Version 2026-09-13.v1
This Data Processing Agreement (the “DPA”) forms part of the agreement between InnoQualis LTD, a company registered in England and Wales (company number 17066029) (“InnoQualis”, the processor) and the organisation that holds the subscription (the “Customer”, the controller). It applies to all personal data InnoQualis processes on the Customer’s behalf in providing the InnoQualis eQMS (the “Service”), and is incorporated into the Terms of Service for every subscription without a signature. Customers who need a countersigned copy can request one from dpo@innoqualis.com.
For customer content — the quality records the Customer stores in its workspace (documents, training records, deviations, CAPAs, audits, complaints, equipment records and similar, together with the audit trails generated over them) — the Customer is the controller and InnoQualis is the processor. For the account, billing and usage data InnoQualis needs to operate the Service, InnoQualis is an independent controller; that processing is described in the Privacy Policy and is outside this DPA.
Terms such as personal data, processing, controller, processor, personal data breach and supervisory authority have the meanings given in the UK GDPR and, where it applies, the EU GDPR (together with the Data Protection Act 2018, “Data Protection Law”).
Subject matter: provision of a multi-tenant electronic quality management system for regulated industries, delivered as a subscription service. Duration: the subscription term plus the 30-day retention-and-return window in section 10. Nature: hosting, storage, retrieval, display, transmission, backup and deletion of customer content; generation of immutable audit trails over that content; optional AI-assisted analysis of content the Customer submits to AI features; email delivery of service notifications. Purpose: operating the Service for the Customer as described in the Terms of Service and the product documentation.
Data subjects: the Customer’s workforce members who hold user accounts; external auditors the Customer grants scoped access; and individuals whose personal data appears in the quality records the Customer chooses to store (for example complainants, supplier or customer contacts, trainees). Categories of personal data: user identification data (name, email address, role); authentication events; the content of quality records as determined by the Customer; audit-trail entries (actor, action, time); AI usage metering (model, token counts, cost) attributed to the workspace and user. The Service is not designed for special categories of personal data; the Customer decides what it stores and remains responsible for having a lawful basis for it.
InnoQualis processes customer content only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by a law it is subject to — in which case InnoQualis informs the Customer of the requirement before processing, unless the law prohibits it. The Terms of Service, this DPA and the Customer’s use of the Service’s own controls (configuration, workflows, exports and deletions started in the product) are the Customer’s documented instructions. InnoQualis will tell the Customer if, in its opinion, an instruction infringes Data Protection Law.
People authorised by InnoQualis to process customer content are bound by contractual or statutory confidentiality obligations. Access is limited to what is needed to operate the Service and to provide support the Customer has requested; vendor support access goes through a separate, two-factor-protected operator account type, sees aggregate and user-management data rather than record content, and is written to the same tamper-evident audit log as tenant activity. The trust page describes this in full.
InnoQualis implements the technical and organisational measures appropriate to the risk, summarised here (the trust page carries the fuller description): encryption in transit (TLS 1.2 or higher, HSTS) on every public endpoint; a multi-tenant architecture in which every data access is scoped to the Customer’s workspace and cross-tenant access is tested against; role-based access control with four tenant-scoped roles; passwordless sign-in by single-use, short-lived email codes with rate limiting and attempt lockout; immutable, hash-chained audit trails over quality records; electronic signatures that are never hard-deleted; nightly backups encrypted before they leave the production host and stored with two independent providers in the EU; and secrets kept out of source code and rotated at defined events.
The Customer authorises the sub-processors listed below, each engaged under written terms that impose data-protection obligations materially equivalent to this DPA. InnoQualis remains responsible to the Customer for their performance.
