1. Roles and scope
The customer is controller (or processor for another controller) for personal data it uploads to or generates through PowderQuote. The Provider acts as processor only to the extent it processes that customer data to provide, secure, support and maintain the service. Account, billing, security and Provider analytics data processed for the Provider's own purposes are governed by the Privacy Policy.
2. Processing instructions
The Provider will process customer personal data only on documented instructions contained in the Terms, this DPA and the customer's use of the service, unless EU or Member State law requires otherwise. The customer will be informed before legally required processing unless law prohibits this.
3. Processing details
Subject matter: operation of PowderQuote quotation and drawing-processing functions. Duration: the customer relationship plus applicable deletion/backup periods. Nature and purpose: hosting, calculation, quotation generation, storage, retrieval, support, security and deletion. Data may include business contact details, customer/part names, quotation metadata, uploaded drawings and information contained in them. Data subjects may include the customer's staff, customers, suppliers and other business contacts.
4. Confidentiality and security
The Provider will ensure authorised persons are bound by confidentiality and will maintain technical and organisational measures proportionate to risk, including access controls, transport security, application security practices, backups where applicable and data minimisation.
5. Subprocessors
The customer gives general authorisation to use subprocessors listed on the Subprocessors page. The Provider will impose appropriate data-protection obligations and remains responsible as required by Article 28 GDPR. Material changes will be reflected in the published list.
6. International transfers
Where a subprocessor processes personal data outside the EEA, the Provider will rely on an applicable GDPR Chapter V transfer mechanism, such as an adequacy decision or European Commission Standard Contractual Clauses, with supplementary measures where required.
7. Data-subject requests
Taking into account the nature of processing, the Provider will reasonably assist the customer with appropriate technical and organisational measures for responding to data-subject requests. The Provider will not independently respond on the customer's behalf unless authorised or legally required.
8. Security incidents
The Provider will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data and will provide reasonably available information to support the customer's GDPR obligations.
9. DPIAs and supervisory authorities
Taking into account the nature of processing and available information, the Provider will provide reasonable assistance with data-protection impact assessments and prior consultations where required.
10. Deletion and return
On termination or a valid deletion request, the Provider will delete or return customer personal data, at the customer's choice where technically practicable, except where retention is required by law. Residual backup copies may remain until overwritten in normal cycles and remain protected meanwhile.
11. Audit information
The Provider will make available information reasonably necessary to demonstrate Article 28 GDPR compliance and reasonably cooperate with required audits or inspections, subject to confidentiality, security, proportionality and reasonable advance notice.
12. Priority and contact
If this DPA conflicts with the Terms regarding customer personal data processing, this DPA controls. Data-protection requests may be sent to support@zatforge.com.