Data Processing Addendum

Processor terms for customer data, with the GDPR Article 28 annexes.

Effective
24 August 2026
Last updated
24 August 2026

This Data Processing Addendum ("DPA") forms part of the Quotiv Terms of Service (the "Agreement") between QUOTIV LIMITED (NZ company number 9444423) ("Quotiv", "Processor") and the customer identified in the Agreement ("Customer", "Controller").

It applies where Quotiv processes Customer Personal Data on the Customer's behalf. Where this DPA conflicts with the Agreement in relation to personal data, this DPA prevails.


1. Definitions

"Applicable Data Protection Law" means the NZ Privacy Act 2020; the EU GDPR; the UK GDPR and Data Protection Act 2018; the Australian Privacy Act 1988; the CCPA/CPRA; and any other data protection law applicable to a party's processing.

"Customer Personal Data" means personal data within Customer Data that Quotiv processes on the Customer's behalf under the Agreement, as described in Annex I.

"Data Subject", "controller", "processor", "personal data", "processing" and "personal data breach" have the meanings in the GDPR, and equivalent terms under other Applicable Data Protection Law have corresponding meanings.

"Sub-processor" means a third party engaged by Quotiv to process Customer Personal Data.


2. Roles and scope

2.1 The Customer is the controller and Quotiv is the processor in respect of Customer Personal Data. Where the Customer is itself a processor for a third-party controller, Quotiv is a sub-processor and the Customer warrants it has authority to engage Quotiv on these terms.

2.2 Quotiv is an independent controller for personal data it collects for its own purposes — account administration, billing, security, and its website and marketing. That processing is governed by the Quotiv Privacy Policy, not this DPA.

2.3 Details of processing — subject matter, duration, nature, purpose, data categories and data subject categories — are set out in Annex I, as required by GDPR Art. 28(3).


3. The Customer's obligations

3.1 The Customer will comply with Applicable Data Protection Law in its capacity as controller.

3.2 The Customer warrants that it has a lawful basis and all necessary rights, consents and notices to enable Quotiv and its Sub-processors to process Customer Personal Data as contemplated — including in respect of the Customer's own end customers, whose personal data the Customer uploads or generates in the Service.

3.3 The Customer is responsible for the accuracy of Customer Personal Data and for the lawfulness of its instructions.

3.4 The Customer must not submit special categories of personal data (GDPR Art. 9), criminal conviction data, government identifiers, or payment card numbers to the Service. The Service is not designed for that data and Quotiv's obligations here do not contemplate it.


4. Quotiv's obligations

Quotiv will:

4.1 Process only on instructions. Process Customer Personal Data only on the Customer's documented instructions, which comprise the Agreement, this DPA, and the Customer's configuration and use of the Service — unless required otherwise by law, in which case Quotiv will inform the Customer beforehand unless the law prohibits it.

4.2 Not sell or repurpose. Not sell, rent, or disclose Customer Personal Data, nor use it for its own purposes, nor combine it with data from other sources, except as permitted by this DPA.

4.3 Confidentiality. Ensure personnel authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data protection training, and limit access on a need-to-know basis.

4.4 Security. Implement and maintain the technical and organisational measures in Annex II, appropriate to the risk, in accordance with GDPR Art. 32.

4.5 Sub-processors. Engage Sub-processors only in accordance with clause 5.

4.6 Assistance with data subject requests. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise Data Subject rights. The Service provides functionality for the Customer to access, correct, export and delete Customer Personal Data directly. Where Quotiv receives a request directly from a Data Subject, it will not respond substantively but will promptly refer the request to the Customer.

4.7 Assistance with compliance. Provide reasonable assistance with data protection impact assessments, prior consultations with supervisory authorities, and security obligations under GDPR Arts. 32 to 36, taking into account the information available to it.

4.8 Breach notification. Notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to describe the nature of the breach, likely consequences, and measures taken or proposed. Quotiv's notification is not an acknowledgement of fault. Where a breach is a notifiable privacy breach under the NZ Privacy Act 2020, the parties will cooperate on notification required to the Office of the Privacy Commissioner and affected individuals.

