Legal
Quottum — Data Processing Agreement
Last updated: June 24, 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Quottum Terms of Service (the "Agreement") between Gaviso Digital Marketing, LLC ("Quottum," "we," "Processor"), located at 10250 Constellation Blvd., Ste. 2300, Los Angeles, CA 90067, and the customer that agrees to the Agreement (the "Customer," "you," "Controller"). It governs Quottum's processing of Customer Personal Data when Quottum acts as a processor on the Customer's behalf.
If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls. Capitalized terms not defined here have the meaning given in the Agreement.
1. Definitions
- "Data Protection Laws" — all laws applicable to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
- "Customer Personal Data" — personal data within Customer Data that Quottum processes on the Customer's behalf as described in Schedule 1.
- "Controller," "Processor," "Sub-Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach" — have the meanings in the Data Protection Laws. Under the CCPA/CPRA, "Controller" maps to "Business," "Processor" to "Service Provider," and "Data Subject" to "Consumer."
- "Standard Contractual Clauses" / "SCCs" — the clauses annexed to Commission Implementing Decision (EU) 2021/914 for the transfer of personal data to third countries, Module Two (Controller to Processor).
- "UK Addendum" — the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (the "UK IDTA Addendum").
2. Roles and Scope
2.1 For Customer Personal Data, the Customer is the Controller and Quottum is the Processor. Where the Customer is itself a processor for another controller, Quottum acts as a sub-processor, and the Customer warrants it has authority to instruct Quottum on that controller's behalf.
2.2 Quottum is the controller for Account Data (data about Account Users and Workspaces used to operate and secure the Service), which is governed by the Privacy Policy and not this DPA.
2.3 This DPA applies to the extent Quottum processes Customer Personal Data subject to the Data Protection Laws.
3. Processing of Customer Personal Data
3.1 Instructions. Quottum will process Customer Personal Data only on the Customer's documented instructions, including as set out in the Agreement, this DPA, and the Customer's configuration and use of the Service. The Agreement and this DPA constitute the Customer's complete and final instructions, and additional instructions must be agreed in writing.
3.2 Subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Schedule 1.
3.3 Lawful instructions. Quottum will inform the Customer if, in its reasonable opinion, an instruction infringes the Data Protection Laws, unless legally prohibited from doing so. Quottum is not responsible for determining whether the Customer's instructions comply with law.
3.4 Legal requirement. If Quottum is required by applicable law to process Customer Personal Data beyond the Customer's instructions, it will inform the Customer of that requirement before processing, unless the law prohibits such notice on important grounds of public interest.
4. Customer Responsibilities
4.1 The Customer is solely responsible for the accuracy, quality, and legality of Customer Personal Data and for having a valid lawful basis and any required notice or consent to collect it and enter it into the Service.
4.2 The Customer's instructions must comply with the Data Protection Laws. The Customer is responsible for providing required privacy notices to, and handling the requests of, its own Data Subjects (including its Clients/Recipients).
4.3 The Customer must not enter into the Service any government identifiers, full payment-card numbers, financial-account credentials, or special-category/sensitive data requiring heightened safeguards, except as separately agreed in writing.
5. Confidentiality
Quottum will ensure that persons authorized to process Customer Personal Data are bound by appropriate confidentiality obligations (contractual or statutory) and access Customer Personal Data only as necessary to perform the Agreement.
6. Security
6.1 Quottum will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Schedule 2, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing.
6.2 Quottum may update its measures over time provided the updates do not materially reduce the overall level of protection.
7. Sub-Processors
7.1 General authorization. The Customer provides general written authorization for Quottum to engage Sub-Processors to process Customer Personal Data. The current Sub-Processors are listed in Schedule 3.
7.2 Flow-down. Quottum will impose data protection obligations on each Sub-Processor that are no less protective than those in this DPA, and remains liable to the Customer for its Sub-Processors' performance of those obligations.
7.3 Change notice. Quottum will notify the Customer of any intended addition or replacement of a Sub-Processor at least [30] days in advance (for example, via in-app notice, email, and/or a sub-processors page), giving the Customer the opportunity to object on reasonable, data-protection grounds. If the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected Service as its sole remedy.
8. Data Subject Requests
8.1 Taking into account the nature of the processing, Quottum will provide reasonable assistance, including by appropriate technical and organizational measures and self-service features of the Service, to help the Customer respond to Data Subject requests to exercise rights under the Data Protection Laws.
8.2 If Quottum receives a request directly from a Data Subject concerning Customer Personal Data, it will, without undue delay, direct the Data Subject to the Customer and not respond substantively except on the Customer's instruction or as legally required.
9. Assistance, DPIAs, and Consultation
Taking into account the nature of processing and the information available to Quottum, Quottum will provide reasonable assistance to the Customer with: (a) data protection impact assessments; (b) prior consultations with supervisory authorities; and (c) the Customer's obligations regarding security of processing.
