Data Processing Addendum

Effective date: 22 July 2026 · Last updated: 25 July 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you (the "Customer") and Up Top Technologies ("QuotaFlo", "we", "us") and applies whenever your use of the QuotaFlo AI application and website (the "App") involves us processing personal information about your clients on your behalf. No signature is needed — it applies automatically as part of the Terms. If you need a countersigned copy for your own records or compliance, email support@quotaflo.com.

Quick summary

Private beta. QuotaFlo AI is currently in private, invite-only beta. This DPA applies to beta use now and will continue to apply at general availability.

1. Definitions

2. Roles

For Client Personal Data, you are the controller and we are your processor. You are responsible for having a lawful basis to collect and enter your clients' information and for telling your clients how it is used, as described in Section 2 of the Privacy Policy.

This DPA does not cover the information we hold about you as our customer (your account email, name, company name, subscription status, AI-usage tallies). For that data we are the controller, and the Privacy Policy governs.

3. Our instructions and limits

We will process Client Personal Data only on your documented instructions, which are: the Terms, this DPA, and your use of the App's features (each feature you trigger is an instruction to run that feature). We will not process Client Personal Data for any other purpose. In particular we do not sell it, use it for advertising, or use it to train our own models. If we believe an instruction breaches Data Protection Laws, we will tell you. If a law requires us to process differently, we will tell you before we do (unless that law prevents us).

4. What processing happens (Annex 1)

The subject matter, nature, purpose and duration of processing, the categories of data subjects, and the categories of data are set out in Annex 1 below. The design principle: client data stays on your device except for the specific flows listed there.

5. Confidentiality

We ensure that any person we authorise to process Client Personal Data is bound by confidentiality obligations (contractual or statutory).

6. Security

We implement the technical and organisational measures set out in Annex 2, which mirror Section 7 of the Privacy Policy — including its honest statements about what is and is not covered. Taking into account the nature of the processing and the state of the art, these measures are designed to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

7. Subprocessors

You give us general authorisation to use the subprocessors listed in Annex 3 (which matches Section 5 of the Privacy Policy). If we add or replace a subprocessor that processes Client Personal Data, we will update the Privacy Policy and this page and, for material changes, give you notice by email or in-app message at least 14 days before the change takes effect. If you reasonably object on data-protection grounds and we cannot offer you a way to avoid the new subprocessor, you may cancel under the Refund & Cancellation Policy. Each subprocessor is bound by data-protection terms that protect Client Personal Data to a standard no less protective in substance than this DPA, and we remain responsible to you for their performance.

8. Helping with your clients' requests

If one of your clients asks to access, correct or delete their information, you can usually handle that entirely from the copy on your device — for cloud backups we hold only ciphertext we cannot read or edit. Where we do hold reachable Client Personal Data (for example a quote-approval record), we will, taking into account the nature of the processing, give you reasonable assistance to respond — email support@quotaflo.com.

9. Breach notification

If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Client Personal Data, we will notify you without undue delay, and give you information we reasonably can to help you meet your own notification obligations (for example under NZ's notifiable-breach scheme, Australia's Notifiable Data Breaches scheme, or the UK GDPR / GDPR 72-hour regulator rule). Our notification is not an admission of fault.

10. Assistance with impact assessments

Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data-protection impact assessments and prior consultations with regulators, where Data Protection Laws require them for your use of the App.

11. Deletion and return

Client Personal Data on your device is yours to export or delete at any time (the App can export an encrypted backup). On our side: deleting your account permanently deletes your stored encrypted cloud backup and your account records as described in Section 6 of the Privacy Policy. Quote-approval records are standalone (not linked to your login) — on written request we will delete the ones you identify, and at the end of the services we will delete or return reachable Client Personal Data on request, unless a law requires us to keep it. Data sent to AI subprocessors is retained under their policies (Annex 3); we do not keep a separate copy beyond what is needed to return your result.

12. Demonstrating compliance

On written request (no more than once in any 12-month period, unless a regulator requires otherwise or there has been a breach), we will make available the information reasonably necessary to demonstrate compliance with this DPA — such as completing your written security questionnaire or providing our current security documentation. We are a small company and do not currently hold formal certifications (for example ISO 27001 or SOC 2); we won't pretend otherwise. Where that is not enough to satisfy a genuine legal requirement, we will allow an audit by you or your independent auditor, at your cost, on at least 30 days' notice, during business hours, no more than once in any 12-month period, under confidentiality, and scoped to avoid disrupting the service or exposing other customers' data.