4.9 Deletion or return. On termination or expiry of the Agreement, delete or return Customer Personal Data at the Customer's election. The Customer may export Customer Personal Data using the Service until the end of the then-current billing period, as set out in clause 14.5 of the Agreement. After that period, Quotiv will delete it within 30 days, except to the extent retention is required by law, and subject to backup media which are overwritten in the ordinary course within 35 days.

4.10 Records and audit. Maintain records of processing as required by GDPR Art. 30(2), and make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. The Customer may audit no more than once in any 12-month period (unless required by a supervisory authority or following a personal data breach), on 30 days' written notice, during business hours, subject to confidentiality, at the Customer's cost, and without access to other customers' data or to systems where access would compromise security. Quotiv may satisfy an audit request by providing a current third-party report or completed security questionnaire.


5. Sub-processors

5.1 The Customer gives general written authorisation for Quotiv to engage Sub-processors. The current list is at Annex III.

5.2 Quotiv will impose on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Sub-processor's performance.

5.3 Quotiv will give at least 30 days' notice before adding or replacing a Sub-processor, by email to the account's notification address.

5.4 The Customer may object on reasonable data protection grounds within 15 days of notice. The parties will discuss in good faith. If Quotiv cannot offer a reasonable alternative, the Customer may terminate the affected part of the Service without penalty, with a pro-rata refund of prepaid fees for the unused period.


6. International transfers

6.1 Quotiv is established in New Zealand, which benefits from a European Commission adequacy decision. Transfers of Customer Personal Data from the EEA to Quotiv in New Zealand therefore do not require additional safeguards.

6.2 Where Customer Personal Data is transferred from the EEA, UK or Switzerland to a Sub-processor in a country without an adequacy decision, the transfer is made under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three (processor to processor), which are incorporated by reference and completed as follows:

  • Clause 7 (docking): applies
  • Clause 9 (sub-processors): Option 2, general written authorisation, 30 days' notice
  • Clause 11 (redress): optional independent dispute resolution body does not apply
  • Clause 17 (governing law): the law of Ireland
  • Clause 18 (forum): the courts of Ireland
  • Annexes I, II and III of the SCCs are populated by Annexes I, II and III of this DPA

6.3 For transfers subject to UK law, the UK International Data Transfer Addendum (version B1.0) applies to the SCCs, with Tables 1 to 4 completed by reference to this DPA and the Importer able to end the Addendum under Section 19.

6.4 For transfers from Switzerland, references to the GDPR are read as references to the Swiss FADP and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

6.5 For disclosures of personal information outside New Zealand, Quotiv complies with the Privacy Act 2020.


7. CCPA / CPRA

7.1 Where the CCPA applies, Quotiv acts as a service provider. The Customer discloses personal information to Quotiv only for the limited and specified business purpose of providing the Service.

7.2 Quotiv will not: sell or share personal information; retain, use or disclose it for any purpose other than performing the Service or as permitted by the CCPA; retain, use or disclose it outside the direct business relationship; or combine it with personal information from other sources except as permitted by the CCPA.

7.3 Quotiv certifies that it understands and will comply with these restrictions.


8. Shopify protected customer data

8.1 Where the Service accesses protected customer data through the Shopify API, Quotiv will comply with Shopify's protected customer data requirements applicable to its access level, including data minimisation, purpose limitation, applying merchant and customer consent decisions, encryption of data at rest and in backups, separation of test and production data, and the mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact).

8.2 On receipt of a customers/redact or shop/redact webhook, Quotiv will delete the relevant data within the period Shopify requires.


9. Liability

9.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except to the extent Applicable Data Protection Law prohibits limiting liability to a Data Subject or a supervisory authority.

9.2 Nothing in this DPA limits a Data Subject's rights under Applicable Data Protection Law or under the SCCs.


10. Term and general

10.1 This DPA takes effect when the Customer accepts the Agreement and continues until Quotiv ceases to process Customer Personal Data.

10.2 Quotiv may update this DPA where required by a change in Applicable Data Protection Law or to its Sub-processors, provided the update does not materially reduce the protections. Material changes are notified under clause 5.3.

10.3 This DPA is governed by the law stated in the Agreement, except where Applicable Data Protection Law or the SCCs require otherwise.


ANNEX I — Details of processing

A. List of parties

Data exporter (controller): the Customer identified in the Agreement. Data importer (processor): QUOTIV LIMITED, 93a Hetherington Road, Ranui, Auckland 0612, New Zealand. Contact: privacy@quotiv.io.

