Data Processing Addendum
1. Purpose
This Data Processing Addendum applies when Quesabyte processes personal information on behalf of a customer in providing managed-cloud, support, licensing or related services. It supplements the commercial agreement and applies only to the extent required by applicable data-protection law.
2. Roles and instructions
The customer acts as controller or equivalent business for customer-controlled data, and Quesabyte acts as processor or operator only on documented instructions needed to provide the service, unless law requires otherwise. The customer is responsible for lawful instructions, notices, consent, legal bases and data-subject requests relating to its own clients and users.
3. Security and confidentiality
Quesabyte will maintain appropriate technical and organisational measures, limit personnel access on a need-to-know basis and require confidentiality commitments. The customer must use appropriate account security, access control, configuration, encryption and backup measures for its own environment.
4. Subprocessors and transfers
Quesabyte may use subprocessors for infrastructure, communications, payments, support and security where necessary to provide the service, subject to appropriate contractual safeguards. International transfers will use lawful transfer mechanisms where applicable.
5. Assistance, incidents and deletion
Quesabyte will provide reasonable assistance with security incidents, data-subject requests, assessments and audits to the extent required by law and proportionate to the service. On termination, data handling, export and deletion are governed by the applicable service terms, technical capabilities, legal retention obligations and written instructions.
6. Priority and execution
This page is a public summary and does not replace a signed customer-specific data-processing agreement where one is required. In case of conflict, an executed written DPA or mandatory law prevails.
