Data Processing Addendum
Effective September 5, 2026. This addendum applies when you, an account holder, use Quote and Sign to process personal data of your clients and the GDPR, UK GDPR or a similar law makes you the controller and us the processor. It forms part of the Terms of Service. No signature is needed; it applies automatically.
1. Roles
You are the controller of the personal data in your proposals and of your recipients' data. We are the processor. For our own account data (your email, billing status, security logs) we are the controller and the Privacy Policy applies.
2. Details of processing
- Subject matter: hosting, sending and recording acceptance of proposals.
- Duration: the life of your account, plus the retention of signed records described in the Privacy Policy.
- Nature and purpose: storage, display to recipients, email delivery, PDF generation, engagement counts, acceptance records.
- Data subjects: your clients and the people who open your proposals.
- Categories of data: names, email addresses, business details, prices and terms, IP addresses and browser details of recipients, typed signatures.
3. Our obligations
- Process personal data only on your documented instructions, which are the Terms and your use of the product features, unless the law requires otherwise, in which case we tell you first where we may.
- Keep the data confidential and ensure anyone with access is bound by confidentiality.
- Apply the security measures in the Privacy Policy, and not reduce them during the term.
- Help you respond to data subject requests: the product lets you export and delete, and we assist with the rest within 30 days.
- Tell you without undue delay, and within 72 hours, if we become aware of a personal data breach affecting your data, with the information you need for your own notifications.
- Delete or return the data at the end of the service, subject to the signed-record retention that protects both parties to an agreement and to legal holds.
- Make available the information needed to show compliance and allow audits, at your cost and on reasonable notice, no more than once a year unless a regulator requires otherwise.
4. Subprocessors
You authorise the subprocessors listed in the Privacy Policy: Cloudflare, Polar and Resend. We will email account holders at least 14 days before adding a new one; you may object, and if we cannot resolve it you may close your account and export your data.
5. International transfers
Data may be processed in Canada, the United States and the EU. Canada holds an EU adequacy decision for PIPEDA-covered organisations. Transfers to the United States rely on standard contractual clauses in our subprocessors' agreements.
6. Liability
Liability under this addendum is subject to the limitations in the Terms of Service, to the extent the applicable law allows.
7. Contact
The Privacy Officer, Quote and Sign, through the contact form.