Qualsis Data Processing Addendum
Version: 1.0.0
1. About this Addendum
This Data Processing Addendum (the "DPA" or "Addendum") forms part of the Qualsis Terms of Service available at https://qualsis.com/legal/terms (the "Terms") between Qualsis, LLC ("Qualsis") and the Customer organization that has accepted the Terms ("Customer"). It applies to Qualsis's processing of personal data on behalf of Customer in connection with the Services (as defined in the Terms).
This DPA is automatically incorporated into the Terms by reference. Acceptance of the Terms constitutes acceptance of this DPA without separate signature, except where Customer's applicable law requires a separately signed version (in which case, Customer may request a counterpart copy at Contact Privacy).
In the event of any conflict between this DPA and the Terms with respect to the processing of personal data, this DPA controls. Capitalized terms used but not defined in this DPA have the meanings given in the Terms or in applicable Data Protection Laws.
2. Definitions
For purposes of this DPA:
- "Applicable Data Protection Laws" means all laws and regulations applicable to the processing of personal data under the Terms, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the United Kingdom General Data Protection Regulation and the UK Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively "CCPA"), other US state privacy laws including the Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, and similar state, federal, or foreign laws as they apply to the processing.
- "Authorized Personnel" means Qualsis employees, contractors, and agents authorized to process Customer Personal Data under this DPA.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Special Categories of Personal Data," "Supervisory Authority," and similar terms have the meanings given in the GDPR or, for personal data subject to a different Applicable Data Protection Law, the meanings given in that law. Where the equivalent role in a non-GDPR jurisdiction (for example, "Business" and "Service Provider" under CCPA) has a different name, this DPA treats those terms as equivalents to the extent the underlying obligations are functionally the same.
- "Customer Personal Data" means personal data contained in Customer Data (as defined in the Terms) that Qualsis processes on behalf of Customer in providing the Services. Customer Personal Data does not include data Qualsis collects from Customer's authorized administrators in connection with the Customer's account (which is covered by the Privacy Policy and Qualsis's role as Controller of that data).
- "Personal Data Breach" has the meaning given in Article 4(12) of the GDPR (or the equivalent definition in another Applicable Data Protection Law): a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the Standard Contractual Clauses approved by the European Commission in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries pursuant to the GDPR, as those clauses may be updated, amended, or superseded by the European Commission.
- "UK IDTA" means the United Kingdom's International Data Transfer Agreement, issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, or the UK Addendum to the SCCs, as applicable.
- "Subprocessor" means a third party engaged by Qualsis to process Customer Personal Data on Qualsis's behalf in providing the Services.
3. Scope, Roles, and Term
3.1. Roles
For Customer Personal Data:
- Customer is the Controller (or, where Customer is itself a Processor for its own customers, Customer is the Controller for purposes of this DPA between Qualsis and Customer; the upstream controller-processor relationship between Customer and its own customers is outside the scope of this DPA except where Qualsis acts as a Sub-Processor pursuant to Section 3.2 below).
- Qualsis is the Processor.
For CCPA-covered Personal Data:
- Customer is the Business (or another applicable CCPA role).
- Qualsis is the Service Provider (or, where applicable, a Contractor).
3.2. Sub-Processor capacity
Where Customer is itself a Processor of personal data for one or more of Customer's own customers, controllers, or other upstream parties, Qualsis acts as a Sub-Processor to Customer under this DPA, and Customer represents and warrants that it has obtained the authorizations required by Customer's upstream agreements to engage Qualsis in that capacity. Qualsis's obligations to Customer as a Sub-Processor are no greater than its obligations as a Processor under this DPA.
Customer declares the role in which it uses the Services (Controller, or Processor acting for upstream parties) in its account configuration or in an Order Form; absent a declaration, Customer is deemed to act, and to have warranted that it acts, as Controller of the Customer Personal Data. Where Customer has declared the Processor role and Qualsis accordingly acts as a Sub-Processor under this Section 3.2, Customer will: (a) maintain a current record of the upstream controllers on whose behalf Customer engages Qualsis and make that record promptly available to Qualsis on Qualsis's request, including where Qualsis requires it to comply with Applicable Data Protection Laws or the Standard Contractual Clauses; (b) warrant that its processing instructions to Qualsis reflect the instructions of Customer's upstream controller(s); and (c) notify Qualsis without undue delay if the role in which Customer uses the Services changes (Controller to Processor or the reverse), because that role selects the applicable SCC module under Section 8.2.
3.3. Term
This DPA applies for as long as Qualsis processes Customer Personal Data in connection with the Services, including any retention period after termination of the Customer's subscription as described in Section 12.
3.4. Customer responsibility for instructions
Customer is responsible for the lawfulness of Customer Personal Data and the lawfulness of its instructions to Qualsis, including ensuring that Customer has obtained all necessary consents, notices, and lawful bases from Data Subjects under Applicable Data Protection Laws before transmitting Customer Personal Data to Qualsis.
4. Processing on Customer's Instructions
4.1. Documented instructions
Qualsis will process Customer Personal Data only on Customer's documented instructions. Customer's documented instructions consist of: (a) the Terms and this DPA, (b) the configuration of Customer's account and the integrations Customer enables in the Services, (c) Customer's lawful written instructions issued from time to time, and (d) any other written instructions that the parties agree in writing constitute documented instructions.
4.2. Compliance with law
Qualsis will not process Customer Personal Data in a manner that violates Applicable Data Protection Laws known to Qualsis as of the processing. If Qualsis is required to process Customer Personal Data in a manner that goes beyond Customer's instructions because of a legal obligation, Qualsis will inform Customer of that legal requirement before processing, unless prohibited by law on important grounds of public interest.
