Data Processing Agreement
Last updated: April 2026
1. Introduction
This Data Processing Agreement ("DPA") applies to organizations using the QNSQY Business tier and governs how QNSQY processes personal data on behalf of its customers. This DPA supplements the Terms of Service and the Privacy Policy.
By subscribing to the Business tier, you ("Controller") appoint QNSQY ("Processor") to process personal data as described in this agreement.
2. Definitions
- Controller: The organization that determines the purposes and means of processing personal data.
- Processor: QNSQY, which processes personal data on behalf of the Controller.
- Data Subject: An identified or identifiable natural person whose personal data is processed.
- Personal Data: Any information relating to a Data Subject, as defined by applicable data protection law.
- Processing: Any operation performed on personal data, including collection, storage, retrieval, use, and deletion.
3. Scope of Processing
Data QNSQY Processes
- Email address (for account identification and communications)
- Name (for account display and correspondence)
- API usage metadata (operation type, file size range, timestamp)
- Payment information (processed via Razorpay, QNSQY stores only transaction references)
- Organization name and membership data (Business tier)
Data QNSQY Does NOT Process
QNSQY operates on a zero-knowledge architecture. The following data never leaves your device and is never accessible to QNSQY:
- File contents (all encryption and decryption occurs locally on your device)
- Encryption keys (generated and stored locally)
- Passwords (never transmitted to QNSQY servers)
Billing metadata is limited to operation type, approximate file size range, and timestamp. No file names, paths, or content indicators are collected.
4. Data Security Measures
QNSQY implements the following technical and organizational measures to protect personal data:
- All data encrypted in transit using TLS 1.3. The Cloudflare edge supports post-quantum hybrid key exchange (X25519MLKEM768) for clients that negotiate it.
- API keys stored as SHA-256 hashes (original keys are never stored)
- Post-quantum envelope encryption available for API communications
- Cloudflare Workers edge computing (data processed close to the user, minimizing transit exposure)
- Automatic data expiration and cleanup on defined schedules
- Role-based access controls for organizational accounts
- Audit logging for all administrative actions (Business tier)
5. Sub-processors
QNSQY uses the following sub-processors to deliver its services:
- Cloudflare, Inc. (United States) - Infrastructure, D1 database, Workers edge computing, CDN. Processes: account data, API metadata, session tokens.
- Razorpay Software Pvt. Ltd. (India) - Payment processing. Processes: payment card details, billing address, transaction records.
- Resend, Inc. (United States) - Transactional email delivery. Processes: email addresses, email content for account notifications.
- Functional Software, Inc. dba Sentry (United States) - Error tracking and website telemetry only. Processes: browser error stack traces, session metadata, truncated IP addresses. Sentry does not run inside the QNSQY desktop software; it is scoped to the public website.
QNSQY will notify Business tier customers at least 30 days before engaging any new sub-processor. Customers may object to a new sub-processor by contacting [email protected] within that notice period.
6. Data Subject Rights
QNSQY supports the following data subject rights in accordance with applicable data protection laws:
- Right to Access: Data subjects may request a copy of their personal data via the account dashboard or by contacting [email protected].
- Right to Rectification: Data subjects may update their personal data through the account dashboard or by contacting support.
- Right to Erasure: Data subjects may delete their account at any time. All personal data is purged within 30 days of account deletion.
- Right to Data Portability: Data subjects may export their account data in JSON format via the QNSQY API.
- Right to Restrict Processing: Data subjects may request restriction of processing by contacting support. QNSQY will cease processing except for storage and legally required activities.
7. Data Breach Notification
In the event of a confirmed personal data breach, QNSQY will notify the Controller without undue delay, and in any case within 72 hours of becoming aware of the breach.
The notification will include:
- The nature of the breach, including categories and approximate number of data subjects affected
- The categories of personal data affected
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach, including remedial actions
- Contact information for QNSQY's designated point of contact
Note: because QNSQY never processes file contents, encryption keys, or passwords, a breach of QNSQY's infrastructure cannot expose the contents of your encrypted files.
8. Data Retention
- Active accounts: Personal data is retained for the duration of the active subscription.
- Deleted accounts: All personal data is purged within 30 days of account deletion.
- Usage logs: API usage logs are retained for 90 days to support billing dispute resolution, then automatically deleted.
- Webhook events: Retained for 48 hours, then automatically purged.
- Payment records: Transaction references may be retained as required by applicable tax and financial regulations.
9. International Transfers
QNSQY uses Cloudflare's global edge network to deliver its services. Personal data may be processed at Cloudflare edge locations worldwide to minimize latency and provide optimal performance.
For transfers of personal data outside the European Economic Area (EEA), QNSQY relies on Standard Contractual Clauses (SCCs) as approved by the European Commission. A copy of the applicable SCCs is available upon request by contacting [email protected].
10. Term and Termination
This DPA takes effect when the Controller subscribes to the QNSQY Business tier and remains in effect for the duration of the subscription. Upon termination of the subscription, QNSQY will delete or return all personal data within 30 days, unless retention is required by applicable law.
Sections 7 (Data Breach Notification), 8 (Data Retention), and 9 (International Transfers) survive termination of this DPA.
11. Changes to This Agreement
QNSQY may update this DPA to reflect changes in data protection law, sub-processors, or our processing practices. Material changes will be communicated to Business tier customers at least 30 days in advance via email.
12. Contact
For questions about this Data Processing Agreement, contact us at:
- Legal inquiries: [email protected]
- Privacy inquiries: [email protected]
- General support: [email protected]