This Data Processing Agreement (“DPA”) forms part of the Master Terms of Service (the “Terms”) between Quayutec and the Customer that accepted them. It applies wherever Quayutec processes personal data on Customer’s behalf in providing the Services, and it takes effect when Customer accepts the Terms, with no separate signature. It is written to meet Article 28 GDPR and Article 28 of the UK GDPR. Capitalised terms it does not define have the meaning the Terms give them.
1Parties and roles
Processor. Quayutec Technologies Private Limited, a company incorporated in India, whose postal address is 289, Saraswati Kunj, Golf Course Road, Sector 53, Gurugram, Haryana 122011, India, trading as Quayutec (“Quayutec”). Questions about this DPA go to hello@quayutec.com.
Controller. The Customer: the Organization that accepted the Terms, acting as controller of the personal data that it, its people and its Agents put into the Services. Where Customer itself processes that data for another controller, Customer is a processor, Quayutec is its sub-processor, and Customer passes on to that controller whatever this DPA requires.
In a Room, each Organization — the Host and each Guest — is the controller of the personal data it puts into that Room, and Quayutec processes it for each of them under this DPA. For the account, billing, waitlist and public-site data described in the Privacy Policy, Quayutec is a controller in its own right, and the Privacy Policy, not this DPA, governs that data. Quayutec is not a party to the arrangements between the Organizations in a Room, including any agreement they make with each other about the content they share.
2Definitions
- Data Protection Law
- The GDPR (Regulation (EU) 2016/679); the UK GDPR and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection; India’s Digital Personal Data Protection Act 2023 and the rules made under it, and, for as long as they apply, section 43A of the Information Technology Act 2000 and the rules made under it; the US State Privacy Laws (Section 15); and any other law on the processing of personal data that applies to the processing under this DPA.
- Customer Personal Data
- Personal data that Quayutec processes on Customer’s behalf in providing the Services, as Section 3 describes.
- Sub-processor
- A third party Quayutec engages that processes Customer Personal Data.
- Personal Data Breach
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- Standard Contractual Clauses
- The standard contractual clauses for transfers to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
- UK Addendum
- The International Data Transfer Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
“Personal data”, “processing”, “controller”, “processor”, “data subject” and “supervisory authority” have the meanings Data Protection Law gives them.
3Details of the processing
| Particular | Detail |
|---|---|
| Subject matter | Providing the Services: Project Rooms and their messages, tasks and shared memory; the Approval Gate; the Room’s ledger; the connection of Agents and of the AI tools that act as them; and the email notices these produce. |
| Duration | For as long as the Terms are in force, and afterwards until the data is returned or deleted under Section 11. |
| Nature of the processing | Storing, organising and indexing Room content (search vectors are computed by a model that runs inside Quayutec’s own application); making it available to the people and Agents that Customer, and the Organizations Customer shares a Room with, allow to see it; sending it to the model provider an always-on Agent’s owner chose (Section 5); sending notices by email; recording decisions and events; and returning or deleting it. |
| Purpose | To run the Services as Customer configures them, under the Terms and this DPA, and for no other purpose. |
| Data subjects | Customer’s people who use the Services, including its Top Manager and any observers; people whose names, messages or details Customer, its people or its Agents put into a Room, such as colleagues, clients or contacts named in a task or a specification; and the people of other Organizations in the same Room, where Customer’s Agents process what they write. |
| Categories of personal data | Names and work email addresses; account and organisation identifiers; anything personal in the Room content Customer chooses to put in (messages, task text, specifications, files and shared memory); Approval Gate records (what was proposed, who decided it, and when); run telemetry; and connection records for Agents and connected apps, stored as hashes where Section 7 says so. |
| Special categories | None is needed to use the Services. Customer will not put special categories of personal data (Article 9 GDPR), or data about criminal convictions and offences, into a Room unless it has a lawful basis to do so and has judged the measures in Section 7 appropriate for it. |
4Customer’s responsibilities
Customer is responsible for having a lawful basis for the personal data it puts into the Services and for giving the people it concerns any notice Data Protection Law requires. Customer decides what it shares with other Organizations in a Room, through the Bilateral Room Agreements it sets or accepts and the content it posts, and which model provider its own always-on Agents use. Customer’s instructions to Quayutec must comply with Data Protection Law.
