QAAIFY

Data Processing Agreement (DPA)

Draft — requires legal review before publishing

Internal note (remove before publishing to customers)

Effective date: [PLACEHOLDER] · Version 0.1 (draft)

1. General provisions

This Agreement governs the processing of personal data that the Client submits or makes available through the QAAIFY Platform. By using the Platform, the Client confirms that it is the controller of the personal data submitted, or lawfully acts as an authorized representative of the controller. The Provider processes personal data only on the Client's documented instructions, unless otherwise required by law or necessary for security, service protection, audit, or compliance with mandatory requirements.

2. Subject of the Agreement

The Client instructs, and the Provider undertakes, to process personal data in connection with providing access to the Platform. Processing may include collection, registration, accumulation, storage, adaptation, alteration, use, transfer, de-identification, destruction, and other actions necessary to provide the Service.

3. Categories of data and data subjects

Categories of data subjects may include the Client's employees, agents, team leads, administrators, managers, the Client's own customers, and other individuals whose data appears in tickets, transcripts, notes, or related materials.

Categories of data may include: identification data, contact data, work roles, technical metadata, ticket content, call transcripts, evaluations, coaching and performance data, log files, access data, and other data that the Client submits to the Platform.

4. Purpose and duration of processing

Data is processed for the purpose of providing access to the Platform, quality analysis, reporting, coaching, ensuring security, backups, audit, technical support, and performance of the agreement.

Processing takes place for the term of the agreement and thereafter to the extent necessary for legal compliance, protection of rights, retention of backups, system recovery, or dispute resolution.

5. Client's instructions

The Client gives instructions to the Provider by using the Platform, configuring access, uploading data, activating integrations, written or electronic directions, or other actions provided for by the Platform. If a Client instruction contravenes the law or creates an evident risk of infringing third-party rights, the Provider may refuse to carry it out or suspend the relevant processing.

6. Subprocessors

The Provider may engage subprocessors to deliver the Platform, including AI providers, helpdesk providers, email providers, cloud providers, and other technical contractors — the current list is on the Subprocessor List. The Provider undertakes to impose on subprocessors data-protection obligations no less stringent than those set out in this Agreement, to the extent commercially and legally feasible.

7. Security

The Provider applies appropriate technical and organizational security measures, including encryption, access control, environment isolation, logging, backups, monitoring, rate limiting, and other reasonable measures — see more detail on the Trust Center. The Provider ensures that access to personal data is granted only to authorized personnel who need such access to perform their duties.

8. Security incidents and notification

If a security incident that may affect personal data is detected, the Provider notifies the Client no later than 72 hours after the Provider becomes aware of the breach.

9. Return or deletion of data

After termination of the agreement, the Client may export its data within the period available in the Platform or separately agreed by the parties. After the export period ends, the Provider may delete or de-identify active data, unless otherwise required by law or needed for backup retention, audit, or the protection of rights. Backups are kept for a limited time and are automatically overwritten in accordance with the recovery policy.

10. Client's rights

The Client has the right to request from the Provider confirmation of processing, clarification of processes, assistance with data-subject requests, and deletion or return of data to the extent permitted by law and the agreement. The Client is solely responsible for ensuring the legal basis for submitting personal data to the Platform and for informing data subjects, where required by law.

11. International transfers

The Client agrees that data may be processed outside Ukraine through the use of international infrastructure and third-party services listed in the Subprocessor List. If such a transfer requires additional agreements or safeguard mechanisms, the parties apply them within the scope of applicable law.

12. Confidentiality

The Provider maintains the confidentiality of personal data and does not use it other than to perform this Agreement, the underlying contract, and applicable legal requirements.

13. Order of precedence

In the event of a conflict between this Agreement and the Offer regarding the processing of personal data, this Agreement prevails to the extent it concerns data processing.

14. Term

This Agreement remains in effect for the term of the agreement between the parties and until all obligations related to the processing of personal data have been fulfilled.

See also Terms of Use, Privacy Policy, Subprocessor List and Trust Center.