Last updated 22 August 2026
When you put a customer's name, address and phone number on an invoice, that's personal data and you are responsible for it. In the language of the law you are the controller. We hold it for you and do nothing with it except what you tell us, which makes us your processor.
UK GDPR Article 28 says that relationship has to be written down before it starts. This is that document. It applies automatically to every QuoteBash account — you don't need to sign anything or ask us for a copy, and it forms part of the Terms of Service.
If one of your customers ever asks what happens to their details, or your accountant asks whether you have a DPA with your software, this is the answer.
| Subject matter | Providing QuoteBash to you |
|---|---|
| Duration | For as long as your account is open, plus the retention period in the Privacy Policy |
| Nature and purpose | Storing, organising and displaying your records so you can quote, invoice and get paid; producing PDFs; sending documents you choose to send; exporting to your accounting software |
| Types of personal data | Names, postal addresses, email addresses, phone numbers, job descriptions and site addresses, payment records, and any photos or notes you attach |
| Categories of data subject | Your customers and prospective customers, and any staff you add |
| Special category data | None. QuoteBash isn't built for it and you shouldn't put it in |
We process this data only to provide the service, and only as you direct through the product. We won't use it for our own purposes, we won't sell it, and we won't use it to train anything. If the law ever required us to process it some other way, we'd tell you first unless we were legally forbidden from doing so.
Anyone with access to your data is bound to keep it confidential. In practice access is limited to the people who run the service, and only when there's a reason — a fault to fix or a request from you.
These are the measures actually in place, not a wish list:
You give us general authorisation to use the sub-processors listed on the sub-processors page. Each is bound by terms no weaker than these, and we remain responsible to you for what they do.
We'll give you at least 30 days' notice before adding or replacing one. If you object on reasonable data protection grounds, tell us and we'll work it out with you; if we can't, you can cancel without penalty and take your data with you.
Your data is currently hosted in US West (Railway), which means it leaves the UK. That transfer relies on standard contractual clauses with the UK Addendum in our agreement with the hosting provider. The Privacy Policy says more about it.
If one of your customers exercises a right — asks for their data, asks to be corrected, asks to be forgotten — you can usually do it yourself in the product: edit or delete the client record, or export it. Where you can't, tell us and we will help, at no charge, in time for you to meet your own one-month deadline.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 48 hours, with what we know: what happened, who's affected, what we're doing. That's deliberately tighter than the 72 hours you have to report to the ICO, so you have time to act rather than time to panic.
We'll give you the information you reasonably need to satisfy yourself we're meeting this agreement. For a business of our size that means answering your questions properly and in writing, rather than hosting an on-site audit.
When your account closes you can export everything. After that we keep it for the retention period in the Privacy Policy in case you need it, and then delete it. Ask us to erase it sooner and we will — completely, including the files on disk, and we'll tell you exactly what was removed.
Where this agreement and the Terms of Service disagree about the handling of personal data, this agreement wins.
GGFlows Ltd.
QuoteBash is a product of GGFlows Ltd.
Last updated 22 August 2026.