Last Updated: September 21, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between VARANTECH ENERJİ SAN. TİC. LTD. ŞTİ. ("Quote3D", "we", "processor") and the customer ("Customer", "you", "controller"). It applies whenever we process personal data on your behalf. It is concluded in electronic form, which satisfies the writing requirement in Article 28(9) GDPR.
If any term of this DPA conflicts with the Terms of Service, this DPA prevails for the processing of personal data. Nothing in this DPA reduces rights that data subjects hold under mandatory law.
We act in two different roles, and it matters which one applies, because the obligations differ.
As controller, we decide the purposes and means: your own account data, your billing profile, your support correspondence, and our security and abuse logs. Our Privacy Policy governs that processing, not this DPA.
As processor, you decide the purposes and means and we act on your instructions. This is the processing covered by this DPA:
Where you embed the widget on your website, you are the controller for your end-users' data and we are your processor. You remain responsible for the lawfulness of the collection, for informing your end-users, and for obtaining any consent that applies.
Required by the opening words of Article 28(3) GDPR.
We do not use personal data processed under this DPA for any other purpose. In particular, we do not use it to train machine-learning models, we do not use it for advertising, and we do not use it for cross-context behavioral advertising.
Types of personal data: identification and contact data; order and quote reference data; technical data such as IP address, user agent and session identifiers; file content and file metadata; and any additional data you choose to send through the API.
Categories of data subjects: your end-customers, your employees and contractors who use the service on your behalf, and any individual whose personal data is contained in a file submitted to us.
The service is not designed to receive special categories of personal data within the meaning of Article 9 GDPR. If your use case involves anatomical, dental, prosthetic or other health-related geometry, tell us before you send it, so we can assess whether we can lawfully process it and on what additional terms. Do not send special category data without a written agreement covering it.
We process personal data only on your documented instructions, including with regard to transfers to a third country, unless we are required to process by a law we are subject to. Where such a law applies, we will inform you of that legal requirement before processing, unless the law prohibits that information on important grounds of public interest.
Your instructions are: this DPA, the Terms of Service, the configuration you set in your account, and the parameters you send with each API request. Any other instruction must be agreed in writing, and we may charge for instructions that require work outside the service as configured.
If, in our opinion, an instruction infringes the GDPR or other applicable data protection law, we will inform you immediately. We maintain an internal escalation route so that this is a real check and not a formality.
We do not determine the purposes and means of processing covered by this DPA. If we ever did, we would become a controller for that processing under Article 28(10) GDPR, and we would tell you rather than let the role change silently.
Every person we authorise to process personal data under this DPA is bound by a duty of confidentiality, whether by contract or by an equivalent statutory obligation. That duty survives the end of their engagement. Access is granted on a need-to-know basis and is withdrawn when the need ends.
We implement the technical and organisational measures described in Annex 1 (section 16), which are designed to meet Article 32 GDPR and to provide the level of privacy protection that the California Consumer Privacy Act requires of a business.
We state our measures precisely rather than broadly, because an overstated security claim is itself a legal exposure. In particular: our encryption of files at rest protects the storage medium. It does not make your data unreadable to us. The service has to decrypt a model in order to analyse it, so we can access file content, and you should not represent otherwise to your end-users.
You give us general written authorisation to engage sub-processors. The current list is published at /legal/subprocessors and forms part of this DPA.
Before we add or replace a sub-processor, we will update that list and notify you at least 30 days in advance through the email address registered on your account. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for the unused period.
We impose the same data protection obligations on each sub-processor by contract, including the California terms in section 13 where they apply. If a sub-processor fails to fulfil those obligations, we remain fully liable to you for its performance.
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, to fulfil your obligation to respond to requests to exercise data subject rights under Chapter III GDPR, and to consumer requests to know, delete and correct under the California Consumer Privacy Act.
If a data subject contacts us directly about data we process on your behalf, we will not respond on the merits. We will tell them to contact you, and we will notify you without undue delay.
We will acknowledge a request for assistance within 5 business days and provide the assistance within 15 business days, or sooner where your own statutory deadline requires it. Requests are sent to [email protected].
We assist you in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to us. This includes assistance with data protection impact assessments and with prior consultation of a supervisory authority.
If we become aware of a personal data breach affecting personal data we process on your behalf, we will notify you without undue delay and in any event within 24 hours of becoming aware. Where a United States state breach law applies, we will notify you immediately following discovery, as those laws require of a processor.
Our notification will include, to the extent known at the time and supplemented as we learn more:
We will not notify data subjects or any supervisory authority about a breach affecting your data on your behalf unless you instruct us to, or unless a law we are subject to requires it. You remain responsible for your own notification decisions and deadlines.
Because we have no establishment in the European Union, the one-stop-shop mechanism is not available to us. Where a breach affects data subjects in several Member States, notification may be required in each affected Member State, and we will assist you accordingly.
