Data Processing Agreement (Template)
This Data Processing Agreement ("DPA") forms part of the QAcademy AI Terms of Service between QAcademy AI ("Processor") and the Customer ("Controller") and governs the processing of personal data carried out by QAcademy AI on the Controller's behalf in connection with the QAcademy AI services.
1. Subject matter and duration
QAcademy AI processes personal data only on documented instructions from the Controller and only for the duration of the underlying services agreement.
2. Nature and purpose of processing
Hosting learner accounts, delivering course content, recording learning progress, issuing certificates, and providing analytics and support related to the QAcademy AI platform.
3. Categories of data subjects
- Learners and authorised users provisioned by the Controller.
- Administrators acting on the Controller's behalf.
- Where applicable, parents or guardians of minor learners.
4. Categories of personal data
- Identity data: name, email, optional avatar, role.
- Learning data: progress, submissions, exercise answers, certificate claims.
- Technical data: IP address, browser, timestamps for security and audit.
- Communications: support tickets and email correspondence.
5. Sub-processors
QAcademy AI uses the following sub-processors. The Controller is informed of any addition or replacement and may object on legitimate grounds.
- Supabase (database, auth, storage) — EU region available on request.
- Cloudflare (CDN, edge runtime) — global.
- Email delivery provider — disclosed at signature.
- Optional AI providers per Customer configuration — disclosed in product documentation.
6. International transfers
Where data is transferred outside the EEA or UK, transfers are protected by the European Commission's Standard Contractual Clauses (2021/914) and, where required, the UK International Data Transfer Addendum, plus supplementary technical measures (encryption in transit and at rest).
7. Security measures
QAcademy AI implements industry-standard organisational and technical measures, including: TLS 1.2+ in transit, AES-256 at rest, row-level security on all user data, role-based access, mandatory MFA for production admin, audit logs, least-privilege service accounts, encrypted secrets, and a documented incident response plan with 72-hour breach notification.
8. Data subject rights
QAcademy AI assists the Controller with responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timeframes set by applicable law.
9. Audit rights
QAcademy AI makes available all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits by the Controller or an independent auditor mandated by the Controller, on reasonable notice and during business hours.
10. Return or deletion
On termination of the services QAcademy AI deletes or returns all Controller personal data within 30 days, except where retention is required by law. Backups are purged on their standard 35-day rotation.
How to execute this DPA
This template is the starting point for a signed DPA between QAcademy AI and your organisation. To put it in force, email legal@qacademyai.com with your organisation name, billing entity and contracting jurisdiction. We will return a counter-signed copy within 5 business days.
This page is a template provided for transparency. The binding text is the version counter-signed with your organisation. Template effective July 2026.