Data Processing Agreement

Data Processing Agreement (art. 28 GDPR)

The agreement governing the processing of the personal data you upload to Quot: you remain the controller, we are the processor that handles it only on your instructions.

Last updated: 20 June 2026 · version v2026-06-20

This Personal Data Processing Agreement (hereinafter the "Agreement" or "DPA") supplements the subscription contract for the Quot application (hereinafter the "Main Contract") and governs the processing of the personal data that the Customer uploads and manages through the application. The Agreement is concluded pursuant to art. 28 of Regulation (EU) 2016/679 ("GDPR"). In the event of conflict between this Agreement and the Main Contract, this Agreement prevails as regards the processing of personal data.

1. Parties and roles

The parties to this Agreement are:

  • the Customer (the shop or company holding the Quot subscription), which acts as data controller for the personal data it enters into the application (records of its own customers and contacts, quotes);
  • Donzella di Thomas Donzella, a sole proprietorship with registered office at Via S. Francesco D'Assisi 47E, 20073 Opera (MI), Italy, P.IVA IT02865930180, C.F. DNZTMS00M31F205N, email info@quotlab.com (hereinafter "Quot" or the "Processor"), which acts as data processor on behalf of the Customer. Quot is a product of Lyreth.

With regard solely to account data, sign-in and subscription billing, Quot instead acts as an independent data controller: this activity is described in the privacy policy and is not covered by this Agreement.

2. Subject matter, duration, nature and purpose of the processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1 to this Agreement. In short: Quot processes personal data solely to provide the application (storage and calculation of quotes) on behalf of and in the interest of the Customer, for the entire duration of the main Contract.

Quot declares that the application does not use artificial intelligence and does not carry out automated decision-making or profiling, and that no special categories of personal data within the meaning of Art. 9 GDPR are processed.

3. Controller's instructions (Art. 28(3)(a))

Quot processes personal data only on the basis of the Customer's documented instructions, including those relating to the transfer of data to third countries. Documented instructions consist of this Agreement, the main Contract, the configuration and ordinary use of the application's functions by the Customer, and any further subsequent written instructions.

Quot informs the Customer immediately if it considers that an instruction infringes the GDPR or other data protection provisions. Quot does not use the Customer's personal data for its own purposes.

4. Confidentiality (Art. 28(3)(b))

Quot ensures that the persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to the data is limited to those persons who actually need it for the provision of the service.

5. Security measures (Art. 28(3)(c), Art. 32)

Quot adopts technical and organisational measures suitable to ensure a level of security appropriate to the risk, pursuant to Art. 32 GDPR. The measures adopted are described in Annex 2 and may be updated over time to maintain or improve the level of protection, without reducing it.

6. Sub-processors (Art. 28(3)(d), Art. 28(2) and 28(4))

The Customer grants Quot a general authorisation to engage other processors (sub-processors) for the provision of the service. The up-to-date list of sub-processors is published and available on the page sub-responsabili.html and is summarised in Annex 3.

Quot notifies the Customer, with at least 30 days' notice, of any change concerning the addition or replacement of sub-processors, so as to allow the Customer to object. The Customer may object to the change on reasoned grounds in writing within the notice period, by writing to info@quotlab.com. In the event of an objection that the parties are unable to resolve, the Customer may withdraw from the service for the part affected by the change.

Quot imposes on each sub-processor, by means of a contract, the same data protection obligations set out in this Agreement and is liable towards the Customer for the failure of sub-processors to fulfil their obligations.

7. Assistance with data subject requests (Art. 28(3)(e))

Taking into account the nature of the processing, Quot assists the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests from data subjects exercising the rights laid down in Articles 12 to 22 GDPR (access, rectification, erasure, restriction, portability, objection). The application's features allow the Customer to consult, modify, export and erase on their own the individual data they have entered (for example customers and quotes). Full deletion of the account and of all associated data is requested by writing to info@quotlab.com and is carried out by Quot without undue delay (as a rule within 30 days), pursuant to clause 9. Should a data subject request reach Quot directly, it is forwarded to the Customer without delay.

