Qua
MultiplayerWhy QuaHow it worksProofCompareSkillsDeployment
Login →
MultiplayerWhy QuaHow it worksProofCompareSkillsDeploymentLogin →
Legal

Data Processing Agreement

Qua's processor terms for customers, matching the data flows the product actually runs: what we process and why, which subprocessors are involved, how transfers are covered, the security measures in place, and how to reach us for data requests.

Last updated: August 25, 2026Applies to: qua.dev and the Qua application
  1. 1. Scope, roles and order of precedence
  2. 2. Details of processing (Annex I)
  3. 3. Processing instructions
  4. 4. Personnel and confidentiality
  5. 5. Security measures (Annex II)
  6. 6. Subprocessors (Annex III)
  7. 7. International transfers
  8. 8. Data subject requests and assistance
  9. 9. Personal data breach notification
  10. 10. Return and deletion of data
  11. 11. Audits and demonstrating compliance
  12. 12. US state privacy law terms
  13. 13. Contact for data requests

1. Scope, roles and order of precedence

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Qua and the customer ("Customer"). It applies whenever Qua processes personal data on Customer's behalf in providing the Qua workspace.

  • Customer is the controller (Data Fiduciary under India's DPDP Act; "business" under the CCPA/CPRA) of personal data contained in Customer Content.
  • Qua is the processor (Data Processor; "service provider" under the CCPA/CPRA) and processes that data only on Customer's documented instructions.
  • Qua is an independent controller for its own account, billing, security and website data, as described in the Privacy Policy.

Where this DPA conflicts with the Agreement in respect of the processing of personal data, this DPA controls. The EU Standard Contractual Clauses, where they apply, prevail over both.

2. Details of processing (Annex I)

Subject matterProvision of the Qua governed AI workspace: session resolution, retrieval over Customer knowledge sources, artifact generation, and cost/outcome measurement.
DurationThe term of the Agreement, plus the deletion window in section 10.
Nature and purposeHosting, storage, indexing, transmission to model and retrieval providers selected by Customer's users and policies, generation of outputs, logging, security and support.
Categories of data subjectsCustomer's personnel and authorised users; any individuals referenced in prompts, uploaded documents or connected sources.
Categories of personal dataIdentification and contact data; employment and organizational data (department, role); content data (prompts, messages, documents, artifacts, memory entries); usage and technical data (session metadata, receipts, IP address, device and log data); derived data (embeddings, cache entries, scores).
Special category / sensitive dataNot contemplated. Customer must not submit special category data, protected health information, payment card data, or government identifiers unless separately agreed in writing.
FrequencyContinuous, for the duration of the Agreement.
Competent supervisory authorityDetermined by Customer's establishment or its Article 27 representative.

3. Processing instructions

Qua processes Customer personal data only (a) to provide, secure and support the service in accordance with the Agreement, (b) as further instructed in writing by Customer, and (c) where required by law, in which case Qua will notify Customer unless legally prohibited.

Customer's configuration of the workspace — policies, budgets, model approvals, whether the Open Models tier and web retrieval are enabled, knowledge scopes and connectors — constitutes documented instructions. Qua will inform Customer if, in its opinion, an instruction infringes applicable data protection law.

No training, no sale, no secondary use. Qua does not use Customer personal data to train models, does not sell or share it as those terms are defined under the CCPA/CPRA, and does not retain, use or disclose it for any purpose outside the direct business relationship. Qua certifies it understands and will comply with these restrictions.

4. Personnel and confidentiality

Qua limits access to Customer personal data to personnel who need it to deliver the service, binds them to written confidentiality obligations that survive employment, applies least-privilege access with audit logging of privileged actions, and trains personnel on data protection and security.

5. Security measures (Annex II)

  • Encryption — TLS 1.2+ in transit; AES-256 at rest for the database, object storage and backups.
  • Tenant isolation — row-level security in the database enforcing organization, department and user scope on every read and write; no cross-organization access path.
  • Access control — role-based access (member, functional admin, org admin, platform operator), unique accounts, SSO/OAuth support, and multi-factor authentication on administrative systems.
  • Governance controls — policy evaluation before routing, maximum-tier clamps, prompt masking rules, and an explicit confirmation step before unselected private sources can be sent to an external provider.
  • Logging and monitoring — administrative audit ledger, moderation ledger, per-turn resolution traces, and alerting on anomalous activity.
  • Resilience — managed, encrypted, point-in-time backups with a rolling 35-day window and periodic restore testing.
  • Secure development — code review, dependency scanning, secret management outside source control, and separated environments.
  • Vendor management — security review of subprocessors before onboarding and periodically thereafter.

Qua may update these measures provided the overall level of security is not reduced.

6. Subprocessors (Annex III)

Customer grants general authorisation for Qua to engage the subprocessors listed on the subprocessor page, which is incorporated into this DPA and kept current with the product's data flows. Each is engaged under a written contract with protections no less protective than this DPA, and Qua remains liable for their performance.