4.3. Notice if instructions infringe applicable law
If Qualsis reasonably believes that Customer's instructions violate Applicable Data Protection Laws, Qualsis will inform Customer in writing and may, after giving Customer reasonable opportunity to clarify or modify the instruction, decline to follow it.
4.4. No use for own purposes
Qualsis will not: (a) sell Customer Personal Data; (b) share or otherwise disclose Customer Personal Data with any third party for cross-context behavioral advertising or for any third party's own commercial purposes; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Qualsis and Customer or for any commercial purpose other than performing the Services and other purposes permitted by the Terms; or (d) combine Customer Personal Data with personal data that Qualsis receives from or on behalf of any other person, or collects from its own interaction with the Data Subject, except as expressly permitted by Applicable Data Protection Laws.
4.5. No training on Customer Personal Data without opt-in
Qualsis will not use Customer Personal Data to train any artificial intelligence or machine learning model that Qualsis develops or operates, and Qualsis will not authorize any of its Subprocessors (including providers of AI services) to use Customer Personal Data for such training, except where Customer has explicitly opted in to a feature that uses Customer Personal Data for that purpose. The opt-in is off by default, is granular (specific model, specific feature, specific data category), and may be withdrawn by Customer at any time.
4.6. De-identified and aggregated data
Notwithstanding Section 4.4, Qualsis may use information derived from Customer Personal Data after it has been de-identified or aggregated so that it is not reasonably capable of being associated with or linked to Customer or an identifiable individual, taking into account means reasonably likely to be used (consistent with GDPR Recital 26 for personal data subject to GDPR or UK GDPR; with the CCPA de-identification standard for personal data subject to CCPA; and with comparable standards under other Applicable Data Protection Laws) to operate, secure, and improve the Services, generate aggregated benchmarks, and conduct research. De-identified data is not Customer Personal Data while it remains de-identified to that standard. Qualsis will maintain measures designed to prevent re-identification and will not attempt to re-identify de-identified data except where necessary to test or verify the effectiveness of the de-identification process.
5. Personnel
5.1. Authorized Personnel only
Qualsis will limit access to Customer Personal Data to Authorized Personnel who need access to perform Qualsis's obligations under the Terms and who have agreed in writing (in employment, contractor, or comparable agreements) to confidentiality obligations that survive the end of the relevant relationship.
5.2. Training
Qualsis will provide its Authorized Personnel with appropriate training on data protection and information security, including the requirements of this DPA, before granting them access to Customer Personal Data and at regular intervals thereafter.
5.3. Accountable individual
Qualsis will appoint an internal individual or function responsible for compliance with this DPA and applicable data protection requirements. As of the effective date, this individual is the Qualsis founder; as Qualsis grows, this responsibility may be transferred to a dedicated data protection officer or equivalent and Customer will be notified of the change.
6. Security of Processing
6.1. Security measures
Qualsis will implement and maintain the technical and organisational measures described in Annex II ("TOMs") to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of Data Subjects.
6.2. Updates to TOMs
Qualsis may update the TOMs from time to time to maintain or improve their effectiveness. Any change will not materially reduce the overall level of protection. Qualsis will publish material updates at https://qualsis.com/legal/trust/dpa.
6.3. Certifications and attestations
Qualsis is committed to obtaining and maintaining SOC 2 Type II attestation within twelve (12) months of the general availability of the affected Services. Until that attestation is achieved, Qualsis maintains documented internal information security practices summarized at https://qualsis.com/legal/trust/security, and will provide a copy of its security overview, security questionnaire response, or other reasonable security documentation on request from a Customer with a legitimate need.
7. Subprocessors
7.1. General authorization
Customer hereby provides general authorization for Qualsis to engage Subprocessors to process Customer Personal Data in connection with the Services, subject to the conditions of this Section 7. The list of current Subprocessors is maintained at https://qualsis.com/legal/trust/subprocessors.
As of the effective date, Qualsis's Subprocessors for Customer Personal Data include:
- Amazon Web Services, Inc. (United States; where Qualsis makes an EU region option generally available and Customer selects it, EU regional placement will apply per that selection): hosting, computing, storage, networking, and backup, including the Amazon Bedrock foundation-model service that runs the Services' AI features. The third-party foundation models used in the Services (Anthropic Claude and Cohere Embed) are operated entirely on AWS infrastructure; under the Amazon Bedrock service design, and on Qualsis's current approved Amazon Bedrock deployment channel and approved models, the model providers have no access to prompts, outputs, or logs from Qualsis's use of the models, model inputs and outputs are not used to train the models, and the model providers are therefore not Subprocessors
- Databricks, Inc. (operating on AWS infrastructure): data analytics and machine-learning pipelines
7.2. Subprocessor obligations
Qualsis will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those in this DPA, including (where applicable) the relevant Standard Contractual Clauses for the transfer of Customer Personal Data outside the European Economic Area or United Kingdom.
7.3. Notice of new Subprocessors
Qualsis will notify Customer at least thirty (30) days in advance before engaging a new Subprocessor or replacing an existing one in connection with the processing of Customer Personal Data. Notification will be made by updating the Subprocessor list at https://qualsis.com/legal/trust/subprocessors and either (a) sending email notice to Customer's designated administrator contact address, or (b) posting a notice in the Services.
7.4. Right to object
Customer may object in writing to the engagement of a new Subprocessor on reasonable data protection grounds within thirty (30) days of notice. If Customer objects, the parties will discuss the objection in good faith. If Qualsis cannot accommodate the objection in a manner reasonably acceptable to Customer, Customer may terminate the affected Services as Customer's sole and exclusive remedy by giving Qualsis thirty (30) days' written notice of termination. In that event, Qualsis will refund pre-paid fees for the unused portion of the term covering the affected Services. If Customer does not object within the thirty-day window, Customer is deemed to have approved the new Subprocessor.
