Effective date: 11 September 2026
Last updated: 11 September 2026
This Data Processing Addendum ("DPA") forms part of the agreement between QuoteMasterPro, doing business as Quote Master Pro ("QMP", "Processor", "Service Provider", "we", "us") and the customer that has accepted QMP’s Terms of Service or an order form ("Customer", "Controller", "you"). It applies where QMP processes Personal Data on the Customer’s behalf in providing the QMP Service.
1. Definitions and precedence
"Applicable Data Protection Law" means privacy, data-protection and data-security laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss data-protection law, the California Consumer Privacy Act as amended ("CCPA"), and Mexico’s Federal Law on Protection of Personal Data Held by Private Parties.
"Agreement" means the Terms of Service and any applicable order form, statement of work or subscription agreement. "Customer Personal Data" means Personal Data contained in Customer Data. "Personal Data Breach" has the meaning given by Applicable Data Protection Law. Other capitalized terms have the meaning given in the Agreement.
If this DPA conflicts with the Agreement on processing of Customer Personal Data, this DPA controls. The parties will comply with the Standard Contractual Clauses or UK transfer addendum where incorporated under Section 9; those clauses control in the event of conflict on an international transfer.
2. Roles and scope
The Customer is the Controller (or a Processor acting on behalf of another Controller) of Customer Personal Data; QMP is the Processor (or Subprocessor, as applicable). The Customer appoints QMP to process Customer Personal Data only to provide, support, secure and improve the Service, as described in the Agreement, this DPA and Annex 1.
The Customer is responsible for ensuring that it has all rights, lawful bases, notices, permissions and consents needed for QMP to process Customer Personal Data as contemplated by the Agreement and this DPA. The Customer will issue documented processing instructions through the Service, Agreement or written communication. QMP will immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits it from doing so.
3. QMP’s processing obligations
QMP will:
- process Customer Personal Data only on the Customer’s documented instructions, unless required by applicable law; in that case, QMP will inform the Customer before processing unless the law prohibits notice;
- ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality;
- implement appropriate technical and organizational measures designed to meet the requirements of Applicable Data Protection Law and protect Customer Personal Data, as described in Annex 2;
- not sell or share Customer Personal Data, retain/use/disclose it for any purpose other than providing the Service and permitted business purposes, or combine it with personal information obtained from another source, except as permitted by the CCPA and this DPA;
- promptly notify the Customer if it can no longer meet its CCPA/CPRA obligations and allow the Customer to take reasonable and appropriate steps to stop and remediate unauthorized use; and
- make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and security restrictions.
QMP may process Customer Personal Data for its own purposes only where it has first de-identified or aggregated the information so that it does not identify the Customer or any individual.
4. Security and Personal Data Breaches
QMP will maintain the measures in Annex 2 and may update them from time to time, provided that updates do not materially decrease the overall security of the Service.
If QMP becomes aware of a Personal Data Breach affecting Customer Personal Data, QMP will notify the Customer without undue delay and, where feasible, within 48 hours of awareness. The notice will include available information reasonably needed for the Customer to meet its obligations, including the nature of the incident, affected data and subjects where known, likely consequences, and measures taken or proposed. QMP will reasonably cooperate with the Customer’s investigation and response. QMP will not notify affected individuals or a regulator on the Customer’s behalf unless required by law or authorized by the Customer.
5. Assistance
Taking account of the nature of processing and information available to QMP, QMP will provide reasonable assistance to the Customer with:
- responding to verified requests from data subjects to exercise their rights;
- security obligations, Personal Data Breach notifications, data-protection impact assessments, and consultations with regulators; and
- demonstrating compliance with Applicable Data Protection Law.
If QMP receives a request relating to Customer Personal Data, it will promptly forward the request to the Customer unless prohibited by law. The Customer is responsible for responding. Assistance beyond the Service’s standard functionality may be charged at QMP’s then-current professional-services rates where legally permitted.
6. Subprocessors
The Customer gives QMP general written authorization to use Subprocessors. QMP will maintain a current list at https://quotemaster.pro/subprocessors.html, including each Subprocessor’s name, processing activity and location.
QMP will give at least 30 days’ prior notice of a new or replacement Subprocessor by updating the list or another reasonable written method. The Customer may object in writing on reasonable data-protection grounds during that period. The parties will work in good faith on a reasonable solution. If none is possible, the Customer may terminate the affected Service without penalty by written notice before the new Subprocessor begins processing; any prepaid fees for the unused affected Service will be refunded on a pro-rata basis.
QMP will bind each Subprocessor by a written agreement imposing data-protection obligations no less protective than those in this DPA, as applicable to the service performed. QMP remains responsible for its Subprocessors’ performance of those obligations.
7. Audits and information rights
No more than once per 12-month period, and on reasonable written notice, the Customer may request information and available third-party audit reports or certifications relevant to QMP’s compliance with this DPA. QMP may satisfy an audit request by providing these materials.
If the materials are insufficient to demonstrate compliance, the Customer may conduct a remote audit, or an on-site audit only where required by a regulator or following a verified material security incident. Any audit must be conducted during normal business hours, without unreasonable disruption, by an independent auditor bound by confidentiality, and subject to QMP’s reasonable security and confidentiality requirements. The Customer bears its audit costs and QMP may charge reasonable assistance costs, unless the audit reveals QMP’s material breach of this DPA.
8. Return and deletion
During the subscription term, the Customer may export Customer Data using available Service functionality. At termination, and at the Customer’s choice, QMP will return or delete Customer Personal Data within 90 days, unless retention is required by law. Customer Personal Data in backups will be isolated from routine access and deleted in accordance with QMP’s backup-deletion schedule, within 60 days.
