Data Processing Addendum
Last updated 24 September 2026
This Data Processing Addendum (“DPA”) forms part of the Quotewise Terms of Service between you (the “Customer”, controller) and Matthew Ethan Lee-Mattner (ABN 64768343357) (“Processor”). It applies to personal data in Leads and other content the Customer submits to the Service (“Customer Personal Data”). No signature is needed; it applies automatically when you use the Service.
1. Scope and roles
- Subject matter: hosting and processing quote requests submitted through the Customer's calculators, and related support.
- Duration: for the term of the Customer's account and until deletion under section 8.
- Nature and purpose: collection, storage, display, transmission (email, webhooks) and deletion to provide the Service.
- Data subjects: the Customer's prospective and actual customers, and the Customer's team members.
- Categories of data: names, email addresses, phone numbers, job addresses, preferred dates, messages, answers to calculator questions and estimates. The Service is not designed for special category data, payment card data or government identifiers, and the Customer must not collect them through it.
2. Processor obligations
The Processor will:
- process Customer Personal Data only on the Customer's documented instructions (these terms and the Customer's use of the Service), unless required by law;
- ensure people authorised to process it are bound by confidentiality;
- implement appropriate technical and organisational measures (section 5);
- assist the Customer, taking into account the nature of the processing, with data subject requests, security, breach notification, impact assessments and consultations;
- make available information reasonably needed to demonstrate compliance with this DPA.
3. Subprocessors
The Customer authorises the Processor to use the subprocessors listed at /legal/subprocessors. The Processor will give at least 30 days' notice of a new subprocessor by updating that page and emailing account owners; the Customer may object on reasonable data protection grounds and, if we can't resolve it, terminate the affected service with a pro-rata refund of prepaid fees. The Processor imposes data protection terms on each subprocessor that are no less protective than this DPA and remains responsible for their performance.
4. International transfers
Customer Personal Data may be processed in the United States and other countries where our subprocessors operate. Where the GDPR, UK GDPR or Swiss law applies to a transfer to a country without an adequacy decision, the parties agree that the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor) and, where applicable, Module 3 (processor to processor), are incorporated by reference, with: optional clause 7 not included; clause 9 option 2 (general authorisation, 30 days' notice); clause 11 optional language not included; clause 17 governed by Irish law; clause 18 courts of Ireland; Annex I and II populated by this DPA. For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated, and for Swiss transfers the FDPIC is the competent authority.
5. Security measures
- Encryption in transit (TLS) and at rest.
- Database row-level security; all writes go through server-side code with explicit authorisation checks.
- Least-privilege access for personnel and services; secrets stored in managed environment configuration.
- Rate limiting, spam filtering and abuse monitoring on public endpoints.
- Signed webhooks (HMAC-SHA256) and HTTPS-only webhook destinations.
- Daily backups by the database provider; logging and alerting for errors.
- Personal data minimisation: IP addresses are stored only as daily-rotating one-way hashes.
6. Personal data breaches
The Processor will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to help the Customer meet its obligations.
7. Audits
On reasonable written request (no more than once a year unless required by a regulator or following a breach), the Processor will answer security questionnaires and provide available documentation. Where that is insufficient to demonstrate compliance, the parties will agree a reasonable, remote audit at the Customer's cost.
8. Deletion and return
The Customer can export Leads (paid plans) and delete them at any time. When the Customer's account is deleted, the Processor deletes Customer Personal Data within 30 days, and from backups within their rotation period, unless storage is required by law.
9. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service, except where the law does not allow it. If this DPA conflicts with the Terms, this DPA prevails for Customer Personal Data; the Standard Contractual Clauses prevail over both.
Contact
Privacy questions and requests: support@getquotewise.com