Security & Data Protection

Protecting the information you trust QPD with.

QPD combines application-level security, established cloud infrastructure and per-company data protection and recovery controls to protect the operational information stored within the platform.

Last updated: September 2026

At QPD, we recognise that the information stored within our platform can be commercially and operationally important to our customers. This may include customer and contact information, quotes and costings, project information, Bills of Materials, resource plans, timesheets and other operational data.

We have designed QPD around a multi-layered approach to security, data protection and recovery.

1. Our role under UK GDPR

When a customer uses QPD to process personal data for its own business purposes, the customer will normally act as the data controller and QPD will act as the data processor.

This means our customers determine what personal data is entered into QPD and how that information is used. QPD processes that information as necessary to provide, maintain and support the QPD service and in accordance with our contractual obligations.

QPD may separately act as a data controller for information we process for our own legitimate business purposes, such as managing customer accounts, responding to enquiries, providing support and administering our commercial relationship with customers.

2. Infrastructure and hosting

QPD is delivered using modern cloud infrastructure designed to provide security, resilience and availability.

Our core application and database infrastructure is provided through Bubble, with underlying cloud infrastructure including Amazon Web Services (AWS) and Cloudflare.

Bubble maintains SOC 2 Type II compliance and uses established cloud infrastructure and security controls to protect the applications and data hosted through its platform.

QPD combines these infrastructure controls with its own application-level security and access controls.

3. Encryption

QPD data is protected both while it is being transmitted and while it is stored.

Data transmitted between users and the platform is protected using encrypted HTTPS/TLS connections.

Data stored within the underlying database infrastructure is encrypted at rest using industry-standard encryption provided by the underlying cloud infrastructure.

4. Customer data separation

QPD is a multi-customer platform, and customer data is logically separated between company environments.

QPD uses server-side access controls to determine whether an authenticated user is authorised to access requested information before that information is returned. These controls are applied against the authenticated user's company and the permissions they have been granted within QPD.

Complex operational requests may be processed through QPD's Cloudflare-based application services. These services do not independently determine a user's identity or permissions.

Authenticated requests are passed to QPD's backend using the user's active session, where the user is resolved and the applicable access controls are enforced before data can be read or changed.

This approach applies across QPD's operational data, including CRM records, opportunities, quotes, projects, resources, manufacturing information and other customer records.

5. Authentication and access

Access to QPD requires authenticated user access.

QPD uses session-based authentication for requests between the application, its operational services and the QPD backend. Requests requiring authenticated access must include a valid user session before they can proceed to protected backend operations.

The QPD backend resolves the authenticated user from that session and applies the relevant company and user permissions before accepting or rejecting the requested operation.

User sessions are refreshed as part of the authentication process and invalidated when the user logs out.

Administrative access to customer information by QPD personnel is restricted to authorised purposes such as implementation, support, maintenance, security and data recovery.

6. Per-company backup and recovery

QPD uses a per-company backup and recovery approach designed specifically for a multi-customer environment.

Every company's data is backed up on a regular schedule, preserving both individual records and the relationships between them — for example, how a quote line connects to its quote, a task to its project, or an assignment to its resource.

If customer data needs to be recovered following an accidental deletion, problematic import or other data issue, QPD can restore the affected company's data from an appropriate backup while rebuilding the relationships between recovered records.

Recoveries are staged and validated before being applied to the live environment, helping ensure restored data is complete and internally consistent before it is returned to use.

7. Third-party services and subprocessors

QPD uses carefully selected technology providers to operate and deliver the service.

These include providers supporting areas such as application infrastructure, cloud hosting, network services and optional integrations.

Where a third party processes personal data as part of providing QPD, appropriate contractual and data protection arrangements are maintained.

Customers can contact QPD for further information about the subprocessors relevant to the services they use.

8. Microsoft and Google integrations

Where customers choose to connect supported Microsoft or Google services, authentication is handled using established OAuth authentication mechanisms.

Users authenticate with the relevant external provider rather than providing their Microsoft or Google password to QPD. QPD receives the permissions and tokens required to provide the authorised integration.

Access granted to connected services can be revoked through the relevant provider.

9. Data ownership

Customer data remains the customer's data.

QPD does not acquire ownership of the business information customers enter into the platform.

Customers remain responsible for determining what personal data they process through QPD, the lawful basis for that processing and their own responsibilities as data controller.

10. Data access, export and deletion

QPD provides mechanisms for customer data to be exported from the platform.

When a QPD subscription ends, customer data is handled in accordance with the applicable contractual retention and deletion arrangements, with customers provided an appropriate opportunity to export their data before final deletion.

Backup copies may remain for a limited period as part of QPD's normal backup and recovery processes before being removed in accordance with the applicable retention schedule.

11. Data subject rights

Individuals have rights relating to their personal data under applicable data protection legislation.

Where QPD holds personal data on behalf of a customer, the customer remains responsible for responding to requests from individuals as the data controller.

QPD will provide reasonable assistance where required to help customers respond to valid requests relating to personal data processed through the platform.

12. Security and data incidents

QPD maintains procedures for identifying, investigating and responding to security and personal data incidents.

If QPD becomes aware of a personal data breach affecting information processed on behalf of a customer, the affected customer will be notified without undue delay and provided with relevant information to help them meet their own obligations under applicable data protection law.

13. Data Processing Agreement

Where QPD processes personal data on behalf of a customer, the processing relationship is governed by appropriate data processing terms.

These cover matters including processing instructions, confidentiality, security, subprocessors, assistance with data subject rights, incident management and the return or deletion of customer personal data.

A copy of QPD's Data Processing Agreement is available to customers as part of the contracting process.

14. Contacting QPD

Questions about QPD's security, infrastructure or data protection arrangements can be directed to:

QPD

Email: rob.shropshire@qpdcloud.com

Customers carrying out supplier due diligence or security reviews can also contact us for further information about our technical and organisational measures.

HAVE A QUESTION?

Looking for more information about QPD?

Find answers about the platform, implementation, integrations, pricing and how QPD works.

View frequently asked questions