This Data Processing Agreement ("DPA") supplements the Terms of Service between AI Innovation Technologies Inc., doing business as Quriosly ("Processor"), and the customer using the Service ("Controller"). It applies when Controller submits personal data to the Service in the course of using it. Where there is a conflict between this DPA and the Terms of Service regarding personal data processing, this DPA controls.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Service. The following definitions apply throughout this DPA:
- Personal Data:
- Any information relating to an identified or identifiable natural person that is submitted to the Service by Controller or its users.
- Processing:
- Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- Data Subject:
- The natural person whose Personal Data is processed.
- Sub-processor:
- A third party engaged by Processor to process Personal Data on behalf of Controller.
- Applicable Law:
- Any data protection or privacy laws applicable to the Processing of Personal Data, which may include the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR), and the UK Data Protection Act 2018.
2. Roles and scope
The parties acknowledge that:
- Controller is the data controller and Processor is the data processor in relation to Personal Data submitted to the Service
- Processor processes Personal Data only on behalf of Controller, for the purposes of providing the Service, in accordance with Controller's documented instructions
- Controller is responsible for the lawfulness of the Personal Data and for obtaining any necessary consents from Data Subjects
This DPA applies to all Processing of Personal Data by Processor in connection with the Service.
3. Processor obligations
Processor will:
- Process Personal Data only on documented instructions from Controller, including the instructions in the Terms of Service and this DPA
- Ensure persons authorized to process Personal Data are bound by appropriate confidentiality obligations
- Implement and maintain appropriate technical and organizational measures to protect Personal Data, as described in section 6
- Assist Controller in fulfilling Data Subject rights requests, where reasonably required
- Notify Controller of any Personal Data Breach without undue delay, as described in section 7
- Make available information necessary to demonstrate compliance with this DPA
- Delete or return Personal Data at the end of the Service, except where retention is required by law
4. Sub-processors
Controller authorizes Processor to engage the sub-processors listed below to process Personal Data in connection with the Service:
Processor will impose data protection obligations on each sub-processor that are no less protective than those in this DPA. Processor remains responsible for the acts and omissions of its sub-processors.
When Processor adds or replaces a sub-processor, Processor will notify Controller at least 30 days in advance through email or in-product notification. Controller may object to the change for legitimate data protection reasons. If the parties cannot resolve the objection in good faith, Controller may terminate the affected portion of the Service.
5. Data Subject rights
Processor will, taking into account the nature of the Processing, assist Controller by appropriate technical and organizational measures in fulfilling Controller's obligations to respond to Data Subject requests under Applicable Law. This includes requests for access, correction, deletion, restriction, portability, and objection.
Most Data Subject rights can be fulfilled directly by Controller through the Service. For requests requiring Processor's assistance, contact dpa@quriosly.com. Processor will respond within a reasonable timeframe, generally within 30 days.
6. Security measures
Processor implements and maintains the following technical and organizational measures to protect Personal Data:
6.1 Access controls
- Role-based access controls limiting employee access to Personal Data on a need-to-know basis
- Multi-factor authentication required for access to production systems
- Logging and auditing of access to production systems
- Periodic review of access privileges
6.2 Encryption
- Encryption in transit using TLS 1.2 or higher for all Personal Data
- Encryption at rest for Personal Data stored in databases and file storage
- Encrypted backups
6.3 Organizational measures
- Confidentiality obligations for all personnel with access to Personal Data
- Security training for personnel
- Documented incident response process
- Regular review of security practices and dependencies
6.4 Infrastructure
- Production infrastructure hosted on Vercel in the United States
- Network segmentation between production and non-production environments
- Regular patching of systems and dependencies
- Vulnerability scanning and dependency monitoring
7. Breach notification
In the event of a Personal Data Breach, Processor will notify Controller without undue delay and in any case within 72 hours of becoming aware of the Breach, where feasible.
Notification will include, to the extent known at the time:
- Description of the nature of the Breach, including categories and approximate number of Data Subjects and records affected
- Likely consequences of the Breach
- Measures taken or proposed to address the Breach and mitigate its effects
- Contact details for the person handling the Breach
Processor will cooperate with Controller in investigating the Breach and providing information necessary for Controller to meet its own notification obligations under Applicable Law.
8. Audits
Processor will make available to Controller information reasonably necessary to demonstrate compliance with this DPA, including responses to security questionnaires.
Where Applicable Law requires Controller to audit Processor, Processor will allow audits, including inspections, conducted by Controller or an auditor designated by Controller, subject to confidentiality obligations and reasonable scheduling. Processor may charge reasonable fees for audits that go beyond responding to standard security questionnaires.
9. International transfers
Personal Data submitted by Controller is processed in the United States. Processor and its sub-processors are based in the United States.
For Controllers based in the European Union, the United Kingdom, or Switzerland, the parties acknowledge that additional safeguards (such as Standard Contractual Clauses) may be required for transfers of Personal Data to the United States. Processor is working to put these safeguards in place. Until they are available and announced, Controllers in those regions should consider whether the Service is appropriate for their use case.
10. Return and deletion of Personal Data
Upon termination of the Service, Processor will, at Controller's choice, delete or return all Personal Data to Controller, and delete existing copies, unless Applicable Law requires storage. Standard retention timelines apply: data is deleted from active systems within 30 days of termination, and from backups within 90 days.
Controller may export its data at any time during the Service through standard export features.
11. Liability
Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service.
12. Changes to this DPA
Processor may update this DPA from time to time to reflect changes in Applicable Law or operational practice. Material changes will be communicated to Controller at least 30 days in advance. The "Last updated" date at the top reflects the most recent revision.
13. Contact
For questions about this DPA, contact:
c/o United States Corporation Agents, Inc.
131 Continental Drive
Newark, DE 19713
United States