Data Processing Agreement

Last Updated: September 21, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between VARANTECH ENERJİ SAN. TİC. LTD. ŞTİ. ("Quote3D", "we", "processor") and the customer ("Customer", "you", "controller"). It applies whenever we process personal data on your behalf. It is concluded in electronic form, which satisfies the writing requirement in Article 28(9) GDPR.

If any term of this DPA conflicts with the Terms of Service, this DPA prevails for the processing of personal data. Nothing in this DPA reduces rights that data subjects hold under mandatory law.

1. Which data this covers, and in which role

We act in two different roles, and it matters which one applies, because the obligations differ.

As controller, we decide the purposes and means: your own account data, your billing profile, your support correspondence, and our security and abuse logs. Our Privacy Policy governs that processing, not this DPA.

As processor, you decide the purposes and means and we act on your instructions. This is the processing covered by this DPA:

Where you embed the widget on your website, you are the controller for your end-users' data and we are your processor. You remain responsible for the lawfulness of the collection, for informing your end-users, and for obtaining any consent that applies.

  • Personal data contained in or attached to 3D model files that your own end-users upload through a Quote3D widget embedded on your website.
  • Personal data you or your end-users submit with a quote request through the API or the widget, such as a name, an email address, a reference number, or a delivery destination.
  • Personal data contained inside the model file itself, including metadata written by the originating CAD or scanning software.

2. Subject-matter, duration, nature and purpose

Required by the opening words of Article 28(3) GDPR.

We do not use personal data processed under this DPA for any other purpose. In particular, we do not use it to train machine-learning models, we do not use it for advertising, and we do not use it for cross-context behavioral advertising.

  • Subject-matter: provision of the Quote3D pricing, analysis and quoting service.
  • Duration: for as long as your subscription is active, plus the deletion period described in section 10.
  • Nature: collection, storage, structured analysis, computation and retrieval by automated means.
  • Purpose, stated specifically rather than generically: file ingestion and format validation; geometry analysis; slicing simulation; support, orientation and packing computation; price computation; quote delivery and retrieval; quota enforcement; abuse and fraud prevention; and technical support you request.

3. Types of personal data and categories of data subjects

Types of personal data: identification and contact data; order and quote reference data; technical data such as IP address, user agent and session identifiers; file content and file metadata; and any additional data you choose to send through the API.

Categories of data subjects: your end-customers, your employees and contractors who use the service on your behalf, and any individual whose personal data is contained in a file submitted to us.

The service is not designed to receive special categories of personal data within the meaning of Article 9 GDPR. If your use case involves anatomical, dental, prosthetic or other health-related geometry, tell us before you send it, so we can assess whether we can lawfully process it and on what additional terms. Do not send special category data without a written agreement covering it.

4. Processing only on documented instructions

We process personal data only on your documented instructions, including with regard to transfers to a third country, unless we are required to process by a law we are subject to. Where such a law applies, we will inform you of that legal requirement before processing, unless the law prohibits that information on important grounds of public interest.

Your instructions are: this DPA, the Terms of Service, the configuration you set in your account, and the parameters you send with each API request. Any other instruction must be agreed in writing, and we may charge for instructions that require work outside the service as configured.

If, in our opinion, an instruction infringes the GDPR or other applicable data protection law, we will inform you immediately. We maintain an internal escalation route so that this is a real check and not a formality.

We do not determine the purposes and means of processing covered by this DPA. If we ever did, we would become a controller for that processing under Article 28(10) GDPR, and we would tell you rather than let the role change silently.

5. Confidentiality

Every person we authorise to process personal data under this DPA is bound by a duty of confidentiality, whether by contract or by an equivalent statutory obligation. That duty survives the end of their engagement. Access is granted on a need-to-know basis and is withdrawn when the need ends.

6. Security measures

We implement the technical and organisational measures described in Annex 1 (section 16), which are designed to meet Article 32 GDPR and to provide the level of privacy protection that the California Consumer Privacy Act requires of a business.

We state our measures precisely rather than broadly, because an overstated security claim is itself a legal exposure. In particular: our encryption of files at rest protects the storage medium. It does not make your data unreadable to us. The service has to decrypt a model in order to analyse it, so we can access file content, and you should not represent otherwise to your end-users.

7. Sub-processors

You give us general written authorisation to engage sub-processors. The current list is published at /legal/subprocessors and forms part of this DPA.

Before we add or replace a sub-processor, we will update that list and notify you at least 30 days in advance through the email address registered on your account. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for the unused period.

