Legal

Data Processing Agreement

Framework terms for personal data processing when QData operates a QData Projects environment on your behalf. A signed DPA (or agreement schedule) governs each customer engagement.

Version: 2026-08-10 · Last updated: 10 August 2026

This page describes the standard DPA framework for QData Projects. Commercial contracts may attach an executed DPA that prevails if there is a conflict.

1. Scope

This DPA applies when:

  • The customer is a controller (or processor for its own clients), and
  • QData processes personal data in the QData Projects SaaS service operated by QData.

QData Projects is offered only as SaaS. This DPA does not cover on-premises or customer-hosted installations because those delivery models are not sold.

2. Roles

  • Customer: controller (or processor) of workspace personal data.
  • QData: processor (or sub-processor) for operated environments in scope.

3. Nature and purpose of processing

Providing project management and collaboration software operations: hosting, authentication support as configured, backups, monitoring, maintenance, support, and related security operations.

4. Types of personal data

Depending on customer configuration and use, processing may include:

  • Account identifiers (name, email, login)
  • Role / membership metadata
  • Project collaboration content users choose to store (tasks, comments, files)
  • Technical logs and security events related to the service

Customers must not instruct QData to process special categories of data unless the contract explicitly allows it and appropriate safeguards are agreed.

5. Data subjects

Customer employees, contractors, partners and other users the customer invites to the workspace.

6. Instructions

QData processes personal data only on documented customer instructions (the agreement, configuration chosen by the customer, and written instructions), unless required by law.

7. Confidentiality and personnel

Persons authorized to process personal data are bound by confidentiality obligations and access is limited on a need-to-know basis.

8. Security measures

Technical and organizational measures include, as applicable to the offering:

  • TLS encryption in transit at the public edge
  • Access control and authentication controls in the application
  • Network isolation patterns for application components
  • Backup routines for operated environments
  • Operational logging and vulnerability/update handling processes

Encryption at rest, residency and specific SLA metrics are defined per SaaS contract schedule — not as blanket global claims on this page. Primary data location and colocation are available in Europe and North America; the chosen region is recorded in the executed schedule.

9. Subprocessors

QData may use subprocessors to deliver operated services (for example infrastructure hosting under QData control). A current list for a given offering is provided on request and/or in the Trust Center when published. Customers will be informed of material subprocessor changes as required by the executed DPA.

As of this version, public Website/application hosting for the reference deployment is operated on QData-controlled infrastructure (qnode) serving projects.qdata.cloud. No additional named subprocessors are asserted here without an active published list.

10. International transfers

If processing involves transfers outside the customer's applicable region, safeguards required by law (such as SCCs where applicable) will be addressed in the executed DPA / transfer addendum.

11. Assistance, breaches, audits

  • QData assists with reasonable data-subject request handling to the extent the request concerns data in the operated environment.
  • Security incidents involving personal data in operated environments are handled under the incident process described to the customer; notification timelines follow the executed DPA and applicable law.
  • Audit rights (including questionnaires and, where agreed, inspections) follow the executed DPA.

12. Return and deletion

Upon termination of an operated service, QData will return or delete customer personal data from operated systems within the period stated in the contract (after which backups age out according to backup retention), unless law requires longer retention.

13. Liability and precedence

Liability caps and precedence between this framework, the main agreement, and an executed DPA are defined in the signed documents. This web page alone is not a signed contract.

14. Contact

To request an executed DPA PDF/schedule for your organization, use the security / legal contact form.

Related: Privacy Policy · Cookie Policy · Terms of Use · Trust Center