Data processing addendum
Last updated: August 10, 2026
This data processing addendum (“DPA”) forms part of the terms of service and governs the relationship between you (controller) and the operator of Quote Bench Pro — Ondřej Bárta, a sole trader entered in the Czech Trade Register, company ID (IČO) 74140850, place of business: Poštolčí 678, 182 00 Prague, Czech Republic (processor) — under Article 28 GDPR. On data protection matters this DPA prevails over the terms of service.
1. Subject matter, duration, nature and purpose
The subject matter is the processing of personal data necessary to deliver the Quote Bench Pro service — building, calculating, and preparing priced quotes from inputs provided by the controller. The nature of processing includes extracting data from job requests (text or voice), storing it in the database, deterministic price calculation, generating quote PDFs, and delivering them by email on the controller’s instruction. Types of personal data: the controller’s organization-user identifiers, email addresses and roles; their action and audit metadata (who did what, when, and to which object); end-customer identification and contact data (name, email, phone, project address); the content of job requests including dictation transcripts; transient dictation audio; quote line items, prices, versions, and the recipient and delivery metadata of sent quotes; price lists, rates and margins to the extent they relate to a person; logo and branding; and data-export archives. Categories of data subjects: the controller’s employees and contractors (the service’s users), the controller’s end customers, and the recipients of sent quotes where they differ from the end customers. Processing lasts for the duration of the service contract and thereafter as set out in section 8.
2. Controller instructions
The processor processes personal data only on the controller’s documented instructions, including instructions regarding transfers to third countries — the instructions consist of this DPA, the terms of service, service settings, and actions taken by the controller’s users in the service UI — unless processing is required by Union or Member State law to which the processor is subject; in that case the processor informs the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. If the processor considers that an instruction infringes the GDPR or other data protection law, it will inform the controller without undue delay.
3. Confidentiality of persons
The processor ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. Security measures (Art. 32)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risks to the rights and freedoms of natural persons, the processor implements and maintains all technical and organisational measures required by Art. 32 GDPR. The measures currently maintained in the production service include, without limitation:
- Encryption at rest (Postgres + Cloudflare R2 in the EU).
- Encryption in transit (TLS 1.2+).
- Multi-tenant isolation in the database via Row-Level Security; sensitive credentials and integration tokens are encrypted with a per-controller key (AES-GCM).
- An audit log of state-changing operations on quotes, customers, and settings.
- Role-based access control (OWNER / FOREMAN / VIEWER) on a least-privilege basis, with periodic access review.
- Regular automated database backups with periodically tested restoration.
- Ongoing vulnerability and patch management, and an incident-response procedure.
- Controlled deletion at the end of the retention period and when processing ends.
5. Subprocessors
The controller grants general written authorisation to engage the subprocessors named in list (1) of the versioned inventory in section 6 of the privacy policy. The recipients in list (2) of that section are independent controllers, not subprocessors, and this authorisation does not extend to them. The processor will give at least 30 days’ notice of additions or replacements by email to the controller’s contact address; the controller may object on reasonable data-protection grounds, and if the objection cannot be resolved, the controller may terminate the affected service without penalty. The processor imposes by contract the same data protection obligations as set out in this DPA on each subprocessor, to the extent applicable to the subprocessor’s services, and remains liable to the controller for the subprocessors’ performance. Clerk, Inc. is a subprocessor only to the extent it processes personal data solely on documented instructions; for account information it processes for its own purposes, Clerk acts as an independent controller (see section 6 of the privacy policy) and such processing is outside this DPA.
6. Assistance (Arts. 32–36)
Taking into account the nature of the processing, the processor assists the controller with appropriate technical and organisational measures in fulfilling the controller’s obligation to respond to data subject requests (access, rectification, erasure, portability, restriction, objection), and assists in ensuring compliance with Articles 32 to 36 GDPR — security, breach notification, data protection impact assessments, and prior consultation with the supervisory authority. In this DPA, “data protection law” means the GDPR and, to the extent applicable to the controller’s use of the service, US state privacy laws — including, for Texas end-customer data, the Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541); the processor will likewise assist the controller with consumer-rights requests, security and breach duties, and data-protection assessments required by such applicable law, including §541.105 TDPSA. The OWNER role in the service UI can delete the organisation, including its data, self-service; a data export is available self-service in settings.
7. Breach notification
In the event of a personal data breach affecting the controller’s data, the processor notifies the controller without undue delay — and, where practicable, within 48 hours — after becoming aware of it, via email to the registered address. The notification includes, insofar as known at the time: the nature of the breach, the categories and approximate numbers of affected data subjects and records, a contact point for the incident, the likely consequences, and the measures taken or proposed; information not initially available is provided in phases as it becomes known.
8. Return or deletion after processing ends
When the service ends, the controller chooses whether the personal data is returned or deleted. The controller may (i) request an export followed by deletion, or (ii) instruct immediate deletion without an export. If it gives no instruction, the controller may request a machine-readable export during the 30 days after termination, after which the processor deletes the data. An immediate-deletion instruction is given either in writing to privacy@quotebenchpro.com or by the owner performing self-service organization deletion in the service — that action is itself a documented instruction to delete immediately, and its execution immediately and irreversibly disables access, so any export must be taken beforehand. After return, or on an immediate-deletion instruction, the processor initiates deletion without undue delay. Active service copies are deleted no later than 30 days after the termination or deletion instruction that triggered them — the export window does not extend this; backup copies expire on the ordinary backup cycle (currently approximately 3 days) and are not restored except for disaster recovery; the processor ensures that subprocessors delete or return the data under the same instruction, within the schedules stated in the privacy policy — including any vendor trust-and-safety retention disclosed there. Beyond those disclosed schedules, the sole exception is data whose retention is required by Union or Member State law. Records of contract acceptance (document identifier and version, content hash, the exact assent sentence, the customer’s legal name, the accepting user’s identifier and role, tenant identifier, timestamp, IP, and user agent) are held by the provider as an independent controller for contract evidence, contain no end-customer data, and are outside the customer personal data processed under this DPA — see the privacy policy, section 2.
9. Audit
The processor makes available to the controller, on request, all information necessary to demonstrate compliance with the obligations of Article 28 GDPR. Compliance is demonstrated first through documentation and written answers; the processor also allows and contributes to audits (ordinarily no more than once in any 12-month period, with 30 days’ notice, during business hours, without access to other customers’ data), including audits by an independent auditor bound by confidentiality. Those ordinary limits do not apply where an additional or faster audit is reasonably necessary to verify compliance following a personal data breach, a material suspected breach of this DPA or data protection law, a material change in the processing, or a request or instruction of a supervisory authority.
10. International transfers
Personal data is transferred to a third country only through the subprocessors named in the list referenced in section 5 and only under Chapter V GDPR safeguards. The specific transfer mechanism for each recipient is stated in section 6 of the privacy policy (EU–U.S. Data Privacy Framework certification while the recipient’s active certification covers the transferred data, otherwise Standard Contractual Clauses under Decision (EU) 2021/914 in the appropriate module). Information about a specific subprocessor’s safeguards is available on request.
11. Liability
Claims under this DPA are subject to the single aggregate limitation of liability agreed in the terms of service (section 14), except where mandatory law provides otherwise. Nothing in this DPA limits the rights of data subjects, the powers of supervisory authorities, or either party’s liability under Articles 82–83 GDPR, any executed standard contractual clauses, or other mandatory law; the allocation between the parties operates only to the extent legally permitted.