Data Processing Addendum
In one line
The contract terms that apply when we process personal data for your business. It covers instructions, security, subprocessors, breaches, transfers, and deletion.
The short version
This short version helps you understand the full text. Read the full text for the complete terms.
- This addendum is part of our Terms. It applies whenever we process personal data on your behalf. (Full text, section 1)
- We act only on your documented instructions, and the main instruction is "run the service as configured". (Section 3)
- Our staff keep your data confidential. We protect it with the measures in Annex 2. (Sections 4 and 5)
- We use only the subprocessors on our list, and we give you 30 days' notice before adding one. You may object. (Section 6)
- We tell you about a personal data breach without undue delay, and within 48 hours of confirming it. (Section 7)
- We help you answer people's requests and carry out impact assessments. (Section 8)
- For international transfers we use the EU Standard Contractual Clauses, the UK Addendum, and the Swiss amendments. (Section 9)
- When the service ends, we delete or return your data within 30 days, unless the law requires us to keep it. (Section 10)
Full text
Read the full text (about 6 minutes)
1. Scope and order of precedence
1.1 This Data Processing Addendum ("DPA") forms part of the agreement between [ENTITY NAME] ("Processor") and the Customer ("Controller") for qypu (the "Agreement").
1.2 It applies to Personal Data that we process on the Customer's behalf ("Customer Personal Data"). Terms such as "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings in the GDPR, or the nearest equivalent under other Data Protection Laws.
1.3 "Data Protection Laws" means all privacy and data protection laws that apply to the processing, including: the GDPR; the UK GDPR and the Data Protection Act 2018; the revFADP; PIPEDA and Quebec Law 25; US state privacy laws (including the CCPA as amended by the CPRA); the Singapore PDPA; the Australian Privacy Act 1988; and the New Zealand Privacy Act 2020.
1.4 If this DPA conflicts with the Agreement, this DPA wins. If it conflicts with the Standard Contractual Clauses, the Clauses win.
2. Details of processing
Annex 1 describes the subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects.
3. Instructions
3.1 We process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless the law requires otherwise; in that case we will tell the Customer first, unless the law forbids it.
3.2 The Agreement, the Customer's configuration of qypu, and signed posts are the Customer's complete instructions at the time of signing. Further instructions must be in writing and consistent with the Agreement.
3.3 We will tell the Customer promptly if we believe an instruction breaks Data Protection Laws.
3.4 US service provider terms. We will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes in the Agreement; or combine it with personal data from other sources except as the CCPA permits. We will comply with the CCPA and give the same level of privacy protection it requires, and we will notify the Customer if we can no longer meet our obligations. The Customer may take reasonable steps to stop and remedy unauthorised use.
4. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality obligations.
5. Security
We implement the technical and organisational measures in Annex 2 and keep them appropriate to the risk. We may update them, provided the update does not reduce overall protection.
6. Subprocessors
6.1 The Customer gives general authorisation for us to use the subprocessors listed at qypu.ai/trust/subprocessors.
6.2 We will give at least 30 days' notice of a new subprocessor by updating that page and emailing subscribers. The Customer may object, giving data protection reasons, during that period. If we cannot resolve the objection, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
6.3 We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain liable for their performance.
7. Personal data breaches
7.1 We will notify the Customer without undue delay, and in any case within 48 hours, after we confirm a personal data breach affecting Customer Personal Data.
7.2 The notice will include what we know about the nature of the breach, the categories and approximate number of people and records affected, likely consequences, the measures taken or proposed, and a contact point. We will send further information as it becomes available.
7.3 Notifying a breach is not an admission of fault.
8. Assistance
8.1 Taking into account the nature of the processing, we will help the Customer respond to data subject requests, mainly through self-service tools in qypu.
8.2 We will provide reasonable help with data protection impact assessments, prior consultations, and security obligations.
8.3 We will forward to the Customer any request we receive directly from a data subject about Customer Personal Data, without responding beyond acknowledging it, unless the Customer authorises us.
9. International transfers
9.1 Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor) and, where we act as a subprocessor, Module 3, are incorporated by reference, with: optional Clause 7 included; Clause 9 option 2 (general authorisation, 30 days' notice); Clause 11 optional language omitted; Clause 17 and 18 governed by the law and courts of [EU MEMBER STATE — counsel to choose]; and the Annexes completed by Annexes 1 and 2 of this DPA.
9.2 For UK data, the International Data Transfer Addendum to the EU SCCs issued by the ICO (version B1.0) applies, with Table 1 to 3 completed from this DPA and either party able to end it as Section 19 permits.
9.3 For Swiss data, the SCCs apply with these changes: the FDPIC is the competent supervisory authority; "Member State" includes Switzerland so Swiss data subjects can sue where they live; and references to the GDPR include the revFADP.
9.4 Where a recipient is certified under the EU–US Data Privacy Framework (or its UK or Swiss extensions), we may rely on that certification instead.
9.5 For transfers from other jurisdictions (for example, out of Quebec, Singapore, Australia, or New Zealand), we provide comparable contractual protection and support any assessment the law requires.
10. Return and deletion
Within 30 days after the Agreement ends, we will delete Customer Personal Data, or return it in a portable format if the Customer asks before the end date, unless the law requires us to keep it. Backups roll off within a further 35 days.
11. Audits
11.1 We will make available information reasonably needed to demonstrate compliance with this DPA, including our Security Overview, policies, and answers to a reasonable security questionnaire once a year.
11.2 If that information is not enough, or a regulator requires it, the Customer may audit us on 30 days' notice, during business hours, at its own cost, through an independent auditor bound by confidentiality, no more than once in 12 months unless a breach has occurred.
12. Liability
Liability under this DPA is subject to the liability terms of the Agreement, except where Data Protection Laws or the SCCs do not allow that.
Annex 1 — Details of processing
- Subject matter and duration: providing qypu for the term of the Agreement.
- Nature and purpose: hosting, storing, generating drafts with AI, running Checks, publishing signed content to connected channels, collecting results, and support.
- Data subjects: the Customer's Authorised Users, staff, customers, and followers who appear in content, comments, or messages; people whose voice or likeness the Customer licenses.
- Personal data: names; handles; profile images; messages and comments; contact details; voice and image data (only with consent); and usage data.
- Special categories: none intended. The Customer must not upload special category data unless agreed in writing.
- Frequency: continuous.
- Retention: as in the Data Retention and Deletion Policy.
Annex 2 — Technical and organisational measures
See the Security Overview at qypu.ai/trust/security. Each measure is labelled "In place" or "Planned". Only measures labelled "In place" form part of this Annex until we update it.
Annex 3 — Subprocessors
See qypu.ai/trust/subprocessors (machine-readable at /trust/subprocessors.json).
Change log
- 2026-10-10 · 0.1.0 · First draft for counsel review.
Open questions for counsel
We publish these while the page is a draft, so you can see what is not settled yet.
- Choose SCC governing law and courts (Clause 17 and 18), and complete the SCC Annex I.A party details once the entity exists.
- If the entity is in the UK or Switzerland and not in the EU, confirm the transfer modules and whether Module 4 is needed for any flows back to customers.
- 48-hour breach notice to customers: confirm this is operationally achievable; the GDPR requires processors to notify "without undue delay".
- US: confirm the CCPA service provider terms match the current regulations (11 CCR §7051).
- Quebec: a privacy impact assessment is required before transferring personal information outside Quebec (s.17 Private Sector Act).
- Annex 2 lists "Planned" controls; make sure only "In place" controls are contractually committed.
Useful for: Business owners, IT and security reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.