Data Processing Agreement

Version: 1.0
Effective Date: November 17, 2025

This Data Processing Agreement (“DPA”) forms an integral part of the Terms and Conditions (“Agreement”) between:

Data Processor:
QuantixAI s.r.o.
IČO 57306290 Svatoplukova 15, 903 01, Senec, Slovak Republic
(“Processor”, “we”, “us”, “our”)

Data Controller:
The Customer as identified in the Agreement
(“Controller”, “you”, “your”)

(each a “Party” and collectively the “Parties”)

This DPA is entered into in accordance with Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation - “GDPR”) and governs the Processing of Personal Data by the Processor on behalf of the Controller.


1. Definitions

Terms not defined herein shall have the meaning set forth in the GDPR. Additionally:


2. Relationship of the Parties

2.1 Independent Controller Determination

The Controller has independently determined the purposes and means of Processing Personal Data.

2.2 Processor Obligations

The Processor shall Process Personal Data only as a Processor on behalf of and for the benefit of the Controller.

2.3 Individual Instructions

The Parties acknowledge that this DPA along with the Agreement constitute the Controller’s complete and final documented instructions to the Processor regarding the Processing of Personal Data. Any additional or alternate instructions must be agreed in writing.


3. Duration and Termination

3.1 Duration

This DPA shall remain in effect for the duration of the Agreement and as long as the Processor Processes Personal Data on behalf of the Controller.

3.2 Termination

This DPA shall automatically terminate upon termination of the Agreement, subject to survival provisions in Section 14.

3.3 Post-Termination Processing

Upon termination, the Processor shall, at the Controller’s written instruction:


4. Nature, Purpose, and Scope of Processing

4.1 Nature of Processing

The Processor shall perform the following Processing activities:

4.2 Purpose of Processing

Personal Data shall be Processed solely for:

4.3 Duration of Processing

Personal Data shall be Processed for the duration specified in Section 3.

4.4 Types of Personal Data

The following categories of Personal Data may be Processed:

4.5 Categories of Data Subjects


5. Processor Obligations

5.1 Compliance with Instructions

The Processor shall:

5.2 Confidentiality

The Processor shall:

The Processor remains liable for actions and omissions of its Authorized Persons as if they were its own.

5.3 Security of Processing

The Processor shall implement and maintain the Technical and Organizational Measures specified in Annex 1.

5.4 Data Subject Rights

The Processor shall:

5.5 Data Protection Impact Assessment

The Processor shall provide reasonable assistance for the Controller’s:

5.6 Personal Data Breach Notification

The Processor shall:

5.7 Data Protection Officer

The Processor shall designate a data protection contact point:

5.8 Records of Processing Activities

The Processor shall maintain complete and accurate records of all Processing activities as required by GDPR Article 30.


6. Sub-processors

6.1 General Authorization

The Controller provides general authorization for the Processor to engage Sub-processors, subject to the requirements in this Section.

6.2 Current Sub-processors

The Controller acknowledges and approves the use of the following Sub-processors:

Sub-processor Purpose Location Data Transferred
Auth0 Inc. (Okta) Authentication & Identity Management USA User credentials, email, IP addresses
Paddle.com Market Ltd. Payment Processing UK Billing information, email
Hetzner Online GmbH Cloud Infrastructure Germany All Service data
Scaleway Cloud Infrastructure Poland Service data
SmartSelling a.s. Email Notifications Czech Republic Email addresses, notification content, email marketing, marketing preferences
Google LLC (Google Analytics) Website Analytics USA Website usage data, IP addresses (anonymized)

6.3 Sub-processor Requirements

The Processor shall:

6.4 Notification of Changes

The Processor shall:

6.5 Objection Rights

The Controller may object to new Sub-processors within 14 days by providing reasonable grounds related to data protection. If objection cannot be resolved within 30 days, the Controller may terminate the affected Services.


7. International Data Transfers

7.1 Transfer Mechanisms

For transfers outside the EEA, the Processor shall ensure:

7.2 Transfer Impact Assessment

The Processor has conducted and maintains a Transfer Impact Assessment (TIA) confirming adequate protection levels.

