Data processing agreement

Last updated 30 Sept, 2026.

1. Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between QualityLabs Inc., a Delaware corporation ("Quality", "Processor"), and the customer that has entered into the Agreement ("Customer", "Controller"). It applies whenever Quality processes Customer Personal Data in providing the Quality browser extension and web dashboard (the "Service"), and takes effect automatically when Customer accepts the Agreement.

2. Definitions

  • Customer Personal Data: Personal data within Customer Content that Quality processes on Customer's behalf under the Agreement.
  • Data Protection Laws: All laws that apply to the processing of Customer Personal Data under the Agreement, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the CPRA ("CCPA").
  • Security Incident: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • Subprocessor: Any third party Quality engages to process Customer Personal Data.

Terms such as "controller", "processor", "data subject", and "service provider" have the meaning given in Data Protection Laws. Other capitalized terms have the meaning given in the Agreement.

3. Roles of the parties

  • Customer is the controller of Customer Personal Data: its workspace members' data, and any personal data of visitors or users of Customer's websites that appears in the screenshots or session recordings Customer chooses to capture.
  • Quality is a processor, and a service provider under the CCPA, acting only on Customer's documented instructions.
  • Quality is an independent controller of the account, billing, and usage data it processes to run its own business, as described in its Privacy Policy. This DPA does not apply to that data.

4. Customer instructions and obligations

The Agreement, this DPA, and Customer's use and configuration of the Service are Customer's complete instructions to Quality. Customer is responsible for the lawfulness of those instructions and of the data it submits, including having a legal basis and giving any notices or obtaining any consents needed to capture pages that display personal data. Quality will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

5. Quality's obligations

  • Process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case Quality will inform Customer first unless the law prohibits it.
  • Ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
  • Implement and maintain the technical and organizational measures described in Annex 2, updating them over time without reducing the overall level of protection.
  • Taking into account the nature of the processing, assist Customer with data subject requests (access, correction, deletion, portability, restriction, objection), and with data protection impact assessments and consultations with supervisory authorities. If Quality receives a request directly, it will refer the data subject to Customer.
  • Not sell or share Customer Personal Data, or retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than providing the Service, and not combine it with personal data received from other sources except as the CCPA permits.

6. Security incidents

Quality will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident. The notice will describe the nature of the incident, the likely consequences, and the measures taken or proposed, as far as that information is available, and Quality will update Customer as more becomes known. Notifying Customer is not an admission of fault.

7. Subprocessors

Customer authorizes Quality to engage Subprocessors to provide the Service, including providers of infrastructure and hosting, media storage for screenshots and recordings, and transactional email. Quality will:

  • Bind each Subprocessor to written data protection terms no less protective than this DPA.
  • Make its current list of Subprocessors available to Customer on request.
  • Notify Customer at least 30 days before a new Subprocessor begins processing Customer Personal Data. Customer may object on reasonable data protection grounds within that period; the parties will then work in good faith toward a resolution, and if none is found, Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused term.
  • Remain liable for each Subprocessor's performance of its obligations.

8. International transfers

Quality is based in the United States and may process Customer Personal Data there and in other countries where it or its Subprocessors operate. Where Customer Personal Data subject to the EU GDPR is transferred to a country without an adequacy decision, the parties incorporate by reference Module Two (controller to processor) of the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, completed with the details in Annex 1, Annex 2 as their Annex II, and the laws and courts of Ireland for clauses 17 and 18. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies to those clauses; for transfers subject to Swiss law, they apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority.

9. Audits

Quality will make available the information reasonably necessary to demonstrate compliance with this DPA, including written responses to reasonable security questionnaires. Where that is not sufficient, Customer, or an independent auditor bound by confidentiality, may audit Quality's compliance on at least 30 days' notice, during business hours, no more than once a year unless a Security Incident or a supervisory authority requires otherwise, and at Customer's expense.

10. Return and deletion

When the Agreement ends, Customer may export Customer Content for 30 days as described in the Terms of Service. After that, Quality will delete Customer Personal Data within 30 days, apart from copies in backups, which expire on their normal cycle, and data it must keep by law, which remains protected under this DPA for as long as it is kept.

11. Liability, precedence, and term

Each party's liability under this DPA is subject to the limitations of liability in the Agreement, to the extent Data Protection Laws allow. If this DPA conflicts with the Agreement, this DPA controls as to the processing of Customer Personal Data; if it conflicts with the Standard Contractual Clauses, the clauses control. This DPA lasts as long as Quality processes Customer Personal Data.

12. Governing law

This DPA is governed by the laws of the State of Delaware, USA, as set out in the Agreement, except where Data Protection Laws or the Standard Contractual Clauses require otherwise.

Annex 1: Description of processing

  • Parties: Customer, as data exporter and controller; QualityLabs Inc., a Delaware corporation, as data importer and processor. Contact details are those on Customer's account and at the end of this DPA.
  • Categories of data subjects: Customer's workspace members and guests; and visitors to or users of the web pages Customer chooses to capture in a screenshot or recording.
  • Categories of personal data: Names, email addresses, and profile photos; comments and other feedback content; screenshots and session recordings of Customer's web pages, including their network and console activity and any personal data displayed on them; authentication and session identifiers.
  • Sensitive data: None intended. Password fields are masked in recordings, but Customer controls which pages it captures and should not capture special-category or other sensitive data.
  • Frequency: Continuous, for as long as Customer uses the Service.
  • Nature and purpose: Hosting, storing, transmitting, and displaying Customer Content to provide the Service, including sending it to third-party integrations Customer connects.
  • Duration and retention: For the term of the Agreement, then as described in section 10.

Annex 2: Technical and organizational measures

  • Encryption: Data is encrypted in transit (TLS) between the extension, dashboard, and backend. Third-party integration credentials such as OAuth tokens are encrypted at rest.
  • Access control: Access to a workspace's data is limited by workspace and project membership and role, and checked on every authenticated request.
  • Authentication: Sign-in uses one-time email codes or Google sign-in. Sessions are held server-side and can be revoked immediately.
  • Data minimization: The extension runs only on the website of the project a user has activated. Recent page activity is buffered in the browser's memory and uploaded only when the user creates feedback or saves a recording. Password fields are masked before data leaves the browser.
  • Personnel: Access to production systems is limited to personnel who need it and are bound by confidentiality obligations.
  • Incident response: Security Incidents are investigated and notified as described in section 6.

Contact

Questions about this DPA, requests for the current Subprocessor list, and security questionnaires can be sent to [email protected].

Build with Quality.