QuillCaddieLegal center
ConsumerBusiness
Sign up

Business legal

QuillCaddie Data Processing Addendum

Business data processing terms for Customer Personal Data.

Effective date: May 28, 2026Last updated: May 28, 2026

Business policies

Business terms, DPA, security, addenda, and shared policy references.

Business TermsTerms for Team, Business, Enterprise Preview, Enterprise, and order-form use.Data Processing AddendumBusiness data processing terms for Customer Personal Data.Security and Vulnerability DisclosureSecurity commitments, sensitive-content boundaries, and vulnerability reporting.Subprocessors and AI ProvidersProvider and subprocessor categories with current, preview, and optional status labels.Business Admin, AI, Retention, and Integrations AddendumBusiness workspace admin authority, AI, retention, exports, and integration controls.Enterprise Preview Controls AddendumEnterprise Preview controls and order-form-dependent enterprise features.Support and AvailabilitySupport channels, response targets, availability posture, and incident communications.Privacy and Cookies PolicyPrivacy, cookies, AI processing, connected tools, sharing, retention, and rights requests.AI and Data Use PolicyAI processing, model-training defaults, opt-in controls, human review, and provider boundaries.Data Retention and Deletion PolicyRetention and deletion rules for captures, transcripts, AI outputs, workspaces, and raw audio.Acceptable Use PolicyRules for acceptable use, restricted content, recordings, automation, and enforcement.Audio Recording and Consent PolicyAudio recording, speaker consent, meeting-style capture, raw audio, and transcription boundaries.Integrations and Connected Tools PolicyConnected tools, export actions, MCP, BYOK, and third-party integration boundaries.Billing, Subscriptions, and Refund PolicyBilling, renewals, cancellation, trials, refunds, and taxes.Copyright and DMCA PolicyCopyright notices, counter-notices, repeat-infringer policy, and designated contact.Accessibility StatementAccessibility commitment, current focus areas, feedback, and third-party content boundaries.
Legal CenterConsumer Legal CenterBusiness Legal Center

Version: v1.3 Streamlined
Operator: Bobby Built Ventures LLC d/b/a QuillCaddie

Applies to: Business customers where QuillCaddie processes personal data on behalf of the customer.

Quick summary

This DPA is a practical baseline for business customers. It states that the customer gives processing instructions, QuillCaddie acts as a processor/service provider where applicable, subprocessors are listed, Customer Content is no-training by default, and QuillCaddie will help with deletion, return, and data-subject requests where required.

1. Definitions

Customer, Customer Content, Service, and QuillCaddie have the meanings in the Business Terms.

Personal Data means information relating to an identified or identifiable person that QuillCaddie processes on behalf of Customer through the Service.

Data Protection Laws means privacy, data-protection, and data-security laws that apply to the processing, including where applicable U.S. state privacy laws, GDPR, UK GDPR, Swiss data-protection law, and related regulations.

2. Roles

For Personal Data in Customer Content, Customer is the controller/business and QuillCaddie is the processor/service provider unless the parties agree otherwise in writing or the law requires a different classification.

QuillCaddie may act as an independent controller for account administration, billing, website analytics, security, fraud prevention, communications, and legal compliance as described in the Privacy Policy.

3. Processing instructions

Customer instructs QuillCaddie to process Personal Data to provide, secure, support, maintain, improve, and operate the Service; process captures; generate outputs; store and export content; provide integrations; manage accounts and workspaces; comply with law; enforce agreements; and perform other actions requested by Customer or authorized users.

QuillCaddie will process Personal Data according to Customer’s documented instructions unless required by law.

4. Customer responsibilities

Customer is responsible for providing required notices, obtaining required consents, establishing legal bases, responding to internal governance requirements, and ensuring that Customer Content may lawfully be processed by QuillCaddie and its subprocessors.

