Data Processing Agreement
This agreement is entered into between the business customer named in the Polyquote account (“Controller”) and Liam Vendel (trading as Polyquote), Stein 6, 4851 Gampern, Austria (“Processor”). The Controller expressly accepts it during registration through the versioned mandatory confirmation provided there. It applies from the first processing of personal end-customer data through Polyquote.
1. Subject matter and duration
The subject matter is the provision of the Polyquote SaaS, including the widget, storage of price requests and CAD files, the merchant portal and notifications to the merchant. Polyquote does not send automated offers, order confirmations or invoices to the merchant’s end customers. Processing continues until commissioned data is deleted or returned after the contract ends, subject to statutory obligations and time-limited backups.
2. Nature, purpose, data and data subjects
- Nature and purpose: collection, transmission, storage, calculation, display, backup and deletion of price requests.
- Types of data: name, company, email address, pricing and production parameters, filename, CAD/model file, and technical log and security data.
- Data subjects: customers, prospective customers and contacts of the Controller.
- Special categories of data under Article 9 GDPR are not intended and must not be deliberately submitted.
3. Instructions
The Processor processes personal data only on documented instructions from the Controller. This also applies to transfers of personal data to a third country or an international organisation. Documented instructions include, in particular, this agreement, account settings, documented use of functions and subsequent instructions in text form. If Union or Member State law requires the Processor to process data beyond those instructions, the Processor will inform the Controller of that legal requirement before processing unless the law prohibits such information on important grounds of public interest. If the Processor considers an instruction to infringe the GDPR or other Union or Member State data-protection law, it will inform the Controller without undue delay and suspend the instruction pending clarification to the extent legally permissible.
4. Duties of the Processor
- ensure that all authorised persons are bound by confidentiality;
- implement appropriate technical and organisational measures under Article 32 GDPR;
- assist with data-subject rights through suitable technical and organisational measures insofar as possible in view of the nature of processing;
- assist the Controller in complying with Articles 32 to 36 GDPR, taking account of the nature of processing and information available to the Processor, particularly regarding security, reporting and notification of personal-data breaches, data-protection impact assessments and prior consultations with authorities;
- inform the Controller of commissioned-data breaches without undue delay, providing the information then available under Article 33(3) GDPR and reasonably supplementing missing information as it becomes available;
- make available all information necessary to demonstrate compliance with Article 28 GDPR. The Controller or an independent auditor appointed by it and appropriately bound to confidentiality may conduct inspections and audits; Polyquote will permit and contribute to them. Where equivalent evidence is possible, current reports, certificates and questionnaires will be used first to limit effort, risks to other customers and interference with security. This does not replace or limit the statutory right of inspection. Timing, scope, security, confidentiality and access rules will be reasonably coordinated; mandatory or incident-based inspections remain unaffected.
5. Sub-processors
Subject to confirmation of the specific contracting entities and sub-processors before production launch, general authorisation is granted for: Vercel (hosting and serverless execution), Supabase (database, authentication and file storage), and Resend (account and application notifications to merchants and support email). Polyquote self-hosts browser libraries for the 3D view, CAD import and data transmission, so loading the widget does not create an additional connection to a public library CDN. Changes will be announced in text form at least 14 days in advance; the Controller may object for important data-protection reasons.
Polyquote contractually subjects every sub-processor to at least the same data-protection duties imposed on Polyquote by this DPA and Article 28 GDPR, particularly sufficient technical and organisational measures. If a sub-processor fails to fulfil those duties, Polyquote remains fully liable to the Controller for the sub-processor’s performance.
6. Third-country transfers
Transfers outside the EEA take place only where the requirements of Chapter V GDPR are met, particularly an adequacy decision, valid certification under the EU-US Data Privacy Framework, or Standard Contractual Clauses together with any necessary supplementary measures. Current provider terms and sub-processor lists must be reviewed and form part of the contract insofar as they meet legal requirements.
7. Deletion, return and backups
During the contract term, the Controller may delete individual price requests including their CAD file and configure separate automatic periods: at least one day and no longer than the associated price-request period for private CAD/model files (30 days by default), and 30 to 2,555 days for remaining price-request metadata (365 days by default). After the shorter CAD period expires, the price request remains without its model file. When processing ends, the Controller gives a documented choice whether commissioned personal data is to be returned or deleted. The Processor carries out that choice and deletes existing copies unless Union or Member State law requires continued storage; the Controller is informed of such a duty where legally permissible. This agreement and the binding nature of instructions continue until return or deletion is completed. Only where backups are enabled and documented for the actual plan and data type used will deleted data remain blocked from ordinary operation until the confirmed provider or internal rotation plan expires, after which it is overwritten or discarded. Backups are not an archive; database backups do not automatically include private CAD object storage, and restoration of deleted CAD files is not promised.
8. Technical and organisational measures
- tenant separation through Row Level Security and server-side authorisation;
- private file storage using time-limited signed links;
- TLS transport encryption and encrypted provider infrastructure;
- least-privilege access and separate public and privileged keys;
- signed Resend webhooks, input validation and abuse limits;
- logging of security-relevant provider events and documented and tested recovery procedures only for backups actually enabled and their confirmed data scope;
- regular reviews, updates and documented handling of security incidents.
9. Responsibility
The Controller ensures that processing is lawful, fulfils information duties toward its end customers, and correctly configures approved domains and legal texts. Mandatory GDPR provisions prevail in the event of a conflict with this agreement.