QuoteMasterPro Legal

Data Processing Addendum

Effective date: 11 September 2026
Last updated: 11 September 2026

This Data Processing Addendum ("DPA") forms part of the agreement between QuoteMasterPro, doing business as Quote Master Pro ("QMP", "Processor", "Service Provider", "we", "us") and the customer that has accepted QMP’s Terms of Service or an order form ("Customer", "Controller", "you"). It applies where QMP processes Personal Data on the Customer’s behalf in providing the QMP Service.

1. Definitions and precedence

"Applicable Data Protection Law" means privacy, data-protection and data-security laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss data-protection law, the California Consumer Privacy Act as amended ("CCPA"), and Mexico’s Federal Law on Protection of Personal Data Held by Private Parties.

"Agreement" means the Terms of Service and any applicable order form, statement of work or subscription agreement. "Customer Personal Data" means Personal Data contained in Customer Data. "Personal Data Breach" has the meaning given by Applicable Data Protection Law. Other capitalized terms have the meaning given in the Agreement.

If this DPA conflicts with the Agreement on processing of Customer Personal Data, this DPA controls. The parties will comply with the Standard Contractual Clauses or UK transfer addendum where incorporated under Section 9; those clauses control in the event of conflict on an international transfer.

2. Roles and scope

The Customer is the Controller (or a Processor acting on behalf of another Controller) of Customer Personal Data; QMP is the Processor (or Subprocessor, as applicable). The Customer appoints QMP to process Customer Personal Data only to provide, support, secure and improve the Service, as described in the Agreement, this DPA and Annex 1.

The Customer is responsible for ensuring that it has all rights, lawful bases, notices, permissions and consents needed for QMP to process Customer Personal Data as contemplated by the Agreement and this DPA. The Customer will issue documented processing instructions through the Service, Agreement or written communication. QMP will immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits it from doing so.

3. QMP’s processing obligations

QMP will:

QMP may process Customer Personal Data for its own purposes only where it has first de-identified or aggregated the information so that it does not identify the Customer or any individual.

4. Security and Personal Data Breaches

QMP will maintain the measures in Annex 2 and may update them from time to time, provided that updates do not materially decrease the overall security of the Service.

If QMP becomes aware of a Personal Data Breach affecting Customer Personal Data, QMP will notify the Customer without undue delay and, where feasible, within 48 hours of awareness. The notice will include available information reasonably needed for the Customer to meet its obligations, including the nature of the incident, affected data and subjects where known, likely consequences, and measures taken or proposed. QMP will reasonably cooperate with the Customer’s investigation and response. QMP will not notify affected individuals or a regulator on the Customer’s behalf unless required by law or authorized by the Customer.

5. Assistance

Taking account of the nature of processing and information available to QMP, QMP will provide reasonable assistance to the Customer with:

If QMP receives a request relating to Customer Personal Data, it will promptly forward the request to the Customer unless prohibited by law. The Customer is responsible for responding. Assistance beyond the Service’s standard functionality may be charged at QMP’s then-current professional-services rates where legally permitted.

6. Subprocessors

The Customer gives QMP general written authorization to use Subprocessors. QMP will maintain a current list at https://quotemaster.pro/subprocessors.html, including each Subprocessor’s name, processing activity and location.

QMP will give at least 30 days’ prior notice of a new or replacement Subprocessor by updating the list or another reasonable written method. The Customer may object in writing on reasonable data-protection grounds during that period. The parties will work in good faith on a reasonable solution. If none is possible, the Customer may terminate the affected Service without penalty by written notice before the new Subprocessor begins processing; any prepaid fees for the unused affected Service will be refunded on a pro-rata basis.

QMP will bind each Subprocessor by a written agreement imposing data-protection obligations no less protective than those in this DPA, as applicable to the service performed. QMP remains responsible for its Subprocessors’ performance of those obligations.

7. Audits and information rights

No more than once per 12-month period, and on reasonable written notice, the Customer may request information and available third-party audit reports or certifications relevant to QMP’s compliance with this DPA. QMP may satisfy an audit request by providing these materials.

If the materials are insufficient to demonstrate compliance, the Customer may conduct a remote audit, or an on-site audit only where required by a regulator or following a verified material security incident. Any audit must be conducted during normal business hours, without unreasonable disruption, by an independent auditor bound by confidentiality, and subject to QMP’s reasonable security and confidentiality requirements. The Customer bears its audit costs and QMP may charge reasonable assistance costs, unless the audit reveals QMP’s material breach of this DPA.

8. Return and deletion

During the subscription term, the Customer may export Customer Data using available Service functionality. At termination, and at the Customer’s choice, QMP will return or delete Customer Personal Data within 90 days, unless retention is required by law. Customer Personal Data in backups will be isolated from routine access and deleted in accordance with QMP’s backup-deletion schedule, within 60 days.

