Data Processing Addendum

Version 1.0 · Last updated 15 August 2026 · Effective immediately for new accounts

Scope and roles

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Kwota and the customer organization (“Customer”). It applies where Kwota processes personal data on Customer’s behalf.

Customer is the controller. Kwota is the processor. Customer determines what personal data enters Kwota, whose data it is, who may access it, and for how long. Kwota processes it only on Customer’s documented instructions.

Using the Service constitutes Customer’s documented instruction to process personal data as necessary to provide it. Customer may issue further instructions in writing; if an instruction would require work outside the scope of the subscription, or would breach applicable law, Kwota will say so rather than comply silently.

If your procurement process requires a signed, countersigned copy of this DPA on your paper or ours, email legal@usekwota.com. We will sign.

Details of processing

ItemDetail
Subject matterProvision of sales quota, commission, forecasting, and CRM synchronisation software
DurationThe term of the subscription, plus the deletion window in section 8
Nature and purposeHosting, storage, retrieval, calculation, display, transmission, backup, and deletion
Categories of data subjectCustomer’s personnel: sales representatives, managers, and administrators
Categories of personal dataName, work email, job role, login timestamps; quota targets; commission plan tiers and rates; commission amounts earned; sales opportunity records, amounts, stages, notes, and close dates; attainment history
Special category dataNone requested or required. Customer must not enter it.
FrequencyContinuous, for the duration of the subscription

Note on sensitivity. Compensation data is not “special category” data under GDPR, but it is confidential and its disclosure can cause real harm. Kwota treats it accordingly, and Customer should too when deciding who gets admin and manager roles.

Kwota's obligations

Kwota will:

Customer's obligations

Customer will:

Security measures

Kwota maintains the following technical and organisational measures:

AreaMeasure
Encryption in transitTLS 1.2+ for all connections to the application, API, and database
Encryption at restAES-256 at the storage layer, provided by our infrastructure provider
Access controlRow-level security enforced in the database. A sales representative cannot read another user’s compensation or pipeline data even by bypassing the user interface. Deactivated users lose access immediately.
AuthenticationPassword-based authentication with hashed credentials; session tokens issued and rotated by our authentication provider
Credential handlingThird-party OAuth tokens (e.g. Salesforce) stored server-side only and never exposed to the browser. Payment card data never reaches Kwota infrastructure.
SegregationMulti-tenant architecture with organization-scoped access enforced at the data layer on every query
Administrative accessLimited to personnel with an operational need
BackupsAutomated, encrypted, retained on a rolling cycle of no more than 30 days
LoggingApplication and authentication events retained for investigation

Current limitations, stated plainly. Kwota does not hold SOC 2 Type II or ISO 27001 certification, has not completed a third-party penetration test, and does not offer single sign-on, enforced multi-factor authentication, customer-managed encryption keys, or a contractual uptime SLA. We would rather lose a deal than misrepresent this. If any of these are required, contact us before subscribing.

Sub-processors

Customer provides general authorisation for Kwota to engage the sub-processors below.

Sub-processorFunctionLocation
SupabaseDatabase, authentication, serverless functionsUnited States
NetlifyApplication and website hostingUnited States
StripeSubscription billing and payment processingUnited States
ResendTransactional email deliveryUnited States
PostHogProduct analytics and session recordingUnited States
SalesforceCRM synchronisation, only where Customer connects itPer Customer’s own Salesforce agreement

Kwota imposes data protection obligations on each sub-processor no less protective than those in this DPA, and remains fully liable to Customer for their performance.

Kwota will give account administrators at least 30 days’ notice before adding or replacing a sub-processor that handles personal data. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees.

Data subject requests

Kwota will promptly notify Customer if it receives a request from one of Customer’s data subjects, and will not respond to it directly except to confirm the request should be directed to Customer, unless legally required or Customer authorises otherwise.

The Service itself allows Customer to access, correct, export, and delete personal data, which will satisfy most requests without our involvement. Where it does not, Kwota will provide reasonable assistance at no additional charge for requests of ordinary scope.

Return and deletion

Customer may export its data at any time during the subscription.

On termination or expiry, Kwota retains personal data for 30 days to allow for export or reinstatement, then permanently deletes it. Backup copies are purged on the ordinary backup cycle, no later than 30 days after primary deletion.

Customer may request immediate deletion in writing, in which case Kwota will delete within 10 business days. Kwota may retain data where required by law — for example billing records for tax purposes — and such retained data remains subject to this DPA.

Personal data breach

Kwota will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer’s personal data.

The notification will describe, to the extent known: the nature of the breach and categories and approximate numbers of records affected; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Kwota will provide updates as the investigation progresses and will reasonably assist Customer in meeting its own notification obligations.

Notification is not an admission of fault or liability.

Audits

On reasonable written request, no more than once per 12 months, Kwota will make available information necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire.

Where a regulator requires it, or following a personal data breach affecting Customer, Customer may conduct or mandate an audit on 30 days’ notice, during business hours, subject to confidentiality, and in a manner that does not unreasonably disrupt the Service. Customer bears the cost unless the audit reveals material non-compliance.

International transfers

Kwota processes personal data in the United States. Where Customer transfers personal data from the United Kingdom, European Economic Area, or Switzerland:

Where the parties execute a superseding transfer mechanism, that mechanism controls.

Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where applicable data protection law does not permit that.

If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. In all other respects the Terms of Service continue in full force.

This DPA terminates automatically when the subscription terminates and Kwota has completed deletion under section 8.