Legal

Quottum — Data Processing Agreement

Last updated: June 24, 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Quottum Terms of Service (the "Agreement") between Gaviso Digital Marketing, LLC ("Quottum," "we," "Processor"), located at 10250 Constellation Blvd., Ste. 2300, Los Angeles, CA 90067, and the customer that agrees to the Agreement (the "Customer," "you," "Controller"). It governs Quottum's processing of Customer Personal Data when Quottum acts as a processor on the Customer's behalf.

If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls. Capitalized terms not defined here have the meaning given in the Agreement.

1. Definitions

2. Roles and Scope

2.1 For Customer Personal Data, the Customer is the Controller and Quottum is the Processor. Where the Customer is itself a processor for another controller, Quottum acts as a sub-processor, and the Customer warrants it has authority to instruct Quottum on that controller's behalf.

2.2 Quottum is the controller for Account Data (data about Account Users and Workspaces used to operate and secure the Service), which is governed by the Privacy Policy and not this DPA.

2.3 This DPA applies to the extent Quottum processes Customer Personal Data subject to the Data Protection Laws.

3. Processing of Customer Personal Data

3.1 Instructions. Quottum will process Customer Personal Data only on the Customer's documented instructions, including as set out in the Agreement, this DPA, and the Customer's configuration and use of the Service. The Agreement and this DPA constitute the Customer's complete and final instructions, and additional instructions must be agreed in writing.

3.2 Subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Schedule 1.

3.3 Lawful instructions. Quottum will inform the Customer if, in its reasonable opinion, an instruction infringes the Data Protection Laws, unless legally prohibited from doing so. Quottum is not responsible for determining whether the Customer's instructions comply with law.

3.4 Legal requirement. If Quottum is required by applicable law to process Customer Personal Data beyond the Customer's instructions, it will inform the Customer of that requirement before processing, unless the law prohibits such notice on important grounds of public interest.

4. Customer Responsibilities

4.1 The Customer is solely responsible for the accuracy, quality, and legality of Customer Personal Data and for having a valid lawful basis and any required notice or consent to collect it and enter it into the Service.

4.2 The Customer's instructions must comply with the Data Protection Laws. The Customer is responsible for providing required privacy notices to, and handling the requests of, its own Data Subjects (including its Clients/Recipients).

4.3 The Customer must not enter into the Service any government identifiers, full payment-card numbers, financial-account credentials, or special-category/sensitive data requiring heightened safeguards, except as separately agreed in writing.

5. Confidentiality

Quottum will ensure that persons authorized to process Customer Personal Data are bound by appropriate confidentiality obligations (contractual or statutory) and access Customer Personal Data only as necessary to perform the Agreement.

6. Security

6.1 Quottum will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Schedule 2, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing.

6.2 Quottum may update its measures over time provided the updates do not materially reduce the overall level of protection.

7. Sub-Processors

7.1 General authorization. The Customer provides general written authorization for Quottum to engage Sub-Processors to process Customer Personal Data. The current Sub-Processors are listed in Schedule 3.

7.2 Flow-down. Quottum will impose data protection obligations on each Sub-Processor that are no less protective than those in this DPA, and remains liable to the Customer for its Sub-Processors' performance of those obligations.

7.3 Change notice. Quottum will notify the Customer of any intended addition or replacement of a Sub-Processor at least [30] days in advance (for example, via in-app notice, email, and/or a sub-processors page), giving the Customer the opportunity to object on reasonable, data-protection grounds. If the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected Service as its sole remedy.

8. Data Subject Requests

8.1 Taking into account the nature of the processing, Quottum will provide reasonable assistance, including by appropriate technical and organizational measures and self-service features of the Service, to help the Customer respond to Data Subject requests to exercise rights under the Data Protection Laws.

8.2 If Quottum receives a request directly from a Data Subject concerning Customer Personal Data, it will, without undue delay, direct the Data Subject to the Customer and not respond substantively except on the Customer's instruction or as legally required.

9. Assistance, DPIAs, and Consultation

Taking into account the nature of processing and the information available to Quottum, Quottum will provide reasonable assistance to the Customer with: (a) data protection impact assessments; (b) prior consultations with supervisory authorities; and (c) the Customer's obligations regarding security of processing.

10. Personal Data Breach

10.1 Quottum will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2 The notice will describe, to the extent known and as it becomes available, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for more information. Quottum will reasonably cooperate with the Customer in investigating and mitigating the breach.

