Data Processing Addendum (DPA)
Effective Date: July 31, 2026 | Compliant with Article 28 GDPR
This Data Processing Addendum ("DPA") supplements the Terms of Service entered into by and between Qublin ("Processor") and the organization subscribing to the Service ("Customer" or "Controller"). This DPA governs the processing of Personal Data in connection with the Service pursuant to Article 28 of the General Data Protection Regulation (GDPR).
1. Scope and Roles
Customer acts as Data Controller and Qublin acts as Data Processor regarding any Personal Data contained within Customer Content indexed from connected workspaces (such as Notion, Slack, Google Drive, Jira, Confluence, Asana) or submitted via queries.
2. Processing of Personal Data
- Subject Matter: Provision of enterprise knowledge search, semantic indexing, and AI assistant services.
- Duration: The duration of Customer’s subscription to the Service plus post-termination deletion periods as specified herein.
- Nature & Purpose: Parsing, vector embedding generation, indexing, and LLM answer retrieval strictly to answer authorized Customer queries.
- Categories of Data: User account profile details, text messages, document content, task logs, and metadata within connected Customer workspaces.
3. Processor Obligations
Qublin covenants and agrees that it shall:
- Process Personal Data solely on documented instructions from Customer, including with respect to transfers outside the EEA.
- Ensure that personnel authorized to process Personal Data are bound by strict contractual confidentiality obligations.
- Implement technical and organizational security measures pursuant to Article 32 GDPR, including AES-256 encryption at rest for credentials and TLS encryption in transit.
- Notify Customer without undue delay upon becoming aware of a confirmed Personal Data Breach.
- Assist Customer in fulfilling its obligations to respond to data subjects' requests under Chapter III GDPR.
4. Authorized Sub-processors
Customer hereby grants general authorization to Qublin to engage the following sub-processors to deliver the Service:
- OpenAI, LLC (USA): Commercial LLM completion and embedding API provider. Transferred under EU-U.S. Data Privacy Framework / Standard Contractual Clauses (SCCs). Customer data sent via commercial API is NOT used to train public models.
- Infrastructure & Hosting Providers: Cloud hosting facilities used for web servers and tenant-isolated vector storage.
5. International Data Transfers
Where Personal Data is transferred outside the European Economic Area (EEA), the UK, or Switzerland, such transfers are safeguarded using valid transfer mechanisms under Chapter V GDPR, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs).
6. Deletion and Return of Data
Upon termination of Customer's account or disconnection of a workspace source, Qublin shall delete all corresponding vector indices, cached data, and OAuth credentials from active production systems in accordance with our data retention schedule.
7. Contact & Data Protection Inquiries
For any inquiries or requests regarding this DPA, please contact our Data Protection Officer at privacy@qublin.com.