B. Description of processing

Subject matter: provision of the Quotiv quoting software.

Duration: the term of the Agreement, plus the deletion periods in clause 4.9.

Nature and purpose: hosting, storing, organising, retrieving, transmitting, analysing and generating quoting documentation; producing AI-generated quote content and recommendations; creating vector embeddings to power search and recommendation; sending quote emails to the Customer's end customers; recording quote acceptance.

Frequency: continuous, for the duration of the Agreement.

Categories of data subjects

  • The Customer's personnel who use the Service (authorised users)
  • The Customer's customers and prospective customers ("end customers"), including individuals who receive, view, sign or accept a quote

Categories of personal data

GroupData
Authorised usersWorkspace membership, role and permissions assigned by the Customer, and activity and audit logs relating to actions taken on Customer Data
End customer recordsName, primary contact name, email address, phone number, billing address (address, city, state, country, postcode), shipping address fields, customer type, discount percentage, internal notes, customer-facing notes, and free-text metadata supplied by the Customer
Derived dataVector embeddings generated from end customer text fields, used for search and recommendation
Quote recordsQuote content, line items, pricing, versions, approvals, enquiry details and correspondence
Quote acceptance recordsElectronic signature — either a drawn signature captured as a base64 image, or a typed name — together with IP address, user agent and timestamp of acceptance

Account administration data. Identity, contact details, login credentials and security logs relating to authorised users are collected and controlled by Quotiv for account administration, authentication, billing, support and security. That data is not Customer Personal Data and is governed by the Privacy Policy, not this DPA.

Note. Quote acceptance records are evidentiary. They identify an individual, capture a signature, and record technical identifiers. They are retained for the life of the quote record and should be treated as sensitive by both parties.

Special categories: none. The Customer must not submit special category data (clause 3.4).


ANNEX II — Technical and organisational measures

Encryption. TLS 1.2+ for all data in transit. Encryption at rest for databases and backups. Third-party integration credentials (including Shopify access tokens) encrypted at rest with a dedicated key.

Access control. Role-based access control with least privilege. Passwords stored using a strong adaptive hash (bcrypt). Server-side session revocation via token versioning.

Resilience. Managed database with automated backups and point-in-time recovery. Redundant, managed hosting infrastructure.

Application security. Input validation and schema enforcement on untrusted input; sanitisation of user-supplied markup; rate limiting on authentication and public form endpoints; dependency monitoring and patching.

Environment separation. Production data separated from test and development environments; production credentials not used outside production.

Logging and monitoring. Audit logging of security-relevant events, including authentication, approvals, AI recommendation actions and quote version changes.

Personnel. Confidentiality obligations for all personnel and contractors with access; access revoked promptly on role change or departure.

Incident response. Documented process for detecting, escalating and responding to security incidents, including notification under clause 4.8.

Sub-processor governance. Data protection terms imposed on all Sub-processors; review before engagement.


ANNEX III — Approved Sub-processors

Current as at the effective date of this DPA.

Sub-processorPurposeData processedLocation
OpenAI, L.L.C.AI quote generation; vector embeddings of customer recordsEnd customer text fields, quote contentUnited States
Anthropic, PBCAI quote prompt generation; the website AssistantQuote content and product contextUnited States
Shopify Inc.App platform, catalogue and order data, subscription billingStore data, merchant identifiers, protected customer dataCanada / United States
Vercel Inc.Application hosting and edge deliveryAll data in transit; application logsUnited States / global edge
Neon Inc.Managed Postgres database hosting (marketing site)Marketing site dataAustralia
Railway Corp.Managed database hosting (product application)All stored Customer Personal DataUnited States
Google LLCTransactional and quote email delivery (Google Workspace / Gmail SMTP)Recipient email address, quote contentUnited States / global
Stripe, Inc.Payment processing for direct subscriptionsBilling contact and payment dataUnited States

Quotiv engages each AI provider on that provider's standard API terms and does not currently hold a zero data retention arrangement with either. Each provider publishes its own data usage and retention terms: Anthropic · OpenAI.

Material disclosure — please read. Quotiv generates vector embeddings from end customer records to power search and recommendation. This means end customer personal data is transmitted to OpenAI.


Contact: QUOTIV LIMITED · privacy@quotiv.io