If law requires QMP to retain Customer Personal Data, QMP will continue to protect it under this DPA and process it only for the legally required purpose. Upon request, QMP will confirm deletion or return in writing, except where legally prohibited.
9. International transfers
The Customer authorizes QMP and its Subprocessors to process Customer Personal Data in the locations described in the Subprocessor List and Annex 1. Where a transfer of Customer Personal Data from the EEA, UK or Switzerland requires a transfer mechanism, the parties agree that:
- the European Commission Standard Contractual Clauses adopted on 4 June 2021 ("EU SCCs") are incorporated by reference, with Controller-to-Processor Module Two applying where the Customer is a Controller and QMP is a Processor, and Processor-to-Processor Module Three applying where the Customer is a Processor and QMP is a Subprocessor;
- the details in Annex 1 and Annex 2 complete the relevant SCC annexes; optional Clause 7 (docking) applies, Clause 9(a) (general written authorization) applies, Clause 11(a) (independent dispute resolution) does not apply, and the governing law and courts are Spain; and
- for UK restricted transfers, the UK International Data Transfer Addendum to the EU SCCs applies, with the EU SCCs and Annexes completed as above.
Where the parties use another legally valid mechanism, they will cooperate in good faith to implement it. QMP will provide reasonable information necessary for the Customer’s transfer impact assessment, subject to confidentiality and security restrictions.
10. Liability and term
The liability provisions and exclusions in the Agreement apply to this DPA, to the maximum extent permitted by Applicable Data Protection Law. This DPA takes effect when QMP begins processing Customer Personal Data and remains in effect while QMP processes it.
11. Contact
Privacy and DPA contact: privacy@quotemaster.pro
Security incident contact: security@quotemaster.pro
Legal entity and address: QuoteMasterPro, Calle Nueve de Mayo 2, 33002, Oviedo, Asturias, Spain
Annex 1 — Details of Processing
A. Parties
| Role | Details |
|---|---|
| Controller / data exporter | The Customer accepting the Agreement, including its authorized affiliates and users. Contact details are those in the Customer account or order form. |
| Processor / data importer | QuoteMasterPro, trading as Quote Master Pro. Address: Calle Nueve de Mayo 2, 33002, Oviedo, Asturias, Spain. Privacy contact: privacy@quotemaster.pro. |
B. Subject matter, duration, nature and purpose
| Item | Details |
|---|---|
| Subject matter | Provision of the QMP business-management SaaS platform, including lead/client management, quotations, invoices, approvals, documents, tasks, reports and authorized communications integrations. |
| Duration | For the subscription term and any deletion/backup-retention period described in Section 8. |
| Nature | Hosting, storage, retrieval, organization, access control, transmission, synchronization, support, security monitoring, backup, deletion and other operations needed to provide the Service. |
| Purpose | To provide, secure, support and maintain the Service according to the Agreement and Customer instructions. |
C. Categories of data subjects
The Customer’s authorized users; employees and contractors; clients and prospects; suppliers and business contacts; individuals referenced in quotations, invoices, messages, documents or records; and contacts whose messages or mailboxes are connected by the Customer.
D. Categories of Personal Data
Account/contact details, including names, work email addresses, telephone numbers, job titles, roles and business addresses; client/supplier records; quotation, invoice and transaction information; notes, tasks, approvals and audit/activity records; communications metadata and content; files and attachments; and connected-mailbox configuration, messages and attachments. The Customer determines the data submitted to the Service.
E. Sensitive data and restrictions
No special-category or highly sensitive data is intended. The Customer must not submit it unless QMP expressly agrees in writing and the parties document the necessary safeguards.
F. Frequency and retention
Processing is continuous while the Customer uses the Service. Retention is governed by Section 8 and the Agreement.
Annex 2 — Technical and Organizational Measures
QMP maintains measures appropriate to the nature, scope, context and risks of processing. The following summarizes the current baseline and must be validated against QMP’s actual practices before publication:
| Area | Measures |
|---|---|
| Access control | Individual user authentication; role- and permission-based access; tenant-scoped authorization; least-privilege access for personnel; access revocation processes. |
| Encryption | Encryption in transit using TLS; encryption at rest for connected-mailbox credentials and OAuth tokens; secure secret-management practices. |
| Security operations | Logging and monitoring of relevant system and security events; vulnerability and patch-management processes; malware and abuse controls where appropriate. |
| Availability and resilience | Backups, recovery measures, and procedures designed to maintain availability and restore access following an incident. |
| Data handling | Logical separation of customer teams; controls on production access; documented deletion and backup-retention procedures. |
| Personnel | Confidentiality commitments and appropriate security/privacy training for personnel with access to Customer Personal Data. |
| Incident management | Documented process to investigate, contain, remediate and communicate Personal Data Breaches. |
| Vendor management | Risk-based review of Subprocessors and contractual data-protection obligations appropriate to their services. |
| Review | Periodic review and improvement of security measures in light of changes to the Service, threats and Applicable Data Protection Law. |
Annex 3 — Approved Subprocessors
QMP’s current Subprocessor List is available at https://quotemaster.pro/subprocessors.html and is incorporated into this DPA by reference. It identifies each Subprocessor, the processing purpose and the applicable processing location(s).
QMP will provide at least 30 days’ advance notice of a new or replacement Subprocessor by updating the Subprocessor List and emailing the Customer’s account administrator. The Customer’s objection rights are described in Section 6 of this DPA.