Qualigio — Data Processing Addendum (DPA)

Version 2026-09-05.1 · Effective : 2026-09-05

This DPA forms part of the service agreement between SOMEPASS (Processor) and the individual or organization lawfully determining workspace processing (Controller), including a free workspace. It governs personal data processed on the Controller’s behalf and prevails over conflicting service terms on that subject. The parties’ actual roles and the representative’s authority must be established; an email-domain check alone does not do this.

https://www.qualig.io · France

1. Definitions

Personal Data, Processing, Controller, Processor, Personal Data Breach and Supervisory Authority have the meanings given by the GDPR. Workspace Data includes personal data in accounts, affiliation, configured content, participation, attachments, communications and technical logs needed to provide and secure the service on the Controller’s behalf.

2. Subject matter, scope and duration

Processing covers workspace operations configured or initiated by the Controller and its authorized users. It lasts for the service agreement and the return/deletion process described below. Processing details and data subjects are specified in Annex 1, with security measures in Annex 2 and subprocessors in Annex 3.

Quality-management workspaces provide configurable forms, records, evidence, workflows, actions, reviews and dashboards. The service does not itself grant certification or accreditation. The Owner decides which professional records to enter and which procedures to apply.

3. Processor obligations

Process data only on documented instructions, including for transfers, unless EU or Member State law requires otherwise; inform the Controller of such a requirement before processing unless the law prohibits that information. Authorized persons are bound by confidentiality and receive appropriate awareness. Implement appropriate security measures, assist with rights requests and GDPR Articles 32–36, notify breaches without undue delay and provide compliance and audit information. Immediately inform the Controller if an instruction appears unlawful and suspend that instruction pending clarification where necessary.

4. Controller obligations

Determine the lawful basis and purposes, inform the people concerned, minimize data and manage permissions and user lifecycle. Avoid special-category data unless necessary and lawful. Ensure that administrators are authorized to issue instructions and that connected integrations are appropriate. In education, verify authority to process learner data, organize minors’ access and invite partners; verify any institutional takeover before transferring instructions or administrative authority.

5. Confidentiality

All persons authorized to process Workspace Data are bound by a contractual or statutory duty of confidentiality. Access is limited to their authorized responsibilities.

6. Subprocessors and objections

The Controller grants general written authorization to engage the subprocessors identified in Annex 3. Before adding or replacing a subprocessor, the Processor informs the Controller in writing of the planned change, its processing and location, allowing a reasonable period to object before the new processing starts. A silent update to this page alone does not replace that notice. The parties seek a solution to reasonable data-protection objections; if none is feasible, the affected service may be terminated under the agreement.

The Processor imposes the same relevant data-protection obligations on each subprocessor by written contract, including appropriate security guarantees, and remains fully responsible to the Controller for the subprocessor’s performance.

7. International transfers

Core hosting is in France. Processing by global providers can take place outside the EEA, UK or Switzerland as applicable. Such transfers follow documented instructions and applicable transfer requirements, using an adequacy decision or Standard Contractual Clauses and supplementary measures where required. Information on the relevant destinations and safeguards is available through the privacy contact.

8. Personal data breaches

Notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Workspace Data. Provide available information on its nature, categories and approximate number of people and records, likely consequences, contact point and remediation. Information may be completed progressively; notification is not delayed until every detail is known. The Controller handles notifications to authorities and people unless otherwise agreed.

9. Return and deletion

At the end of the processing service, return or delete all Workspace Data at the Controller’s choice and delete existing copies, unless EU or Member State law requires retention. Technical difficulties are addressed through an agreed operational process and do not remove this obligation. The parties document the requested scope, available usable return formats, a completion schedule and confirmation of the steps performed. Requests can be made through the privacy form.

Data remaining in protected backups is isolated from ordinary use and deleted through the documented rotation cycle, whose applicable schedule is communicated to the Controller. Backup copies are used only for necessary restoration, resilience checks, security or legal obligations. Deletion instructions are reapplied on restoration. Any legally retained data is restricted to the required purpose and duration.

10. Audits and compliance information

Provide the information needed to demonstrate compliance with this DPA and Article 28, and allow and contribute to audits, including inspections, by the Controller or its appointed auditor. Documentation and written answers can be used where appropriate. On-site audits are arranged with reasonable notice, confidentiality, a proportionate scope and reasonable operating conditions; these arrangements must not prevent an effective audit.

11. Assistance with individual rights

Assist the Controller through appropriate measures, taking account of the nature of processing, with access, rectification, deletion, restriction, portability and objection requests. Direct workspace requests received by the Processor are coordinated with the Controller, without determining a new purpose for the data.

12. Liability

Liability follows the service agreement, subject to mandatory data protection law and the rights of the persons concerned.


Annex 1 — Processing details

Processing occurs continuously during service use and includes hosting, storage, retrieval, display, access control, collaboration, backups, security monitoring and instructed support. Where available and authorized, it also includes mobile notification delivery and optional integration exchanges. These are not intended for special-category data. The applicable product details are as follows.

Workspace data can include employees, contractors, reviewers, auditors, suppliers, customers and other persons represented in configured forms, quality records, evidence, actions, reviews, attachments and reporting data.

An optional external assistant connection to Qualigio through MCP lets that client receive schemas and records accessible under the account’s enabled modules, permissions, fields and visibility rules. The MCP service described here is read-only. Requested content is transmitted to the connected client and may be processed by its provider under the agreement selected by the organisation. The organisation must assess recipients, purposes, retention and any transfers outside the EEA. Interconnection with PB Learning is limited to associated accounts, enabled functions and the corresponding permissions.

Available objects, forms, views, exports and modules depend on the account schema and configuration. Business-specific adaptations, approval processes, data migration and integrations require an agreed scope. The platform does not provide a universal workflow editor or a contract electronic-signature service by default.

An institutional agreement may cover several identified PB Learning and Qualigio workspaces with their annexes and enabled processing activities. Service-specific instructions, contacts, providers, transfers, security measures and return arrangements are specified in the agreed package. Ending one service does not automatically end the other. A new public version does not amend a signed DPA outside its agreed change procedure; any addition or replacement of a subprocessor follows the applicable authorisation and objection process.

Recently accessed workspace records may be cached in encrypted device storage for no more than 14 days and are cleared when you sign out through the application. Camera or photo access is used when you choose to attach an image. If push notifications are enabled, Firebase Cloud Messaging receives a device registration token and routing data. We retain associated platform, version, locale and optional device label. The token is detached on successful sign-out and may be removed when invalid or stale; notification content is limited to alerting and routing.

Annex 2 — Technical and organizational measures

Annex 3 — Subprocessors

The following providers support workspace processing. Optional identity and assistant providers selected by users or the Controller may act under their own agreement; the Privacy Policy describes these exchanges. Providers used for our own billing are described there separately, according to their role, rather than presented as recipients of all workspace data.

ProviderPurpose and dataMain location
OVHcloudHosting, databases, storage and backups: workspace data and operational logs.EU (France)
Cloudflare, Inc.DNS, CDN, traffic delivery, WAF and bot/DDoS protection: technical and traffic data needed for the configured services.Global, including outside the EEA
PostmarkTransactional email: recipient addresses, message content and delivery metadata.United States / global
Google Firebase Cloud MessagingAuthorized mobile push delivery: device registration tokens, technical routing data and the notification payload sent by the service.Global, including outside the EEA