Customer must not submit regulated data requiring special contractual safeguards, such as protected health information under HIPAA, payment-card data subject to PCI-DSS scope, government classified information, or similar data, unless QuillCaddie has agreed in writing.

5. No-training business default

QuillCaddie will not use Customer Content from Team, Business, Enterprise Preview, or Enterprise workspaces for generalized model training, fine-tuning, ASR training, internal source-content datasets, or provider model-improvement programs where QuillCaddie controls the setting, unless Customer authorizes that use through an approved workflow or signed agreement.

Operational processing to provide requested features is permitted and is not model training.

6. Confidentiality

QuillCaddie will require personnel and contractors who access Personal Data to be bound by confidentiality obligations. Access should be limited to personnel with a need to know for authorized purposes.

7. Security measures

QuillCaddie will maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Data, including as applicable:

  • private storage and signed URLs for user content;
  • row-level security or equivalent tenant isolation for workspace-scoped data;
  • encryption in transit;
  • encrypted or protected storage for secrets and OAuth tokens;
  • server-side handling of provider keys;
  • access controls and least-privilege practices;
  • no intentional logging of raw audio, raw transcript text, full AI outputs, signed URLs, provider keys, OAuth tokens, or secrets;
  • sanitized provider errors;
  • audit logs for sensitive admin actions where available; and
  • incident-response procedures.

8. Subprocessors

Customer authorizes QuillCaddie to use subprocessors listed at Subprocessors and AI Providers. QuillCaddie will impose appropriate contractual obligations on subprocessors. Customer-enabled integrations are controlled by Customer and may involve third-party services outside QuillCaddie’s subprocessor relationship.

9. Subprocessor changes

QuillCaddie will update the Subprocessors page when material subprocessors change. If Customer has a signed agreement requiring notice or objection rights, those terms apply.

10. International transfers

QuillCaddie may process Personal Data in the United States and other locations where QuillCaddie or its subprocessors operate. Where required, QuillCaddie will use appropriate transfer mechanisms such as standard contractual clauses, the UK addendum, data-protection framework participation, or other lawful safeguards.

11. Data-subject requests

QuillCaddie will reasonably assist Customer with data-subject requests to the extent required by Data Protection Laws and technically feasible. If QuillCaddie receives a request directly from a person relating to Customer-controlled Personal Data, QuillCaddie may direct the requester to Customer unless required by law to respond directly.

12. Deletion and return

Upon termination or Customer request, QuillCaddie will delete or return Customer Content as described in the Data Retention and Deletion Policy, order form, and applicable law. Some data may remain temporarily in backups, logs, billing records, legal records, security records, audit logs, or exported copies controlled by Customer or third parties.

13. Security incidents

QuillCaddie will notify Customer without undue delay after confirming a security incident involving Personal Data where notice is required by law or contract. Notices may describe the nature of the incident, affected data categories if known, mitigation steps, and recommended customer actions.

14. Audits and information

Upon reasonable request and subject to confidentiality, QuillCaddie may provide security documentation, subprocessors information, policy summaries, or other information reasonably necessary to demonstrate compliance. On-site audits are not available unless required by law or a signed agreement.

15. U.S. state privacy service-provider terms

Where U.S. state privacy laws apply, QuillCaddie will process Personal Data as a service provider/processor for Customer’s business purposes, will not sell or share Customer Personal Data, will not retain/use/disclose it outside the business relationship except as permitted by law, and will help Customer meet applicable consumer-rights obligations to the extent required and technically feasible.

16. Survival

This DPA survives termination as long as QuillCaddie processes Personal Data on behalf of Customer.


Contact

Support: support@quillcaddie.com
Privacy requests: privacy@quillcaddie.com
Security reports: security@quillcaddie.com
Legal notices: legal@quillcaddie.com
DMCA notices: dmca@quillcaddie.com
Mail: Bobby Built Ventures LLC d/b/a QuillCaddie, 1500 N Grand St, STE R, Denver, CO 80203