Last updated: 01/09/2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between Quick Docket and Customer (the “Agreement”). It applies whenever Quick Docket processes personal data on Customer's behalf in the course of providing the Service. Terms not defined in this DPA have the meaning given to them in the Agreement. In the event of any conflict between this DPA and the Agreement in respect of the processing of personal data, this DPA prevails.
The parties agree that, in relation to personal data contained within Customer Data, Customer is the data controller and Quick Docket is the data processor, for the purposes of the UK GDPR and, where applicable, the EU GDPR (together, “Data Protection Law”).
2.1 Subject matter. Quick Docket will process personal data on Customer's behalf as necessary to provide the Service described in the Agreement — an internal business administration tool, including a customer-facing portal made available by Customer to its own customers.
2.2 Duration. Processing will continue for the duration of the Agreement, and thereafter only to the extent necessary to comply with the data export and deletion provisions of the Agreement.
2.3 Nature and purpose. Personal data is processed by means of hosting, storage, retrieval, display, and transmission within the Service, for the purpose of enabling Customer to operate its business and to provide a portal to its own customers.
The personal data processed under this DPA relates to the following categories of data subjects:
The categories of personal data processed are limited to the following, and do not include any special category data (as defined in Data Protection Law):
Customer is responsible for ensuring that the personal data it submits to the Service is accurate and that it has a lawful basis to process and share that data with Quick Docket for the purposes described in this DPA.
4.1 Quick Docket will process personal data only on Customer's documented instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by law that Quick Docket is subject to — in which case Quick Docket will inform Customer of that legal requirement before processing, unless the law prohibits this.
4.2 The Agreement, this DPA, and Customer's ordinary use of the Service's documented features together constitute Customer's complete instructions to Quick Docket for the processing of personal data. Any additional or alternative instructions must be agreed in writing.
4.3 Quick Docket will promptly notify Customer if, in its opinion, an instruction from Customer infringes Data Protection Law.
Quick Docket will ensure that any person authorised to process personal data under this DPA, including its employees and contractors, is subject to a binding obligation of confidentiality, and processes personal data only as necessary for the purposes of the Agreement.
Quick Docket will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the nature of the personal data processed. These measures currently include:
Quick Docket will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide Customer with such information as Customer reasonably needs to meet its own breach notification obligations under Data Protection Law.
7.1 General authorisation. Customer provides Quick Docket with a general written authorisation to engage sub-processors in connection with the provision of the Service, subject to the conditions in this Section 7.
7.2 Current sub-processors. The sub-processors currently engaged by Quick Docket, and the nature of their processing, are listed in Section 8 below.
7.3 Notice of changes. Quick Docket will give Customer at least 14 days' prior notice of the addition or replacement of any sub-processor with access to Customer Data, by email or in-app notice. If Customer reasonably objects to a new sub-processor on data protection grounds, the parties will discuss the concern in good faith; if it cannot be resolved, Customer may terminate the Agreement in respect of the affected Service on written notice, without penalty.
7.4 Sub-processor obligations. Quick Docket will impose data protection obligations on any sub-processor that are substantially equivalent to those set out in this DPA, and remains liable to Customer for the performance of each sub-processor's obligations.
Quick Docket will not transfer personal data outside the UK or European Economic Area except as disclosed in Section 8, and will ensure that any such transfer is subject to an appropriate transfer mechanism recognised under Data Protection Law, such as the UK International Data Transfer Addendum or EU Standard Contractual Clauses.
Taking into account the nature of the processing, Quick Docket will provide reasonable assistance to Customer, insofar as this is possible, to enable Customer to respond to requests from data subjects seeking to exercise their rights under Data Protection Law (such as access, rectification, or erasure requests). If Quick Docket receives such a request directly from a data subject, it will promptly forward it to Customer and will not itself respond, other than to direct the data subject to Customer, unless legally required to do otherwise.
Quick Docket will provide Customer with reasonable assistance, and information reasonably available to it, to help Customer comply with its obligations under Data Protection Law relating to the security of processing, breach notification, and data protection impact assessments, to the extent these relate to Quick Docket's processing of personal data under this DPA.
On reasonable prior notice, and no more than once in any 12-month period (except following a personal data breach), Quick Docket will make available to Customer such information as is reasonably necessary to demonstrate compliance with this DPA, and will permit and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality restrictions and cost-sharing arrangements to be agreed between the parties.
On expiry or termination of the Agreement, Quick Docket will make Customer Data available for export, and will subsequently delete it, in accordance with the timelines set out in the Agreement — including the provisions on residual copies retained in backups or caches, which are deleted in the ordinary course of routine backup rotation within 90 days of cancellation or termination.
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
This DPA takes effect on the date Customer first accepts the Agreement, and remains in effect for as long as Quick Docket processes personal data on Customer's behalf under the Agreement.