Data Processing Agreement
Last updated: 5 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller") and the provider of QuillJet ("Processor", "we", "us") regarding the use of QuillJet ("Service").
QuillJet, registered in the Netherlands, Chamber of Commerce (KvK) no. 97282812.
1. Definitions
Terms used in this DPA have the meanings given in the EU General Data Protection Regulation (GDPR) 2016/679.
2. Subject and duration
| Item | Detail |
|---|---|
| Subject matter | Processing of Personal Data by Processor on behalf of Controller in connection with the Service. |
| Duration | For as long as the Service is provided to Controller, plus any post-termination retention period required by law. |
| Nature and purpose | Synchronizing contact data from Controller's connected Webflow site into Controller's chosen third-party email marketing tool, at Controller's instruction. |
| Processing activities | Storing encrypted connection tokens and API keys, receiving and storing Webflow webhook events, extracting a contact from each event, delivering that contact to Controller's chosen email tool, sending Controller transactional email about their account, and processing Controller's subscription payments. |
| Categories of Data Subjects | Controller's own site visitors, customers, and leads who submit forms or place orders on Controller's Webflow site, and Controller's authorized users. |
| Categories of Personal Data | Email address, first and last name, and any additional Webflow field Controller maps (which may include order details, phone, or address), plus tags. No special-category data is required or intended. |
3. Processor obligations
Processor agrees to:
- Process Personal Data only on documented instructions from Controller (including those in these Terms and this DPA).
- Ensure persons authorized to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organizational measures (see Section 6).
- Assist Controller in responding to Data Subject requests.
- Notify Controller without undue delay (within 72 hours) of a Personal Data breach.
- Delete or return all Personal Data after the end of the provision of Services.
- Make available all information necessary to demonstrate compliance with GDPR Art. 28.
4. Sub-processors
Controller authorizes Processor to engage the following sub-processors:
| Sub-processor | Purpose |
|---|---|
| Hetzner Online GmbH | Cloud hosting and database (EU, Germany) |
| Resend | Transactional email delivery |
| Stripe | Payment and subscription processing |
| Webflow | The source platform Controller connects (OAuth and webhooks) |
| Sentry | Error monitoring (only if enabled) |
In addition, the email marketing tool Controller connects is a recipient of Personal Data at Controller's instruction. Depending on Controller's setup this is one or more of: Mailchimp, Klaviyo, Brevo, MailerLite, ActiveCampaign, Omnisend, or GetResponse. Each receives only the contact email, name, mapped fields, and tags that Controller's sync rules send it, under Controller's own agreement with that provider.
Processor will notify Controller of any intended changes concerning the addition or replacement of sub-processors, giving Controller the opportunity to object within 30 days.
5. International transfers
Hosting and the primary database are located in the EU. Where Personal Data is transferred outside the EEA (for example, to an email tool Controller connects that is established elsewhere), Processor relies on:
- EU Commission adequacy decisions where applicable
- Standard Contractual Clauses (SCCs) for transfers to third countries
- Supplementary measures (encryption in transit and at rest) as recommended by EDPB guidance
6. Technical and organizational measures
Processor implements:
- AES-256-GCM encryption at rest for stored connection tokens and API keys, with delivery adapters never accessing the encryption key
- HTTPS-only connections for all data in transit
- HMAC signature verification of incoming Webflow webhooks before any processing
- Least-privilege, read-only Webflow scopes limited to the triggers Controller enables
- Per-account data isolation so one account cannot access another's data
- HMAC-signed session tokens
- EU-based hosting and database
- Incident response with a 72-hour breach notification commitment
7. Data Subject rights
Processor assists Controller in responding to Data Subject requests for access, rectification, erasure, restriction, portability, and objection. Controller can self-serve most requests via the Service:
- Data export: one-click download from the panel
- Account deletion: available in-app, processed within 30 days
For requests Controller cannot self-serve, use the contact form at https://quilljet.com/support.
8. Audits
Controller may, no more than once per 12 months and with 30 days written notice, audit Processor's compliance with this DPA. Processor will respond to reasonable written audit questionnaires within 30 days.
9. Termination
This DPA terminates automatically when the Terms terminate or when Processor ceases processing Personal Data on Controller's behalf, whichever is later.
10. Governing law
This DPA is governed by the laws of the jurisdiction in which the Processor is established, once that entity is identified above. Disputes are subject to the competent courts of that jurisdiction.
Contact
For DPA signature requests, sub-processor questions, and deletion requests, use the contact form at https://quilljet.com/support.