Data Processing Agreement
Quantum Neuron Inc.
Version: 3.2 (ENG)
Effective date: September 9, 2026
This Data Processing Agreement (the "DPA") forms part of the Master SaaS Agreement (the "Main Agreement") and the applicable Order Form entered into between:
QUANTUM NEURON INC., a corporation organized and existing under the laws of the State of Delaware, United States of America, holding federal tax identification number EIN: 30-1448079, with its principal place of business at 169 Madison Ave STE 15768, New York, NY 10016, United States of America ("Quantum Neuron", "we", "us");
and
the entity identified as the "Client" in the Main Agreement or the Order Form (the "Client", "you");
each a "Party" and together the "Parties", and is incorporated into the Main Agreement by reference.
This DPA governs the Processing of Personal Data by Quantum Neuron on behalf of the Client in connection with the provision of the Services under the Main Agreement and the applicable Order Form. Its purpose is to ensure compliance with the Applicable Data Protection Laws, with the EU GDPR and the UK GDPR machinery set out in this DPA applied as the universal contractual baseline of protection for all Clients, regardless of the Client's jurisdiction.
1. Definitions
Capitalized terms used in this DPA have the meanings set out below. Terms not defined in this DPA have the meanings given to them in the Main Agreement, the Order Form or the Applicable Data Protection Laws.
"Anonymization" means the documented process applied by Quantum Neuron to the Client's Personal Data, intended to be irreversible and to make it, with reasonable certainty, impossible to single out, link or infer any Data Subject, in accordance with the criteria articulated by the European Data Protection Board, and subject to a documented manual verification step ("human check") before any further use.
"Applicable Data Protection Laws" means all data protection and privacy laws applicable to the Processing of the Client's Personal Data under this DPA, including: (a) the EU GDPR; (b) the UK GDPR and the UK Data Protection Act 2018; and (c) where applicable to the Client or the relevant Data Subjects, the data protection laws of the Client's jurisdiction, including UAE Federal Decree-Law No. 45/2021 on the Protection of Personal Data (the "UAE PDPL"), the data protection laws of the DIFC or the ADGM where the Client is established in those free zones, and the Saudi Personal Data Protection Law (the "KSA PDPL").
"Client Personal Data" means Personal Data Processed by Quantum Neuron on behalf of the Client under the Main Agreement or the Order Form, excluding data processed by Quantum Neuron as an independent controller in accordance with Section 16 (Exclusions from scope).
"Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Special Categories of Personal Data" have the meanings given to them in the Applicable Data Protection Laws; with respect to jurisdictions whose data protection laws use different terminology, these terms include the corresponding concepts under such laws as mapped in Annex IV.
"End User" means a natural person interacting with an AI Persona deployed by the Client through any communication channel made available within the Services.
"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
"EU SCCs" means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021, together with any subsequent replacing or amending decisions.
"Functional Scope Annex" has the meaning given to it in the Main Agreement or the Order Form.
"High-Risk AI Use Case" has the meaning given to it in the Main Agreement.
"Instructions" means the documented instructions issued by the Client to Quantum Neuron regarding the Processing of Client Personal Data, including the Main Agreement, this DPA, the Order Form and any subsequent instructions issued by the Client in writing (email being sufficient) in a manner reasonable within the scope of the Services.
"Lead Data" means Personal Data relating to leads, prospects, recipients, customers or potential customers, imported, transmitted, uploaded, synchronized or otherwise made available by or on behalf of the Client for use in connection with the Services, including for inbound or outbound communication.
"Order Form" has the meaning given to it in the Main Agreement.
"Outbound Communication" means any marketing, sales, commercial, telemarketing, email, SMS, WhatsApp, Messenger, Instagram, voice, social media, messaging or other outbound communication initiated, automated, assisted or supported through the Services.
"Security Annex" means the Quantum Neuron Security Annex - an internal document describing in detail the technical and organizational measures implemented by Quantum Neuron, made available to the Client upon request subject to appropriate confidentiality obligations.
"Platform" means the Quantum Neuron technology platform, including the Quantum Neuron Dashboard, used to provide the Services.
"Services" means the services provided by Quantum Neuron to the Client under the Main Agreement and the applicable Order Form.