10. Personal Data Breach
10.1 Quottum will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
10.2 The notice will describe, to the extent known and as it becomes available, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for more information. Quottum will reasonably cooperate with the Customer in investigating and mitigating the breach.
10.3 Quottum's notice is not an acknowledgment of fault or liability.
11. International Data Transfers
11.1 Mechanisms. Where Quottum processes Customer Personal Data originating from the EEA, the UK, or Switzerland in a country without an adequacy decision, the parties agree the following apply:
- EEA transfers: the EU SCCs, Module Two (Controller to Processor), are incorporated by reference and completed as follows:
- Clause 7 (docking clause): [included / not included — select];
- Clause 9 (sub-processors): Option 2 (general written authorization), with the notice period in Section 7.3;
- Clause 11 (independent dispute resolution): not used;
- Clause 17 (governing law): the law of [Ireland — to confirm];
- Clause 18 (forum): the courts of [Ireland — to confirm];
- Annex I is populated by Schedule 1, Annex II by Schedule 2, and the list of sub-processors by Schedule 3.
- UK transfers: the UK IDTA Addendum is incorporated, with the EU SCCs as varied by the Addendum; Tables in the Addendum are completed using the Schedules and the Customer/Quottum details above.
- Swiss transfers: the EU SCCs apply with references to the GDPR read as the Swiss FADP and the competent authority as the Swiss FDPIC, as applicable.
11.2 If a transfer mechanism is invalidated or superseded, the parties will work in good faith to implement an alternative lawful mechanism.
12. CCPA/CPRA Terms (Service Provider)
Where the CCPA/CPRA applies, the Customer is the Business and Quottum is a Service Provider. Quottum:
- will process Customer Personal Data only to perform the Service under the Agreement (the "Business Purpose") and as permitted by the CCPA/CPRA;
- will not sell or share Customer Personal Data, and will not retain, use, or disclose it for any purpose other than the Business Purpose, or outside the direct business relationship with the Customer, except as permitted by the CCPA/CPRA;
- will not combine Customer Personal Data with personal information from other sources, except as permitted by the CCPA/CPRA;
- certifies that it understands and will comply with these restrictions; and
- will assist the Customer in responding to Consumer rights requests as set out in this DPA.
The Customer may take reasonable and appropriate steps to confirm Quottum's use of Customer Personal Data is consistent with the Customer's obligations under the CCPA/CPRA.
13. Deletion and Return of Data
13.1 On termination or expiry of the Agreement, and on the Customer's request, Quottum will delete or return Customer Personal Data and delete existing copies, unless applicable law requires storage.
13.2 In the absence of a specific request, Quottum will delete Customer Personal Data in accordance with the retention periods in Schedule 1 and the Privacy Policy. Data in routine backups is deleted on the rolling backup-expiry cycle, after which it is not recoverable.
14. Audits and Information
14.1 Quottum will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
14.2 To minimize disruption, audits will: occur no more than once per 12-month period (unless required by a supervisory authority or following a Personal Data Breach); be on reasonable prior written notice (at least [30] days); be subject to confidentiality; and may be satisfied first by Quottum providing existing reports, certifications, or completed security questionnaires. The Customer bears its own audit costs.
15. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement.
16. Term and Termination
This DPA takes effect when the Customer accepts the Agreement and continues until Quottum has ceased all processing of Customer Personal Data and deleted or returned it under Section 13. Provisions that by their nature should survive will survive.
17. General
17.1 Governing law. Except where the SCCs or UK Addendum require otherwise for specific transfers, this DPA is governed by the laws of the State of California, consistent with the Agreement.
17.2 Order of precedence. In case of conflict: (1) the SCCs/UK Addendum (for the relevant transfers); (2) this DPA; (3) the Agreement.
17.3 Changes. Quottum may update this DPA to reflect changes in Data Protection Laws, transfer mechanisms, or Sub-Processors, provided it does not materially reduce protections; material changes will be notified per the Agreement.
18. Signatures
By accepting the Agreement, the parties agree to this DPA. Where a signed copy is required, the parties may execute below.
Quottum — Gaviso Digital Marketing, LLC
Name: __________________ · Title: __________________ · Date: ____________
Customer
Entity: __________________ · Name: __________________ · Title: __________________ · Date: ____________
Schedule 1 — Details of Processing
Populates Annex I of the EU SCCs / the relevant tables of the UK IDTA Addendum.
A. List of Parties
- Data exporter (Controller): the Customer identified in the Agreement. Contact: the Customer's account owner / privacy contact on file. Role: Controller.
- Data importer (Processor): Gaviso Digital Marketing, LLC, 10250 Constellation Blvd., Ste. 2300, Los Angeles, CA 90067, USA. Contact: help@gaviso.agency. Role: Processor.