5Processing on Customer’s instructions
Quayutec processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless the law Quayutec is subject to requires otherwise; in that case Quayutec tells Customer of that legal requirement before processing, unless that law prohibits it. Customer’s documented instructions are the Terms, this DPA, and the way Customer configures the Services: the Rooms it creates or joins, the Bilateral Room Agreements it sets or accepts, its Agents and their follow-lists and connections, and its triage settings. Quayutec tells Customer immediately if, in its opinion, an instruction infringes Data Protection Law.
Sharing within a Room. A Room is shared by design. When Customer puts content into a Room, or admits another Organization’s Agents to it, Customer instructs Quayutec to make that content available to the people and Agents of the other Organizations in the Room, within the scope of the Bilateral Room Agreement.
Model providers. When an always-on Agent runs, Quayutec sends the Room’s recent messages, and the shared memory that Agent may read, to the model provider chosen by the Organization that owns the Agent, under that Organization’s own key. The provider is engaged by that Organization directly, under its own terms; it is not Quayutec’s Sub-processor. By admitting another Organization’s always-on Agents to a Room, Customer instructs Quayutec to send that Room’s content to that Organization’s chosen provider in this way. A connected Agent’s tool reads the Room through the Room’s tools and handles what it reads under its owner’s own arrangements.
Quayutec’s own limited purposes. Quayutec uses the records of Agent Runs, Approval Gate decisions and account identifiers that the Services produce, as a controller in its own right, only to: count Agent Runs to meter and bill them; secure the Services and detect and prevent abuse, fraud and breaches of the Acceptable Use Policy; and comply with law that binds Quayutec. It does not use Room content (messages, task text, files and shared memory) for any of these purposes except security and legal compliance, and then only as far as necessary. The Privacy Policy describes this processing.
6Confidentiality
Quayutec ensures that every person it authorises to process Customer Personal Data is bound by a duty of confidentiality, contractual or statutory. Room content is not encrypted at the application layer, so the people who operate Quayutec can technically read it through the database’s administrative access; they access Customer Personal Data only as needed to run, secure and support the Services, to investigate a problem Customer reports, or where the law requires it.
7Security measures
Quayutec implements the technical and organisational measures below, under Article 32 GDPR. They are the measures the Security page describes as enforced, and this section claims no more than that page. The limits of each measure, and what Quayutec has not done, are published on the same page under What we have not done, which forms part of this description. Customer is responsible for judging whether these measures suit the personal data it chooses to put into a Room. Quayutec will not change the Security page, or the measures it describes, in a way that materially reduces the overall protection of Customer Personal Data.
- Access to a Room. Every request that reads or writes something belonging to a Room passes an explicit membership check: for a person, that their Organization owns the Room or has an Agent on its roster; for an Agent, that its key or sign-in token belongs to an Agent on that Room’s roster. A request without a session is refused before any route runs, except at a short list of endpoints the Security page names, each of which answers for its own caller instead. A test in the suite reads every API route and fails if one that touches a Room has neither check and no written reason.
- Between Organizations. Reading and writing a Room’s shared memory and assigning tasks are each checked against the Bilateral Room Agreement’s own permission, and a Guest without an active agreement cannot post, read or write shared memory, assign tasks, or wake its always-on Agents. Each Organization’s private memory is kept apart from the shared record and filtered to the Organization that wrote it.
- Database. Row-level security is enabled on every table, as a second layer against anything querying the database directly; the application’s own routes use a service role that bypasses it, so the membership checks above are the boundary on the path a request takes.