We impose the same data protection obligations on each sub-processor by contract, including the California terms in section 13 where they apply. If a sub-processor fails to fulfil those obligations, we remain fully liable to you for its performance.

8. Assistance with data subject requests

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, to fulfil your obligation to respond to requests to exercise data subject rights under Chapter III GDPR, and to consumer requests to know, delete and correct under the California Consumer Privacy Act.

If a data subject contacts us directly about data we process on your behalf, we will not respond on the merits. We will tell them to contact you, and we will notify you without undue delay.

We will acknowledge a request for assistance within 5 business days and provide the assistance within 15 business days, or sooner where your own statutory deadline requires it. Requests are sent to [email protected].

9. Personal data breaches, impact assessments and prior consultation

We assist you in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to us. This includes assistance with data protection impact assessments and with prior consultation of a supervisory authority.

If we become aware of a personal data breach affecting personal data we process on your behalf, we will notify you without undue delay and in any event within 24 hours of becoming aware. Where a United States state breach law applies, we will notify you immediately following discovery, as those laws require of a processor.

Our notification will include, to the extent known at the time and supplemented as we learn more:

We will not notify data subjects or any supervisory authority about a breach affecting your data on your behalf unless you instruct us to, or unless a law we are subject to requires it. You remain responsible for your own notification decisions and deadlines.

Because we have no establishment in the European Union, the one-stop-shop mechanism is not available to us. Where a breach affects data subjects in several Member States, notification may be required in each affected Member State, and we will assist you accordingly.

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to address the breach and to mitigate its effects;
  • a contact point for further information.

10. Deletion or return at the end of the service

At the end of the provision of the service, you choose whether we delete or return the personal data. The choice is yours, not ours.

Tell us your choice within 30 days of termination. If you choose return, we provide the data in a structured, commonly used, machine-readable format. If you choose deletion, or if you tell us nothing within those 30 days, we delete.

Deletion covers live records, file storage, and derived caches. Encrypted backups are not selectively editable; backup copies are overwritten on their normal rotation cycle and are deleted no later than 35 days after the deletion request. Until then they remain encrypted and are not used for any purpose other than disaster recovery.

We retain data beyond that point only where a law we are subject to requires storage, and only for as long as that law requires. We will tell you which retention applies if you ask.

Derived geometry analysis results are stored in a shared cache keyed by the content hash of the file, so that an identical file does not have to be recomputed. Those records hold measurement values, not file content, and the link to your account is removed when the file is deleted.

11. Information and audit rights

We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and we allow for and contribute to audits, including inspections, conducted by you or by another auditor you mandate.

In practice we ask you to start with our written security documentation and completed questionnaire, which we provide on request and which is often sufficient. If it is not, you may conduct an audit or inspection on the following reasonable terms: 30 days' written notice; no more than once in any 12-month period, except after a personal data breach or where a supervisory authority requires it; during business hours; subject to confidentiality; without access to other customers' data; and at your cost unless the audit reveals a material breach by us, in which case we bear it.

Separately, and as the California Consumer Privacy Act requires, you may take reasonable and appropriate steps at least once every 12 months to verify that we use personal information consistently with your obligations, including manual review, automated scans, regular assessments and other technical and operational testing.

These arrangements are practical limits on how an audit is run. They do not remove your right to an actual inspection.

12. International transfers

Quote3D is established in Türkiye. As at the effective date of this DPA, and unless and until the European Commission adopts one, there is no adequacy decision for Türkiye. Where you are established in the European Economic Area or the United Kingdom and you send us personal data, you are the exporter and we are the importer.

For those transfers we enter into the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), and where you act as a processor for a third party, Module Three (processor to processor). For the United Kingdom we enter into the International Data Transfer Addendum to those clauses. The clauses are incorporated by reference into this DPA and prevail over it in case of conflict.

We maintain documentation supporting the transfer impact assessment required by Clause 14(d) of those clauses, covering the legal framework in Türkiye relevant to public authority access, and we make it available to you on request.

Where we transfer personal data onward to a sub-processor outside the EEA or the UK, we put the appropriate Chapter V safeguard in place with that sub-processor and remain liable to you for it.

For completeness, and because this is commonly stated incorrectly: where an individual in the EEA contacts us directly and sends us their own data, that is not a restricted transfer under Chapter V, because a data subject is not an exporter. It is the flows from you to us, and from us onward, that the clauses cover.

13. California Consumer Privacy Act terms

These terms apply where you are a business and we are a service provider or contractor within the meaning of the California Consumer Privacy Act and its regulations. Defined terms have the meaning given in Cal. Civ. Code § 1798.140.

