# Data Processing Agreement (DPA)

**Draft — generated 2026-05-14. Review with qualified data-protection counsel in your jurisdiction before counter-signing.**

This Data Processing Agreement ("DPA") forms part of the QualCanvas Subscription Agreement (the "Agreement") between **QualCanvas** ("Processor") and the customer organization identified in the Agreement ("Controller"). Where the Agreement and this DPA conflict, this DPA governs the processing of Personal Data.

Capitalised terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679), the UK GDPR, or the Agreement, in that order.

---

## 1. Subject-matter, duration, nature and purpose

| Item                        | Detail                                                                                                                                                                                                                       |
| --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Subject-matter              | Processing of Personal Data uploaded by Controller into the QualCanvas SaaS for qualitative-research workflows (coding, analysis, export).                                                                                   |
| Duration                    | The term of the Agreement, plus a 30-day return/deletion window after termination (see §10).                                                                                                                                 |
| Nature                      | Storage, structured access, encoding, statistical analysis, and onward transfer to Sub-processors strictly for service delivery.                                                                                             |
| Purpose                     | Enabling Controller to conduct qualitative research using QualCanvas's hosted tools.                                                                                                                                         |
| Types of Personal Data      | Names, email addresses, account credentials, IP addresses, hashed device fingerprints, payment metadata, AND any Personal Data contained in research transcripts, codings, memos, or files the Controller chooses to upload. |
| Categories of data subjects | Controller's authorised users, and (in research-content uploads) research participants whose data Controller is responsible for processing lawfully.                                                                         |
| Special-category data       | QualCanvas does **not** undertake to receive or process special-category data (Art. 9) absent a separate written addendum. Controller is responsible for ensuring uploads comply.                                            |

## 2. Roles

- Controller determines the purposes and means of processing Personal Data uploaded into QualCanvas.
- Processor processes Personal Data only on documented instructions from Controller, including with regard to transfers (Art. 28(3)(a)).
- Use of the QualCanvas Service in accordance with the Agreement constitutes Controller's documented instructions.

## 3. Processor obligations (GDPR Art. 28)

Processor will:

a. Process Personal Data only on documented instructions, including transfers, unless required by EU or Member-State law (notifying Controller of such requirement unless legally prohibited).
b. Ensure personnel authorised to process Personal Data are bound by confidentiality.
c. Implement the technical and organisational measures described in **Annex A**.
d. Engage Sub-processors only under §7.
e. Assist Controller in responding to data-subject requests (Arts. 15–22) per §6.
f. Assist Controller in complying with Arts. 32–36 (security, breach notification, DPIA).
g. At Controller's choice, delete or return all Personal Data after termination per §10.
h. Make available to Controller information necessary to demonstrate compliance with Art. 28, and allow / contribute to audits per §8.

## 4. Confidentiality

Processor will treat all Personal Data as confidential and not disclose it except (i) to authorised personnel bound by confidentiality, (ii) to Sub-processors under §7, or (iii) as required by law (with notice to Controller unless prohibited).

## 5. Security (Art. 32)

Processor implements the technical and organisational measures listed in **Annex A**. Controller acknowledges these are appropriate having regard to state-of-the-art, costs of implementation, nature, scope, context, and purposes of processing, and the risk to data subjects.

Personal Data breach notification: Processor will notify Controller without undue delay, and in any case within **72 hours** of becoming aware of a Personal Data breach, providing the information required by Art. 33(3) to the extent then available. Notification address: the security contact email in Controller's QualCanvas account (or as updated in writing).

## 6. Data-subject requests

Processor will, taking into account the nature of the processing, assist Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling Controller's obligation to respond to requests for exercising the data subject's rights under Arts. 15–22.

If Processor receives a request directly from a data subject regarding Personal Data processed on behalf of Controller, Processor will (i) not respond substantively except to confirm the request was received, and (ii) forward the request to Controller without undue delay.

Self-service tooling: Controller's users can already (a) export their data via Account → Export, (b) delete their account via Account → Delete account, (c) export per-canvas data via the canvas Export menu in CSV / QDPX / JSON.

## 7. Sub-processors

7.1. **Authorisation.** Controller authorises Processor's use of the Sub-processors listed at <https://qualcanvas.com/trust#sub-processors> as of the date of this DPA. The current list (as of 2026-05-14) is reproduced in **Annex B**.

7.2. **Change notification.** Processor will notify Controller of the intended addition or replacement of a Sub-processor at least **30 days** in advance, by email to Controller's billing-contact address and by updating the Trust page.

7.3. **Objection.** Controller may object in writing within the 30-day notice period for documented reasons related to data protection. Processor will use reasonable efforts to provide an alternative arrangement; failing that, either party may terminate the affected portion of the Service.

7.4. **Onward obligations.** Processor will impose data-protection obligations on each Sub-processor substantially equivalent to those in this DPA, and remains liable for Sub-processor performance per Art. 28(4).

## 8. Audit

8.1. **Information rights.** Processor will, on request, make available to Controller (i) the most-recent independent audit reports it holds (e.g., SOC 2, ISO 27001 — currently in scoping; see Trust page), and (ii) responses to a standard security questionnaire.