"Subprocessor" means any third party or affiliate engaged by Quantum Neuron to Process Client Personal Data on the Client's behalf.
"Subprocessor List" means the list of authorized Subprocessors published and maintained by Quantum Neuron at https://quantumneuron.ai/legal/m26/subprocessors.
"Suppression Data" means opt-out records, unsubscribe records, objection records, exclusion lists, communication preferences, do-not-contact designations and similar data used to prevent or limit communication with Data Subjects.
"UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office (version B1.0) under section 119A of the Data Protection Act 2018.
2. Roles and Scope
2.1 Roles of the Parties
The Parties acknowledge and agree that, with respect to the Processing of Client Personal Data under this DPA, the Client acts as Controller and Quantum Neuron (Quantum Neuron Inc.) acts as Processor established in a third country (the United States of America) within the meaning of Chapter V of the EU GDPR. Where the Client itself acts as a processor on behalf of a third-party controller, Quantum Neuron is deemed a sub-processor, and the obligations set out in this DPA apply accordingly.
2.2 Scope of this DPA
This DPA applies solely to the Processing of Client Personal Data carried out by Quantum Neuron on the Client's behalf in connection with the Services. It does not apply to the categories of Processing activities described in Section 16 (Exclusions from scope), with respect to which Quantum Neuron acts as an independent controller in accordance with its own privacy notice.
2.3 Description of the Processing
The subject matter, nature, purpose, duration, categories of Data Subjects and categories of Personal Data processed under this DPA are set out in Annex I.
2.4 Joint controllership on third-party platforms
The Client acknowledges that certain integrations with third-party platforms (including without limitation Messenger, Instagram, WhatsApp Business and Facebook operated by Meta) may give rise to joint controllership arrangements between the Client and such third parties under Article 26 EU GDPR, in accordance with the platform terms of the relevant provider. Quantum Neuron is not a party to such joint controllership arrangements.
2.5 Client acting as processor
Where the Client acts as a processor on behalf of a third-party controller, the Client represents that it is authorized to appoint Quantum Neuron as a sub-processor and to issue the Instructions set out in this DPA.
2.6 Universal protection baseline
The protections, technical and organizational measures, cooperation machinery, transfer safeguards, subprocessor regime, breach notification obligations and AI-training safeguards set out in this DPA - designed to the standard of the EU GDPR and the UK GDPR - are applied by Quantum Neuron as the universal contractual baseline to the Client Personal Data of ALL Clients, including Clients established in a GCC Jurisdiction, regardless of whether the EU GDPR or the UK GDPR applies to the Client as a matter of law. Jurisdiction-specific supplements for GCC Jurisdictions are set out in Annex IV.
3. Processing Instructions
3.1 Lawfulness and Instructions
Quantum Neuron Processes Client Personal Data only on the Client's documented Instructions, including with regard to any transfer of Client Personal Data to a third country or an international organization, unless required to do so by European Union or Member State law to which Quantum Neuron is subject. In such a case, Quantum Neuron will inform the Client of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
3.2 Unlawful Instructions
Quantum Neuron will promptly inform the Client if, in its opinion, an Instruction infringes the Applicable Data Protection Laws. Quantum Neuron is entitled to suspend performance of the relevant Instruction until it is confirmed or modified by the Client.
3.3 Controller Obligations
The Client represents and warrants that: (a) it has a valid legal basis under Article 6 EU GDPR and, where applicable, Article 9 EU GDPR - or the equivalent provisions of the Applicable Data Protection Laws of the Client's jurisdiction - for the Processing of Client Personal Data by Quantum Neuron; (b) it has provided all required information notices and obtained all consents required under the Applicable Data Protection Laws; and (c) its Instructions to Quantum Neuron comply with the Applicable Data Protection Laws.
Where Client Personal Data includes Lead Data, contact lists, recipient data, phone numbers, email addresses, social media identifiers, Suppression Data or other data used for Outbound Communication, the Client represents and warrants that such data has been collected, sourced, imported, transmitted and used lawfully and that the Client has obtained and will maintain all legal bases, information notices, consents, permissions, opt-in records, opt-out records, exclusion lists and other records required for the relevant Processing activity, communication channel and jurisdiction.
