Data Processing Addendum
quickCLIENT.ai · operated by Prism AI Apps LLC, a California limited liability company
Version 1.0 · Effective and last updated: October 9, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Prism AI Apps LLC(“we,” “us,” the “Processor”) and the customer that agrees to the Terms (“you,” the “Controller”) for use of quickCLIENT.ai (the “Service”). It applies where you use the Service to process personal data about your own clients, prospects, and contacts (“Client Personal Data”). If this DPA conflicts with the Terms on the subject of data processing, this DPA controls. This DPA is provided for review; it is not legal advice, and it does not certify your own compliance obligations.
1. Roles of the parties
For Client Personal Data you enter, capture, or upload, you are the controller and we act as your processor, processing it only on your documented instructions — which include the Terms, this DPA, your configuration of the Service, and your use of its features. For your own account and usage information, we act as an independent controller as described in our Privacy Policy. You are responsible for the accuracy of, and for having a lawful basis and any required consents to provide, the Client Personal Data you process through the Service.
2. Scope of processing
Subject matter: providing the Service. Duration: for the term of your subscription and until deletion as described below. Nature and purpose: hosting, storage, transcription and text extraction, AI-generated summaries and search, reminders, prospect capture, and related features you enable. Types of personal data: the identifiers and details you choose to store about your clients and contacts (for example, names, phone numbers, email addresses, notes, and uploaded files). Categories of data subjects: your clients, prospects, and contacts. You are responsible for the Client Personal Data you choose to process through the Service, and you must not use the Service to process special categories of personal data. This DPA does not grant any permission to process data that the Terms or Privacy Policy otherwise restrict or prohibit.
3. Our obligations as processor
We will:
- process Client Personal Data only on your documented instructions, including for transfers, unless required to do otherwise by law (in which case we will inform you where legally permitted);
- ensure that personnel authorized to process Client Personal Data are bound by confidentiality;
- implement and maintain the technical and organizational security measures summarized in Section 6 and our Security statement;
- engage subprocessors only as described in Section 5;
- taking into account the nature of processing, assist you by appropriate measures, insofar as possible, in responding to data-subject requests and in your obligations around security, breach notification, and (where applicable) data protection impact assessments;
- make available information reasonably necessary to demonstrate compliance with this DPA; and
- at your choice, delete or return Client Personal Data as described in Section 7.
4. Data-subject requests
The Service provides tools for you to access, export, correct, and delete Client Personal Data. If we receive a request from one of your data subjects, we will, where lawfully permitted, refer them to you rather than respond directly, and we will reasonably assist you in responding.
5. Subprocessors
You authorize us to engage the subprocessors listed on our Subprocessor List to process Client Personal Data to provide the Service. We impose data-protection obligations on each subprocessor that are consistent with this DPA, and we remain responsible for their performance. We will update the Subprocessor List and its date when the list changes; you may request advance notice of a new subprocessor by contacting us at support@quickclient.ai, and may object on reasonable data-protection grounds, in which case we will work with you in good faith to address the concern.
6. Security
We maintain administrative, technical, and organizational measures designed to protect Client Personal Data, including encryption in transit and at rest on industry-standard cloud infrastructure, per-account access isolation, required two-factor authentication, access controls, and a tamper-evident audit log. A fuller description is on our Security page. No method of transmission or storage is completely secure.
7. Return and deletion
You can export Client Personal Data at any time from the Service, and can delete it, or your whole account, using the in-product tools. When you delete content or your account, we remove it from our active systems; residual copies in encrypted backups age out as described in our Privacy Policy (“Data retention”), and our separate file-backup copies of your uploads are removed on account deletion. We retain the limited records described in the Privacy Policy where we have a legal, security, or dispute-resolution basis to do so.
8. International processing and transfers
Our production database is hosted in the United States. We use service providers for hosting, AI processing, payments, communications, and diagnostics; some of these are global companies that may process data in more than one country (see the Subprocessor List). Where a particular onward transfer requires a transfer safeguard under applicable law, we will put an appropriate safeguard in place before relying on that transfer. We do not represent that any specific transfer mechanism is currently executed with every subprocessor; on request we will provide the transfer information we have for a given provider.
9. Personal-data breach
We will notify you without undue delay after becoming aware of a personal-data breach affecting Client Personal Data, and will provide the information reasonably available to us to help you meet your own notification obligations.
10. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written request and subject to confidentiality, respond to reasonable audit inquiries. Audits must not unreasonably disrupt the Service.
11. Term, order of precedence, and contact
This DPA is effective for as long as we process Client Personal Data for you under the Terms. It supplements and is governed by the Terms, including their governing-law and liability provisions. For matters covered here it prevails over the Terms and Privacy Policy. Questions or requests under this DPA: Prism AI Apps LLC, support@quickclient.ai, 2108 N St, Ste N, Sacramento, CA 95816.