8.2. **Audit by Controller.** Once per twelve (12) months, Controller may, on at least thirty (30) days' written notice and at Controller's expense, conduct an audit of Processor's compliance with this DPA, limited to documents, systems, and personnel relevant to the processing of Controller's Personal Data. Audits will occur during business hours, will not disrupt operations, and are subject to confidentiality undertakings reasonable to a SaaS provider.

8.3. **Regulator audits.** Nothing in 8.2 limits a competent supervisory authority's audit rights under Art. 58.

## 9. International transfers

9.1. Where processing involves transfer of Personal Data from the EEA / UK / Switzerland to a third country not subject to an adequacy decision, the parties agree the **European Commission's Standard Contractual Clauses (SCCs)** of 4 June 2021 ((EU) 2021/914), Module 2 (Controller-to-Processor), apply and are incorporated by reference. The UK Addendum to the SCCs (IDTA / UK Addendum, version B.1.0) applies to UK transfers.

9.2. Docking clause, supplementary measures, and Annex completion are set out in **Annex C**.

## 10. Return / deletion

On termination of the Agreement, Controller may, by written request received within thirty (30) days of termination, instruct Processor to (i) return all Personal Data in QDPX or CSV format, or (ii) delete all Personal Data. If no instruction is received within 30 days, Processor will delete all Personal Data (subject to backup-retention rotation in §11). The Trust page documents the practical schedule.

## 11. Retention

| Category                                              | Retention                                                              |
| ----------------------------------------------------- | ---------------------------------------------------------------------- |
| Active research content (transcripts, codings, memos) | Until Controller deletes the account; then hard-delete within 30 days. |
| Backups containing Personal Data                      | Weekly rotation, oldest backups expire 90 days after creation.         |
| Audit / access logs                                   | 90 days rolling.                                                       |
| Billing / tax records                                 | 7 years (statutory).                                                   |

## 12. Liability

The liability provisions of the Agreement apply to claims arising under this DPA.

## 13. Conflict & governing law

In the event of conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict. The DPA is governed by the same law as the Agreement, unless required otherwise by GDPR / UK GDPR.

## 14. Entry into force

This DPA takes effect on the later of (i) execution by both parties and (ii) the start of the Agreement term. It supersedes any prior data-processing terms between the parties.

---

## Annex A — Technical and organisational measures

The full Trust page (<https://qualcanvas.com/trust>) is incorporated by reference and updated as measures evolve. Material measures as of 2026-05-14:

- TLS 1.3 for all in-transit traffic, HSTS, HTTPS-only.
- Provider-managed at-rest encryption on Postgres + R2 storage.
- User-supplied AI API keys AES-256-GCM encrypted with per-deployment master key.
- bcrypt (cost 12) for stored passwords; JWT session cookies HttpOnly + SameSite=Lax; session rotation on password change.
- CSRF protection on state-changing requests.
- Audit logging of all authenticated reads + writes; 90-day retention.
- Weekly off-site backups to a private Cloudflare R2 bucket with a least-privilege API token; monthly restore drill (`docs/runbooks/RESTORE_DRILL.md`).
- Vulnerability disclosure intake at security@qualcanvas.com with 48-hour acknowledgement target.
- Roadmap items (not yet GA at signing): SOC 2 Type I (target Q3 2026), MFA (Q3 2026), SAML SSO (Q4 2026), EU region deployment (Q2 2026).

## Annex B — Sub-processors (as of 2026-05-14)

| Sub-processor                  | Purpose                                | Location    |
| ------------------------------ | -------------------------------------- | ----------- |
| Railway                        | Application + Postgres hosting         | US East     |
| Cloudflare                     | CDN, edge, DNS, R2 storage             | Global edge |
| Stripe                         | Payment processing                     | US          |
| Resend                         | Transactional email                    | US          |
| Google                         | OAuth identity (no data sharing)       | Global      |
| OpenAI / Anthropic / Google AI | LLM inference via Controller's BYO key | US          |
| Sentry                         | Error tracking                         | EU (DE)     |
| GitHub Actions                 | CI + backup automation                 | US          |

Current list always available at <https://qualcanvas.com/trust#sub-processors>.

## Annex C — SCC completion (Module 2, 2021/914)

- **Clause 7 (Docking clause):** Applies. Other parties may accede with the agreement of both parties.
- **Clause 9 (General authorisation):** Applies; the 30-day notice period in §7.2 of this DPA satisfies the option.
- **Clause 11 (Redress):** The optional independent-dispute-resolution language **does not** apply.
- **Clause 17 (Governing law):** Law of Ireland.
- **Clause 18 (Forum and jurisdiction):** Courts of Ireland.
- **Annex I.A (Parties):** Controller and Processor as identified in the Agreement.
- **Annex I.B (Description of transfer):** As set out in §1 of this DPA.
- **Annex II (Technical and organisational measures):** As set out in Annex A of this DPA.
- **Annex III (Sub-processors):** As set out in Annex B of this DPA.

---

_By countersigning the Agreement to which this DPA is attached, the parties confirm acceptance of this DPA._

**Processor:** QualCanvas — legal@qualcanvas.com
**Controller:** ********************************\_********************************
