Data Processing Addendum

Last updated: August 22, 2026

This Data Processing Addendum (DPA) is part of our Terms of Service and applies automatically to workspaces processing personal data on behalf of a business. It is written to be readable; if your compliance process needs a countersigned copy, email support@quoteglide.com.

Parties and roles

The business that holds the QuoteGlideaccount (the "business") is the controller of the personal data its workspace processes. [being finalized — contact support for operator details], operating QuoteGlide, is the processor: we handle that data only to provide the service to the business.

What processing this covers

Subject matter and purpose: processing customer and quote personal data to provide quoting and follow-up — creating and delivering quotes, sending reminders, recording customer responses and acceptances, and carrying the message thread between business and customer. Duration: for as long as the business's subscription or account lasts, plus the deletion handling described below.

  • Data subjects: the business's customers and prospects who requested quotes, and the business's team members.
  • Personal data: contact details, quote contents, correspondence, acceptance records (including IP address and browser user-agent), and reminder-preference records.

Processing on instructions

We process this data only on the business's documented instructions. Those instructions are the service's documented behaviour plus the business's in-app configuration: which quotes to send, to whom, on what reminder schedule, and with which settings. We don't use the business's customer data for our own purposes.

Confidentiality

Personnel with access to workspace data are bound by confidentiality commitments, and authorized personnel access data only as needed to operate and support the service.

Security

The measures in the privacy policy's security section apply: encryption in transit, tenant isolation through row-level security, hashed tokens for quote-page and preference links, and access controls.

Subprocessors

The business gives general authorization for the subprocessors listed at https://quoteglide.com/subprocessors. That page is the notification mechanism: updates are posted there, and businesses should review it for changes. We do not yet send proactive email notifications when the list changes.

Helping with data-subject requests

The product itself gives the business the tools for most requests: viewing, correcting, and deleting customer records and quotes. Where a request needs more than the product provides, we give reasonable assistance.

Breach notification

If we become aware of a personal-data breach affecting the business's data, we notify the business without undue delay.

Deletion at the end

Deleting the account removes the workspace's data, with two exceptions: suppression and opt-out records kept to keep honouring recipients' preferences, and records we are legally required to retain.

Audit and information

On reasonable request, we provide the information needed to demonstrate how this processing works.

International transfers

Our subprocessors operate internationally. Where transfer safeguards are required, we rely on the safeguards in their terms, including standard contractual clauses where applicable.

Scope and governing law

This DPA is intended to address the processor obligations of the UK GDPR and EU GDPR (Article 28), together with the data-protection law that applies where we are established, where they apply. It is a practical baseline pending legal review, not a claim of certified compliance. Governing law follows the Terms of Service.