8. Assistance with security, breaches and DPIA (Art. 28.3 lett. f)

Quot assists the Customer in ensuring compliance with the obligations set out in Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Processor, in particular:

  • Personal data breaches (Articles 33 and 34): Quot notifies the Customer, without undue delay after becoming aware of it, of any personal data breach affecting the data processed on the Customer's behalf, providing the information the Customer needs to fulfil its obligations to notify the supervisory authority and to communicate to the data subjects.
  • Impact assessment (DPIA) and prior consultation (Articles 35 and 36): Quot provides the Customer, on request, with the information reasonably necessary to carry out any data protection impact assessment and any prior consultation of the supervisory authority.

9. Erasure or return of data (Art. 28.3 lett. g)

Upon termination of the service, at the Customer's choice, Quot deletes or returns all the personal data processed on the Customer's behalf, and deletes the existing copies, unless Union or national law requires their retention. Before and after termination the Customer can export its own data on its own through the application's features. Consistent with the soft-block model, upon expiry of the trial or subscription access continues in read-only mode (writes are blocked, the data remains stored and can be exported) until a request for deletion or return is made.

10. Demonstration of compliance and audit (Art. 28.3 lett. h)

Quot makes available to the Customer all the information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or by another party mandated by the Customer. The checks take place with reasonable written notice, during normal working hours, without prejudice to the security and confidentiality of other customers, and in compliance with confidentiality obligations. Quot immediately informs the Customer if it considers that an audit instruction infringes the GDPR or other data protection provisions.

11. Transfers of data to third countries

Personal data is processed, where possible, within the European Union. Some sub-processors may process data outside the European Union (in particular in the United States for payment services and for the delivery of the app's push notifications). In such cases, the transfer takes place solely in the presence of appropriate safeguards pursuant to Chapter V of the GDPR, in particular the provider's adherence to the EU-US Data Privacy Framework and/or the Standard Contractual Clauses (SCC) adopted under Commission Implementing Decision (EU) 2021/914, where applicable supplemented by additional measures. The details for each provider are set out in Annex 3 and on the sub-responsabili.html page.

12. Term and applicable law

This Agreement is effective for the entire term of the main Contract and ceases together with it, without prejudice to the obligations intended by their nature to survive (for example deletion or return of the data and confidentiality). The Agreement is governed by Italian law. The Court of Milan has exclusive jurisdiction over any dispute.


Annex 1 · Description of the processing

Subject matter of the processing Provision of the Quot software application to the Customer, in subscription-based SaaS mode.
Duration For the entire term of the main Contract (free trial and/or subscription), until deletion or return of the data pursuant to clause 9.
Nature and purpose Storage and calculation of quotes on behalf of the Customer: recording, organisation, storage, consultation, processing, extraction (export) and deletion of the data entered by the Customer, for the sole purpose of operating the application.
Types of personal data Identification and contact data of the Customer's customers, contained in the records and in the quotes (for example: company name or name, address, VAT number or tax code, telephone, email, notes). No special categories of data within the meaning of Art. 9 GDPR.
Categories of data subjects Customers and contacts of the Customer (clients, companies and their reference persons) whose information is entered into the application by the Customer.

Annex 2 · Technical and organisational security measures

Quot adopts, among others, the following measures pursuant to Art. 32 GDPR:

  • Encryption in transit (TLS): all communications between the user's browser and the application take place over encrypted HTTPS/TLS connections.
  • Credential protection: passwords and access tokens ("remember me") are stored in hashed form, not in plain text.
  • Access control: user authentication, authorisation management and two-factor authentication (2FA) for administrative access.
  • Backup with rotation: periodic security copies of the data kept outside the public folder, with rotation of the most recent copies, to ensure recovery and continuity.
  • Logging and traceability (logs and audit): recording of relevant events and changes, in support of security and auditability.
  • Vulnerability management: updating of components, limiting the exposure of sensitive files and application of security headers, with prompt corrective actions.
  • Minimisation and separation: processing only of the data necessary to provide the service and logical separation of the data between customers.

Annex 3 · Sub-processors

The complete, up-to-date and always current list of sub-processors, indicating the service provided, the location of the processing and the safeguards for any non-EU transfers, is published on the sub-responsabili.html page, which forms an integral part of this Agreement. That page lists, among others, the providers of hosting and email, payments, VAT number verification, invoicing, anti-bot security and site analytics, and delivery of the app's push notifications.

Contacts

For any request relating to this Agreement, to the exercise of data subjects' rights or to verification activities, write to info@quotlab.com.