7.5. Liability for Subprocessors
Qualsis remains liable to Customer for the acts and omissions of its Subprocessors with respect to Customer Personal Data, to the same extent Qualsis would be liable if it performed the relevant processing itself, subject to the limitation of liability in the Terms and in Section 14 below.
8. International Data Transfers
8.1. Transfer mechanism
Where the processing of Customer Personal Data under this DPA involves the transfer of Customer Personal Data from a jurisdiction with cross-border transfer restrictions (including the European Economic Area, the United Kingdom, Switzerland, and other jurisdictions) to a jurisdiction not deemed adequate by the relevant authority, the parties rely on the following transfer mechanisms:
- For transfers from the EEA: the Standard Contractual Clauses (Module Two: Controller to Processor, or Module Three: Processor to Processor where Customer is itself a Processor per Section 3.2) are incorporated by reference, as further described in Section 8.2.
- For transfers from the United Kingdom: the UK Addendum to the SCCs (or, where the parties agree in writing, the standalone UK IDTA) is incorporated by reference, as further described in Section 8.3.
- For transfers from Switzerland: the SCCs apply with modifications for the Federal Data Protection Act of Switzerland (the "Swiss FADP"), including references to the Swiss FDPIC as the supervisory authority where applicable, as further described in Section 8.6.
- Adequacy decisions: where the recipient country has been deemed by the European Commission or the United Kingdom government to provide an adequate level of data protection, the parties rely on that adequacy decision.
8.2. EU Standard Contractual Clauses (Modules Two and Three)
The SCCs are deemed entered into by Customer (as data exporter) and Qualsis (as data importer) on the effective date of this DPA, with the following completions. Module Two (Controller to Processor) applies where Customer acts as Controller of the Customer Personal Data; Module Three (Processor to Processor) applies where Customer is itself a Processor acting on behalf of upstream controllers and has warranted that role under Section 3.2. The applicable module is selected by the role Customer has warranted, and only one module applies to any given transfer:
- Clause 7 (Docking clause): Not applicable in the initial transfer; may be invoked for subsequent additions of third parties as exporters or importers.
- Clause 9 (Use of sub-processors): Option 2 (general written authorization) applies. The list of Subprocessors and the procedure for notice and objection are described in Section 7 of this DPA.
- Clause 11 (Redress): The optional independent dispute resolution mechanism is not included.
- Clause 17 (Governing law): The SCCs are governed by the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction): Disputes under the SCCs will be resolved in the courts of Ireland.
- Annex I.A (List of Parties): Customer is the data exporter; Qualsis is the data importer. Under Module Three, Customer acts as processor on behalf of its upstream controller(s) and Qualsis acts as its sub-processor; the upstream-controller record obligation in Section 3.2 applies. The parties' contact details are as set out in the Terms and at https://qualsis.com/legal/privacy Section 19.
- Annex I.B (Description of transfer): As set out in Annex I of this DPA.
- Annex I.C (Competent supervisory authority): The supervisory authority of the EEA Member State in which the data exporter is established. If the data exporter is not established in the EEA but has appointed an EU representative, the supervisory authority of the EEA Member State in which the representative is established. Otherwise, the supervisory authority of any EEA Member State in which the affected Data Subjects whose Customer Personal Data is transferred under the SCCs are located.
- Annex II (TOMs): As set out in Annex II of this DPA.
- Annex III (List of Sub-processors): Maintained at https://qualsis.com/legal/trust/subprocessors.
To the extent of any conflict between the SCCs and this DPA or the Terms, the SCCs control with respect to the data protection matters they address.
8.3. UK transfers
For transfers of Customer Personal Data from the United Kingdom to a country not deemed adequate by the UK Secretary of State, the parties enter into the UK Addendum to the SCCs (the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office). The UK Addendum applies by default. The parties may instead agree in writing to use the standalone UK IDTA. Unless the parties agree otherwise in writing, the current ICO Approved Addendum B.1.0 applies, including its Section 18 revision mechanism.
The UK Addendum's Part 1 tables are completed as follows:
- Table 1 (Parties and key contacts): as set out in Annex I of this DPA.
- Table 2 (Addendum EU SCCs): the SCCs as incorporated in Section 8.2 of this DPA, with the module and completions selected there.
- Table 3 (Appendix Information): Annexes I, II, and III of this DPA.
- Table 4 (Ending this Addendum when the Approved Addendum changes): both Importer and Exporter may end this Addendum as set out in Section 19 of the Addendum.
8.4. Transfer impact assessment
Before commencing transfers of Customer Personal Data from the EEA, the United Kingdom, or Switzerland under this DPA, Qualsis conducts, and thereafter maintains, a transfer impact assessment for those transfers to the United States (where Qualsis's primary processing infrastructure is located; where Qualsis makes a regional deployment option generally available under Section 3.3 of the Terms and Customer selects a different region, the location of primary processing for that Customer will follow the selection). The assessment considers the laws and practices of the country of destination, supplementary technical and organizational measures, and the contractual safeguards in this DPA. A summary of the then-current assessment is available to Customer on request.
8.5. Government access requests
If Qualsis receives a legally binding request from a public authority for access to Customer Personal Data, Qualsis will: (a) where lawful and not prohibited from doing so, promptly notify Customer of the request and consult with Customer before responding; (b) challenge the request where there are reasonable grounds to do so; (c) provide only the minimum necessary information; and (d) maintain documentation of all such requests sufficient to demonstrate compliance with Article 28(3) GDPR and the SCCs. Qualsis publishes aggregate transparency information about government access requests at https://qualsis.com/legal/trust/incidents (when available; this transparency function will be built before the first material government request is received).
