Data processing
Last updated 11 September 2026
Parties and scope
These terms form part of the Quokka agreement between the customer and Growth Insights Limited, incorporated in Hong Kong, at Unit 1603, 16/F, The L. Plaza, 367–375 Queen's Road Central, Sheung Wan, Hong Kong. They apply when we process personal data on the customer's behalf. The customer determines the purposes and lawful basis of that processing; we act as its processor. Our separate account, security and billing purposes are described in the privacy policy.
Processing lasts for the provision of the service and the agreed return, retention or deletion of the customer's records. These terms take precedence over conflicting service terms concerning processing on the customer's behalf. They do not by themselves constitute an international-transfer agreement or certification of compliance with every jurisdiction.
Processing instructions and information covered
The customer's instructions are its use and configuration of authorized features, these terms and any additional instructions agreed in writing. We process data only on those instructions unless applicable law requires otherwise. Where legally permitted, we will inform the customer of such a requirement. We will raise an instruction we believe infringes applicable data protection law and work with the customer to resolve it.
The service retrieves and filters work email and calendar events, reduces Google Drive activity to daily counts without retaining file names or contents, accepts notes and CRM imports, stores selected information, produces sales records and source evidence, answers questions, translates quotes, prepares company profiles and summaries, and creates replies for the mailbox owner to review and approve. It also records access, actions and operational results for the service.
Data subjects include the customer's users, employees, contractors, prospects, customers and other correspondents or people named in supplied records. Data includes identities and contact details, correspondence and metadata, meeting information and RSVP outcomes, CRM/deal records, notes, chat content, derived facts, drafts, sent copies and source references. Personal or sensitive information can appear incidentally despite filtering; the customer must not deliberately supply information subject to requirements we have not agreed to support.
Customer responsibilities and access
The customer is responsible for authority to connect sources, lawful processing instructions, required notices and consents, accuracy of its own records, user access and an appropriate retention policy. It must explain that managers and administrators can read work correspondence linked to company deals. Only the connected mailbox owner can approve sending from that mailbox.
The customer retains its rights in its data. We do not sell it or use it to train AI models. Personnel authorized to process customer information must be subject to confidentiality obligations and access it only as necessary for their authorized role. Access to Google-derived content is additionally limited by the Google Limited Use commitments in the privacy policy.
Service providers
- Vercel: application hosting, execution and related delivery/operational infrastructure.
- Supabase: hosted PostgreSQL storage and associated database operations and backups.
- AI service providers: receive selected content, manage processing requests and responses, and run AI models for extraction, assistance, translation, company profiles, summaries and drafts.
Current AI provider identities and processing details are available from info@askquokka.com before connecting data or on request. The customer authorizes service providers for the functions described here. We remain responsible for our processor obligations and must put appropriate data protection obligations in place with subprocessors. Before adding or replacing a subprocessor that handles customer content, we will notify affected customers, explain its purpose and provide a reasonable opportunity to raise a data-protection objection. We will seek an alternative or discuss ending the affected processing if an objection cannot be resolved.
We do not use customer content to train AI models or permit our AI service providers to do so. We use privacy settings to limit their retention of content. Operational records may still be retained, and these controls do not erase the workspace information stored by Quokka. Provider retention and Quokka's own retention are separate matters.
Stripe handles hosted checkout and subscription administration if the customer expressly starts a paid plan. It does not provide the AI features. Roles and any additional applicable payment terms depend on the chosen billing service.
Security and incident assistance
We implement measures appropriate to the processing, including encrypted connections, application encryption for message bodies, chat bodies, quote translations and OAuth tokens, workspace access checks, database row-level security and records of supported access and actions. Facts, metadata, drafts and sent copies are separate records and are not erased by removing a message-body key. The Security page explains the measures and their limits; we do not promise that every infrastructure access is covered by the product audit log.
We will notify the customer without undue delay after becoming aware of a personal data breach affecting data processed on its behalf, provide information reasonably available to support its response and cooperate with containment and remediation. Information may be supplied in stages as the investigation develops. This is not a guarantee that every incident will be detected within a fixed time.
Requests, accountability and assistance
We will provide reasonable assistance with data-subject requests, security obligations, impact assessments and regulator consultations relevant to our processing, taking into account its nature and the information available to us. We will direct requests concerning customer-controlled data to the customer unless required by law to respond directly.
We will provide information reasonably needed to demonstrate our obligations and cooperate with proportionate audits agreed with the customer. The arrangements must protect other customers' data, confidential information and service security. Scope, timing and any reasonable assistance costs should be agreed in advance; this does not restrict a legally required audit or regulatory power.
Return, retention and erasure
At the end of processing, we will follow the customer's agreed choice to return or erase personal data processed on its behalf, unless retention is required by applicable law. Contact us to agree the available export format, records covered and handling of copies. Retention decisions take account of those instructions, legal obligations and necessary security or dispute records. Any required exception should be documented and remaining data protected and limited to its permitted purpose.
Disconnecting a source, removing account access or cancelling billing does not automatically erase workspace records. Removing a person's live encryption key makes associated encrypted content unreadable in the live database. Facts, contacts, metadata, drafts, sent copies, audit records and other separately stored data need separate handling.
Older backups can contain keys and records until the provider's configured retention expires. We do not state an unverified backup lifetime or universal deletion deadline. Our restore procedure requires retained erasure instructions to be reapplied before a restored database is opened for use. We will explain the applicable backup handling when agreeing an erasure request.
Processing locations and transfers
Growth Insights Limited is in Hong Kong. The listed providers may process data in other countries. Specific operating locations, provider agreements and applicable transfer safeguards must be checked for the customer's requirements. These terms do not assert that EU standard contractual clauses, a UK transfer addendum or another prescribed instrument has already been executed.
Where a legally required transfer mechanism or location restriction applies, the parties must document the applicable arrangements before the affected transfer or processing begins. Contact us before connecting data that requires such arrangements. No wording on this page replaces that work.
Contact info@askquokka.com. Read the privacy policy, security information and terms of service.