Effective date: September 17, 2026
Data Processing Agreement
1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller") and Requo ("Processor") for the provision of the Requo service. This DPA governs the processing of personal data by the Processor on behalf of the Controller.
Requo acts as a Processor when processing business customer data on behalf of businesses that use Requo. The business (Controller) determines the purposes and means of processing personal data submitted through the Service.
2. Definitions
- "Controller" means the business entity that determines the purposes and means of processing personal data using the Service.
- "Processor" means Requo, which processes personal data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Personal Data" means any information relating to a Data Subject that is processed through the Service.
- "Subprocessor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Standard Contractual Clauses" (SCCs) means the contractual clauses adopted by the European Commission for transfers of personal data to third countries.
3. Scope and Role of the Processor
Requo is designated as the Processor for all business customer data processed through the Service. The Controller instructs the Processor to process Personal Data only as necessary to provide the Service, as described in the Terms of Service and this DPA.
Categories of Data Subjects
- End users who submit inquiries through the Controller's public inquiry forms
- Recipients of quotes generated by the Controller through the Service
- Business contacts managed by the Controller within the Service
Categories of Personal Data
- Contact information (name, email address, phone number)
- Inquiry content and communications
- Quote details and response data
- Files and attachments uploaded through the Service
Processing Activities
- Storage and retrieval of inquiry and quote data
- Email delivery for quote sharing and notifications
- AI-assisted drafting of quotes and responses
- Analytics and reporting on inquiry and quote activity
4. Standard Contractual Clauses (Module 2: Controller-to-Processor)
For transfers of Personal Data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not received an adequacy decision, the parties agree to be bound by the Standard Contractual Clauses (Module 2: Controller-to-Processor) as adopted by the European Commission Decision 2021/914.
Module 2 Applicability
Module 2 applies where the Controller (data exporter) transfers Personal Data to the Processor (data importer) located in a third country. Under Module 2:
- The Controller determines the purposes and means of processing
- The Processor processes Personal Data only on documented instructions from the Controller
- The Processor ensures that persons authorized to process Personal Data have committed to confidentiality
- The Processor implements appropriate technical and organizational measures to ensure data security
- The Processor assists the Controller with data subject requests and compliance obligations
- The Processor deletes or returns all Personal Data upon termination of the Service, at the Controller's choice
Supplementary Measures
In addition to the SCCs, the Processor implements supplementary technical and organizational measures as described in the Technical and Organizational Measures Annex below, to ensure an adequate level of protection for transferred Personal Data.
5. Technical and Organizational Measures Annex
The Processor implements and maintains the following technical and organizational measures to protect Personal Data:
Encryption
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for all data at rest (via Supabase managed storage)
- Encrypted database connections between application and database layers
- Secure key management through infrastructure provider controls
Access Control
- Role-based access control (RBAC) with business-scoped data isolation
- Authentication via email verification, OAuth providers, and magic links
- Session management with secure, HttpOnly cookies
- Principle of least privilege for all system access
- Business-scoped data isolation ensuring users access only their own business data
Monitoring and Logging
- Security event logging for authentication and access events
- Rate limiting on public-facing endpoints to prevent abuse
- AI security event monitoring for prompt injection attempts
- Audit logging for sensitive business actions
Incident Response
- Notification to affected Controllers within 72 hours of confirming a Personal Data breach
- Documentation of security incidents including nature, scope, and remediation steps
- Cooperation with Controllers in fulfilling their breach notification obligations
- Post-incident review and implementation of preventive measures
Data Minimization and Retention
- Processing limited to what is necessary for providing the Service
- Defined retention periods per data category (see Privacy Policy)
- Secure deletion of data upon account or business deletion (export beforehand; no post-termination export window is promised)
- AI provider data processed with zero-data-retention policies where available
6. Subprocessors
The Controller provides general authorization for the Processor to engage Subprocessors to assist in providing the Service. The Processor maintains a current list of Subprocessors, including their purpose and data locations.
The current list of Subprocessors is available at requo.app/subprocessors.
The Processor shall notify the Controller of any intended changes to Subprocessors, giving the Controller the opportunity to object. The Processor ensures that each Subprocessor is bound by data protection obligations no less protective than those in this DPA.
7. Controller Obligations
The Controller shall:
- Ensure a lawful basis exists for the processing of Personal Data
- Provide Data Subjects with appropriate privacy notices
- Ensure instructions to the Processor comply with applicable data protection laws
- Respond to Data Subject requests, with the Processor's reasonable assistance
8. Data Subject Rights
The Processor shall assist the Controller in responding to Data Subject requests to exercise their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, portability, and objection.
Where a Data Subject contacts the Processor directly, the Processor shall promptly redirect the request to the relevant Controller unless prohibited by law.
9. Term and Termination
This DPA remains in effect for as long as the Processor processes Personal Data on behalf of the Controller. Upon termination of the Service agreement, the Processor shall, at the Controller's choice, delete or return all Personal Data within 30 days, except where retention is required by applicable law.
The Controller may export inquiries and quotes to CSV while the account is active, and should do so before termination.
10. Governing Law
This DPA is governed by The laws of the Republic of the Philippines. For transfers subject to the Standard Contractual Clauses, the SCCs shall be governed by the law of the EU Member State in which the Controller is established, or where the Controller is not established in the EU, the law of the country where the Processor is established.
11. Contact
For questions about this DPA or to request a signed copy, contact us at privacy@requo.app or by mail at Lucena City, Quezon, Philippines.