8.6. Swiss transfers
For transfers of Customer Personal Data subject to the Swiss FADP, the SCCs as incorporated in Section 8.2 apply with the following modifications: (a) references in the SCCs to the GDPR are read as references to the Swiss FADP insofar as the transfer is subject to the Swiss FADP; (b) the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority for transfers subject to the Swiss FADP; (c) Data Subjects in Switzerland are entitled to enforce their rights in Switzerland, and the place of habitual residence for purposes of Clause 18(c) of the SCCs includes Switzerland; and (d) references in the SCCs to a "Member State" are not read so as to exclude Data Subjects in Switzerland from enforcing those rights.
9. Assistance with Data Subject Rights
9.1. Cooperation
Qualsis will, taking into account the nature of the processing, assist Customer through appropriate technical and organisational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Laws. This includes rights of access, rectification, erasure, restriction of processing, portability, objection, withdrawal of consent, and the right to opt out of automated decision-making.
9.2. Direct Data Subject requests
If Qualsis receives a request from a Data Subject relating to Customer Personal Data, Qualsis will: (a) not respond to the request on the substance (other than to acknowledge receipt and direct the Data Subject to the Customer where appropriate), (b) promptly notify Customer, and (c) provide reasonable assistance to Customer in responding.
9.3. Self-service tools
Where Qualsis provides self-service tools in the Services that enable Customer to fulfill Data Subject requests directly (for example, deletion or export of an individual user's data), Qualsis's obligation under this Section 9 is satisfied to the extent of those self-service tools.
9.4. Costs
Qualsis may charge reasonable costs for assistance with Data Subject requests that go beyond Qualsis's standard self-service tools or that involve unusual scope, except where prohibited by Applicable Data Protection Laws.
10. Personal Data Breach Notification
10.1. Notification timing
Qualsis will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay after Qualsis becomes aware of it. Qualsis's target timing for initial notification is twenty-four (24) hours from Qualsis's confirmed awareness of the Personal Data Breach. Initial notification may be preliminary; Qualsis will supplement and update the notification as the investigation progresses.
10.2. Content of notification
To the extent the information is reasonably available to Qualsis at the time and to the extent it can be lawfully shared, the notification will describe: (a) the nature of the Personal Data Breach, including categories and approximate numbers of Data Subjects and Customer Personal Data records concerned; (b) the likely consequences of the Personal Data Breach; (c) the measures Qualsis has taken or proposes to take to address the Personal Data Breach, including (where appropriate) measures to mitigate its possible adverse effects; and (d) the name and contact details of Qualsis's responsible person for the breach response. Where information is unavailable at the time of the initial notification, Qualsis will provide it in updates as soon as reasonably practicable.
10.3. Cooperation
Qualsis will reasonably cooperate with Customer in Customer's investigation, mitigation, regulatory notification, and Data Subject notification activities in connection with the Personal Data Breach. This includes providing Customer with such information and assistance as Customer reasonably requires to comply with its own notification obligations.
10.4. Documentation
Qualsis will maintain records of Personal Data Breaches affecting Customer Personal Data sufficient to demonstrate compliance with Article 33(5) GDPR and equivalent provisions under other Applicable Data Protection Laws.
10.5. No admission of liability
Qualsis's notification of a Personal Data Breach is not an admission of liability or fault.
11. Audits and Inspections
11.1. Demonstration of compliance
Qualsis will make available to Customer information reasonably necessary to demonstrate compliance with the obligations in this DPA. This information includes: (a) Qualsis's then-current SOC 2 Type II report (when available; otherwise, Qualsis's then-current security overview at https://qualsis.com/legal/trust/security), (b) Qualsis's then-current Subprocessor list, (c) Qualsis's then-current Annex II TOMs, and (d) Qualsis's responses to Customer's reasonable written security questionnaires consistent with industry standard practices.
11.2. Audit rights
Customer (or a mutually agreed independent third-party auditor bound by appropriate confidentiality obligations) has the right to audit Qualsis's compliance with this DPA, subject to the following:
- Audits may be conducted no more than once per twelve-month period, except where additional audits are required to investigate a specific Personal Data Breach affecting Customer Personal Data, or where required by a Supervisory Authority.
- Customer must give Qualsis at least sixty (60) days' prior written notice of an audit (except in the case of a Personal Data Breach investigation or Supervisory Authority requirement, in which case shorter notice is acceptable).
- Audits will be conducted during regular business hours, will be limited in scope to what is reasonably necessary to verify Qualsis's compliance with this DPA, and will not unreasonably interfere with Qualsis's normal business operations.
- The default form of audit is a virtual audit (review of documentation, interviews with Qualsis personnel via video conference, evaluation of policies and procedures, and walkthroughs of relevant controls). On-site audits at Qualsis's facilities may be requested where a virtual audit is reasonably insufficient to verify compliance for a specific matter, subject to mutual scheduling and reasonable security and confidentiality protocols.
- Customer pays its own audit costs. Qualsis will not charge for the cost of its personnel's time spent supporting a virtual audit conducted within reasonable scope. Qualsis may charge for reasonable cost of its personnel and any third parties supporting on-site audits or audits that exceed reasonable scope.
11.3. SOC 2 alternative
In lieu of conducting an audit, Customer may accept Qualsis's then-current SOC 2 Type II report (once available) as evidence of compliance with the security and operational portions of this DPA. Qualsis will provide its SOC 2 report to Customer on request, subject to the confidentiality obligations in the Terms.