3.4 Prohibited Processing purposes
Quantum Neuron will not Process Client Personal Data for its own marketing purposes, for the sale of data, for unrelated product analytics, for profiling independent of the Services, for training or fine-tuning AI models in identifiable form, or for any purpose independent of the documented Instructions applicable to the Services, subject to the activities described in Section 16 (Exclusions from scope), with respect to which Quantum Neuron acts as an independent controller, and the Processing of data effectively Anonymized in accordance with Section 14.
4. Special Categories of Personal Data
The Services are not specifically designed for the Processing of Special Categories of Personal Data within the meaning of Article 9 EU GDPR or of equivalent sensitive-data categories under other Applicable Data Protection Laws. The Client shall not submit such data to the Platform unless all of the following conditions are met:
- the Client has a valid legal basis under Article 9(2) EU GDPR and, where applicable, the equivalent provisions of the UK GDPR, of national law or of the Applicable Data Protection Laws of the Client's jurisdiction;
- the Client has informed the relevant Data Subjects and obtained all consents required under the Applicable Data Protection Laws;
- the scope of the Services agreed in the Order Form or in a separate written arrangement expressly covers such Processing, to the extent the relevant functionality is offered by Quantum Neuron; and
- the Parties have entered into any additional provisions, addenda or technical and organizational measures reasonably required by Quantum Neuron in connection with the processing of such data.
The Client shall not use the Services to infer, target, segment or conduct Outbound Communication on the basis of Special Categories of Personal Data unless the conditions of this Section 4 are met and the Parties have agreed additional provisions.
For Clients established in a GCC Jurisdiction, the attention of the Client is additionally drawn to the express exclusion of health data, patient data and government-classified data set out in Section RT-8.3 of the Regional Terms to the Main Agreement, including the UAE health-data localization requirements referenced there.
5. Confidentiality and Personnel
Quantum Neuron will ensure that its personnel and any other persons authorized to Process Client Personal Data:
- Process Client Personal Data only on the Client's Instructions and only to the extent necessary (need-to-know);
- have committed themselves to confidentiality, by contract or statutory obligation, surviving the end of their engagement with Quantum Neuron;
- have received appropriate training on their Personal Data protection obligations; and
- are subject to user access management practices limiting access to Client Personal Data to the extent strictly necessary for the performance of their duties.
6. Security of Processing
6.1 Technical and organizational measures
Quantum Neuron will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of the Processing, in accordance with Article 32 EU GDPR and the equivalent provisions of the UK GDPR. A summary of such measures is set out in Annex II. A more detailed description is contained in the Security Annex, made available to the Client upon request subject to appropriate confidentiality obligations.
6.2 Updates to security measures
Quantum Neuron may update the technical and organizational measures from time to time, provided that such updates do not materially reduce the overall level of protection of Client Personal Data.
6.3 Diagnostic and monitoring tools
Where session replay, error monitoring or diagnostic tools are used in connection with the Services, Quantum Neuron will configure masking, scrubbing or equivalent controls for sensitive form fields and user-entered content, to the extent technically supported by the relevant tool.
7. Data Protection Officer and Representatives
7.1 Data Protection Officer
Quantum Neuron has appointed and maintains - voluntarily, in accordance with the principles of Articles 37-39 EU GDPR - a Data Protection Officer. The Data Protection Officer is Mr. Krzysztof Kochanowski, contact: ido@quantumneuron.ai. The Data Protection Officer is the primary point of contact for matters concerning the Processing of Personal Data under this DPA, alongside privacy@quantumneuron.ai for general privacy inquiries.
7.2 EU Representative
Quantum Neuron has no establishment in the European Union, and its Processing activities fall within the scope of Article 3(2) EU GDPR. Quantum Neuron has therefore appointed, on the basis of a written mandate, Quantum Neuron Sp. z o.o. with its registered office in Warsaw, ul. Żurawia 6/12/745, 00-503 Warsaw, Poland, entered in the register of entrepreneurs of the National Court Register under KRS number: 0001222865, as its representative in the European Union pursuant to Article 27 EU GDPR. The representative constitutes a point of contact - alongside Quantum Neuron - for Data Subjects and supervisory authorities in all matters relating to the Processing of Client Personal Data; contact: privacy@quantumneuron.ai and the representative's postal address indicated above. Quantum Neuron Sp. z o.o. does not participate in the Processing of Client Data or Client Personal Data and does not act as a processor or subprocessor.
