Quizanta.

Data Processing Agreement

Last updated: 4 August 2026

This Agreement applies when you use Quizanta to collect leads. For that data you are the controller and we are your processor. It forms part of our Terms of Service: by creating an account you accept it, and we record when you did. No signature is needed — if your organisation requires a countersigned copy, write to support@quizanta.com.

1. Roles and subject matter

You (the “Customer”) act as controller for the personal data submitted by people who answer your quizzes. Quizanta — Denis Malov, sole proprietor, Mlinska ulica 22, 2000 Maribor, Slovenia — acts as processor and processes that data only to provide the service and only on your instructions.

For your own account and billing data we are the controller; that is covered by our Privacy Policy, not by this Agreement.

Your instructions are the configuration you set in the product: the questions you ask, the integrations you enable, the retention period you choose, and whether lead details are included in notification emails.

2. Duration

This Agreement applies for as long as we process lead data for you — that is, while your account exists. It survives termination for as long as any of your data remains with us.

3. Nature and purpose of processing

Storing quiz answers and contact details; scoring and qualifying them according to rules you define; showing them to you in the cabinet; exporting them when you ask; delivering them to destinations you configure (webhook, CRM, spreadsheet); notifying you that a lead arrived; and deleting them when your retention period elapses or you delete them.

4. Categories of data and data subjects

Data subjects: people who answer your quizzes — your prospective customers.

Categories: identifiers and contact details they submit (typically name, phone number, email address), the answers they give, files they upload (for example a photo of a room, if your quiz asks for one), a score derived from those answers, and technical data such as UTM parameters, referrer and a session identifier.

We do not ask you for special-category data (health, beliefs, biometrics and the like) and the product is not designed for it. If your questions collect it, that is your decision as controller and your legal basis to establish.

5. Security

Data is hosted on servers in Germany (EU). Transport is encrypted with TLS; passwords are hashed; access to production is limited to the provider’s own administrators; webhook deliveries are signed so your receiving system can verify them.

We keep a log of delivery attempts and of application errors so failures are visible rather than silent. Error logs deliberately contain no lead data.

6. Subprocessors

We use the subprocessors listed at /subprocessors, which states each provider’s country and whether it can touch lead data. By accepting this Agreement you authorise them.

We will update that page before adding or replacing a subprocessor that touches lead data, and will notify account holders by email. If you object on reasonable data-protection grounds you may terminate the affected service.

Notification emails are the one place where lead data can leave the EU, and that is off by default: unless you switch it on in Settings, a notification says only that a lead arrived and links you to the cabinet.

7. International transfers

Storage and processing take place in the EU. Where a subprocessor is outside the EEA, the transfer relies on the EU Standard Contractual Clauses and, where applicable, the provider’s participation in the EU–US Data Privacy Framework.

8. Confidentiality

Anyone with access to lead data is bound by confidentiality obligations and only has the access needed to operate and support the service.

9. Assisting you with data-subject requests

The product gives you the tools directly: you can search, export and delete individual leads yourself, and set a retention period after which they are deleted automatically along with any uploaded files.

If a data subject contacts us instead of you, we will not answer on your behalf — we will pass the request to you. Where you need help beyond what the product does, we will provide reasonable assistance.

10. Personal data breaches

We will notify you without undue delay, and in any case within 48 hours of becoming aware of a breach affecting your lead data, with the information available at the time so you can meet your own notification duties.

11. Audits

On request we will provide the information needed to demonstrate compliance with this Agreement. For an audit beyond that, we will agree a reasonable scope and timing; audits must not compromise other customers’ data.

12. Deletion and return

You can export your leads as CSV at any time, and delete them — or your whole account — from the product. On account deletion we delete lead data and the uploaded files that belong to it.

13. Liability, changes, and what this document is not

Liability is governed by the Terms of Service. We may update this Agreement where the law or the service changes; material changes will be notified by email, and the version in force is the one published here.

This page describes how the product works and the commitments we make. It is not legal advice, and it does not tell you what your own obligations as controller are — for that, take advice on your specific situation.

← Back to homeTermsPrivacyCookiesRefundsImprint
Denis Malov, sole proprietor · Mlinska ulica 22, 2000 Maribor, Slovenia · Tax No. 14795914 · Reg. No. 7306024000 · support@quizanta.com · Servers in Germany (EU)