11.4. Supervisory Authority audits
If a Supervisory Authority requires an audit or inspection of Qualsis's processing of Customer Personal Data, Qualsis will reasonably cooperate with the Supervisory Authority, will give Customer prompt notice to the extent permitted, and will provide Customer with copies of any final reports issued by the Supervisory Authority to the extent they relate to Customer Personal Data.
12. Return or Deletion of Customer Personal Data
12.1. On termination
Upon termination of the Customer's subscription, or earlier upon Customer's written instruction, Qualsis will delete Customer Personal Data from active production systems within sixty (60) days of termination or earlier instruction. On request, Qualsis will certify completion of deletion from active production systems and identify any residual backup retention governed by Section 12.2. As an alternative to deletion, Customer may, by written request received before or within thirty (30) days after termination, instruct Qualsis to return Customer Personal Data in a structured, commonly used, machine-readable format. The return is in lieu of, not in addition to, deletion.
12.2. Retention of backups
Qualsis's backup systems may retain Customer Personal Data for a limited period after deletion from active production systems. Residual encrypted backup and versioned copies will expire through Qualsis's ordinary retention processes no later than ninety (90) days after production deletion and will not be restored to an active environment except as necessary for disaster recovery, correction of accidental corruption, loss, or erroneous deletion, or legal compliance. Any restoration containing Customer Personal Data previously deleted under Section 12.1 will remain isolated, and Qualsis will re-apply the completed deletion before the restored environment returns to service.
12.3. Retention for legal reasons
Qualsis may retain Customer Personal Data beyond the deletion windows in Sections 12.1 and 12.2 where, and only to the extent, required by Applicable Data Protection Laws or other applicable law (for example, retention of financial records required by US tax law). Qualsis will document any such retention, will identify the legal basis to Customer on request, and will continue to apply the security and confidentiality protections of this DPA to retained data.
12.4. De-identified data
Notwithstanding this Section 12, Qualsis may retain de-identified data derived from Customer Personal Data (consistent with Section 4.6) without restriction, because de-identified data is no longer Customer Personal Data.
12.5. Customer record-retention responsibility
Customer is responsible for determining and satisfying its legal record-retention obligations for Customer Data, including medical-record, billing, claims, laboratory, employment, tax, and other regulated records. Unless expressly stated in an Order Form, Business Associate Agreement, or applicable law, Qualsis is not a medical-record custodian and does not undertake to retain Customer Data for any legally required retention period after termination. Where Qualsis retains Customer Data, logs, or backups due to applicable law, legal hold, security, disaster recovery, or contractual obligation, Qualsis may retain such data in secure archival form only for so long as necessary and at a level of detail reasonably required to satisfy the applicable retention, audit, security, or legal purpose.
13. CCPA Service Provider Provisions
13.1. Service Provider role
To the extent Qualsis processes Personal Information (as defined in the CCPA) of California residents on behalf of Customer, Qualsis acts as a Service Provider (or, where applicable, a Contractor) to Customer (the Business). The specific business purpose for which Customer discloses Personal Information to Qualsis, and for which Qualsis processes it, is the provision of the Services described in the Terms and in Annex I of this DPA (hosting, storage, analysis, transmission, display, and security operations on Customer Data); Customer discloses Personal Information to Qualsis only for that limited and specified business purpose.
13.2. Service Provider commitments
Qualsis: (a) will not sell or share (as those terms are defined in the CCPA) any Personal Information received from Customer; (b) will not retain, use, or disclose Personal Information received from Customer outside the direct business relationship between Qualsis and Customer, for any purpose other than the business purpose specified in Section 13.1, or for any commercial purpose other than for providing the Services, in each case unless expressly permitted by the CCPA and its regulations; (c) will not combine Personal Information received from Customer with Personal Information received from or on behalf of any other person, or collected from its own interaction with the consumer, except as expressly permitted by the CCPA; (d) will comply with applicable Service Provider obligations under the CCPA, including Customer's reasonable directions for compliance; (e) will, with respect to the Personal Information received from Customer, provide the same level of privacy protection as is required of Customer by the CCPA and its regulations; and (f) will notify Customer after Qualsis makes a determination that it can no longer meet its obligations under the CCPA and its regulations.
13.3. CCPA Data Subject requests
Qualsis will reasonably assist Customer in responding to verifiable consumer requests under the CCPA (including rights to know, delete, correct, opt out of sale/share, and limit use and disclosure of sensitive personal information). Qualsis's obligations under Section 9 apply to CCPA consumer requests. Taking into account the nature of the processing and with respect to the Personal Information Qualsis processes on Customer's behalf, Qualsis will also provide reasonable assistance and information to Customer for Customer's cybersecurity audits (Article 9 of the CCPA regulations), risk assessments (Article 10), and automated decisionmaking technology compliance (Article 11), to the extent those obligations relate to Qualsis's processing.
13.4. CCPA certification
Qualsis certifies that it understands the restrictions of Section 13.2 and the CCPA's Service Provider obligations (and, where Qualsis acts as a Contractor, the Contractor obligations under Civil Code section 1798.140(j)), and will comply with them.
13.5. CCPA audit cooperation
Qualsis will comply with Customer's reasonable instructions for purposes of ensuring that Customer Personal Data is processed in compliance with the CCPA, and Qualsis will allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information, and to take the reasonable and appropriate steps contemplated by the CCPA regulations to ensure that Qualsis uses Personal Information consistently with Customer's CCPA obligations, including through the audit and demonstration-of-compliance rights in Section 11.