Qua gives at least 30 days' notice before a new subprocessor begins processing. Customer may object on reasonable data-protection grounds; if no reasonable alternative configuration is available, Customer may terminate the affected subscription with a pro-rata refund of prepaid, unused fees.

CategorySubprocessors
Infrastructure and platformLovable Labs Incorporated (Lovable Cloud) · Supabase Inc. (managed through Lovable Cloud) · Amazon Web Services, Inc. · Cloudflare, Inc.
Model providers — United StatesLovable AI Gateway · Google LLC (Gemini models) · OpenAI, L.L.C. · Anthropic PBC · Groq, Inc.
Model providers — outside the US/EUHangzhou DeepSeek Artificial Intelligence Co., Ltd. · Alibaba Cloud (Qwen) · Moonshot AI (Kimi)
Retrieval, media and communicationsFirecrawl (Sideguide Technologies, Inc.) · Exa Labs, Inc. · ElevenLabs Inc.

7. International transfers

The primary application database is hosted in Australia (AWS ap-southeast-2). Model, retrieval and speech providers are located primarily in the United States; the optional Open Models tier includes providers in mainland China and Singapore.

  • For transfers of personal data from the EEA, the parties adopt the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two(controller to processor), with Customer as data exporter and Qua as data importer; Module Three applies where Customer is itself a processor. Docking clause applies; the governing law is Ireland and the courts of Ireland have jurisdiction; Annexes I–III are populated by sections 2, 5 and 6 of this DPA.
  • For transfers from the United Kingdom, the UK International Data Transfer Addendum (version B1.0) applies to the Clauses, with the UK Information Commissioner as competent authority.
  • For transfers from Switzerland, references to the GDPR are read as references to the Swiss FADP and the Federal Data Protection and Information Commissioner is the competent authority.
  • Qua maintains transfer impact assessments and will notify Customer if it becomes unable to comply with the Clauses.

8. Data subject requests and assistance

Qua provides Customer with self-service controls to access, export, correct and delete Customer Content, which will ordinarily be sufficient to respond to a data subject request. Where a request is made directly to Qua, Qua will not respond substantively and will refer the individual to Customer without undue delay.

Taking into account the nature of processing, Qua will provide reasonable assistance with data subject requests, data protection impact assessments, prior consultations with supervisory authorities, and security obligations under Articles 32–36 of the GDPR and the equivalent provisions of the UK GDPR and the DPDP Act.

9. Personal data breach notification

Qua will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer personal data. The notice will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point. Qua will cooperate with Customer's own notification obligations. Notifications are not an admission of fault.

10. Return and deletion of data

  • During the term, Customer may delete any session, artifact, knowledge source or user through the application; deletions remove derived embeddings and index entries in the same operation.
  • Customer may export sessions, ledger data and artifacts at any time in machine-readable formats.
  • On termination, Qua will delete or return all Customer personal data within 30 days at Customer's election, except where retention is required by law.
  • Encrypted backups containing deleted data expire on a rolling 35-day cycle; deleted data is not restored into the live system.
  • Qua will confirm deletion in writing on request.

11. Audits and demonstrating compliance

Qua will make available the information necessary to demonstrate compliance with this DPA, including security documentation, its subprocessor list and available third-party reports. Customer may, no more than once in any twelve-month period and on 30 days' written notice, audit Qua's compliance — or appoint an independent auditor bound by confidentiality — during business hours, without unreasonably disrupting Qua's operations and without access to other customers' data. Additional audits are permitted where required by a supervisory authority or following a confirmed breach. Requests: dpo@qua.dev.

12. US state privacy law terms

With respect to personal information subject to the California Consumer Privacy Act as amended by the CPRA, and to comparable laws in Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana, Qua acts as a service provider or processor. Qua will not sell or share that personal information, will not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by law, will not combine it with personal information from other sources except as permitted, and will comply with applicable obligations. Qua will notify Customer if it determines it can no longer meet these obligations and will permit reasonable steps to stop and remediate unauthorised use.

13. Contact for data requests

To request a signed copy of this DPA, execute the Standard Contractual Clauses, or make any data protection request:

DPA execution and auditsdpo@qua.dev
Data subject requests, access, correction and deletionprivacy@qua.dev
Grievance Officer (India, DPDP Act)grievance@qua.dev — response within 30 days
Security incidents and vulnerability reportssecurity@qua.dev
Contractual and legal noticeslegal@qua.dev
Subprocessor change notificationsprivacy@qua.dev — subject "Subprocessor notifications"

We acknowledge data requests within 10 business days and respond within 30 days (45 days in California where an extension applies). This DPA was last updated on August 25, 2026.

Qua
Pioneering enterprise-scale multiplayer AI.
QUA — Quantified · Unified · Autonomy.
Try Qua·Compare·Skills·Deployment·Open the app
Privacy Policy·Terms of Service·Cookie Policy·Data Processing Agreement·Subprocessors