Legal
Data Processing Addendum
1. Scope and precedence
This Data Processing Addendum (“DPA”) forms part of the Master Subscription Agreement or Order Form (the “Agreement”) between quako, Inc. (“quako,” “Processor”) and the customer identified in the Agreement (“Customer,” “Controller”), and applies whenever quako processes personal data on Customer’s behalf in connection with the quako application. In the event of a conflict between this DPA and the Agreement with respect to data protection obligations, this DPA controls.
2. Roles of the parties
Customer is the controller (or, where applicable, business) of personal data that Customer or its authorized users submit to the quako application. quako is a processor (or service provider) acting only on Customer’s documented instructions, as set out in the Agreement, this DPA, and Customer’s configuration and use of the application.
3. Sub-processors
3.1 General authorization
Customer provides general authorization for quako to engage sub-processors to support the quako application, subject to the notice and objection rights in this Section.
3.2 Notice period
quako will give Customer at least thirty (30) days’ advance notice before authorizing a new sub-processor to process Customer personal data. Notice is given by publishing the change to the sub-processor list and to the legal changelog, and is deemed received on the date of publication.
3.3 Subscribing to notice
Customer may subscribe to sub-processor notices directly, rather than checking the changelog page manually, via the Atom feed published at /legal/changelog.xml. Any point-in-time entry Customer receives through that feed announcing a new sub-processor satisfies the thirty (30)-day notice obligation in Section 3.2 as of its publication date.
3.4 Objection
If Customer has a reasonable, documented objection to a new sub-processor on data protection grounds, Customer may notify quako in writing at privacy@quako.io within the thirty (30)-day notice period. quako will work with Customer in good faith to address the objection, which may include providing additional information about the sub-processor’s safeguards or, where feasible, a change in configuration. If the objection cannot be resolved within a further thirty (30) days, either party may terminate the affected subscription without penalty as its sole remedy.
4. Data subject requests
quako will provide reasonable assistance to Customer in responding to requests from data subjects to exercise their rights under applicable data protection law, using the tools and support channels made available with the Customer’s subscription tier. Contact privacy@quako.io for requests retained for < 7 years; requests concerning data that has already been deleted under Customer’s configured retention settings cannot be fulfilled, because the underlying record no longer exists.
5. Security measures
quako maintains administrative, technical, and physical safeguards designed to protect Customer personal data, including access controls, audit logging, and encryption of data in transit and at rest, as described in the Security section of our Trust page and, where applicable, our SOC 2 Type II report available under NDA.
6. Personal data breach notification
quako will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data. A breach notification will include, to the extent known at the time of initial notification: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, measures quako has taken or proposes to take to mitigate the breach, and a contact point for further information.
Initial breach notifications may be incomplete, as factual details about an incident are often unavailable immediately. quako will supplement its notification with additional information as its investigation progresses, and does not commit to providing complete details at the time of first notification.
quako will provide reasonable assistance to Customer in meeting Customer’s own obligations to notify regulators and data subjects, since Customer is the controller of that personal data and those notification duties are Customer’s responsibility.
A breach notification is not an acknowledgement of fault or liability on quako’s part.
7. Sub-processor obligations
quako imposes data protection obligations on each sub-processor that are no less protective than those set out in this DPA, through a written agreement, and remains liable to Customer for a sub-processor’s performance of those obligations.
8. International transfers
Where quako or a sub-processor processes Customer personal data outside the jurisdiction in which it originated, quako relies on an appropriate transfer mechanism recognized under applicable data protection law (such as Standard Contractual Clauses) to the extent required. Specific sub-processor details, including processing location, are maintained in the sub-processor list rather than restated here, so that this DPA does not go stale each time an operational detail changes.
9. Return and deletion
On termination of the Agreement, quako will, at Customer’s election, delete or return Customer personal data within the timeframe set out in the Agreement, except to the extent applicable law requires quako to retain some or all of it.
10. Audit rights
quako will make available information reasonably necessary to demonstrate compliance with this DPA, including current audit reports (such as our SOC 2 Type II report, available under NDA), and will permit Customer or an independent auditor mutually agreed by the parties to conduct an audit no more than once per calendar year, subject to reasonable notice and confidentiality safeguards.
11. Changes to this DPA
Changes to this DPA are published to the legal changelog and its Atom feed in the same way as sub-processor notices. The “Effective” date at the top of this page reflects when the current version took effect.
12. Contact
Questions about this DPA can be sent to privacy@quako.io.