- Provider keys and other secrets. A model provider key is encrypted with AES-256-GCM under a 32-byte master key held in an environment variable on Quayutec’s own servers, which is not an external key management service and is not hardware-backed. It is decrypted in memory at one place in the code for the call that needs it and is never returned in an API response, and the service refuses to store one at all if the master key is missing or the wrong length. A routine’s wake token and a connected app’s event signing secret are encrypted the same way.
- Agent keys and sign-in. An Agent’s Quayutec key is 32 random bytes, stored only as its SHA-256 hash; regenerating it replaces the hash and signs every connected app out of that Agent. Signing in is OAuth 2.1 with PKCE: a code works once, within 60 seconds; an access token lasts an hour and a refresh token 30 days, replaced each time it is used; only hashes of either are stored; a token works only through the Room’s MCP addresses and meets the same roster check as a key; and it stops working when the app is signed out, when the Agent’s key is replaced, or when the person who allowed it leaves the company.
- The Approval Gate. An always-on Agent’s declared action that is read as irreversible is held until a person at that Agent’s own Organization decides it, and expires untaken after 72 hours; no plan, setting or role can clear it. A declared action read as read-only is held the same way unless the Organization has switched automatic approval on, which a new Organization starts with off.
- Secret scanning. Before anything is written to a Room’s shared memory, a deterministic check refuses content that looks like a credential.
- The record. Each approval or rejection carries a hash of the decision before it, and every Room event is appended to the Room’s ledger as a hash, signed where a signing key is configured, so an altered record fails the published check.
- The web layer. Every response carries strict transport security with a two-year age, subdomains included and preload requested; framing is denied, content sniffing is off, camera, microphone, geolocation and payment are disabled, and client source maps are not published.
8Sub-processors
Customer gives Quayutec general authorisation to engage Sub-processors. Those that process Customer Personal Data are:
| Sub-processor | What it does with Customer Personal Data |
|---|---|
| Supabase, Inc. | Hosts the database: Room content, shared memory and its search vectors, accounts and authentication, and realtime delivery. |
| Trigger.dev (Trigger Software Ltd) | Runs always-on Agents’ work as durable tasks, and holds the Approval Gate’s waitpoints. |
| Vercel Inc. | Hosts and delivers the application and its API. |
| Hostinger | Delivers transactional email: invitations, approval requests and sign-in links. |
| Resend | Delivers setup emails and reminders, which name the recipient, their company and, where relevant, a Room or an Agent. |
| Sentry | Server-side error tracking. |
A model provider chosen by an Agent’s owner is not a Sub-processor (Section 5). Quayutec also uses Paddle, Slack, Google Sheets, PostHog, Google Analytics, Microsoft Clarity, Warmly, Dreamdata and Leadfeeder as a controller, for its own purposes described in the Privacy Policy; none of them processes the content of a Room.
Changes. Quayutec gives Customer notice of any intended addition or replacement of a Sub-processor at least 30 days before it processes Customer Personal Data, by updating this list and by email to Customer’s account owner. Customer may object on reasonable grounds relating to data protection by writing to hello@quayutec.com within that period. The parties will discuss the objection in good faith; if Quayutec cannot meet it, Customer may end its subscription before the change takes effect and is not charged for any period after it ends.
Obligations passed on. Quayutec imposes on each Sub-processor, by written contract, data protection obligations that give Customer Personal Data the same protection as this DPA, in particular sufficient guarantees of appropriate technical and organisational measures. Quayutec remains fully liable to Customer for each Sub-processor’s performance of those obligations.
9Assistance
Requests from data subjects. If Quayutec receives a request from a data subject about Customer Personal Data, it does not answer it itself, beyond telling the person to contact Customer, and passes it to Customer without undue delay. Taking into account the nature of the processing, Quayutec helps Customer answer such requests: Customer can see a Room’s content in the Services and export its records where its plan includes export (Section 12), and Quayutec carries out a correction, deletion or export Customer asks for in writing.
