Data processing

Last updated 11 August 2026

This describes how Quokka processes personal data on behalf of a customer. Your company is the controller; Quokka is the processor.

Subject matter and purpose

Reading connected work email, calendar entries, call transcripts and CRM records in order to build and maintain a sales pipeline for the customer, and to draft follow-up messages for a human to approve.

Categories of data subject

The customer’s connected employees, and the people they correspond with in the course of business.

Sub-processors

  • Our hosting and database provider, for storage and running the service
  • Anthropic, for extracting facts from message text

We will tell customers before adding a sub-processor, and a customer may object.

Security measures

  • Message contents encrypted at rest with a key unique to each person
  • Separation between customers enforced by the database itself, not only by application code
  • Personal, medical, financial and job-related mail excluded before it is opened
  • A complete audit log of reads, answers and actions
  • Access to production limited to named people and recorded

Erasure

On request, or 30 days after a customer leaves, we destroy the relevant encryption keys. The data becomes permanently unreadable everywhere it exists, including backups. We do not need to locate every copy, which is precisely why it is done this way.

International transfers

Where personal data is transferred outside the customer’s jurisdiction, it is done under standard contractual clauses or an equivalent approved safeguard. That applies both to our hosting providers and to the extraction step. We will tell customers the current hosting region on request.

Audit

We will answer reasonable security questions in writing and provide the audit log for the customer’s own workspace at any time.