Data Processing Agreement

Quantum 2x Ltd — Last updated: June 2025

This DPA is incorporated by reference into the MPP Registry Terms of Service and is automatically applicable to all customers who process personal data through the Service in their capacity as data controllers. No separate signature is required.

1. Definitions

In this DPA:

  • Controller” means you (the Customer), the entity that determines the purposes and means of processing personal data.
  • Processor” means Quantum 2x Ltd, processing personal data on behalf of the Controller.
  • Personal Data”, “Processing”, “Data Subject”, and “Supervisory Authority” have the meanings given in UK GDPR and the Data Protection Act 2018.
  • Service Data” means any personal data that the Controller submits to the Service for processing on their behalf.

2. Processing Instructions

The Processor shall process Service Data only on documented instructions from the Controller, unless required to do so by applicable law. The principal instructions are set out in Schedule 1. The Controller may issue additional written instructions from time to time.

3. Confidentiality

The Processor shall ensure that persons authorised to process Service Data are bound by appropriate confidentiality obligations. The Processor shall not disclose Service Data to any third party without the Controller's prior written consent, except as required by law or as described in Section 5.

4. Technical and Organisational Measures

The Processor implements and maintains the security measures described in Schedule 2 and in the Security Policy. The Processor will notify the Controller without undue delay (and in any event within 72 hours) of becoming aware of a personal data breach affecting Service Data.

5. Sub-Processors

The Controller authorises the Processor to engage the sub-processors listed in Schedule 3. The Processor will notify the Controller of any intended changes to sub-processors with at least 14 days notice. The Controller may object to a new sub-processor on reasonable grounds within that period.

The Processor ensures that sub-processing agreements impose equivalent data protection obligations to those in this DPA.

6. Data Subject Rights

The Processor will assist the Controller in fulfilling its obligations to respond to data subject rights requests (access, correction, deletion, restriction, portability). Where the Processor receives a rights request directly from a data subject, it will forward it to the Controller within 5 business days.

7. Data Protection Impact Assessments

The Processor will provide reasonable assistance to the Controller in conducting DPIAs and prior consultation with supervisory authorities where required by UK GDPR Article 35/36.

8. Deletion and Return

At the termination of the Service or upon written request, the Processor will delete or return all Service Data within 90 days, except where retention is required by applicable law. The Processor will certify deletion in writing on request.

9. Audit Rights

The Controller may, on reasonable written notice (minimum 14 days), audit the Processor's compliance with this DPA, no more than once per calendar year. Audits shall be conducted in a manner that minimises disruption to the Processor's business. The Processor may satisfy audit rights by providing its most recent SOC 2 Type I report or equivalent certification where available.

10. International Transfers

Where Service Data is transferred outside the UK or EEA, the Processor ensures appropriate safeguards are in place (EU-US Data Privacy Framework, UK IDTA, Standard Contractual Clauses, or adequacy decision). Details are in Schedule 3.

Schedule 1 — Subject Matter of Processing

  • Nature: Storage, retrieval, and processing of Service Data as part of providing the MPP Registry service
  • Purpose: Provision of the Service as described in the Terms of Service
  • Duration: For the term of the service agreement, plus 90 days post-termination
  • Categories of data subjects: The Controller's employees, contractors, and service account users
  • Types of personal data: Names, email addresses, IP addresses, usage records, and audit log metadata

Schedule 2 — Security Measures

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AES-256)
  • Row-level security for multi-tenant data isolation
  • Ed25519 / ECDSA package signing and verification
  • Append-only audit logs enforced at the database trigger level
  • MFA available for all accounts
  • Access to production systems limited to authorised personnel
  • Regular security reviews and dependency audits

Schedule 3 — Sub-Processors

Sub-ProcessorPurposeLocation
Supabase Inc.Database & AuthenticationUS (AWS us-east-1)
Stripe Inc.Payment ProcessingUS
Resend Inc.Transactional EmailUS
Vercel Inc.Hosting & Edge NetworkUS / Global CDN
Sentry Inc.Error MonitoringUS

Contact

For DPA-related enquiries: support@quantum2x.com