10.3 Quottum's notice is not an acknowledgment of fault or liability.

11. International Data Transfers

11.1 Mechanisms. Where Quottum processes Customer Personal Data originating from the EEA, the UK, or Switzerland in a country without an adequacy decision, the parties agree the following apply:

11.2 If a transfer mechanism is invalidated or superseded, the parties will work in good faith to implement an alternative lawful mechanism.

12. CCPA/CPRA Terms (Service Provider)

Where the CCPA/CPRA applies, the Customer is the Business and Quottum is a Service Provider. Quottum:

The Customer may take reasonable and appropriate steps to confirm Quottum's use of Customer Personal Data is consistent with the Customer's obligations under the CCPA/CPRA.

13. Deletion and Return of Data

13.1 On termination or expiry of the Agreement, and on the Customer's request, Quottum will delete or return Customer Personal Data and delete existing copies, unless applicable law requires storage.

13.2 In the absence of a specific request, Quottum will delete Customer Personal Data in accordance with the retention periods in Schedule 1 and the Privacy Policy. Data in routine backups is deleted on the rolling backup-expiry cycle, after which it is not recoverable.

14. Audits and Information

14.1 Quottum will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

14.2 To minimize disruption, audits will: occur no more than once per 12-month period (unless required by a supervisory authority or following a Personal Data Breach); be on reasonable prior written notice (at least [30] days); be subject to confidentiality; and may be satisfied first by Quottum providing existing reports, certifications, or completed security questionnaires. The Customer bears its own audit costs.

15. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement.

16. Term and Termination

This DPA takes effect when the Customer accepts the Agreement and continues until Quottum has ceased all processing of Customer Personal Data and deleted or returned it under Section 13. Provisions that by their nature should survive will survive.

17. General

17.1 Governing law. Except where the SCCs or UK Addendum require otherwise for specific transfers, this DPA is governed by the laws of the State of California, consistent with the Agreement.

17.2 Order of precedence. In case of conflict: (1) the SCCs/UK Addendum (for the relevant transfers); (2) this DPA; (3) the Agreement.

17.3 Changes. Quottum may update this DPA to reflect changes in Data Protection Laws, transfer mechanisms, or Sub-Processors, provided it does not materially reduce protections; material changes will be notified per the Agreement.

18. Signatures

By accepting the Agreement, the parties agree to this DPA. Where a signed copy is required, the parties may execute below.

Quottum — Gaviso Digital Marketing, LLC
Name: __________________ · Title: __________________ · Date: ____________

Customer
Entity: __________________ · Name: __________________ · Title: __________________ · Date: ____________


Schedule 1 — Details of Processing

Populates Annex I of the EU SCCs / the relevant tables of the UK IDTA Addendum.

A. List of Parties

B. Description of Processing

C. Categories of Data Subjects

D. Categories of Personal Data

E. Special-Category Data

None is intended or permitted. The Customer must not submit special-category/sensitive data except as separately agreed in writing (DPA Section 4.3).

F. Retention

Customer Personal Data is retained for the term of the Agreement and deleted per DPA Section 13 and the Privacy Policy: Workspace/Customer Data purged within 30 days of Workspace deletion; attachment files deleted within 30 days, with backups expiring within 35 days; activity logs 18 months.

G. Competent Supervisory Authority

For EEA transfers, the supervisory authority of the EEA member state in which the Customer (data exporter) is established, or its EU Art. 27 representative is located. For the UK, the Information Commissioner's Office (ICO).


Schedule 2 — Technical and Organizational Measures

Populates Annex II of the EU SCCs.

Quottum maintains the following measures, which it may update provided protection is not materially reduced:

1. Access control and authentication

2. Tenant isolation

3. Public/recipient access control

4. Operator support access

5. Encryption

6. Network, hosting, and operational security

7. Logging and monitoring

8. Backups and resilience

9. Data minimization and governance

10. Sub-processor management

11. Incident response


Schedule 3 — Approved Sub-Processors

Populates Annex III of the EU SCCs.

As of the "Last updated" date above:

Sub-ProcessorPurposeProcessing location
SupabasePostgres database, authentication, session management (core)United States
Backblaze B2File attachment storageUnited States (us-west-001)
ResendOutbound transactional and authentication email[Region — to confirm]
Kinetic Cloud / CoolifyApplication hosting[Region — to confirm]
GitHubSource control and release infrastructure (no Customer Personal Data)United States

n8n (self-hosted) is used for internal workflow automation and does not process Customer Personal Data today; it will be added here if that changes.

The current list is also maintained at [sub-processors page URL — recommended].