Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between you (“Customer”, the controller) and Queezy (the processor) and governs our processing of personal data you enter into the app about your own customers (“Customer Personal Data”). It reflects Article 28 UK GDPR.
1. Roles & scope
You are the controller of Customer Personal Data (your clients' names, contact details, addresses and the quotes/jobs you create). Queezy processes it only as your processor to provide the app. For your own account data, Queezy is the controller (see the Privacy Policy).
2. Details of processing
- Subject matter: providing the Queezy quoting/job-management app.
- Duration: for the term of your account, then deletion per §8.
- Nature & purpose: storing and processing quotes, clients and jobs on your behalf.
- Types of data: names, addresses, phone numbers, email addresses, job/quote details and photos you enter.
- Data subjects: your customers and contacts.
3. Our obligations as processor
- Process Customer Personal Data only on your documented instructions (including this DPA and your use of the app), unless required by law.
- Ensure people authorised to process it are under a duty of confidentiality.
- Implement appropriate technical and organisational security measures (§5, Art 32).
- Respect the conditions for engaging sub-processors (§4).
- Assist you, so far as possible, in responding to data-subject requests.
- Assist you with security, breach notification and DPIAs (Arts 32–36).
- Delete or return Customer Personal Data at the end of the service (§8).
- Make available information needed to demonstrate compliance and allow for reasonable audits.
4. Sub-processors
You authorise us to engage the sub-processors listed in our Privacy Policy (currently Neon, Render, Cloudflare, Stripe, Resend, Expo, Apple and Google). We impose data-protection terms on each of them and remain responsible for their performance. We will give reasonable notice of any intended change so you can object.
5. Security
We maintain measures appropriate to the risk, including encryption in transit and at rest, EU data residency for core data, hashed credentials, per-account access scoping, and minimised logging (see the Privacy Policy and our internal security controls).
6. International transfers
Core data is stored in the UK/EEA. Where a sub-processor is outside the UK/EEA, transfers are protected by appropriate safeguards such as the UK IDTA / Standard Contractual Clauses.
7. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and provide information to help you meet your own notification duties.
8. Return & deletion
On termination or account deletion, Customer Personal Data is deleted from our production systems (see the Privacy Policy for how in-app deletion works and its timing), save where retention is required by law.
9. Precedence & contact
If this DPA conflicts with other agreement terms on data protection, this DPA prevails for Customer Personal Data. Questions: [email protected].