Data Processing Addendum
Last updated: August 22, 2026
This Data Processing Addendum (DPA) is part of our Terms of Service and applies automatically to workspaces processing personal data on behalf of a business. It is written to be readable; if your compliance process needs a countersigned copy, email support@quoteglide.com.
Parties and roles
The business that holds the QuoteGlideaccount (the "business") is the controller of the personal data its workspace processes. [being finalized — contact support for operator details], operating QuoteGlide, is the processor: we handle that data only to provide the service to the business.
What processing this covers
Subject matter and purpose: processing customer and quote personal data to provide quoting and follow-up — creating and delivering quotes, sending reminders, recording customer responses and acceptances, and carrying the message thread between business and customer. Duration: for as long as the business's subscription or account lasts, plus the deletion handling described below.
- Data subjects: the business's customers and prospects who requested quotes, and the business's team members.
- Personal data: contact details, quote contents, correspondence, acceptance records (including IP address and browser user-agent), and reminder-preference records.
Processing on instructions
We process this data only on the business's documented instructions. Those instructions are the service's documented behaviour plus the business's in-app configuration: which quotes to send, to whom, on what reminder schedule, and with which settings. We don't use the business's customer data for our own purposes.
Confidentiality
Personnel with access to workspace data are bound by confidentiality commitments, and authorized personnel access data only as needed to operate and support the service.
Security
The measures in the privacy policy's security section apply: encryption in transit, tenant isolation through row-level security, hashed tokens for quote-page and preference links, and access controls.
Subprocessors
The business gives general authorization for the subprocessors listed at https://quoteglide.com/subprocessors. That page is the notification mechanism: updates are posted there, and businesses should review it for changes. We do not yet send proactive email notifications when the list changes.
Helping with data-subject requests
The product itself gives the business the tools for most requests: viewing, correcting, and deleting customer records and quotes. Where a request needs more than the product provides, we give reasonable assistance.
Breach notification
If we become aware of a personal-data breach affecting the business's data, we notify the business without undue delay.
Deletion at the end
Deleting the account removes the workspace's data, with two exceptions: suppression and opt-out records kept to keep honouring recipients' preferences, and records we are legally required to retain.
Audit and information
On reasonable request, we provide the information needed to demonstrate how this processing works.
International transfers
Our subprocessors operate internationally. Where transfer safeguards are required, we rely on the safeguards in their terms, including standard contractual clauses where applicable.
Scope and governing law
This DPA is intended to address the processor obligations of the UK GDPR and EU GDPR (Article 28), together with the data-protection law that applies where we are established, where they apply. It is a practical baseline pending legal review, not a claim of certified compliance. Governing law follows the Terms of Service.