7.3 UK Representative
To the extent Quantum Neuron Processes Personal Data subject to the UK GDPR and has no establishment in the United Kingdom, Quantum Neuron has appointed, on the basis of a written mandate, Kochanowski Consulting Ltd, 151 Picton Road, Liverpool, Merseyside L15 4LG, United Kingdom, as its representative in the United Kingdom pursuant to Article 27 UK GDPR. The UK representative constitutes a point of contact for Data Subjects and for the Information Commissioner's Office. Contact: ido@quantumneuron.ai.
8. Subprocessors
8.1 General authorization
The Client grants Quantum Neuron a general written authorization to engage Subprocessors in connection with the provision of the Services. The current list of authorized Subprocessors is set out in the Subprocessor List published at https://quantumneuron.ai/legal/m26/subprocessors.
8.2 Obligations imposed on Subprocessors
Quantum Neuron will enter into a written contract, including in electronic form (Article 28(9) EU GDPR), with each Subprocessor, containing data protection obligations substantially equivalent to those set out in this DPA. Where a Subprocessor is located outside the European Economic Area or the United Kingdom, Quantum Neuron will ensure that an appropriate transfer mechanism under Chapter V of the EU GDPR or the UK GDPR is implemented, including, as applicable, the EU SCCs, the UK Addendum or a relevant adequacy decision.
8.3 Notice of changes
Quantum Neuron will give the Client written notice at least thirty (30) days in advance of any intended change consisting of the addition or replacement of a Subprocessor. Such notice will be given by sending an email to the Client's privacy contact and by updating the Subprocessor List.
8.4 Right to object
The Client may object to a proposed change within thirty (30) days of receiving the notice, on reasonable grounds relating to data protection. The Parties will use good-faith efforts to reach a mutually acceptable solution within thirty (30) days of the Client's objection.
8.5 Liability for Subprocessors
Quantum Neuron remains liable to the Client for the acts and omissions of its Subprocessors to the same extent as if such acts or omissions had been performed by Quantum Neuron itself, subject to the limitations of liability set out in the Main Agreement.
9. International Data Transfers
9.1 Primary Processing location
The primary Processing of Client Personal Data takes place within the European Economic Area. The production environment of the core infrastructure operates on Amazon Web Services in the Ireland region (eu-west-1). Any transfers of Client Personal Data outside the European Economic Area or the United Kingdom are carried out on the basis of a valid transfer mechanism under Chapter V of the EU GDPR or the UK GDPR.
9.2 Transfers to Quantum Neuron in the United States
To the extent Quantum Neuron accesses Client Personal Data from the United States or Client Personal Data is transferred to Quantum Neuron in the United States, such transfer is safeguarded by the EU SCCs, in particular Module Two (Controller-to-Processor), entered into between the Client as data exporter (controller) and Quantum Neuron as data importer (processor), and, where the Client acts as a processor in accordance with Section 2.1, Module Three (Processor-to-Processor). With respect to Client Personal Data subject to the UK GDPR, the transfer is additionally safeguarded by the UK Addendum, entered into between the Client as exporter and Quantum Neuron as importer. Quantum Neuron does not rely on the EU-U.S. Data Privacy Framework or the UK-US Data Bridge as a transfer mechanism.
9.3 EU Standard Contractual Clauses
Where Quantum Neuron or its Subprocessor Processes Client Personal Data subject to the EU GDPR outside the European Economic Area in circumstances requiring a transfer mechanism under Chapter V of the EU GDPR, the EU SCCs are incorporated into this DPA by reference and deemed entered into between the relevant parties to the transfer. For the purposes of Clause 17 of the EU SCCs, the Parties select Option 1 and the law of the Republic of Poland as the governing law. For the purposes of Clause 18(b), the Parties select the courts of the Republic of Poland. Annex I and Annex II to this DPA serve as Annex I and Annex II to the EU SCCs, respectively. Annex III to the EU SCCs is completed by reference to the Subprocessor List.