We impose these same terms on every sub-processor by contract. If you designate us a contractor rather than a service provider, we certify that we understand these restrictions and will comply with them.

  • We will not sell or share the personal information we collect under this DPA.
  • We will not retain, use or disclose that personal information for any purpose other than the specific business purposes and services set out in section 2, or as otherwise permitted by the CCPA.
  • We will not retain, use or disclose that personal information for any commercial purpose other than those specified business purposes.
  • We will not use that personal information outside the direct business relationship between you and us.
  • We will not combine that personal information with personal information we receive from, or on behalf of, another person, or that we collect from our own interactions with a consumer, except as permitted by the regulations.
  • We will not engage in cross-context behavioral advertising using that personal information.
  • We will comply with the applicable obligations of the CCPA and provide the same level of privacy protection the CCPA requires of a business, including reasonable security procedures and practices appropriate to the nature of the personal information.
  • We will notify you after we determine that we can no longer meet our obligations under the CCPA.
  • You may, on notice, take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information.
  • We will enable you to comply with consumer requests to know, delete and correct, as set out in section 8, and we will assist with your risk assessments, cybersecurity audits and automated decision-making obligations to the extent they concern processing we carry out for you.

14. Türkiye — Law No. 6698

Where Law No. 6698 on the Protection of Personal Data applies, you are the data controller and we are the data processor within the meaning of that law. Article 12(2) makes the controller and the processor jointly responsible for the security measures required by that article; this DPA and Annex 1 set out how we discharge our part.

Where we transfer personal data abroad, we rely on the mechanisms available under Article 9 of that law, and we complete any filing that the applicable regulation requires within its deadline.

Nothing in this DPA limits a data subject's rights under Article 11 of that law, or your obligations under Article 10.

15. Liability, term and changes

This DPA takes effect when you accept the Terms of Service or first send us personal data, whichever is earlier, and continues for as long as we process personal data on your behalf.

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where those limitations are not permitted by applicable law. Limits of liability between us do not affect a data subject's rights or a supervisory authority's powers.

We may update this DPA where the law, our sub-processors or the service change. Where a change materially reduces your rights, we will give at least 30 days' notice through the email address registered on your account, and you may terminate the affected part of the service without penalty within that period. The version in force is the one published here, with the effective date shown above.

16. Annex 1 — Technical and organisational measures

These are the measures actually implemented, described specifically enough to be checked.

Encryption

Uploaded model files are encrypted at rest using envelope encryption.

  • AES-256-GCM, with a per-file key derived through HKDF-SHA256 from a master key and a random per-file salt.
  • The file format carries a key identifier, so master keys can be rotated and retired without rewriting stored files.
  • Files are stored in authenticated 256 KB frames. Each frame carries its own authentication tag, and the nonce and additional authenticated data bind each frame to its position and to end-of-file, so frames cannot be reordered, dropped, or the stream truncated without detection.
  • Data in transit to and from our public interfaces is protected with TLS.
  • Limitation, stated plainly: the service decrypts files in order to analyse them. Encryption at rest protects the storage medium; it is not end-to-end encryption and does not put file content beyond our reach.

Access control

Access to production data is restricted and recorded.

  • Authentication with credentials or a federated identity provider, with account lockout after repeated failed sign-ins.
  • Role-based authorisation; internal access on a need-to-know basis, withdrawn when the need ends.
  • Per-customer isolation of stored files, with restrictive filesystem permissions on the storage directory.
  • Scoped API tokens, with rate limits and quota enforcement per account.

Availability and resilience

Measures addressing Article 32(1)(b) and (c).

  • Encrypted backups on a defined rotation cycle.
  • Service health monitoring with recorded availability samples.
  • Scheduled cleanup jobs that enforce the retention periods stated in our Privacy Policy.

Testing and review

Measures addressing Article 32(1)(d).

  • An automated test suite that runs on every change, including regression gates covering consent enforcement and the published legal documents.
  • Dependency and secret scanning in the development workflow.
  • Review of these measures at least annually, and after any material change to the service.

17. Annex 2 — Sub-processors

The current sub-processor list, including each sub-processor's name, function, the categories of personal data it receives, and its location, is published at /legal/subprocessors and forms part of this DPA. Section 7 sets out the notice and objection process.

18. Contact and signature

For any matter under this DPA, including audit requests, assistance requests and sub-processor objections, contact [email protected].

If your procurement process requires a countersigned copy, or requires the Standard Contractual Clauses to be executed as a separate instrument, write to us and we will provide one.