B. Description of Processing
- Subject matter: provision of the Quottum quote-to-contract-to-renewal SaaS at app.quottum.io.
- Duration: for the term of the Agreement and until deletion/return under Section 13 of the DPA.
- Nature and purpose: hosting, storing, transmitting, displaying, generating PDFs of, and otherwise processing Customer Personal Data to provide, secure, and support the Service, including sending transactional emails and rendering public tokenized Quote/Contract/portal pages on the Customer's instruction.
- Frequency of transfer: continuous, for the duration of the Agreement.
C. Categories of Data Subjects
- The Customer's Clients/Recipients and their personnel (end-clients of the Customer who receive Quotes/Contracts/portal links).
- The Customer's own personnel referenced within Customer Data (e.g., named on a document) to the extent included.
D. Categories of Personal Data
- Client/contact data: company name, contact name(s), email, phone, role, website, company size, location, industry, logo/branding, notes, secondary contacts, lifecycle stage.
- Document data: Quotes and Contracts and their content — numbers, titles, status, line items (name, description, qty, price), pricing (subtotal, discount, tax, total), currency, validity dates, terms/T&C text, messages, billing cycle, term length, MRR/ARR/TCV, auto-renew, coupon codes.
- Attachments: files uploaded by the Customer, which may contain personal data chosen by the Customer (filename, MIME type, size, client-visibility flag).
- Activity/event data: records of when a Recipient views, accepts, or declines a Quote/Contract, and
attachment_downloadedevents, including IP-anonymized actor metadata for some event types.
E. Special-Category Data
None is intended or permitted. The Customer must not submit special-category/sensitive data except as separately agreed in writing (DPA Section 4.3).
F. Retention
Customer Personal Data is retained for the term of the Agreement and deleted per DPA Section 13 and the Privacy Policy: Workspace/Customer Data purged within 30 days of Workspace deletion; attachment files deleted within 30 days, with backups expiring within 35 days; activity logs 18 months.
G. Competent Supervisory Authority
For EEA transfers, the supervisory authority of the EEA member state in which the Customer (data exporter) is established, or its EU Art. 27 representative is located. For the UK, the Information Commissioner's Office (ICO).
Schedule 2 — Technical and Organizational Measures
Populates Annex II of the EU SCCs.
Quottum maintains the following measures, which it may update provided protection is not materially reduced:
1. Access control and authentication
- Email/password and magic-link sign-in; optional TOTP 2FA for Account Users.
- Passwords stored hashed by the authentication provider (Supabase); Quottum does not store plaintext passwords.
- Role-based access within a Workspace (Owner / Admin / Member); platform administrators are a separate role and are never Workspace members.
2. Tenant isolation
- Multi-tenant data segregation enforced by Postgres row-level security (RLS) so a Workspace's data is accessible only within that Workspace.
3. Public/recipient access control
- Client-facing Quote/Contract/portal pages are gated by long, random per-record tokens that can expire; per-file client-visibility flags control exposure.
4. Operator support access
- Workspace impersonation by platform administrators is off by default and requires a Workspace owner or admin to enable a per-Workspace "Support access" toggle.
- All administrator actions are recorded in an admin audit log.
5. Encryption
- Encryption of data in transit (TLS).
- Encryption at rest as provided by infrastructure sub-processors (Supabase, Backblaze B2).
6. Network, hosting, and operational security
- Application hosted on Kinetic Cloud / Coolify infrastructure with provider-level controls; least-privilege staff access to production systems.
- Source control and release infrastructure via GitHub; internal workflow automation (n8n) does not process Customer Personal Data.
7. Logging and monitoring
- Server-side logging of authentication and document/attachment events for security and integrity, with IP anonymization for applicable event types.
8. Backups and resilience
- Regular backups with a rolling expiry cycle; deleted data becomes unrecoverable after backup expiry.
9. Data minimization and governance
- Prohibition on submitting sensitive/special-category data; transactional-only email; no analytics, advertising, or third-party tracking in the app.
10. Sub-processor management
- Written data protection terms with Sub-Processors and a documented sub-processor change-notice process.
11. Incident response
- A process to detect, investigate, and notify Personal Data Breaches without undue delay (DPA Section 10).
Schedule 3 — Approved Sub-Processors
Populates Annex III of the EU SCCs.
As of the "Last updated" date above:
| Sub-Processor | Purpose | Processing location |
|---|---|---|
| Supabase | Postgres database, authentication, session management (core) | United States |
| Backblaze B2 | File attachment storage | United States (us-west-001) |
| Resend | Outbound transactional and authentication email | [Region — to confirm] |
| Kinetic Cloud / Coolify | Application hosting | [Region — to confirm] |
| GitHub | Source control and release infrastructure (no Customer Personal Data) | United States |
n8n (self-hosted) is used for internal workflow automation and does not process Customer Personal Data today; it will be added here if that changes.
The current list is also maintained at [sub-processors page URL — recommended].