QuillJet

Data Processing Agreement

Last updated: 5 July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller") and the provider of QuillJet ("Processor", "we", "us") regarding the use of QuillJet ("Service").

QuillJet, registered in the Netherlands, Chamber of Commerce (KvK) no. 97282812.

1. Definitions

Terms used in this DPA have the meanings given in the EU General Data Protection Regulation (GDPR) 2016/679.

2. Subject and duration

Item Detail
Subject matter Processing of Personal Data by Processor on behalf of Controller in connection with the Service.
Duration For as long as the Service is provided to Controller, plus any post-termination retention period required by law.
Nature and purpose Synchronizing contact data from Controller's connected Webflow site into Controller's chosen third-party email marketing tool, at Controller's instruction.
Processing activities Storing encrypted connection tokens and API keys, receiving and storing Webflow webhook events, extracting a contact from each event, delivering that contact to Controller's chosen email tool, sending Controller transactional email about their account, and processing Controller's subscription payments.
Categories of Data Subjects Controller's own site visitors, customers, and leads who submit forms or place orders on Controller's Webflow site, and Controller's authorized users.
Categories of Personal Data Email address, first and last name, and any additional Webflow field Controller maps (which may include order details, phone, or address), plus tags. No special-category data is required or intended.

3. Processor obligations

Processor agrees to:

  • Process Personal Data only on documented instructions from Controller (including those in these Terms and this DPA).
  • Ensure persons authorized to process Personal Data are bound by confidentiality.
  • Implement appropriate technical and organizational measures (see Section 6).
  • Assist Controller in responding to Data Subject requests.
  • Notify Controller without undue delay (within 72 hours) of a Personal Data breach.
  • Delete or return all Personal Data after the end of the provision of Services.
  • Make available all information necessary to demonstrate compliance with GDPR Art. 28.

4. Sub-processors

Controller authorizes Processor to engage the following sub-processors:

Sub-processor Purpose
Hetzner Online GmbH Cloud hosting and database (EU, Germany)
Resend Transactional email delivery
Stripe Payment and subscription processing
Webflow The source platform Controller connects (OAuth and webhooks)
Sentry Error monitoring (only if enabled)

In addition, the email marketing tool Controller connects is a recipient of Personal Data at Controller's instruction. Depending on Controller's setup this is one or more of: Mailchimp, Klaviyo, Brevo, MailerLite, ActiveCampaign, Omnisend, or GetResponse. Each receives only the contact email, name, mapped fields, and tags that Controller's sync rules send it, under Controller's own agreement with that provider.

Processor will notify Controller of any intended changes concerning the addition or replacement of sub-processors, giving Controller the opportunity to object within 30 days.

5. International transfers

Hosting and the primary database are located in the EU. Where Personal Data is transferred outside the EEA (for example, to an email tool Controller connects that is established elsewhere), Processor relies on:

  • EU Commission adequacy decisions where applicable
  • Standard Contractual Clauses (SCCs) for transfers to third countries
  • Supplementary measures (encryption in transit and at rest) as recommended by EDPB guidance

6. Technical and organizational measures

Processor implements:

  • AES-256-GCM encryption at rest for stored connection tokens and API keys, with delivery adapters never accessing the encryption key
  • HTTPS-only connections for all data in transit
  • HMAC signature verification of incoming Webflow webhooks before any processing
  • Least-privilege, read-only Webflow scopes limited to the triggers Controller enables
  • Per-account data isolation so one account cannot access another's data
  • HMAC-signed session tokens
  • EU-based hosting and database
  • Incident response with a 72-hour breach notification commitment

7. Data Subject rights

Processor assists Controller in responding to Data Subject requests for access, rectification, erasure, restriction, portability, and objection. Controller can self-serve most requests via the Service:

  • Data export: one-click download from the panel
  • Account deletion: available in-app, processed within 30 days

For requests Controller cannot self-serve, use the contact form at https://quilljet.com/support.

8. Audits

Controller may, no more than once per 12 months and with 30 days written notice, audit Processor's compliance with this DPA. Processor will respond to reasonable written audit questionnaires within 30 days.

9. Termination

This DPA terminates automatically when the Terms terminate or when Processor ceases processing Personal Data on Controller's behalf, whichever is later.

10. Governing law

This DPA is governed by the laws of the jurisdiction in which the Processor is established, once that entity is identified above. Disputes are subject to the competent courts of that jurisdiction.

Contact

For DPA signature requests, sub-processor questions, and deletion requests, use the contact form at https://quilljet.com/support.