This Data Processing Addendum (“DPA”) forms part of the agreement between QuoteByte and the customer using QuoteByte.
It applies where QuoteByte processes personal information on behalf of a customer in connection with the QuoteByte service.
This DPA should be read together with the Terms of Service, Privacy Policy, Sub-processor List and Data Retention Statement.
1. Parties
The parties are:
- Customer: the business or person using QuoteByte; and
- QuoteByte: QuoteByte is operated by the QuoteByte team.
2. Purpose
QuoteByte processes customer-provided personal information only to provide, secure, support and improve the QuoteByte service, and as otherwise permitted by the agreement or applicable law.
3. Roles
For customer/job data entered by a user:
- the Customer generally controls the relationship with its own customers and decides what information is entered into QuoteByte;
- QuoteByte processes that information to provide the service.
Depending on the legal context, the Customer may be considered the controller, principal, APP entity or equivalent responsible party for its customer/job data, and QuoteByte may act as a processor, service provider or equivalent.
The parties acknowledge that legal roles may vary depending on applicable law.
4. Categories of data subjects
Personal information may relate to:
- QuoteByte users;
- employees, contractors or authorised users of the Customer;
- the Customer’s clients or customers;
- property owners or occupants;
- job contacts;
- billing contacts;
- support contacts.
5. Categories of personal information
Personal information processed may include:
- names;
- email addresses;
- phone numbers;
- business contact details;
- job addresses;
- service addresses;
- quote details;
- job notes;
- invoice details;
- payment status;
- support communications;
- technical metadata;
- account identifiers;
- usage logs.
Users should avoid entering unnecessary sensitive information.
6. Processing activities
Processing may include:
- hosting;
- storing;
- transmitting;
- structuring;
- displaying;
- backing up;
- retrieving;
- deleting;
- securing;
- logging;
- troubleshooting;
- generating documents;
- providing AI-assisted drafting or summarising;
- providing support;
- processing subscription billing;
- maintaining and improving the service.
7. Customer instructions
QuoteByte will process customer-provided personal information in accordance with:
- the Terms of Service;
- this DPA;
- the Privacy Policy;
- user settings and actions within QuoteByte;
- lawful and reasonable written instructions from the Customer.
QuoteByte is not required to follow instructions that are unlawful, technically unreasonable, outside the scope of the service, or inconsistent with the agreement.
8. Confidentiality
QuoteByte will take reasonable steps to ensure that personnel with access to personal information are subject to confidentiality obligations or equivalent duties.
9. Security measures
QuoteByte will maintain reasonable technical and organisational measures designed to protect personal information against misuse, interference, loss, unauthorised access, modification and disclosure.
Measures may include:
- access controls;
- authentication;
- encryption in transit;
- least-privilege practices;
- secure infrastructure providers;
- logging and monitoring;
- backup processes;
- incident response practices;
- separation of environments where practical;
- provider security review.
10. Sub-processors
Customer authorises QuoteByte to use sub-processors to provide the service.
Current or expected sub-processors are listed in the Sub-processor List.
QuoteByte will take reasonable steps to ensure sub-processors are suitable for their role and subject to appropriate contractual or operational controls.
QuoteByte may update sub-processors from time to time.
11. International processing
Customer acknowledges that QuoteByte and its sub-processors may process or store information outside Australia.
Where required, QuoteByte will take reasonable steps to manage overseas disclosure or transfer risks having regard to the provider, location, data type and service involved.
12. AI processing
Where AI-assisted features are used, relevant customer/job information may be processed by an AI provider to generate or support the requested output.
QuoteByte aims to limit AI processing to information reasonably needed for the feature.
Customer is responsible for ensuring that information submitted to AI-assisted features is lawful, appropriate and not unnecessarily sensitive.
13. Assistance with requests
Where legally required and reasonably practical, QuoteByte will assist the Customer with requests relating to personal information processed through QuoteByte.
This may include reasonable assistance with:
- access requests;
- correction requests;
- deletion requests;
- export requests;
- privacy complaints;
- data breach assessments.
QuoteByte may charge reasonable fees for assistance that is complex, excessive, outside normal support scope or caused by Customer misuse, unless prohibited by law.
14. Data breach notification
If QuoteByte becomes aware of a confirmed or reasonably suspected data breach involving customer-provided personal information, QuoteByte will assess the incident and take appropriate steps.
Where required by law or the agreement, QuoteByte will notify affected Customers within a reasonable time after becoming aware of the incident.
Notifications may include available information about:
- the nature of the incident;
- affected data;
- likely consequences;
- steps taken or proposed;
- recommended user actions.
15. Return or deletion
On account closure or termination, QuoteByte will delete, de-identify or retain customer-provided personal information in accordance with the Terms of Service, Privacy Policy and Data Retention Statement.
Where export tools are available, Customer should export required records before closing the account.
16. Audits and information
Upon reasonable written request, QuoteByte may provide information about its security and data practices.
Any audit or review rights must be reasonable, proportionate, subject to confidentiality, and not compromise QuoteByte’s security, other customers’ data, or third-party obligations.
17. Customer responsibilities
Customer is responsible for:
- deciding what information to enter into QuoteByte;
- ensuring it has the right to collect and use that information;
- giving required notices to its own customers;
- obtaining required consents;
- reviewing AI-assisted outputs;
- managing authorised users;
- securing its own devices, emails and passwords;
- exporting required business records;
- complying with applicable laws in its own business.
18. Conflict
If this DPA conflicts with the Terms of Service, this DPA applies only to the extent of the conflict and only for personal information processing matters.
19. Contact
For DPA or privacy questions, contact QuoteByte at hello@quotebyte.com.au.