14. Other US State Privacy Laws
To the extent Qualsis processes personal data of residents of US states with comprehensive privacy laws other than California (including Virginia under the VCDPA, Colorado under the CPA, Connecticut under the CTDPA, Utah under the UCPA, Texas under the TDPSA, Oregon under the OCPA, and other states as their laws come into effect), Qualsis acts in the equivalent processor role under each such law. The commitments in this DPA are intended to satisfy the requirements applicable to processors under each such state law. Where a specific state law imposes a requirement on Qualsis as processor that is not expressly addressed elsewhere in this DPA, Qualsis will comply with that requirement to the extent applicable to Qualsis's role and processing.
15. Liability
The liability of each party arising out of or relating to this DPA is governed by the limitation of liability provisions of the Terms. The carveout for personal data incidents in Section 13.2 of the Terms (cap at two times the fees paid or payable by Customer in the twelve months preceding the event giving rise to the liability, as a separate carveout from the standard cap) applies to claims under this DPA.
For the avoidance of doubt, the limitations and exclusions of liability in the Terms apply to this DPA except where: (a) a different result is required by Applicable Data Protection Laws (in which case the Terms' limitations apply to the maximum extent permitted), (b) Qualsis's gross negligence or willful misconduct caused the loss, or (c) the loss is the subject of an indemnification obligation under the Terms.
16. Order of Precedence
In the event of conflict between documents governing the parties' relationship, precedence is determined by the subject matter of the conflict:
- For data protection matters: the Standard Contractual Clauses, the UK IDTA / UK Addendum, and equivalent transfer instruments prevail over this DPA (with respect only to the data protection matters they address), and this DPA prevails over all other documents governing the parties' relationship (including the Terms, any Order, and the Acceptable Use Policy).
- For all other matters: the Order prevails over the Terms, and the Terms prevail over the Acceptable Use Policy, as set out in Section 16.1 of the Terms.
17. General
17.1. Notices
Notices required or permitted under this DPA will be sent in the manner described in the Terms' notices section. Notices specifically regarding data protection matters may also be sent to Privacy Request.
17.2. Modifications
Qualsis may update this DPA in response to changes in Applicable Data Protection Laws, regulatory guidance, or the structure of the Services. Material changes will be communicated to Customer with at least thirty (30) days' notice (or such longer period as required by Applicable Data Protection Laws). If Customer does not agree to a material change, Customer may terminate the affected Services as Customer's sole and exclusive remedy by giving notice within the notice period.
17.3. Severability
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in effect.
17.4. Governing law
This DPA is governed by the law specified in the Terms for the Customer's region, except where the SCCs, UK IDTA, or other transfer instruments specify a different governing law for matters they cover.
Annex I: Description of Processing
Part A: List of the Parties
Data Exporter (Controller, or Processor acting on behalf of upstream controllers under Module Three per Section 8.2):
Customer, the organization that has accepted the Terms.
- Contact: as specified in the Customer's account
- Activities relevant to the data transferred under this DPA: as specified in Annex I.B
Data Importer (Processor, or Sub-processor under Module Three):
Qualsis, LLC
3540 Toringdon Way, Suite 200
Charlotte, NC 28277, United States
- Contact: Privacy Request
- Activities relevant to the data transferred under this DPA: providing the Services described in the Terms
Part B: Description of Transfer
- Categories of Data Subjects: the Customer's employees, contractors, agents, contacts, customers, vendors, prospects, and other individuals whose Personal Data is included in Customer Data
- Categories of Personal Data:
- Identification and contact data (names, email addresses, phone numbers, postal addresses, employer / role / title information)
- Operational data (financial, transactional, performance, capacity, scheduling, and other business-operational data that may include personal data of the categories of Data Subjects above)
- Authentication data (login identifiers, password hashes, multi-factor authentication tokens)
- Usage and telemetry data (interaction logs, IP addresses, device identifiers)
- Communications data (the content of communications between Customer's personnel and Customer's contacts processed through the Services)
- Any other categories of personal data Customer chooses to upload to or generate through the Services
- Special Categories of Personal Data: none expected by default. Customer is responsible for not uploading Special Categories of Personal Data (including, without limitation, health data, biometric data, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation, criminal convictions or offenses, and data of children under the applicable age threshold) except where expressly permitted under the Customer's subscription plan and accompanied by all necessary lawful bases and additional safeguards Customer is required by Applicable Data Protection Laws to provide.
- Frequency of transfer: continuous, for as long as the Customer's subscription is active
- Nature of the processing: all processing activities necessary to provide the Services, including hosting, storage, analysis, transmission, display, and security operations
- Purpose of the processing: delivery of the Services in accordance with the Terms
- Duration of processing: for the term of the Customer's subscription, plus the retention windows in Section 12 of this DPA
Part C: Competent Supervisory Authority
For transfers under the SCCs from the European Economic Area: as set out in Section 8.2 of this DPA.
For Customer Personal Data of UK residents: the United Kingdom Information Commissioner's Office.
Annex II: Technical and Organisational Measures
The following technical and organisational measures apply to the processing of Customer Personal Data by Qualsis. These measures may be updated from time to time consistent with Section 6.2 of this DPA; the then-current version is published at https://qualsis.com/legal/trust/dpa.
1. Pseudonymisation and encryption
- All Customer Personal Data is encrypted at rest using AES-256 or equivalent.
- Traffic between external clients and the load-balancer layer is encrypted in transit using TLS. Traffic between the load balancer and application services traverses private, access-controlled subnets and is not currently re-encrypted at the service layer. TLS termination is enforced at the CloudFront / load-balancer layer and Aurora PostgreSQL is configured to require SSL connections.
- Authentication for Qualsis Customer admin accounts is managed via AWS Cognito User Pools. Passwords are never stored in plaintext at any layer; Cognito handles password hashing and verification using industry-standard algorithms, and the underlying PostgreSQL password layer (for database service accounts) uses SCRAM-SHA-256.
