Legal · DPA

Data Processing Agreement

Last updated1 June 2026
Effective date1 June 2026
Version2.1
Forms part ofthe Terms of Service

This Data Processing Agreement ("DPA") forms part of the Terms of Service between QuaBook (the "Processor") and the Subscriber (the "Controller") and governs the processing of personal data carried out by the Processor on the Controller's behalf.

1. Definitions

Terms such as "Controller", "Processor", "Personal Data", "Processing", "Data Subject", and "Supervisory Authority" have the meanings given in the applicable data-protection law, including the GDPR where it applies. "Subscriber Data" means personal data processed by the Processor on behalf of the Controller under the Terms of Service.

2. Scope and Roles

The Controller determines the purposes and means of processing Subscriber Data and is responsible for establishing a lawful basis, obtaining necessary consents from data subjects (including employees), and ensuring the accuracy of data entered into the Service. The Processor processes Subscriber Data only on documented instructions from the Controller, including as set out in the Terms of Service and this DPA.

3. Details of Processing

Subject matterProvision of the QuaBook quality-management Service
DurationThe term of the subscription, plus the retention period in §11
Nature & purposeHosting, processing, and display of Subscriber Data to operate the Service
Categories of dataEmployee identifiers, contact details, operational and quality records
Data subjectsThe Controller's employees, operators, and authorized users

4. Processor Obligations

The Processor shall: process Subscriber Data only on the Controller's documented instructions; ensure persons authorized to process the data are bound by confidentiality; implement the security measures in §5; assist the Controller with data-subject requests, security, breach notification, and impact assessments; and, at the Controller's choice, delete or return Subscriber Data at the end of the engagement, except where retention is required by law.

5. Technical and Organizational Security Measures

The Processor maintains measures appropriate to the risk, including:

  • Encryption of personal data in transit and at rest;
  • Role-based access controls and least-privilege administration;
  • Network segmentation, monitoring, and audit logging;
  • Regular backups and tested restoration procedures;
  • Ongoing assessment of the effectiveness of these measures.

6. Sub-Processors

The Controller authorizes the Processor to engage sub-processors (such as hosting, email, and payment providers) to support delivery of the Service. The Processor shall impose data-protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance. The Processor will give notice of intended changes to sub-processors, allowing the Controller a reasonable opportunity to object.

7. Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting Subscriber Data, and shall provide information reasonably necessary to enable the Controller to meet its own notification obligations to supervisory authorities and data subjects.

8. Audit Rights

The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA. The Controller may conduct audits, including inspections, no more than once per twelve (12) month period, on at least thirty (30) days' written notice, subject to confidentiality and reasonable security and operational constraints.

9. Data Subject Requests

Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures in responding to requests from data subjects exercising their rights. The Processor shall not respond to such requests directly unless authorized by the Controller or required by law.

10. International Data Transfers

Where Subscriber Data is transferred outside its country of origin, the Processor shall ensure an appropriate transfer mechanism is in place, such as Standard Contractual Clauses or an equivalent safeguard, and offers regional data-residency options where available.

11. Term and Termination

This DPA remains in effect for as long as the Processor processes Subscriber Data on the Controller's behalf. On termination, personal data is retained for thirty (30) days to allow export and then permanently deleted within ninety (90) days, except as required by applicable law.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

13. Contact

Data-protection enquiries under this DPA may be directed to solutions@quabook.com, QuaBook, Riyadh · Dubai.