13. International transfers

We are operated from New Zealand and use subprocessors located overseas, primarily in the United States (see Annex 3 and Section 10 of the Privacy Policy). Transfers happen under each provider's data-processing terms. For the optional encrypted cloud backup, the safeguard we rely on is that the backup is encrypted on your device with a key we never receive, so only ciphertext is transferred and stored (with the honest limitation described in Section 7 of the Privacy Policy). We have not currently put separate cross-border transfer contracts in place (such as EU/UK Standard Contractual Clauses or a UK IDTA). If you are subject to the GDPR or UK GDPR and require additional transfer mechanisms for your use of the App, contact us before relying on those features — we will tell you honestly what is and is not in place, and will update this section if we add further mechanisms.

14. Liability and precedence

This DPA is subject to the limitations of liability in the Terms of Service. Nothing in this clause limits liability that cannot be excluded under applicable law, or your clients' own statutory rights against either of us. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. This DPA lasts as long as we process Client Personal Data for you.

15. Governing law

This DPA is governed by the laws of New Zealand, the same as the Terms — without limiting any mandatory application of the Data Protection Laws of the place where you operate.

Annex 1 — Details of processing

ItemDescription
Subject matter & durationProcessing of Client Personal Data to provide the App's features, for as long as you use the App (plus the retention periods in Section 6 of the Privacy Policy).
Nature & purposeHosting and transmitting quote-approval records; relaying AI feature inputs to AI providers and returning results; storing your encrypted cloud backup (if enabled); delivering notifications (if enabled). No other use.
Data subjectsYour clients and other individuals whose details you enter (e.g. site contacts).
Categories of dataNames, addresses, phone numbers, email addresses, job descriptions and site details, photos you submit (which may show people or identifying details), quotes, prices/GST, approval status and signatures. The App is not intended for sensitive/special-category data — please don't put medical or similar details in job notes.
Processing flows(a) Quote-approval links — quote content, client name, approval status and signature stored in our database (Supabase); (b) AI features you trigger — the text/photos you submit, relayed via our server to the AI provider; (c) Automatic cloud backup (optional, off by default) — an AES-GCM-256 client-side-encrypted copy of your on-device data, unreadable to us; (d) Web Push and email notifications (optional) — may include a client's name and quote total.

Annex 2 — Technical and organisational measures

Annex 3 — Approved subprocessors for Client Personal Data

SubprocessorRole for Client Personal DataLocation
SupabaseDatabase: quote-approval records; encrypted cloud backup (ciphertext only); Web Push subscriptionsRegion we select (may be outside your country)
AnthropicAI generation — processes the text/photos you submit to AI featuresUnited States
ElevenLabsText-to-speech — processes text you ask to be read aloudUnited States
RenderAPI hosting — Client Personal Data transits our serverUnited States
GoogleEmail delivery (Gmail) of notification emails; Web Push delivery (Firebase Cloud Messaging) on Chrome/Android — content can include a client's name and quote totalUnited States / global
Mozilla & AppleWeb Push delivery on Firefox / Safari (only if you enable push)United States / global

Other providers named in Section 5 of the Privacy Policy (Stripe, Open-Meteo, BigDataCloud, CARTO/RainViewer/OpenStreetMap, PostHog, Sentry, Cloudflare Pages, your browser vendor) process your own data as our customer or anonymous/technical data — not your clients' personal data — and so sit outside this DPA's subprocessor list. In particular, our error-reporting sub-processor Sentry receives only technical error events with the request context stripped and personal identifiers redacted (see Privacy Policy §3.9), so no Client Personal Data is sent to it by design.

Sharing by text message or WhatsApp is your own disclosure, not a subprocessor. Where you choose to send a quote or invoice link by SMS, WhatsApp or another app in your device's share sheet, the App hands the message to that app on your device; it does not pass through our systems and we are not a processor for that transmission. You make that disclosure as controller, under the terms of the messaging app and carrier you select, and you remain responsible for sending it only to the intended client.

Contact

Up Top Technologies
Greymouth, West Coast, New Zealand
support@quotaflo.com