QuercusQuote
SecuritySubprocessorsDPA

DATA PROCESSING ADDENDUM

Customer data processing terms

Launch-review draft · 7 September 2026

Pre-launch notice: these documents remain subject to final solicitor review and public paid subscriptions are not yet open.

This launch-review DPA is intended to form part of the business Terms when paid subscriptions open. The customer is normally controller and QuercusQuote is processor for Customer Data entered into a workspace.

1. Scope and instructions

QuercusQuote will process Customer Data only to provide, secure, support and improve the contracted service, follow documented lawful customer instructions, comply with law, and as otherwise stated in the agreement. The service is not intended for special-category or criminal-offence data unless expressly agreed in writing.

2. People and confidentiality

Access is limited to authorised personnel and providers with a need to know, appropriate confidentiality duties and role-based controls. QuercusQuote will maintain reasonable technical and organisational measures appropriate to the risk.

3. Security and incidents

Measures include encrypted transport, specialist identity services, secure sessions, server-side tenant separation, access control, backups, logging and tested recovery procedures. QuercusQuote will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Data and provide available information reasonably needed for the customer’s duties.

4. Subprocessors

The customer authorises the providers in the published subprocessor schedule. QuercusQuote will impose materially equivalent data-protection obligations, remain responsible for their performance to the extent required by law, and give reasonable notice of material additions. A customer may object on reasonable data-protection grounds; the parties will seek a practical solution, failing which the affected service may be terminated.

5. Rights, assessments and regulators

Taking account of the processing and information available, QuercusQuote will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments and regulator consultations. The customer remains responsible for its lawful basis, notices, data accuracy and responding to individuals.

6. Return, deletion and audit

During the subscription, workspace owners can export data. At the customer’s choice after termination, QuercusQuote will delete or return Customer Data unless law requires retention; isolated backups age out under the retention schedule. On reasonable written request, QuercusQuote will provide relevant compliance information and permit a proportionate audit, subject to confidentiality, security, non-disruption and reasonable cost controls.

7. International transfers

Restricted transfers will use an applicable adequacy decision, the UK IDTA or UK Addendum, recognised standard clauses, or another lawful mechanism with supplementary measures where needed. The parties incorporate any mandatory country terms needed for UK GDPR, Canadian private-sector privacy law, the Australian Privacy Act/APPs, New Zealand’s Privacy Act, and applicable US state service-provider or contractor rules.

Annex: processing description

SubjectArborist quoting, job costing, customer estimates, business administration and support.
DurationFor the account term plus documented deletion and backup expiry periods.
PeopleCustomer users, staff, contractors, prospects, end customers and job contacts.
DataIdentity/contact details, job locations and descriptions, quotes, notes, costs, staff labels, outcome records and related files. No intentional special-category data.
QuercusQuote Ltd · Company 17427337 · Registered in England and WalesRegistered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
TermsPrivacySecurityContact