OVHcloud (OVH SAS) — infrastructure hosting, Frankfurt (Limburg), Germany; the production platform is moving there and this list is updated when the cutover completes. Hetzner Online GmbH — nightly off-site encrypted backup copies, Germany. Backblaze, Inc. — secondary encrypted backup copies, EU region. Cloudflare, Inc. — authoritative DNS for innoqualis.com today (DNS-only records, so no customer traffic passes through it yet), with content delivery and access control planned for the same rollout. Stripe Payments Europe Ltd. — payment processing (card details are entered on Stripe’s pages and never reach InnoQualis). Microsoft 365 — transactional email delivery and, where the Customer connects it, the optional SharePoint integration; for the current term the Microsoft 365 tenant is resold and contracted through GoDaddy, which is therefore named in this list, with Microsoft Ireland Operations Ltd. processing downstream. OpenAI, L.L.C. — AI features (the prompts and text needed to serve each request, and embeddings for search), United States, with a training opt-out in force.
Change process: InnoQualis gives the Customer at least 15 days’ written notice (email to the workspace administrators, and the trust page) before adding or replacing a sub-processor. The Customer may object within those 15 days on reasonable, data-protection-related grounds. InnoQualis will then work with the Customer to resolve the objection; if it cannot be resolved, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the remaining term, with the retention-and-return window in section 10 applying.
Change of provider: the same notice and objection process applies if InnoQualis changes its hosting or backup provider. Any replacement provider will be located in the EU or the United Kingdom and the Customer’s data will not leave those territories as a result of the change.
Customer content is hosted and backed up in the European Union. InnoQualis LTD is established in the United Kingdom, which holds an adequacy decision from the European Commission, and the United Kingdom recognises the EEA as adequate; access from the UK to the EU-hosted Service needs no further safeguard. Where a sub-processor processes limited data outside the UK and EEA — today, OpenAI in the United States for AI feature requests — the transfer relies on the EU Standard Contractual Clauses and the UK Addendum incorporated in that sub-processor’s data-processing terms. Customers who require no non-EU processing can ask InnoQualis to disable AI features for their workspace (dpo@innoqualis.com), after which no customer content leaves the EU.
Taking the nature of the processing into account, InnoQualis assists the Customer with in-product access, correction and export controls in responding to data subject requests, and forwards without undue delay any request it receives directly that concerns customer content. InnoQualis assists the Customer with its obligations on security, breach notification, data protection impact assessments and prior consultation, using the information available to it.
InnoQualis notifies the Customer’s administrators of a personal data breach affecting customer content without undue delay and no later than 48 hours after becoming aware of it, with the information reasonably needed for the Customer’s own notification duties, and supplements the notice as more becomes known. Incidents affecting availability are published on status.innoqualis.com.
InnoQualis makes available the information reasonably needed to demonstrate compliance with this DPA, including written answers to security questionnaires and its supplier qualification pack. The Customer or an auditor it mandates may audit InnoQualis’s compliance with this DPA by arrangement: on at least 30 days’ written notice, during business hours, no more than once in any 12 months unless a supervisory authority requires it or a personal data breach has occurred, subject to confidentiality, and at the Customer’s cost. Certifications and third-party attestations held by sub-processors are provided in place of on-site access to their facilities.
The Customer can export its records at any time during the term in open, machine-readable formats. On termination or expiry InnoQualis keeps the workspace intact for a 30-day retention-and-return window during which the Customer’s administrator can take a complete copy of the data, then deletes the workspace within a further 30 days and confirms the deletion in writing, unless and to the extent a law requires InnoQualis to keep specific records.
Deletion is a verified procedure: the request is confirmed with the Customer’s administrator, every record scoped to the workspace is deleted, and the deletion is confirmed in writing. Encrypted backup copies age out on their fixed rolling cycle and are never used to restore deleted data except in a disaster-recovery event, after which the deletion is re-applied. Audit trails are immutable during the life of the workspace and are deleted with it.
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, save that nothing limits either party’s liability where Data Protection Law does not allow it to be limited. On any question of the processing of personal data this DPA prevails over the Terms of Service. It takes effect on subscription and lasts as long as InnoQualis processes customer content, including the retention-and-return window. It is governed by the laws of England and Wales.
Questions about this DPA: dpo@innoqualis.com. The version shown at the top of this page identifies the text in force; changes are notified to workspace administrators.
This agreement is incorporated into our Terms of Service and works alongside our Privacy Policy. The current sub-processor table is on the trust page.