Data Processing Addendum

Last Updated: August 27, 2026

Effective: August 27, 2026

All policiesVersion history

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Quantum Solutions (Private) Limited ("Processor", "we", "us") and the organisation that accepted them ("Controller", "you").

It applies whenever you use the Service to process personal data about people other than your own staff — in practice, whenever you add a customer record or issue an invoice to a person.

It is accepted by an administrator on behalf of the organisation, because it binds the organisation rather than an individual. Where this DPA conflicts with the Terms of Service, this DPA prevails on matters of personal data protection.

1. Definitions

"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the Sri Lanka Personal Data Protection Act and any other data protection law applicable to you. "GDPR" means the EU General Data Protection Regulation 2016/679, which this DPA adopts as its drafting standard — we hold ourselves to its obligations by contract, whether or not it applies to you by law.

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR.

"Customer Personal Data" means Personal Data contained in Customer Data, which you provide or which is generated on your behalf, and which we process under this DPA.

"Sub-processor" means any third party we engage to process Customer Personal Data.

2. Roles and scope

2.1 You are the Controller and we are the Processor of Customer Personal Data. Where you are yourself a processor for a third-party controller, we are a sub-processor and you confirm you have the authority to appoint us.

2.2 We are an independent controller for the data described in Part A of our Privacy Policy — your account, your organisation and your subscription. This DPA does not apply to that data.

2.3 The subject matter, duration, nature, purpose, types of Personal Data and categories of Data Subject are set out in Annex I.

3. Your obligations as Controller

3.1 You will comply with Data Protection Law in your use of the Service.

3.2 You are responsible for the accuracy, quality and legality of Customer Personal Data, for having a lawful basis to process it, and for giving Data Subjects the notices Data Protection Law requires.

3.3 Your instructions must not require us to act unlawfully. You confirm that your instructions, taken as a whole, comply with Data Protection Law.

3.4 You will not submit special categories of Personal Data (Article 9 GDPR) or criminal-offence data (Article 10) through the Service. It is not designed for them and Annex II is not calibrated to them.

4. Our obligations as Processor

We will:

4.1 Process only on your instructions. We process Customer Personal Data only on your documented instructions, which comprise this DPA, the Terms of Service, and your configuration and use of the Service. If the law requires us to process otherwise, we will tell you first unless the law forbids it. If we consider an instruction to breach Data Protection Law, we will tell you.

4.2 Keep it confidential. We ensure that everyone we authorise to process Customer Personal Data is bound by confidentiality obligations and is trained appropriately.

4.3 Secure it. We implement and maintain the technical and organisational measures in Annex II, appropriate to the risk. We may update them provided security is not materially reduced.

4.4 Assist with Data Subject requests. Taking account of the nature of the processing, we will assist you with appropriate technical and organisational measures in responding to Data Subject requests. Where a Data Subject contacts us directly about Customer Personal Data, we will not respond substantively — we will forward the request to you without undue delay and tell the Data Subject we have done so.

4.5 Assist with your wider obligations. Taking account of the nature of the processing and the information available to us, we will assist you with your obligations on security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR).

4.6 Notify breaches. See section 7.

4.7 Delete or return. See section 8.

4.8 Demonstrate compliance. See section 9.

5. Sub-processors

5.1 General authorisation. You give us general authorisation to engage Sub-processors. Those engaged at the date of this DPA are listed at https://quantumsolutions.dev/sub-processors, which forms Annex III.

5.2 Notice of change. We will give at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data, by updating that page and emailing your administrators.

5.3 Your right to object. You may object on reasonable data-protection grounds within the notice period, by writing to hello@quantumsolutions.dev. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the period after termination.

5.4 Flow-down and liability. We impose on each Sub-processor data protection obligations at least as protective as those in this DPA. We remain fully liable to you for a Sub-processor's performance.

6. International transfers

6.1 We process Customer Personal Data in the United States, and we are established in Sri Lanka. Personal Data is therefore processed outside the country the Controller and the Data Subjects are in, and we make those transfers only with appropriate safeguards in place — the measures in Annex II, and any transfer mechanism required by the Data Protection Law applicable to you.

6.2 EEA, UK and Swiss transfers. The Service is not offered to individuals in the European Economic Area, the United Kingdom or Switzerland, so the Standard Contractual Clauses and the UK Addendum are not incorporated into this DPA. Should we begin offering it there, we will incorporate the appropriate mechanism and give you notice before doing so. 6.5 Alternative mechanism. If a transfer mechanism in this section is invalidated, we will adopt an alternative lawful mechanism without undue delay.

7. Personal Data Breach

7.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide everything at once, we will provide it in phases without undue delay.

7.3 We will not make any public statement identifying you in relation to a breach without your prior written consent, unless legally required.

7.4 Notifying you is not an acknowledgement of fault or liability.

8. Deletion and return

8.1 On termination or expiry of the Terms of Service, and at your choice, we will delete or return Customer Personal Data. Your export window is 30 days from termination, as set out in the Terms.

8.2 We will delete remaining copies within 30 days of the end of that window, except to the extent that law requires us to retain them — in particular invoices and payment records, which are retained for the statutory tax period described in our Privacy Policy.

