractual relationship is Frankfurt am Main; the place of performance is Frankfurt am Main. Statutory venues apply to consumers under § 13 BGB.
If individual provisions are ineffective, the effectiveness of the remaining provisions remains unaffected.