QuoteProcess

Data processing agreement

The article 28 GDPR terms governing QuoteProcess processing of the personal data contained in the customer mailbox.

Last updated: 31 August 2026

Draft document: the provider identification details (legal name, tax ID and address) are still missing. It should not go live in this state.

Purpose

This agreement governs the processing of personal data that Alexis Zanotti Orellana (the processor) carries out on behalf of the customer (the controller) when providing the QuoteProcess service. It forms an inseparable part of the Terms and conditions and is accepted together with them.

In the event of conflict with the Terms and conditions, this document prevails on data protection matters.

Scope of the processing

  • Subject matter: reading incoming messages in the connected mailbox, identifying transport requests, extracting their data, pricing them and drafting and sending the reply.
  • Duration: for as long as the service contract is in force, plus thirty days.
  • Nature and purpose: providing the contracted service, and nothing else.
  • Types of data and categories of data subjects: as set out in Annex I.

Processor obligations

  • Process the data only on the documented instructions of the controller. Use of the service in line with its documentation constitutes a documented instruction. If an instruction infringes data protection law, we will say so immediately.
  • Not use the data for our own purposes, not disclose it, and not use it to train artificial intelligence models.
  • Ensure that anyone with access to the data is bound by a contractual or statutory duty of confidentiality.
  • Apply the technical and organisational measures set out in Annex II.
  • Assist the controller, taking into account the nature of the processing, in responding to data subject requests. If a data subject contacts us, we will refer them to the controller and inform the controller.
  • Assist the controller in complying with articles 32 to 36 GDPR, including impact assessments, with the information available to us.
  • Notify the controller of any personal data breach affecting their data without undue delay and in any event within forty-eight hours of becoming aware of it, with the information needed for the controller to meet its own notification duty.
  • Make available the information needed to demonstrate compliance with these obligations and allow audits, on the terms set out below.

Controller obligations

  • Have a legal basis for the processing of the data brought into the service and have properly informed data subjects, including about the use of a processor.
  • Not introduce special categories of data under article 9 GDPR, or data relating to criminal convictions and offences, into the service.
  • Give instructions through use of the service and, where they differ, in writing to info@quoteprocess.com.

Subprocessors

The controller gives general authorisation for the engagement of the subprocessors listed on the subprocessors page, which is published and accessible at all times.

Any addition or replacement will be notified at least thirty days in advance. During that period the controller may object on reasonable data protection grounds; if the objection cannot be resolved, the controller may terminate without penalty and with a refund of the unused proportion.

The same obligations set out here are imposed on every subprocessor. The processor remains liable to the controller for its subprocessors performance.

International transfers

Where a subprocessor is located outside the European Economic Area, the transfer relies on an adequacy decision, on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission standard contractual clauses with any necessary supplementary measures. The database holding the content is hosted in the European Union, in the Frankfurt (Germany) region.

Audit

The processor will provide documented information evidencing compliance. The controller may audit, itself or through an independent third party bound by confidentiality, once a year, on thirty days notice, during business hours and without interrupting the service. Audit costs are borne by the controller, unless the audit reveals a material breach.

Return and deletion

On termination the controller has thirty days to export its data. After that period it is deleted from production systems, except for what must be retained by legal obligation, which will be blocked until the end of the applicable limitation period.

Annex I. Data and data subjects

  • Categories of data subjects: people who send transport requests to the controller mailbox — customers, prospective customers, staff of shippers and agencies — and the controller own staff with access to the application.
  • Categories of data: name, email address, phone number and signature where they appear in the message; the full content of messages identified as requests, including subject and body; logistics data on origin, destination, dates, weight, pallets, packages, volume and goods; amounts and breakdowns of the quotes issued.
  • Operations: collection, recording, storage, structured extraction by a language model, calculation, consultation, disclosure by sending the reply, and erasure.

Annex II. Security measures

  • Encryption in transit using TLS on all communications.
  • Encryption of mailbox access credentials with AES-256-GCM, under a key managed outside the database.
  • Logical isolation between customers: every query is scoped by company identifier.
  • Production access limited to essential personnel and protected with two-factor authentication.
  • Minimisation: no content is retained from messages discarded by the pre-filter.
  • Backups managed by the database provider, with point-in-time recovery.
  • Logging of errors and polling runs, without message content.