- Customer-managed encryption keys are segmented by security domain, including infrastructure, platform, authentication-token signing, analytics pipelines, and per-tenant object storage. Some CloudWatch log streams use AWS service-managed encryption.
2. Confidentiality, integrity, availability, resilience
- Confidentiality: Customer Personal Data is logically segregated by Customer tenancy in shared infrastructure. Multi-tenant isolation is enforced in depth: (a) application-layer scoping requires every repository call to provide an authenticated or system service-account Customer tenant context; (b) the database layer enforces PostgreSQL Row-Level Security (RLS) policies that scope every query to the requesting Customer's tenancy regardless of application logic; and (c) RLS policy effectiveness is validated in continuous integration tests that execute as a non-superuser database account, so RLS bypass cannot occur at the test layer. This is defense-in-depth, not a single control.
- Integrity: application-layer controls validate data format and origin (typed schema validation via Zod at every input-bearing API boundary); database integrity is enforced through transactional controls and parameterized queries (Kysely); audit fields are recorded on every write through the repository pattern.
- Availability: the Services are designed for high availability using AWS managed services (Aurora Serverless v2, multi-AZ deployment, AWS-managed scaling). The Qualsis Service Level Schedule at https://qualsis.com/legal/trust/sla applies only where the Customer's Order Form or subscription tier expressly incorporates it; where incorporated, the applicable targets, measurement methodology, exclusions, and credits are set out in that Schedule.
- Resilience: infrastructure is configured for automatic failover within an AWS region and across availability zones; Aurora Serverless v2 provides continuous transaction-log replication and automated point-in-time recovery; backups are stored in the same legal block as the primary processing region (today, US-to-US; upon general availability of Qualsis's EU region option and where Customer selects it, backups for EU deployments will be stored within the EU/EEA or in a jurisdiction subject to an EU adequacy decision).
3. Ability to restore availability
- Backup frequency: at least daily for primary databases; continuous for transaction logs.
- Restoration testing: documented restoration testing is performed at least annually; results are reviewed by Qualsis's accountable individual and incorporated into incident-response runbooks.
- Disaster recovery: documented disaster recovery procedures address the recovery time objective and recovery point objective for the Services; specific objectives are documented in Qualsis's business continuity and disaster recovery documentation and made available to Customer on request.
4. Regular testing of effectiveness
- Continuous threat detection. AWS GuardDuty monitors the AWS account hosting the Services for malicious activity and unauthorized behavior; AWS Security Hub aggregates and prioritizes security findings across AWS services; VPC Flow Logs capture network-layer activity in KMS-encrypted storage for retrospective analysis.
- Continuous vulnerability assessment. Application dependencies are scanned on every change in continuous integration (pnpm audit at high severity threshold, advisory); ESLint architectural rules (layer-boundary discipline and import hygiene) run on every change; secret detection (Gitleaks) runs on every change to detect accidental credential disclosure.
- Periodic external testing. Qualsis engages qualified third parties for external security testing (including penetration testing) on at least an annual cadence beginning with the first SOC 2 Type II audit cycle. Results are retained for audit purposes and material findings are remediated under documented timelines aligned with severity.
- Alerting and triage. Monitoring and logging systems generate alerts on anomalies; alerts route to the on-call accountable individual per the Qualsis Incident Response Plan; triage follows the severity classification (P0-P3) defined in the Plan and aligned with the Service Level Schedule.
5. Access controls
- Least privilege: access to Customer Personal Data is granted to Authorized Personnel only on the principle of least privilege.
- Authentication: Qualsis Authorized Personnel access internal systems using multi-factor authentication where supported by the system.
- Access review: access rights are reviewed at least quarterly; departing personnel have access revoked promptly.
- Privileged access: administrative and elevated-privilege access is logged, and requires additional approval once Qualsis has more than one Authorized Personnel.
6. Application security
- Secure SDLC. The Services are developed under a pull-request-based workflow in which automated checks run on every pull request and merge: linting (ESLint, with Biome for formatting), formatting verification, type checking (TypeScript strict), automated test suites including tenant-isolation tests that execute against a real PostgreSQL database as a non-superuser account so that RLS bypass at the test layer is not possible, build verification, and dependency vulnerability scanning. Continuous integration uses pinned GitHub Action commit SHAs (not movable version tags) to prevent supply-chain attacks from action authors.
- Static analysis. ESLint rules enforce architectural patterns at lint time, including layer-boundary discipline and import hygiene; findings fail the continuous-integration checks that run on every pull request. Tenant isolation is enforced at the database layer (Row-Level Security) and validated by the non-superuser test suite described above.
- Dependency management. Third-party libraries and dependencies are tracked via the package manager; vulnerability scanning runs in CI to flag high-severity vulnerabilities; automated dependency updates currently cover the continuous-integration workflow ecosystem. Vulnerabilities are remediated on timelines consistent with their severity.
- Secret detection. Secret-leak detection runs in CI on every change to detect credentials accidentally committed to the repository.
- Application defenses. The Services apply layered defenses against common application attacks: AWS WAF at the CloudFront edge, with regional WAF on directly-exposed regional endpoints; parameterized queries (Kysely query builder) prevent SQL injection; Zod schema validation at every input-bearing API boundary prevents malformed-input attacks; React's contextual escaping and security headers including a Content-Security-Policy mitigate cross-site scripting (hardening to a nonce-based policy is planned); CSRF token validation on state-changing endpoints; per-request rate limiting; PostgreSQL Row-Level Security as a final defense against cross-tenant data access even if application logic has a bug; per-request structured audit logging with automatic PII redaction.
