Data Processing Addendum
Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Kwota and the customer organization (“Customer”). It applies where Kwota processes personal data on Customer’s behalf.
Customer is the controller. Kwota is the processor. Customer determines what personal data enters Kwota, whose data it is, who may access it, and for how long. Kwota processes it only on Customer’s documented instructions.
Using the Service constitutes Customer’s documented instruction to process personal data as necessary to provide it. Customer may issue further instructions in writing; if an instruction would require work outside the scope of the subscription, or would breach applicable law, Kwota will say so rather than comply silently.
If your procurement process requires a signed, countersigned copy of this DPA on your paper or ours, email legal@usekwota.com. We will sign.
Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of sales quota, commission, forecasting, and CRM synchronisation software |
| Duration | The term of the subscription, plus the deletion window in section 8 |
| Nature and purpose | Hosting, storage, retrieval, calculation, display, transmission, backup, and deletion |
| Categories of data subject | Customer’s personnel: sales representatives, managers, and administrators |
| Categories of personal data | Name, work email, job role, login timestamps; quota targets; commission plan tiers and rates; commission amounts earned; sales opportunity records, amounts, stages, notes, and close dates; attainment history |
| Special category data | None requested or required. Customer must not enter it. |
| Frequency | Continuous, for the duration of the subscription |
Note on sensitivity. Compensation data is not “special category” data under GDPR, but it is confidential and its disclosure can cause real harm. Kwota treats it accordingly, and Customer should too when deciding who gets admin and manager roles.
Kwota's obligations
Kwota will:
- Process personal data only on Customer’s documented instructions, including regarding international transfers, unless required otherwise by law — in which case Kwota will inform Customer first, unless legally prohibited.
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement the technical and organisational measures described in section 5.
- Respect the conditions in section 6 for engaging sub-processors.
- Assist Customer, insofar as reasonably possible, in responding to data subject requests (section 7).
- Assist Customer with security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and information available to Kwota.
- Delete or return personal data at the end of the engagement, per section 8.
- Make available information necessary to demonstrate compliance with this DPA and allow for audits as described in section 9.
Customer's obligations
Customer will:
- Have a valid legal basis for the personal data it puts into Kwota, and provide any required notices to its personnel — including that managers and administrators can view their pipeline and compensation data, and that attainment appears on a team leaderboard visible to the organization.
- Configure roles appropriately, and deactivate users promptly when they leave.
- Not enter special category data, payment card numbers, government identifiers, or health information into free-text fields.
- Be responsible for the accuracy of the compensation plans and quotas it configures.
Security measures
Kwota maintains the following technical and organisational measures:
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2+ for all connections to the application, API, and database |
| Encryption at rest | AES-256 at the storage layer, provided by our infrastructure provider |
| Access control | Row-level security enforced in the database. A sales representative cannot read another user’s compensation or pipeline data even by bypassing the user interface. Deactivated users lose access immediately. |
| Authentication | Password-based authentication with hashed credentials; session tokens issued and rotated by our authentication provider |
| Credential handling | Third-party OAuth tokens (e.g. Salesforce) stored server-side only and never exposed to the browser. Payment card data never reaches Kwota infrastructure. |
| Segregation | Multi-tenant architecture with organization-scoped access enforced at the data layer on every query |
| Administrative access | Limited to personnel with an operational need |
| Backups | Automated, encrypted, retained on a rolling cycle of no more than 30 days |
| Logging | Application and authentication events retained for investigation |
Current limitations, stated plainly. Kwota does not hold SOC 2 Type II or ISO 27001 certification, has not completed a third-party penetration test, and does not offer single sign-on, enforced multi-factor authentication, customer-managed encryption keys, or a contractual uptime SLA. We would rather lose a deal than misrepresent this. If any of these are required, contact us before subscribing.
Sub-processors
Customer provides general authorisation for Kwota to engage the sub-processors below.
| Sub-processor | Function | Location |
|---|---|---|
| Supabase | Database, authentication, serverless functions | United States |
| Netlify | Application and website hosting | United States |
| Stripe | Subscription billing and payment processing | United States |
| Resend | Transactional email delivery | United States |
| PostHog | Product analytics and session recording | United States |
| Salesforce | CRM synchronisation, only where Customer connects it | Per Customer’s own Salesforce agreement |
Kwota imposes data protection obligations on each sub-processor no less protective than those in this DPA, and remains fully liable to Customer for their performance.
Kwota will give account administrators at least 30 days’ notice before adding or replacing a sub-processor that handles personal data. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees.
Data subject requests
Kwota will promptly notify Customer if it receives a request from one of Customer’s data subjects, and will not respond to it directly except to confirm the request should be directed to Customer, unless legally required or Customer authorises otherwise.
The Service itself allows Customer to access, correct, export, and delete personal data, which will satisfy most requests without our involvement. Where it does not, Kwota will provide reasonable assistance at no additional charge for requests of ordinary scope.
Return and deletion
Customer may export its data at any time during the subscription.
On termination or expiry, Kwota retains personal data for 30 days to allow for export or reinstatement, then permanently deletes it. Backup copies are purged on the ordinary backup cycle, no later than 30 days after primary deletion.
Customer may request immediate deletion in writing, in which case Kwota will delete within 10 business days. Kwota may retain data where required by law — for example billing records for tax purposes — and such retained data remains subject to this DPA.
Personal data breach
Kwota will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer’s personal data.
The notification will describe, to the extent known: the nature of the breach and categories and approximate numbers of records affected; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Kwota will provide updates as the investigation progresses and will reasonably assist Customer in meeting its own notification obligations.
Notification is not an admission of fault or liability.
Audits
On reasonable written request, no more than once per 12 months, Kwota will make available information necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire.
Where a regulator requires it, or following a personal data breach affecting Customer, Customer may conduct or mandate an audit on 30 days’ notice, during business hours, subject to confidentiality, and in a manner that does not unreasonably disrupt the Service. Customer bears the cost unless the audit reveals material non-compliance.
International transfers
Kwota processes personal data in the United States. Where Customer transfers personal data from the United Kingdom, European Economic Area, or Switzerland:
- The European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated by reference and take effect on Customer’s acceptance of this DPA.
- For the United Kingdom, the ICO International Data Transfer Addendum to those clauses is incorporated, with Kwota as data importer and Customer as data exporter.
- Docking clause: optional. Clause 9: Option 2, general written authorisation, 30 days’ notice. Clause 11: the optional independent dispute body is not used. Clause 17: governed by the law of Ireland. Clause 18: courts of Ireland.
- Annexes I, II, and III are populated by sections 2, 5, and 6 of this DPA respectively.
Where the parties execute a superseding transfer mechanism, that mechanism controls.
Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where applicable data protection law does not permit that.
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. In all other respects the Terms of Service continue in full force.
This DPA terminates automatically when the subscription terminates and Kwota has completed deletion under section 8.