For the avoidance of doubt, the selection of Polish law and Polish courts in this Section 9.3 operates solely within and for the purposes of the EU SCCs, as required by Clauses 17 and 18 of the EU SCCs (which require the law and courts of an EU Member State), and does not affect the governing law and dispute resolution provisions of the Main Agreement.
9.4 UK International Data Transfer Addendum
Where Quantum Neuron or its Subprocessor Processes Client Personal Data subject to the UK GDPR outside the United Kingdom in circumstances requiring a transfer mechanism under Chapter V of the UK GDPR, the UK Addendum is incorporated into this DPA by reference and applies as a supplement to the EU SCCs, whereby for transfers between the Client and Quantum Neuron the Client is the exporter and Quantum Neuron is the importer. The tables of the UK Addendum are deemed completed with the information contained in Annex I and Annex II to this DPA and in the EU SCCs incorporated under Section 9.3.
9.5 Transfer impact assessment
Where Client Personal Data is transferred to a country not covered by an adequacy decision, Quantum Neuron has carried out or will carry out a transfer impact assessment, taking into account the law and practice of the destination country and identifying appropriate supplementary technical, contractual and organizational measures where necessary. A summary of the transfer impact assessment concerning transfers to Quantum Neuron in the United States is made available to the Client upon reasonable request, subject to appropriate confidentiality obligations.
9.6 Conflict
In the event of any conflict or inconsistency between this DPA and the EU SCCs or the UK Addendum with respect to a given transfer of Client Personal Data, the provisions of the EU SCCs or the UK Addendum prevail.
9.7 Subprocessor locations and transfer mechanism
The Subprocessor List indicates, where available, the location of and the transfer mechanism applicable to each Subprocessor.
9.8 GCC transfers
For Clients established in a GCC Jurisdiction, the direction of the relevant data flow is from the Client's jurisdiction into the European Economic Area (Section 9.1), where the data benefits from the protection standard of this DPA. The Client remains responsible for confirming that its submission of Client Personal Data to the Services complies with any cross-border transfer conditions and localization requirements of its own jurisdiction, as set out in Section RT-8 of the Regional Terms to the Main Agreement and in Annex IV to this DPA.
10. Data Subject Rights
10.1 Assistance to the Client
Taking into account the nature of the Processing, Quantum Neuron will assist the Client by appropriate technical and organizational measures, insofar as this is possible, in the fulfillment of the Client's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the EU GDPR or Chapter III of the UK GDPR, or the corresponding data subject rights provisions of other Applicable Data Protection Laws.
10.2 Requests received from Data Subjects
If Quantum Neuron receives a request from a Data Subject concerning Client Personal Data, it will not respond to it directly, other than to acknowledge receipt or redirect the Data Subject to the Client, and will forward such request to the Client without undue delay.
10.3 Response time
Quantum Neuron will respond to the Client's request for assistance in connection with a Data Subject request within fourteen (14) days of receiving the Client's request.
10.4 Costs
Assistance with Data Subject requests is provided at no additional cost to the Client and is covered by the fees due under the Main Agreement, provided that the volume and frequency of such requests are reasonable.
11. Personal Data Breach Notification
11.1 Notification deadline
Quantum Neuron will notify the Client without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a Personal Data Breach affecting Client Personal Data.
11.2 Content of the notification
The notification will include, to the extent reasonably available at the time of notification: (a) a description of the nature of the Personal Data Breach; (b) the contact details of Quantum Neuron's privacy contact point at privacy@quantumneuron.ai, the Data Protection Officer at ido@quantumneuron.ai or another designated contact point; (c) a description of the likely consequences of the Breach; and (d) a description of the measures taken or proposed to be taken by Quantum Neuron.
11.3 Further cooperation
Quantum Neuron will cooperate in good faith with the Client in connection with the Client's own obligations to notify competent supervisory authorities and, where applicable, Data Subjects, including - for Clients established in a GCC Jurisdiction - the Client's breach notification obligations under the UAE PDPL, the KSA PDPL or other Applicable Data Protection Laws of the Client's jurisdiction, in accordance with Annex IV.
11.4 No admission of liability
Notification of a Personal Data Breach by Quantum Neuron does not constitute an admission by Quantum Neuron of any fault or liability.
