Chargement...
Traitement en cours...

Data Processing Addendum (DPA)

Last updated 2026-07-07

Legal Contact

This Data Processing Addendum (“DPA”) forms part of the agreement between SOMEPASS (“Processor”) and the verified individual or organization operating a Workspace (“Controller”), regarding the processing of personal data under the Services (the “Services”).

Host location: France · Public site: https://www.qualig.io
Procurement-ready summary
Designed to align with Article 28 GDPR and common procurement expectations: subprocessors transparency, security measures, incident response, audit support, and international transfer safeguards.
GDPR Art. 28 Subprocessors TOMs Audit
Priority / order of precedence
In case of conflict between this DPA and the main agreement regarding the processing of Workspace Data, this DPA shall prevail.

1. Definitions

“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Supervisory Authority” have the meanings set out in the GDPR.

“Workspace Data” means Personal Data processed on behalf of the Controller within a Workspace, including account affiliation, Controller-configured Content, participation and activity data, attachments, communications and technical logs necessary to provide, secure and operate the Services.

2. Subject-matter, scope and duration

  • Subject-matter: provision of quality-management Workspace features, including configurable forms, records, evidence, workflows, actions, reviews, dashboards, Content hosting and access control.
  • Scope: processing is performed only for workspace operations configured or initiated by the Controller (admins/instructors) and the Controller’s users.
  • Duration: for the term of the Services agreement, plus limited periods for deletion/return and backups as described in section 9.

3. Processor obligations

  • Process Workspace Data only on documented instructions from the Controller (including configuration/admin actions, support requests, and written instructions).
  • Ensure authorized persons are bound by confidentiality and receive appropriate data protection/security awareness.
  • Implement appropriate technical and organizational measures (“TOMs”) to protect Workspace Data (see Annex 2).
  • Assist the Controller with GDPR obligations (Articles 32–36) as reasonably required given the nature of processing and available tools.
  • Notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Workspace Data (see section 8).
  • Make available information necessary to demonstrate compliance and support audits as described in section 10.
Unlawful instruction safeguard: If the Processor believes an instruction infringes applicable data protection law, the Processor will inform the Controller and may suspend execution of the instruction until clarified or modified.

4. Controller obligations

  • Ensure a valid legal basis and provide required notices to data subjects and users.
  • Ensure data minimization and avoid uploading special categories of data unless strictly necessary and lawful.
  • Manage permissions, access, and user lifecycle within the workspace.
  • Use the Services in compliance with applicable data protection and sector-specific laws.
  • Ensure each person acting as an Administrator is authorized to issue instructions on the Controller’s behalf.

5. Confidentiality

Processor ensures persons authorized to process Workspace Data are under an appropriate duty of confidentiality, whether contractual or statutory.

6. Subprocessors

The Controller grants a general authorization for the Processor to engage subprocessors as necessary to provide the Services. The Processor remains responsible for each subprocessor’s performance of its obligations.

The Processor maintains an up-to-date list of subprocessors (Annex 3) and will provide notice of material changes where reasonably possible. Notice may be provided via the Services, a legal page update, or other reasonable written notice. Where practicable, the Processor will provide advance notice.

If the Controller objects to a new subprocessor on reasonable data protection grounds, the parties will work in good faith to resolve the objection. If no resolution is feasible, the Controller may terminate the affected part of the Services in accordance with the main agreement.

7. International transfers

Processing is hosted in France. Where a subprocessor processes Workspace Data outside the EEA/UK/Switzerland (as applicable), the Processor will implement appropriate safeguards (e.g., adequacy decision and/or Standard Contractual Clauses), and additional measures where required by law.

8. Incident response & breach notification

  • Processor will notify Controller without undue delay after becoming aware of a confirmed Personal Data Breach affecting Workspace Data.
  • Notification will include (to the extent available): nature of breach, categories and approximate number of data subjects/records, likely consequences, and remediation steps taken or proposed.
  • Controller is responsible for regulatory notifications and communications to data subjects unless otherwise agreed in writing.

9. Deletion / return of Workspace Data

Upon termination or expiry of the Services, the Processor will, at the Controller’s choice and where technically feasible: (a) return Workspace Data; and/or (b) delete Workspace Data.

Processor may retain Workspace Data where required by law, or where data remains in protected backups until overwritten through the documented backup lifecycle. Backup data is isolated from ordinary use and is not processed further except for restoration, resilience testing, security or legal obligations. If restored, applicable deletion instructions are reapplied.

10. Audit & compliance support

Processor will provide reasonable information necessary to demonstrate compliance with this DPA and Article 28 GDPR. Where possible, audits will be satisfied through documentation, written responses, and security reports.

If an on-site audit is required, it must be: (i) pre-scheduled with reasonable notice, (ii) limited in scope to Workspace Data processing, (iii) conducted during business hours, (iv) subject to confidentiality, and (v) not unreasonably disruptive.

11. Assistance with data subject requests

Processor will provide reasonable assistance to enable the Controller to respond to requests to exercise data subject rights (access, rectification, deletion, restriction, portability, objection), taking into account the nature of processing and available tools. Requests can be initiated via the privacy request form.

12. Liability

Liability under this DPA follows the main agreement, subject to mandatory data protection law.


Annex 1 — Processing details

  • Categories of data subjects: employees, contractors, Workspace Administrators, reviewers, auditors, suppliers, customers or other persons represented in records configured by the Controller.
  • Categories of Personal Data: identifiers (name, email, username), role and affiliation, Workspace participation and activity data, form responses, quality records, evidence, actions, reviews, attachments and reporting data, plus audit and security logs necessary to operate the Services , and mobile session, device, application-version and locale metadata where the native application is used , including notification-registration metadata.
  • Special categories of data: not intended. Controller should avoid uploading special categories unless strictly necessary and lawful.
  • Processing operations: hosting, storage, retrieval, display, collaboration features, access control, backups, security monitoring, support troubleshooting , and delivery of authorized mobile push notifications (as instructed).
  • Frequency of processing: continuous during use of the Services.

Annex 2 — Technical & organizational measures (TOMs)

Area Measures
Access control Role-based access control (RBAC), least privilege, admin-managed invitations, separation between workspaces/tenants.
Encryption TLS for service traffic in transit; infrastructure-level storage protection where configured; encrypted device storage for mobile sessions and cached records; application secrets kept outside source-controlled application data.
Logging & monitoring Security and audit logs to detect abuse, investigate incidents, and support operational troubleshooting.
Backups Restricted backup access, defined backup cycles, restoration procedures and reapplication of deletion controls after restoration.
Secure development Dependency management, vulnerability remediation and separation of development and production configuration and credentials.
Incident response Triage, containment, remediation, communications workflow, post-incident review and corrective actions.
Business continuity Operational procedures for service recovery; backup validation; change management for critical components.

Annex 3 — Subprocessors

Transparency

The following subprocessors support the current Services. Optional sign-in and integration providers selected by a user or Controller are described in the Privacy Policy and may act under their own terms rather than as Processor subprocessors.

Subprocessor Purpose Data categories Primary location
OVHcloud Hosting infrastructure (compute, databases, object storage), backups Workspace Data + operational logs EU (France)
Cloudflare, Inc. DNS, CDN, WAF / DDoS protection, bot protection, performance & security Technical data (IP, headers, security signals) Global (incl. non-EEA)
Postmark Transactional email delivery (account emails, notifications) Email address + message metadata (delivery) US / Global
Google Firebase Cloud Messaging Delivery of mobile push notifications Device registration token, platform and limited notification-routing data EEA / Global

Published by: SomePass.net