7.3 Supplementary Measures

Where necessary, the Processor implements supplementary measures including:

7.4 Transparency

The Processor shall:


8. Security Measures

8.1 Technical and Organizational Measures

The Processor implements the measures detailed in Annex 1, including but not limited to:

The Processor may update the TOMs as necessary, provided such changes do not materially diminish the protection of Personal Data. Controller shall be notified of material changes in advance.

8.2 Security Assessments

The Processor shall:

8.3 Business Continuity

The Processor maintains:


9. Audit Rights

9.1 Information and Audit

The Controller may exercise audit rights through:

9.2 Audit Procedures

9.3 Third-Party Audits

The Controller may accept third-party certifications (ISO 27001, SOC 2) in lieu of audits.


10. Liability and Indemnification

10.1 Liability Allocation

Each Party’s liability shall be determined in accordance with Articles 82 GDPR and the limitation of liability provisions in the Agreement.

10.2 Indemnification

The Processor shall indemnify the Controller against damages resulting from:

10.3 Insurance

The Processor maintains cyber liability insurance with minimum coverage of €2,000,000 per incident.


11. Controller Obligations

The Controller warrants and represents that:


12. Specific Jurisdictional Provisions

12.1 California Privacy Rights (CCPA/CPRA)

For Controllers subject to California privacy laws:

12.2 UK Data Protection

For UK Controllers:

12.3 Swiss Data Protection

For Swiss Controllers:


13. Miscellaneous

13.1 Order of Precedence

In case of conflict:

  1. Mandatory Data Protection Laws
  2. This DPA
  3. The Agreement
  4. Other contractual documents

13.2 Amendments

Modifications to this DPA must be in writing and signed by both Parties.

13.3 Severability

If any provision is invalid, the remaining provisions continue in full force.

13.4 Entire Agreement

This DPA constitutes the complete agreement regarding Personal Data Processing.


14. Survival

The following provisions survive termination:


15. Governing Law and Jurisdiction

15.1 Governing Law

This DPA is governed by the laws of the Slovak Republic.

15.2 Jurisdiction

Disputes shall be submitted to the exclusive jurisdiction of the courts of Bratislava, Slovak Republic.


Signatures

By accepting the Agreement incorporating this DPA, the Parties agree to comply with all terms herein.

Data Controller:
[Automatically accepted upon Agreement acceptance]

Data Processor:
QuantixAI s.r.o.
[Pre-signed on behalf of Processor]


ANNEX 1: Technical and Organizational Measures (TOMs)

A. Technical Measures

1. Data in Transit Protection

2. Data at Rest Protection

3. Access Control

4. Network Security

5. Application Security Headers

6. Monitoring and Maintenance

7. Data Processing Locations

B. Organizational Measures

1. Incident Management


ANNEX 2: Data Processing Details

Processing Activities

Activity Purpose Legal Basis Retention Period
User Authentication Service access Contract performance Duration of account + 30 days
Usage Analytics Service improvement Legitimate interest 24 months
Support Tickets Customer assistance Contract performance Resolution + 12 months
Billing Records Payment processing Legal obligation 7 years
Security Logs Security monitoring Legitimate interest 12 months
Backup Data Business continuity Legitimate interest 30 days rolling

Data Categories and Subjects

Data Category Data Subjects Purpose
Identity Data Controller employees Account management
Contact Data Controller staff Communications
Authentication Data System users Access control
Usage Data Service users Performance monitoring
Business Data Controller customers Service delivery
Technical Data All users Security and troubleshooting

ANNEX 3: Standard Contractual Clauses

[Incorporated by reference: Commission Implementing Decision (EU) 2021/914 of 4 June 2021]

The Standard Contractual Clauses for transfers of personal data to third countries pursuant to Regulation (EU) 2016/679 are hereby incorporated where applicable, with the following parameters:


Version History:

Version Date Changes
1.0 November 17, 2025 Initial release

This DPA is executed as part of and incorporated into the Agreement between the Parties.