Compliance. Quayutec gives Customer the information it reasonably needs, and that is available to Quayutec, to meet its own obligations under Articles 32 to 36 GDPR: security of processing, notifying a breach, data protection impact assessments and prior consultation with a supervisory authority.
10Personal data breaches
Quayutec notifies Customer without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, by email to Customer’s account owner. The notice describes, as far as Quayutec then knows: the nature of the breach, including the categories and approximate number of data subjects and records concerned; its likely consequences; the measures taken or proposed to address it and to mitigate its possible adverse effects; and a contact for more information. Where Quayutec cannot give all of it at once, it gives it in phases without further undue delay. Quayutec takes reasonable steps to contain and investigate the breach. Notifying a breach is not an admission of fault.
11Return and deletion
When the Terms end, or earlier when Customer asks, Quayutec, at Customer’s choice, deletes Customer Personal Data or returns it and then deletes it, unless the law of the European Union, of a Member State or of the United Kingdom requires Quayutec to keep it. A return is a copy of Customer’s Room records in CSV or JSON, and it is available to every Customer, whatever its plan, on request to hello@quayutec.com, in addition to any self-serve export its plan includes. Where a law that applies to Quayutec, including the law of India, prohibits returning or deleting specific Customer Personal Data or requires Quayutec to keep it, Quayutec keeps only that data, for no longer than that law requires, continues to protect it under this DPA, and processes it for no other purpose. Ending a subscription does not by itself delete anything: deletion follows Customer’s instruction under this section, and Quayutec carries it out without undue delay and confirms it in writing.
Content another Organization put into a shared Room is that Organization’s, and is deleted on its instruction, not Customer’s. The Room’s ledger holds hashes, identifiers and timestamps rather than content and is kept in append-only storage, so that the record of decisions in the Room still verifies; on deletion, Quayutec deletes the account and profile data that link those identifiers to a person. Copies held in the infrastructure providers’ backups are deleted as those backups expire.
12Audits and information
Quayutec makes available to Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, by Customer or an auditor Customer mandates. Quayutec holds no third-party security certification or audit report, so it meets this first with information: the Security page, and on request the source file behind any claim on it; written answers to Customer’s reasonable questions; and the Room’s own record. Customer can export a Room’s messages, memory writes, tasks, memory conflicts and escalations, followed by the Room’s whole ledger, as CSV or JSON, and recompute the decision chain itself; the export needs membership of the Room and is included in the Pro Room and Enterprise Consortium plans, checked against the plan of the Organization that exports.
Where that information is not enough, or a supervisory authority requires it, Customer may audit Quayutec’s processing of Customer Personal Data: on at least 30 days’ written notice; no more than once in any twelve months, unless a Personal Data Breach or a supervisory authority requires otherwise; at Customer’s own cost; during business hours; through an auditor bound by confidentiality; and in a way that does not expose any other customer’s data.
13International transfers
Quayutec is established in India. Its Sub-processors operate in the United States and, for some services, the European Economic Area. Where Customer Personal Data is transferred from the EEA, the UK or Switzerland to Quayutec, or onward to a Sub-processor, in a country without an adequacy decision, the transfer is made under the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed as follows:
- Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. Customer is the data exporter and Quayutec the data importer.
- Clause 7 (the docking clause) applies. Under Clause 9, Option 2 applies: general written authorisation, with the notice period in Section 8. The optional wording in Clause 11 does not apply. Under Clause 13, the competent supervisory authority is the one Clause 13(a) identifies for Customer.
- Under Clause 17, Option 1 applies: the Clauses are governed by the law of Ireland. Under Clause 18(b), disputes arising from the Clauses are resolved by the courts of Ireland; a data subject may also bring proceedings before the courts of the Member State where they habitually reside, as Clause 18(c) provides.
- Annex I is completed by Sections 1 and 3 of this DPA, Annex II by Section 7, and Annex III by Section 8.
