Data Processing Agreement
Quantum 2x Ltd — Last updated: June 2025
1. Definitions
In this DPA:
- “Controller” means you (the Customer), the entity that determines the purposes and means of processing personal data.
- “Processor” means Quantum 2x Ltd, processing personal data on behalf of the Controller.
- “Personal Data”, “Processing”, “Data Subject”, and “Supervisory Authority” have the meanings given in UK GDPR and the Data Protection Act 2018.
- “Service Data” means any personal data that the Controller submits to the Service for processing on their behalf.
2. Processing Instructions
The Processor shall process Service Data only on documented instructions from the Controller, unless required to do so by applicable law. The principal instructions are set out in Schedule 1. The Controller may issue additional written instructions from time to time.
3. Confidentiality
The Processor shall ensure that persons authorised to process Service Data are bound by appropriate confidentiality obligations. The Processor shall not disclose Service Data to any third party without the Controller's prior written consent, except as required by law or as described in Section 5.
4. Technical and Organisational Measures
The Processor implements and maintains the security measures described in Schedule 2 and in the Security Policy. The Processor will notify the Controller without undue delay (and in any event within 72 hours) of becoming aware of a personal data breach affecting Service Data.
5. Sub-Processors
The Controller authorises the Processor to engage the sub-processors listed in Schedule 3. The Processor will notify the Controller of any intended changes to sub-processors with at least 14 days notice. The Controller may object to a new sub-processor on reasonable grounds within that period.
The Processor ensures that sub-processing agreements impose equivalent data protection obligations to those in this DPA.
6. Data Subject Rights
The Processor will assist the Controller in fulfilling its obligations to respond to data subject rights requests (access, correction, deletion, restriction, portability). Where the Processor receives a rights request directly from a data subject, it will forward it to the Controller within 5 business days.
7. Data Protection Impact Assessments
The Processor will provide reasonable assistance to the Controller in conducting DPIAs and prior consultation with supervisory authorities where required by UK GDPR Article 35/36.
8. Deletion and Return
At the termination of the Service or upon written request, the Processor will delete or return all Service Data within 90 days, except where retention is required by applicable law. The Processor will certify deletion in writing on request.
9. Audit Rights
The Controller may, on reasonable written notice (minimum 14 days), audit the Processor's compliance with this DPA, no more than once per calendar year. Audits shall be conducted in a manner that minimises disruption to the Processor's business. The Processor may satisfy audit rights by providing its most recent SOC 2 Type I report or equivalent certification where available.
10. International Transfers
Where Service Data is transferred outside the UK or EEA, the Processor ensures appropriate safeguards are in place (EU-US Data Privacy Framework, UK IDTA, Standard Contractual Clauses, or adequacy decision). Details are in Schedule 3.
Schedule 1 — Subject Matter of Processing
- Nature: Storage, retrieval, and processing of Service Data as part of providing the MPP Registry service
- Purpose: Provision of the Service as described in the Terms of Service
- Duration: For the term of the service agreement, plus 90 days post-termination
- Categories of data subjects: The Controller's employees, contractors, and service account users
- Types of personal data: Names, email addresses, IP addresses, usage records, and audit log metadata
Schedule 2 — Security Measures
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256)
- Row-level security for multi-tenant data isolation
- Ed25519 / ECDSA package signing and verification
- Append-only audit logs enforced at the database trigger level
- MFA available for all accounts
- Access to production systems limited to authorised personnel
- Regular security reviews and dependency audits
Schedule 3 — Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database & Authentication | US (AWS us-east-1) |
| Stripe Inc. | Payment Processing | US |
| Resend Inc. | Transactional Email | US |
| Vercel Inc. | Hosting & Edge Network | US / Global CDN |
| Sentry Inc. | Error Monitoring | US |
Contact
For DPA-related enquiries: support@quantum2x.com