8.3 Data retained under 8.2 remains subject to this DPA and is processed only for the purpose requiring its retention.

8.4 Backups are purged on the normal rotation cycle, currently within 35 days. We do not restore deleted Customer Personal Data from backup except to recover from a system failure, and outstanding deletions are re-applied if we do.

9. Audit

9.1 We will make available the information reasonably necessary to demonstrate compliance with this DPA, and respond to reasonable security questionnaires.

9.2 Where that is not sufficient, you may audit us — or appoint an independent auditor who is not our competitor and who is bound by confidentiality — on at least 30 days' written notice, no more than once in any 12-month period, during business hours, and in a manner that does not disrupt the Service or affect other customers. You may audit more often if a Supervisory Authority requires it or following a confirmed Personal Data Breach.

9.3 You bear the cost of an audit unless it reveals a material breach of this DPA by us, in which case we bear our own costs and yours.

10. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits a Data Subject's rights under Data Protection Law, or either party's liability to a Supervisory Authority.

11. Term

This DPA takes effect when you accept it and continues for as long as we process Customer Personal Data for you.


Annex I — Details of the processing

A. Parties

Data exporter: the Controller — the organisation that accepted the Terms of Service. Contact details are those held on the organisation's billing profile. Role: controller (or processor, where acting for a third-party controller).

Data importer: Quantum Solutions (Private) Limited, NO 61/12, 6th Pope Paul Road, Negombo, 11500, Sri Lanka. Contact: hello@quantumsolutions.dev. Role: processor.

B. Description of the processing

Subject matterProvision of the Quantum Solutions platform — customer records, invoicing and payment collection
DurationFor as long as the Terms of Service are in force, plus the deletion period in section 8
Nature and purposeHosting, storage, retrieval, organisation, transmission, display and deletion of Customer Personal Data, so the Controller can manage its customers and issue and collect invoices
FrequencyContinuous, for as long as the Service is used

C. Categories of Data Subject

  • The Controller's customers and prospective customers, whether individuals or the contact persons of a business
  • Recipients of invoices issued by the Controller
  • Individuals the Controller invites to access its organisation, and to whom the Service issues a login

D. Categories of Personal Data

  • Identity: name, display name, company name where the customer is a business
  • Contact: email address, telephone number
  • Address: billing address, shipping address
  • Financial: invoices issued, line items, amounts, currency, tax details, payment status and history
  • Payment: payment token, card brand, last four digits, transaction identifiers. No full card number, expiry date or security code
  • Account: where a login is issued, the identifiers and authentication records needed to operate it
  • Correspondence: any personal data the Controller places in invoice notes or descriptions

E. Special categories

None. The Service is not designed for special-category or criminal-offence data, and the Controller undertakes not to submit it (section 3.4).

F. Retention

As instructed by the Controller, and as set out in section 8 and in Part B of the Privacy Policy.

G. Sub-processor processing

Each Sub-processor processes for the purpose, and for the duration, stated in Annex III.


Annex II — Technical and organisational measures

These are the measures we maintain under Article 32 GDPR and section 4.3. They describe the platform as operated at the effective date of this document.

1. Encryption

  • All data in transit is encrypted with TLS
  • All data at rest is encrypted, including the primary database, object storage and backups
  • Secrets and credentials are held in a managed secret store, never in source control

2. Access control

  • Role-based access control is enforced centrally on every request, not per feature
  • Access is tenant-scoped: queries are bound to the requesting organisation so a request cannot reach another tenant's data
  • Staff access follows least privilege, is restricted to those who need it to operate or support the Service, and is logged
  • Multi-factor authentication is available to all users and required for our staff

3. Pseudonymisation and data minimisation

  • Cardholder data is never received: payment fields are hosted by the payment provider and we hold only a token and the last four digits
  • We collect only what the Service needs, and do not use Customer Personal Data for our own purposes, advertising, or model training

4. Availability and resilience

  • Managed, redundant infrastructure with automated failover
  • Encrypted backups on a rotating schedule, currently retained for 35 days
  • Restore procedures are exercised periodically

5. Integrity and accountability

  • Consent and security-sensitive records are append-only: they can be added to but not edited or deleted
  • Application and access logs are retained for the periods stated in the Privacy Policy
  • Changes to production go through review and automated testing

6. Vulnerability management

  • Automated dependency and secret scanning in the build pipeline
  • Static analysis on application code
  • Rate limiting and automated abuse detection on public endpoints
  • A published security contact (security@quantumsolutions.dev) and a responsible-disclosure position

7. Personnel

  • Confidentiality obligations for everyone with access to Customer Personal Data
  • Access removed promptly when a role changes or ends

8. Sub-processor governance

  • Contractual data protection terms at least as protective as this DPA
  • A published sub-processor list with advance notice of change (section 5)

Annex III — Sub-processors

The current list, with the purpose, data categories and processing location for each, is published at https://quantumsolutions.dev/sub-processors and forms part of this DPA.


Quantum Solutions (Private) Limited · NO 61/12, 6th Pope Paul Road, Negombo, 11500, Sri Lanka · hello@quantumsolutions.dev