- Infrastructure-as-code. All infrastructure is defined in Terraform / Terragrunt under version control; infrastructure changes follow the same pull-request review process as application code.
7. Personnel security
- Qualsis Authorized Personnel are subject to written confidentiality obligations.
- Qualsis conducts background checks on Authorized Personnel to the extent permitted by applicable law and consistent with the sensitivity of the role.
- Qualsis provides initial and recurring training on data protection and information security.
8. Physical security
- Customer Personal Data is processed in AWS data centers, which are physically secured by AWS in accordance with AWS's published physical security controls.
- Qualsis offices (if any) have physical access controls appropriate to the sensitivity of the work conducted in them.
9. Subprocessor management
- Qualsis maintains a Subprocessor inventory published at https://qualsis.com/legal/trust/subprocessors, including the categories of Customer Personal Data each Subprocessor processes, the locations of processing, and any cross-border transfer mechanism applicable to the relationship.
- For the current Subprocessor roster, Qualsis completed a documented data-protection and security review on July 7, 2026. Before engaging a new Subprocessor, Qualsis reviews its data-processing terms, applicable assurance reports or documented assurance roadmap, AI data-use and training position where relevant, and applicable transfer mechanisms. Qualsis repeats this review at least annually and after material changes to the Subprocessor's services or terms.
- On Qualsis's current approved Amazon Bedrock deployment channel and approved models, AI model providers do not receive Customer Personal Data: the Services' AI features run on third-party foundation models (Anthropic Claude, Cohere Embed) operated through Amazon Bedrock within the AWS Subprocessor relationship, under AWS terms that do not permit customer content to be used to train models or to be accessed by the model providers. Any AI service provider engaged in the future to process Customer Personal Data directly will be engaged on enterprise-tier or API-tier agreements that contractually prohibit training on Customer inputs; consumer-tier terms of service are not approved for production processing of Customer Data by AI Subprocessors at any tier.
10. Event logging
- Authentication events, administrative actions, and security-relevant system events are logged.
- Logs are retained for a period appropriate to detection and investigation purposes (a minimum of twelve (12) months for production environments processing Customer Personal Data; the twelve-month minimum is a production-environment commitment and does not extend to non-production environments, which hold only scrubbed or synthetic data).
- Logs are protected against unauthorized modification and access.
11. Incident response
- Qualsis maintains a written Incident Response Plan covering preparation, detection and analysis, containment, eradication, recovery, and post-incident review, modeled on NIST SP 800-61. The Plan is reviewed at least annually and after any material incident.
- The Plan defines incident severity levels (P0 through P3) aligned with the Service Level Schedule, role responsibilities (Incident Commander, Investigation Lead, Communications Lead, Legal/Compliance Lead, Scribe, On-call) with a defined scale path as the team grows, and specific playbooks for common scenarios including suspected Customer Personal Data exposure, AWS account compromise, vendor incidents affecting Qualsis, lost or stolen personnel devices, ransomware, and bug bounty / coordinated disclosure handling.
- Qualsis conducts tabletop exercises at least annually against scenarios from the Plan to validate the Plan's effectiveness and surface gaps before a real incident occurs.
- Incidents involving Customer Personal Data are escalated promptly to the accountable individual identified in Section 5.3 of this DPA. Qualsis maintains a documented legal-escalation route and will seek qualified legal advice without undue delay for any P0 incident or P1 incident with a privacy or regulatory dimension.
- Post-incident reviews are conducted for all P0 and material P1 incidents within 5 business days of resolution; lessons learned are incorporated into the Incident Response Plan, the monitoring and detection infrastructure, the TOMs, and any related playbooks. Material incident records are retained for at least 6 years to satisfy HIPAA documentation retention requirements (45 CFR § 164.530(j)(2) and § 164.316(b)(2)(i)) for any Customer relationship where a Business Associate Agreement applies.
12. Data minimisation by design
- The Services are designed to collect only the Customer Personal Data necessary for the intended purpose.
- Automated processes anonymize or aggregate data where doing so is consistent with the purpose of the processing.
Annex III: List of Sub-processors
The current list of Sub-processors is published and maintained at https://qualsis.com/legal/trust/subprocessors.
As of the effective date of this DPA:
Sub-processor | Role | Location of processing |
|---|---|---|
Amazon Web Services, Inc. | Cloud infrastructure (hosting, storage, networking, backup), including the Amazon Bedrock foundation-model service that runs the Services' AI features | United States; where Qualsis makes an EU region option generally available and Customer selects it, EU regional placement will apply per that selection |
Databricks, Inc. | Analytics and machine-learning pipelines (operating on AWS infrastructure) | Same as AWS regional placement |
Model providers (not Sub-processors). The Services' AI features run on third-party foundation models built by Anthropic (Claude models) and Cohere (Embed models, used in document-processing and semantic-retrieval features). Qualsis runs these models exclusively through Amazon Bedrock, AWS's managed foundation-model service, under Qualsis's AWS agreements. Under the Amazon Bedrock service design, on Qualsis's current approved Amazon Bedrock deployment channel and approved models, the model providers have no access to the prompts, outputs, or logs from Qualsis's use of the models, and model inputs and outputs are not used to train the models. Because they receive no Customer Personal Data on this channel, Anthropic and Cohere are model providers, not Sub-processors; the operative Sub-processor for AI features is AWS. If a change to Qualsis's model arrangements would cause a model provider to receive or otherwise process Customer Personal Data on Qualsis's behalf, that provider would become a Sub-processor and would be added to this Annex and the published list through the notice procedure in Section 7.3 before the change takes effect.
Qualsis will update Annex III as Sub-processors are added or changed, with the notice procedure in Section 7.3.
Last updated: August 28, 2026 · Effective: August 24, 2026