At the end of the provision of the service, you choose whether we delete or return the personal data. The choice is yours, not ours.
Tell us your choice within 30 days of termination. If you choose return, we provide the data in a structured, commonly used, machine-readable format. If you choose deletion, or if you tell us nothing within those 30 days, we delete.
Deletion covers live records, file storage, and derived caches. Encrypted backups are not selectively editable; backup copies are overwritten on their normal rotation cycle and are deleted no later than 35 days after the deletion request. Until then they remain encrypted and are not used for any purpose other than disaster recovery.
We retain data beyond that point only where a law we are subject to requires storage, and only for as long as that law requires. We will tell you which retention applies if you ask.
Derived geometry analysis results are stored in a shared cache keyed by the content hash of the file, so that an identical file does not have to be recomputed. Those records hold measurement values, not file content, and the link to your account is removed when the file is deleted.
We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and we allow for and contribute to audits, including inspections, conducted by you or by another auditor you mandate.
In practice we ask you to start with our written security documentation and completed questionnaire, which we provide on request and which is often sufficient. If it is not, you may conduct an audit or inspection on the following reasonable terms: 30 days' written notice; no more than once in any 12-month period, except after a personal data breach or where a supervisory authority requires it; during business hours; subject to confidentiality; without access to other customers' data; and at your cost unless the audit reveals a material breach by us, in which case we bear it.
Separately, and as the California Consumer Privacy Act requires, you may take reasonable and appropriate steps at least once every 12 months to verify that we use personal information consistently with your obligations, including manual review, automated scans, regular assessments and other technical and operational testing.
These arrangements are practical limits on how an audit is run. They do not remove your right to an actual inspection.
Quote3D is established in Türkiye. As at the effective date of this DPA, and unless and until the European Commission adopts one, there is no adequacy decision for Türkiye. Where you are established in the European Economic Area or the United Kingdom and you send us personal data, you are the exporter and we are the importer.
For those transfers we enter into the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), and where you act as a processor for a third party, Module Three (processor to processor). For the United Kingdom we enter into the International Data Transfer Addendum to those clauses. The clauses are incorporated by reference into this DPA and prevail over it in case of conflict.
We maintain documentation supporting the transfer impact assessment required by Clause 14(d) of those clauses, covering the legal framework in Türkiye relevant to public authority access, and we make it available to you on request.
Where we transfer personal data onward to a sub-processor outside the EEA or the UK, we put the appropriate Chapter V safeguard in place with that sub-processor and remain liable to you for it.
For completeness, and because this is commonly stated incorrectly: where an individual in the EEA contacts us directly and sends us their own data, that is not a restricted transfer under Chapter V, because a data subject is not an exporter. It is the flows from you to us, and from us onward, that the clauses cover.
These terms apply where you are a business and we are a service provider or contractor within the meaning of the California Consumer Privacy Act and its regulations. Defined terms have the meaning given in Cal. Civ. Code § 1798.140.
We impose these same terms on every sub-processor by contract. If you designate us a contractor rather than a service provider, we certify that we understand these restrictions and will comply with them.
Where Law No. 6698 on the Protection of Personal Data applies, you are the data controller and we are the data processor within the meaning of that law. Article 12(2) makes the controller and the processor jointly responsible for the security measures required by that article; this DPA and Annex 1 set out how we discharge our part.
Where we transfer personal data abroad, we rely on the mechanisms available under Article 9 of that law, and we complete any filing that the applicable regulation requires within its deadline.
Nothing in this DPA limits a data subject's rights under Article 11 of that law, or your obligations under Article 10.
This DPA takes effect when you accept the Terms of Service or first send us personal data, whichever is earlier, and continues for as long as we process personal data on your behalf.
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where those limitations are not permitted by applicable law. Limits of liability between us do not affect a data subject's rights or a supervisory authority's powers.
We may update this DPA where the law, our sub-processors or the service change. Where a change materially reduces your rights, we will give at least 30 days' notice through the email address registered on your account, and you may terminate the affected part of the service without penalty within that period. The version in force is the one published here, with the effective date shown above.
These are the measures actually implemented, described specifically enough to be checked.
Uploaded model files are encrypted at rest using envelope encryption.
Access to production data is restricted and recorded.
Measures addressing Article 32(1)(b) and (c).
Measures addressing Article 32(1)(d).
The current sub-processor list, including each sub-processor's name, function, the categories of personal data it receives, and its location, is published at /legal/subprocessors and forms part of this DPA. Section 7 sets out the notice and objection process.
For any matter under this DPA, including audit requests, assistance requests and sub-processor objections, contact [email protected].
If your procurement process requires a countersigned copy, or requires the Standard Contractual Clauses to be executed as a separate instrument, write to us and we will provide one.