Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the contract betweenQuotely (“Processor”), trading as Quotely, and the business user (“Controller”) when the Controller uses Quotely to store or transmit personal data about their customers.
1. Subject matter
Processor provides quote, invoice, customer, and communication tools. Controller determines the purposes and means of processing customer personal data entered into the service. Processing lasts for the Controller's use of Quotely plus the retention and deletion periods stated in the Privacy Policy.
- Nature and purpose: storage, retrieval, organisation, document generation, communication, backup, support, security, and deletion on the Controller's instructions.
- Data subjects: the Controller's customers, prospective customers, staff, and invited team members.
- Data: contact details, quote and invoice content, jobs and variations, reviews, uploaded receipts and job files, communication status, and related identifiers.
- Special-category data: not intended for the service; the Controller must not upload it unless separately agreed and lawfully permitted.
2. Processor obligations
- Process personal data only on documented instructions from the Controller
- Ensure personnel are bound by confidentiality
- Implement appropriate technical and organisational security measures
- Assist Controller with data subject requests where feasible
- Assist with security, breach notification, DPIAs, and prior consultation where required, taking account of the nature of processing
- Delete or return data on termination, subject to legal retention requirements
- Make available information necessary to demonstrate compliance
- Inform Controller if an instruction appears to infringe applicable data-protection law
3. Subprocessors
Controller authorises Processor to engage subprocessors listed at quotely.ie/subprocessors. Processor remains responsible for placing equivalent data-protection obligations on subprocessors and will provide notice of intended material changes so the Controller can raise reasonable objections.
4. International transfers
Where processing involves transfers outside the EEA, Processor relies on appropriate safeguards such as Standard Contractual Clauses as described in the Privacy Policy.
5. Security incidents
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data, and cooperate on mitigation and regulatory notifications as required by GDPR.
6. Audits and compliance information
On reasonable written request, Processor will provide information needed to demonstrate compliance with Article 28 and permit proportionate audits, including inspections, subject to confidentiality, security, and reasonable advance notice. Existing independent reports and documentation may be used first where appropriate.
7. Return and deletion
At the Controller's choice, Processor will delete or return Controller personal data at the end of the services and delete remaining copies, unless Union or Member State law requires retention. In-product export and deletion tools are the ordinary method; support will assist where those tools are insufficient.
8. Acceptance and precedence
By creating a Quotely account and separately accepting this DPA, Controller agrees to these terms for customer data processed through the service. If this DPA conflicts with the Terms regarding personal-data processing, this DPA controls.
Questions: privacy@quotely.ie