If law requires QMP to retain Customer Personal Data, QMP will continue to protect it under this DPA and process it only for the legally required purpose. Upon request, QMP will confirm deletion or return in writing, except where legally prohibited.

9. International transfers

The Customer authorizes QMP and its Subprocessors to process Customer Personal Data in the locations described in the Subprocessor List and Annex 1. Where a transfer of Customer Personal Data from the EEA, UK or Switzerland requires a transfer mechanism, the parties agree that:

Where the parties use another legally valid mechanism, they will cooperate in good faith to implement it. QMP will provide reasonable information necessary for the Customer’s transfer impact assessment, subject to confidentiality and security restrictions.

10. Liability and term

The liability provisions and exclusions in the Agreement apply to this DPA, to the maximum extent permitted by Applicable Data Protection Law. This DPA takes effect when QMP begins processing Customer Personal Data and remains in effect while QMP processes it.

11. Contact

Privacy and DPA contact: privacy@quotemaster.pro
Security incident contact: security@quotemaster.pro
Legal entity and address: QuoteMasterPro, Calle Nueve de Mayo 2, 33002, Oviedo, Asturias, Spain


Annex 1 — Details of Processing

A. Parties

Role Details
Controller / data exporter The Customer accepting the Agreement, including its authorized affiliates and users. Contact details are those in the Customer account or order form.
Processor / data importer QuoteMasterPro, trading as Quote Master Pro. Address: Calle Nueve de Mayo 2, 33002, Oviedo, Asturias, Spain. Privacy contact: privacy@quotemaster.pro.

B. Subject matter, duration, nature and purpose

Item Details
Subject matter Provision of the QMP business-management SaaS platform, including lead/client management, quotations, invoices, approvals, documents, tasks, reports and authorized communications integrations.
Duration For the subscription term and any deletion/backup-retention period described in Section 8.
Nature Hosting, storage, retrieval, organization, access control, transmission, synchronization, support, security monitoring, backup, deletion and other operations needed to provide the Service.
Purpose To provide, secure, support and maintain the Service according to the Agreement and Customer instructions.

C. Categories of data subjects

The Customer’s authorized users; employees and contractors; clients and prospects; suppliers and business contacts; individuals referenced in quotations, invoices, messages, documents or records; and contacts whose messages or mailboxes are connected by the Customer.

D. Categories of Personal Data

Account/contact details, including names, work email addresses, telephone numbers, job titles, roles and business addresses; client/supplier records; quotation, invoice and transaction information; notes, tasks, approvals and audit/activity records; communications metadata and content; files and attachments; and connected-mailbox configuration, messages and attachments. The Customer determines the data submitted to the Service.

E. Sensitive data and restrictions

No special-category or highly sensitive data is intended. The Customer must not submit it unless QMP expressly agrees in writing and the parties document the necessary safeguards.

F. Frequency and retention

Processing is continuous while the Customer uses the Service. Retention is governed by Section 8 and the Agreement.

Annex 2 — Technical and Organizational Measures

QMP maintains measures appropriate to the nature, scope, context and risks of processing. The following summarizes the current baseline and must be validated against QMP’s actual practices before publication:

Area Measures
Access control Individual user authentication; role- and permission-based access; tenant-scoped authorization; least-privilege access for personnel; access revocation processes.
Encryption Encryption in transit using TLS; encryption at rest for connected-mailbox credentials and OAuth tokens; secure secret-management practices.
Security operations Logging and monitoring of relevant system and security events; vulnerability and patch-management processes; malware and abuse controls where appropriate.
Availability and resilience Backups, recovery measures, and procedures designed to maintain availability and restore access following an incident.
Data handling Logical separation of customer teams; controls on production access; documented deletion and backup-retention procedures.
Personnel Confidentiality commitments and appropriate security/privacy training for personnel with access to Customer Personal Data.
Incident management Documented process to investigate, contain, remediate and communicate Personal Data Breaches.
Vendor management Risk-based review of Subprocessors and contractual data-protection obligations appropriate to their services.
Review Periodic review and improvement of security measures in light of changes to the Service, threats and Applicable Data Protection Law.

Annex 3 — Approved Subprocessors

QMP’s current Subprocessor List is available at https://quotemaster.pro/subprocessors.html and is incorporated into this DPA by reference. It identifies each Subprocessor, the processing purpose and the applicable processing location(s).

QMP will provide at least 30 days’ advance notice of a new or replacement Subprocessor by updating the Subprocessor List and emailing the Customer’s account administrator. The Customer’s objection rights are described in Section 6 of this DPA.