Data Processing Addendum
Effective date: July 22, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between QuickRetail LLC ("QuickRetail," "Processor") and the subscribing business ("Customer," "Controller"). It governs QuickRetail's processing of personal data that the Customer's personnel and customers generate through the Service ("Customer Personal Data").
1. Roles
The Customer is the controller of Customer Personal Data and determines the purposes and means of its processing. QuickRetail is the processor and processes Customer Personal Data only on the Customer's documented instructions, which include the Terms of Service, this DPA, and the Customer's configuration and use of the Service.
2. Scope and purpose of processing
- Subject matter: provision of the Service.
- Duration: the term of the Terms of Service, plus any limited post-termination export/retention period.
- Nature and purpose: hosting, storing, organizing, and transmitting Customer Personal Data to provide retail operations, scheduling, time-and-attendance, tasks, analytics, and outreach features.
- Categories of data subjects: the Customer's personnel (employees, managers, owners) and the Customer's retail customers.
- Categories of personal data: names and contact details, role and employment-related records, time entries and location stamps at clock-in/out, schedules, and customer and purchase information imported from a connected POS.
3. Processor obligations
QuickRetail will:
- process Customer Personal Data only on the Customer's instructions, unless required by law;
- ensure personnel authorized to process Customer Personal Data are bound by confidentiality;
- implement appropriate technical and organizational security measures (see Section 5);
- not sell Customer Personal Data or process it for its own advertising;
- assist the Customer, taking into account the nature of processing, with data-subject requests and with the Customer's own security, breach-notification, and assessment obligations; and
- at the Customer's choice, delete or return Customer Personal Data after the end of the Service, except as retention is required by law.
4. Sub-processors
The Customer authorizes QuickRetail to engage sub-processors (such as cloud hosting and transactional-email providers) to support the Service. QuickRetail will impose data-protection obligations on sub-processors substantially similar to those in this DPA and remains responsible for their performance. We will make available the list of sub-processors on request and give reasonable notice of new ones.
5. Security
QuickRetail maintains security measures designed to protect Customer Personal Data, including encryption in transit, hashed credentials, role-based access controls, network protections, and logging. Measures may be updated so long as they do not materially reduce protection.
6. Personal data breach
QuickRetail will notify the Customer without undue delay after becoming aware of a breach affecting Customer Personal Data and will provide information reasonably available to help the Customer meet its notification obligations.
7. International transfers
If Customer Personal Data is transferred across borders, the parties will rely on a lawful transfer mechanism where one is required.
8. Audits
On reasonable written request and no more than once per year (unless required by a regulator), QuickRetail will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality.
9. Data-subject and regulator requests
If QuickRetail receives a request from a data subject or regulator regarding Customer Personal Data, it will, where legally permitted, direct the request to the Customer and reasonably assist the Customer in responding.
10. Governing law
This DPA is governed by the laws of the State of Tennessee, consistent with the Terms of Service. If any provision conflicts with the Terms of Service on the subject of data protection, this DPA controls.
Contact
QuickRetail LLC — privacy@quickretail.com