Data Processing Agreement
Last updated: August 16, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Quantum AI Research & Solutions ("Quantum", "Processor") and the customer company that accepts it ("Customer", "Controller") and governs the processing of personal data by Quantum on the Customer's behalf in connection with the QuantumPortal platform (the "Service"). It becomes binding when executed by both parties or when the Customer accepts it in the course of using the Service.
1. Definitions
- "Data Protection Laws" means all laws applicable to the processing of personal data under this DPA, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where applicable, the EU General Data Protection Regulation ("GDPR").
- "Controller" (Data Fiduciary), "Processor" (Data Processor), "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the applicable Data Protection Laws.
- "Customer Personal Data" means personal data contained in the Customer's account that Quantum processes on the Customer's behalf, as described in Annex A.
- "Sub-processor" means any third party engaged by Quantum to process Customer Personal Data.
2. Roles and scope
The Customer is the Controller and Quantum is the Processor of Customer Personal Data. Quantum will process Customer Personal Data only to provide and support the Service and only for the subject-matter, duration, nature, and purposes set out in Annex A. Each party will comply with its obligations under the applicable Data Protection Laws.
3. Processing on documented instructions
Quantum will process Customer Personal Data only on the Customer's documented instructions, including as set out in the Terms of Service, this DPA, and the Customer's configuration and use of the Service, unless required to act otherwise by law (in which case Quantum will inform the Customer, unless legally prohibited). Quantum will promptly notify the Customer if, in its opinion, an instruction infringes the Data Protection Laws.
4. Confidentiality
Quantum will ensure that personnel authorised to process Customer Personal Data are bound by appropriate obligations of confidentiality and are informed of the confidential nature of the data. Access is limited to personnel who need it to provide the Service.
5. Security
Quantum will implement appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. A summary of current measures is set out in Annex B.
6. Sub-processors
- The Customer authorises Quantum to engage Sub-processors to process Customer Personal Data, provided that Quantum imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA.
- Quantum's current Sub-processors are listed in Annex C. Quantum will inform the Customer of any intended addition or replacement of a Sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds.
- Quantum remains responsible for the performance of its Sub-processors' data-protection obligations.
7. Assistance with data-subject requests
Taking into account the nature of the processing, Quantum will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights (such as access, correction, and erasure). Where a Data Subject sends such a request directly to Quantum, Quantum will, where permitted, forward it to the Customer and will not respond directly except on the Customer's instructions.
8. Personal data breach
Quantum will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the Customer with information reasonably available to it to assist the Customer in meeting its own breach-notification obligations under the Data Protection Laws.
9. Data protection impact assessments
Quantum will provide the Customer with reasonable assistance, at the Customer's expense where material, with data protection impact assessments and prior consultations with supervisory authorities, in each case solely in relation to the processing of Customer Personal Data by Quantum and taking into account the information available to Quantum.
10. International transfers
Where Quantum transfers Customer Personal Data to a country other than the one in which it was collected, Quantum will ensure an appropriate level of protection as required by the Data Protection Laws, including, for GDPR-governed transfers, the use of Standard Contractual Clauses or another valid transfer mechanism.
11. Return and deletion
On termination or expiry of the Service, and at the Customer's choice, Quantum will delete or return Customer Personal Data and delete existing copies, except to the extent that retention is required by law. As described in the Terms of Service, the Customer may request an export during a 30-day grace period after cancellation, after which data may be deleted. Chat attachments auto-delete approximately 24 hours after sending regardless of account status.
12. Audits
Quantum will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable prior notice, no more than once per year (unless required by a supervisory authority), and subject to confidentiality obligations. Quantum may satisfy this obligation by providing relevant third-party certifications or reports where available.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
14. Term and precedence
This DPA takes effect on acceptance and continues for as long as Quantum processes Customer Personal Data. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
15. Governing law
This DPA is governed by the same law and jurisdiction as the Terms of Service, except where the applicable Data Protection Laws require otherwise.
Annex A — Details of processing
- Subject-matter: provision of the QuantumPortal Service to the Customer.
- Duration: the term of the Customer's use of the Service, plus any post-termination retention period described in the Terms.
- Nature and purpose: hosting, storage, and processing of Customer data to operate project management, corrections, updates, flowcharts, user management, and messaging features.
- Categories of Data Subjects: the Customer's administrators and users, and individuals whose data the Customer includes in its projects, records, and communications.
- Categories of Personal Data: names, business contact details (email, phone, address), company identifiers (e.g. GSTIN), authentication data, and any personal data the Customer chooses to include in project content, corrections, updates, messages, or uploaded files.
- Special categories: the Service is not intended for special-category (sensitive) personal data; the Customer should not submit such data.
Annex B — Technical and organizational measures
- Passwords stored using one-way hashing (bcrypt); no plain-text passwords.
- Two-step sign-in using one-time passcodes (OTP) sent by email.
- Login-attempt throttling to mitigate brute-force attacks.
- CSRF protection on state-changing requests and parameterized database queries to prevent injection.
- Role-based access control and account-level (tenant) isolation, so data is accessible only within the company account it belongs to.
- Automatic deletion of chat attachments approximately 24 hours after sending.
- Restricted administrative access and confidentiality obligations for personnel.
Annex C — Approved sub-processors
- Hostinger International Ltd. — hosting of the application and database, and outgoing transactional email sent from the quantumserves.com mailbox (one-time passcodes and service notifications). Processing takes place in the data-centre region provisioned for the Service.
This list reflects the Sub-processors currently engaged. Quantum will notify the Customer of any intended addition or replacement in accordance with Section 6.
Contact
For any matter relating to this DPA, contact support@quantumserves.com.