These terms apply when a business ("the client") uses LocalQuiver and we process personal data on its behalf. They form part of our terms of service and meet the requirements of Article 28 of the UK GDPR.
1. Roles
1.1 The client is the controller, and LocalQuiver Ltd ("we") is the processor, of the personal data the client adds to or collects through LocalQuiver ("client personal data").
1.2 We act as a controller only for our own business data, such as client account and billing details. That's covered by our privacy policy.
2. What we process
- Subject matter and duration: providing LocalQuiver to the client for as long as the agreement lasts, plus the period needed to delete or return data afterwards.
- Nature and purpose:
- hosting and storing data;
- sending review requests and follow-ups by email and text;
- importing reviews and posting replies;
- publishing social posts and articles;
- hosting websites, forms and review pages;
- running loyalty cards;
- creating invoices and reports.
- Types of personal data:
- names and contact details (email address, phone number);
- review content and ratings, private feedback and video testimonials;
- website enquiries and their attachments;
- loyalty membership and stamp history;
- invoice details;
- opt-out records.
- Data subjects:
- the client's customers and prospects;
- people who visit or contact the client's website;
- loyalty members;
- the client's own team members who use LocalQuiver.
3. Our commitments
3.1 Instructions. We process client personal data only on the client's documented instructions, which are these terms and the client's use and settings of LocalQuiver, unless the law requires otherwise. If so, we'll tell the client first unless the law forbids it.
3.2 Confidentiality. Everyone we authorise to process client personal data is bound by confidentiality.
3.3 Security. We keep appropriate technical and organisational measures in place, including:
- encryption in transit;
- access controls that keep each client's data separate;
- encrypted storage of access keys for connected services;
- regular backups;
- restricted staff access.
3.4 Sub-processors. The client authorises us to use sub-processors to provide the service: hosting, email and text delivery, AI model providers and data providers. Each one is bound by data protection terms at least as protective as these. We'll give the client a list on request, and at least 14 days' notice of any new sub-processor. The client may object on reasonable grounds.
3.5 International transfers. Where client personal data is transferred outside the UK, we make sure it's protected, by UK adequacy regulations or the UK International Data Transfer Agreement or Addendum.
3.6 Helping the client. We'll help the client, as far as reasonably possible, to respond to people exercising their data protection rights, and with security, breach notifications and data protection impact assessments.
3.7 Breaches. We'll tell the client without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting client personal data. We'll give them the information they need to meet their own obligations.
3.8 End of the service. When the agreement ends, we'll delete client personal data within 90 days, unless the law requires us to keep it. Before then, the client can download what LocalQuiver lets them export.
3.9 Audits. We'll make available the information needed to show we meet these terms, and allow reasonable audits with reasonable notice, at the client's cost.
4. The client's commitments
4.1 The client confirms it has a lawful basis for the personal data it gives us and for the messages it asks us to send, and that it has told its customers how their data is used.
4.2 The client won't ask us to process personal data in a way that breaks data protection law.
5. Order of precedence
If these terms conflict with our terms of service on data protection, these terms win.