This version applies to United States.

Data Processing Agreement (DPA)

Agreement under Art. 28 GDPR between the customer as controller and Neithra Technologies – Fabian Lorenz, Thaler Weg 2a, 51647 Gummersbach, Germany as processor. It is deemed concluded upon acceptance of the Quotrail terms and is expressly confirmed when ordering. In case of any discrepancy between language versions, the German version prevails.

Last updated: 10/02/2026

1. Subject matter and duration

The subject matter is the provision and operation of the Quotrail software as a service. The agreement applies for the term of the main contract and ends with the complete deletion of customer data under section 10.

2. Nature and purpose of processing

Storing, reading, matching and displaying requests for quotation, catalog, customer and pricing data; generating draft quotes; optionally retrieving a shared mailbox configured by the customer; export; logging approvals. The sole purpose is performing the agreed service.

3. Types of data and data subjects

Data: names, business contact details and roles of contact persons, contents of requests and emails including attachments, quote, price and condition data, user data and log entries.

Data subjects: the customer’s employees, contact persons at the customer’s customers and suppliers, and other persons whose data is contained in requests.

4. Instructions

Instructions, including those concerning international transfers, may be given in text form to the contact in the legal notice. Where Union or Member State law requires other processing, we inform the customer beforehand unless that law prohibits this on important grounds of public interest.

The processor processes data only on documented instructions from the customer; the instructions result from the main contract, this agreement and the customer’s use of the software. If the processor considers an instruction unlawful, it informs the customer without delay.

5. Confidentiality

Persons with access to the data are bound to confidentiality. The processor is a sole proprietorship; the owner processes the data personally.

6. Technical and organisational measures

The processor takes in particular the following measures under Art. 32 GDPR:

  • Hosting in Germany (netcup GmbH, data centre in Nuremberg); the server is not directly reachable from outside, requests reach it only through an encrypted tunnel.
  • TLS encryption of all connections; passwords stored only as hashes, credentials of configured mailboxes encrypted (AES-256-GCM).
  • Administrative access to the server by key only, without password login.
  • Strict tenant separation: every data access is bound to the customer’s tenant.
  • Logging of sign-ins, security-relevant events and quote approvals.
  • Daily encrypted backups, overwritten after 14 days.
  • Deletion concept: export and deletion by the customer itself, deletion no later than 30 days after the contract ends.

7. Sub-processors

Each sub-processor is bound in writing to equivalent data-protection obligations; the processor remains responsible to the customer for their performance.

The customer consents to the following sub-processors:

The processor announces intended changes at least 30 days in advance by email. The customer may object for an important data protection reason; if no agreement is reached, it may terminate the contract effective on the date of the change.

Not sub-processors for data in the application, but recipients of contract data: Stripe Payments Europe, Limited (1 Grand Canal Street Lower, Dublin, Ireland) processes payments for online orders as an independent controller; Haufe-Lexware GmbH & Co. KG (Munzinger Straße 9, 79111 Freiburg, Germany) is used for the provider’s invoicing and bookkeeping and receives invoice data only.

  • netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany — server, database and backups in the Nuremberg data centre, Germany.
  • Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA — DNS, attack mitigation, encrypted tunnel; EU-US Data Privacy Framework and standard contractual clauses.
  • Plus Five Five, Inc. (“Resend”), 2261 Market Street #5039, San Francisco, CA 94114, USA — sending system emails via the EU region (Ireland); EU-US Data Privacy Framework and standard contractual clauses.

8. Assistance

The processor assists the customer with appropriate measures in responding to data subject requests (Art. 15 to 22 GDPR) and with the obligations under Art. 32 to 36 GDPR. Access and export are available in the software itself.

9. Personal data breaches

The processor notifies the customer of a personal data breach without undue delay, at the latest within 48 hours of becoming aware of it, with the information available to it under Art. 33 (3) GDPR.

10. Deletion and return

The customer can export its data as a ZIP archive at any time. After the contract ends the processor deletes all customer data within 30 days unless a statutory retention obligation applies; data contained in backups is overwritten when they rotate, at the latest after 14 days.

11. Evidence and audits

Reasonable notice, business hours and cost arrangements must not prevent or delay audits required by law or justified by a concrete suspicion, personal data breach or supervisory-authority request. The processor allows and contributes to these audits, including inspections at short notice; statutory audit rights are not conditional on advance payment.

The processor provides the information needed to demonstrate compliance (documentation of measures, this agreement, list of sub-processors). Routine audits are arranged with reasonable notice during business hours; the parties agree reasonable costs beforehand without restricting statutory audit rights. Please send requests to [email protected].

12. Final provisions

The terms and conditions apply otherwise. In case of conflict, this agreement prevails on data protection matters.

Back to the home page

Quotrail Support

I explain Quotrail, its workflows and plans using product documentation. I cannot access account data or make changes.

I am not a lawyer. Legal information is general guidance, not advice on your individual case. Do not enter confidential customer data, passwords or documents. Privacy Policy

Find a suitable plan