‹ All legal

Data Processing Agreement

Last updated 22 August 2026

Why this exists

When you put a customer's name, address and phone number on an invoice, that's personal data and you are responsible for it. In the language of the law you are the controller. We hold it for you and do nothing with it except what you tell us, which makes us your processor.

UK GDPR Article 28 says that relationship has to be written down before it starts. This is that document. It applies automatically to every QuoteBash account — you don't need to sign anything or ask us for a copy, and it forms part of the Terms of Service.

If one of your customers ever asks what happens to their details, or your accountant asks whether you have a DPA with your software, this is the answer.

1. What's being processed

Subject matterProviding QuoteBash to you
DurationFor as long as your account is open, plus the retention period in the Privacy Policy
Nature and purposeStoring, organising and displaying your records so you can quote, invoice and get paid; producing PDFs; sending documents you choose to send; exporting to your accounting software
Types of personal dataNames, postal addresses, email addresses, phone numbers, job descriptions and site addresses, payment records, and any photos or notes you attach
Categories of data subjectYour customers and prospective customers, and any staff you add
Special category dataNone. QuoteBash isn't built for it and you shouldn't put it in

2. We act only on your instructions

We process this data only to provide the service, and only as you direct through the product. We won't use it for our own purposes, we won't sell it, and we won't use it to train anything. If the law ever required us to process it some other way, we'd tell you first unless we were legally forbidden from doing so.

3. Confidentiality

Anyone with access to your data is bound to keep it confidential. In practice access is limited to the people who run the service, and only when there's a reason — a fault to fix or a request from you.

4. Security

These are the measures actually in place, not a wish list:

  • Encrypted in transit (HTTPS enforced, HSTS).
  • Passwords stored as scrypt hashes; nobody can read yours, including us.
  • Optional two-factor sign-in, with the secret encrypted at rest under a key held separately from the session key.
  • Every record is scoped to its owner at the query layer, and an automated test suite checks that no route can bypass it.
  • Content Security Policy, CSRF protection on every state-changing request, rate limiting on sign-in and password reset.
  • Uploads are restricted by type, re-encoded, and stripped of embedded location data.
  • Verified backups taken before every release and kept for 14 days.

5. Sub-processors

You give us general authorisation to use the sub-processors listed on the sub-processors page. Each is bound by terms no weaker than these, and we remain responsible to you for what they do.

We'll give you at least 30 days' notice before adding or replacing one. If you object on reasonable data protection grounds, tell us and we'll work it out with you; if we can't, you can cancel without penalty and take your data with you.

6. International transfers

Your data is currently hosted in US West (Railway), which means it leaves the UK. That transfer relies on standard contractual clauses with the UK Addendum in our agreement with the hosting provider. The Privacy Policy says more about it.

7. Helping you answer your customers

If one of your customers exercises a right — asks for their data, asks to be corrected, asks to be forgotten — you can usually do it yourself in the product: edit or delete the client record, or export it. Where you can't, tell us and we will help, at no charge, in time for you to meet your own one-month deadline.

8. Breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 48 hours, with what we know: what happened, who's affected, what we're doing. That's deliberately tighter than the 72 hours you have to report to the ICO, so you have time to act rather than time to panic.

9. Audits

We'll give you the information you reasonably need to satisfy yourself we're meeting this agreement. For a business of our size that means answering your questions properly and in writing, rather than hosting an on-site audit.

10. What happens at the end

When your account closes you can export everything. After that we keep it for the retention period in the Privacy Policy in case you need it, and then delete it. Ask us to erase it sooner and we will — completely, including the files on disk, and we'll tell you exactly what was removed.

11. Precedence

Where this agreement and the Terms of Service disagree about the handling of personal data, this agreement wins.

GGFlows Ltd.
QuoteBash is a product of GGFlows Ltd. Last updated 22 August 2026.