Data Processing Agreement

Last updated

In short

  • When your company puts personal data into Quoteams, your company decides how it is used and we process it only on its instructions (clauses 2 and 3).
  • We keep it secure, help you respond to the people it concerns, and tell you without undue delay about a breach (clauses 3 and 5).
  • We use a short list of subprocessors, and we tell you before we add one (clause 4 and Annex 3).
  • When the Agreement ends, we delete the data (clause 7).

1About this DPA

1.1

This data processing agreement (the "DPA") is part of the agreement between Quoteams AB ("we" or "us") and the business that uses the Quoteams service ("you"), as described in our Terms and Conditions at https://quoteams.com/terms (the "Terms"). It applies whenever we process personal data on your behalf.

1.2

Words defined in the Terms, such as Service, Users and Your Data, have the same meaning in this DPA. "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the GDPR, Regulation (EU) 2016/679.

1.3

If this DPA and the Terms conflict on personal data, this DPA prevails.

2Roles and instructions

2.1

For personal data in Your Data, you are the controller and we are your processor. Annex 1 describes the processing.

2.2

Your instructions are the Agreement, the way you and your Users set up and use the Service, and any other written instructions you give us that we agree to. We process the personal data only on those instructions, including for transfers outside the European Economic Area (EEA), unless the law requires otherwise. In that case, we tell you before we process it, unless the law forbids it.

2.3

We tell you at once if we believe an instruction breaks the GDPR or other data protection law.

2.4

You are responsible for having a legal basis for the processing, for informing the data subjects, and for the lawfulness of your instructions.

3Our obligations

3.1

We make sure that everyone who processes the personal data for us is bound by confidentiality.

3.2

We take the technical and organizational measures in Annex 2 to protect the personal data, as Article 32 of the GDPR requires. We may improve these measures, but we will not lower the overall level of protection.

3.3

We help you answer requests from data subjects who exercise their rights, mainly through the features of the Service. If we receive a request directly, we pass it to you and do not answer it ourselves, unless you ask us to.

3.4

Taking into account the information available to us, we help you meet your duties on security, breach notification, data protection impact assessments and prior consultation under Articles 32 to 36 of the GDPR.

3.5

We may charge reasonable costs for help under clauses 3.3 and 3.4 that goes beyond what the Service provides, if we tell you the cost in advance.

4Subprocessors

4.1

You authorize us to use the subprocessors listed in Annex 3.

4.2

We give you at least 14 days' notice by email before we add or replace a subprocessor. If you object on reasonable data protection grounds and we cannot resolve the objection together, you may end the affected subscription, and we refund prepaid Fees for the unused period. This is your only remedy for the change.

4.3

We bind each subprocessor in writing to data protection obligations that protect the personal data at least as well as this DPA does. We remain responsible to you for how our subprocessors process it.

5Personal data breaches

5.1

We tell you without undue delay after we become aware of a personal data breach that affects Your Data.

5.2

We give you the information we have that you need to assess the breach and to notify the authority and the data subjects where the law requires it, and we update you as we learn more. We take reasonable steps to contain the breach and limit its effects.

5.3

Telling you about a breach does not mean that we accept responsibility for it.

6Transfers outside the EEA

6.1

We store Your Data in the EEA. Some subprocessors may process it outside the EEA, as Annex 3 shows.

6.2

We transfer personal data outside the EEA only under safeguards that Chapter V of the GDPR allows, such as an adequacy decision or the EU standard contractual clauses.

7Deletion and return

7.1

When the Agreement ends, we return and delete Your Data as the Terms describe, unless the law requires us to keep it.

7.2

Backups are overwritten in the normal course of business.

8Audits

8.1

We make available to you the information you reasonably need to show that we meet our obligations under Article 28 of the GDPR, such as this DPA, our security measures and our providers' certifications.

8.2

If that information is not enough, or an authority requires it, you may audit our processing once a year. You must give us at least 30 days' notice, pay the costs of the audit, including our reasonable costs for the time we spend on it, and use an auditor who is bound by confidentiality and is not our competitor. An audit must not disturb our business or reveal other customers' data.

9Liability and term

9.1

The liability limits in section 15 of the Terms apply to this DPA, as far as the law allows. Nothing in this DPA limits a data subject's rights under Article 82 of the GDPR.

9.2

This DPA applies for as long as we process personal data on your behalf.

Annex 1: Details of the processing

The processing:

  • Subject matter and duration: providing the Service under the Agreement, for its term and until the data is deleted (clause 7).
  • Nature and purpose: storing, organizing, displaying and transmitting Your Data, and the other processing needed to provide, support and secure the Service.
  • Data subjects: your Users, and your Clients, Carriers and other contacts whose data you put into the Service or who use the Client Portal.
  • Personal data: contact details (such as names, email addresses, phone numbers and addresses), the content of emails, documents and Quotes, and technical data such as IP addresses.
  • Special categories: none. The Terms do not allow them unless strictly necessary and lawful.

Annex 2: Security measures

Our measures include:

  • Encryption of data in transit and at rest.
  • Logical separation of each customer's data, and access controlled by role.
  • Individual logins for Users, and access for authorized staff only when their work needs it.
  • Hosting in the EEA with providers that hold recognized security certifications.
  • Regular backups.
  • Confidentiality obligations for everyone who works with customer data.

Annex 3: Subprocessors

We use these subprocessors:

  • Amazon Web Services EMEA SARL: hosting, file storage and email delivery, in the EEA.
  • MongoDB, Inc.: database, in the EEA.
  • Okta, Inc. (Auth0): sign-in, in the EEA.
  • OpenAI Ireland Ltd: AI features, outside the EEA under the EU standard contractual clauses.