From the UK. For a transfer subject to the UK GDPR, the UK Addendum (version B1.0) is incorporated: Table 1 is completed with the parties’ details in Section 1, Table 2 with the Modules and options selected above, and Table 3 by the Annexes as completed above; in Table 4, neither party may end the UK Addendum when the Approved Addendum changes.
From Switzerland. For a transfer subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with these changes: references to the GDPR are read as references to that Act to the extent the transfer is subject to it; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for such a transfer; and “Member State” in Clause 18(c) is not read so as to stop data subjects habitually resident in Switzerland from bringing proceedings there.
Onward transfers. Quayutec transfers Customer Personal Data onward to a Sub-processor in a country without an adequacy decision only as Clauses 8 and 9 of the Standard Contractual Clauses allow: the Sub-processor is bound by the Standard Contractual Clauses under the appropriate Module, an adequacy decision covers that onward transfer, or the Sub-processor otherwise ensures appropriate safeguards under Article 46 GDPR.
14Liability, precedence and term
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in Section 10 of the Terms, except where Data Protection Law does not allow them to apply, and nothing in this DPA limits either party’s liability to data subjects under the Standard Contractual Clauses. If this DPA and the Terms conflict on the processing of personal data, this DPA governs; if the Standard Contractual Clauses conflict with this DPA or the Terms, the Standard Contractual Clauses govern. This DPA is governed by the law that governs the Terms (Terms Section 13), except the Standard Contractual Clauses, which are governed as Section 13 of this DPA sets out.
This DPA lasts for as long as Quayutec processes Customer Personal Data, including after the Terms end. Quayutec may update it to reflect a change in Data Protection Law or in its Sub-processors under Section 8, and will not reduce the protection it gives Customer Personal Data without Customer’s agreement.
15US state privacy laws
In this section, “US State Privacy Laws” means the California Consumer Privacy Act of 2018, as amended (the “CCPA”), and its regulations, and every other comprehensive US state privacy law that applies to Customer Personal Data. To the extent they apply, Quayutec is Customer’s “service provider” or “processor”, and processes Customer Personal Data only for these business purposes, which Section 3 sets out: hosting Project Rooms and their messages, tasks, files and shared memory; running the Approval Gate and the Room’s ledger; connecting Agents and the AI tools that act as them; and sending the email notices these produce. Quayutec will not: (a) sell or share Customer Personal Data, as the CCPA defines those terms; (b) retain, use or disclose it for any purpose other than those business purposes, including any other commercial purpose, or outside the direct business relationship between Quayutec and Customer, except as the US State Privacy Laws permit; or (c) combine it with personal information Quayutec receives from or on behalf of anyone else, or collects from its own interactions with the person concerned, except as the US State Privacy Laws permit. Quayutec will comply with the obligations the US State Privacy Laws place on it, give Customer Personal Data the level of privacy protection they require, and notify Customer if it decides it can no longer meet those obligations. Quayutec helps Customer answer consumers’ requests as Section 9 provides. Customer may take reasonable and appropriate steps to make sure Quayutec uses Customer Personal Data consistently with Customer’s obligations under those laws, including under Section 12, and, on notice, to stop and remediate unauthorised use. Quayutec certifies that it understands these restrictions and will comply with them.
16India
Where Customer is a Data Fiduciary under India’s Digital Personal Data Protection Act 2023 (the “DPDP Act”), Customer is the Data Fiduciary and Quayutec its Data Processor, and “controller” and “processor” in this DPA are read that way. Quayutec processes Customer Personal Data only under this DPA and Customer’s instructions; protects it with the measures in Section 7; notifies Customer of a Personal Data Breach as Section 10 provides, with the information Customer needs to tell the Data Protection Board of India and the people affected; helps Customer answer the requests of Data Principals as Section 9 provides; and erases Customer Personal Data on Customer’s instruction under Section 11, subject to any retention that Indian law requires.