12. Data Protection Impact Assessments and Prior Consultation
Taking into account the nature of the Processing and the information available to it, Quantum Neuron will provide the Client with reasonable assistance in carrying out data protection impact assessments in accordance with Article 35 EU GDPR and in consultations with supervisory authorities in accordance with Article 36 EU GDPR - or the corresponding provisions of other Applicable Data Protection Laws - where the Client reasonably considers that such assessments or consultations are required.
Where the Client uses the Services for Outbound Communication, large-scale lead activation, voice calls, SMS campaigns, WhatsApp campaigns or similar communication, the Client remains responsible for determining whether a data protection impact assessment, a legitimate interest assessment, an ePrivacy assessment, a telemarketing compliance assessment or an equivalent assessment is required for its specific use case.
13. Audits and Information Rights
13.1 Information rights
Quantum Neuron will make available to the Client all information necessary to demonstrate compliance with the obligations set out in this DPA and in the Applicable Data Protection Laws, including responses to reasonable written questionnaires, relevant external audit reports, certificates and attestations, subject to appropriate confidentiality obligations.
13.2 On-site audits
The Client or an auditor appointed by the Client may carry out an on-site audit of the processing activities carried out by Quantum Neuron under this DPA, no more than once per calendar year, upon at least thirty (30) days' prior written notice, during normal business hours, without unreasonable disruption to Quantum Neuron's operations, at the Client's expense and subject to appropriate confidentiality obligations.
13.3 Audit reports
The Client will promptly provide Quantum Neuron with a copy of the audit report and will treat the report and any information obtained in the course of the audit as Quantum Neuron's confidential information.
14. AI Model Training and Test Environments
14.1 No use of Client Personal Data for training
Quantum Neuron does not use Client Personal Data in identifiable form to train, fine-tune or otherwise improve the AI models underlying the Services. Quantum Neuron uses for such purposes only data previously subjected to the documented process of irreversible Anonymization.
14.2 Default anonymization pipeline
By default, Quantum Neuron processes selected Client Personal Data within the documented process of irreversible Anonymization for the purpose of fine-tuning and improving AI models and of using selected production data, after Anonymization, in non-production test environments operated by Quantum Neuron. The Anonymization process is verified by a documented manual verification step before any further use.
14.3 Opt-out
The Client may at any time opt out of the processing described in Section 14.2 by written notice sent to privacy@quantumneuron.ai with a copy to legal@quantumneuron.ai, or through the applicable Order Form. Upon receipt of such notice, Quantum Neuron will cease further processing of newly acquired Client Personal Data in its anonymization pipeline within a reasonable period not exceeding fifteen (15) days.
14.4 Controller obligations
The Client confirms that it has - or will have before the relevant Processing is carried out - a valid legal basis for the Processing described in this Section 14 and that it will inform its own customers, employees and End Users of such Processing where required by the Applicable Data Protection Laws.
14.5 Foundation models
Client Personal Data is not shared with external foundation model developers and is not used to train, fine-tune or otherwise improve such foundation models outside Quantum Neuron's own deployments, unless expressly agreed in writing with the Client. Quantum Neuron uses foundation models through enterprise-grade cloud services on contractual terms prohibiting the use of customer data to train, fine-tune or improve such foundation models by the relevant cloud provider.
15. Return and Deletion of Client Personal Data
15.1 Retention during the term
Quantum Neuron will retain Client Personal Data for the duration of the subscription under the Main Agreement or until earlier deletion on the Client's Instruction.
15.2 Return or deletion upon termination
Upon termination or expiration of the Main Agreement, Quantum Neuron will - at the Client's election - return or delete all Client Personal Data in its possession within thirty (30) days of the effective date of termination, and will delete such data from backup systems within a further ninety (90) days, unless applicable law requires further retention.
15.3 Anonymization exception
Before deletion carried out under Section 15.2, and provided the Client has not opted out or otherwise objected in writing, Quantum Neuron may apply its documented process of irreversible Anonymization to selected Client Personal Data. Data effectively Anonymized no longer constitutes Personal Data and is not subject to the deletion obligations set out in this Section 15.
15.4 Confirmation
Upon the Client's written request, Quantum Neuron will provide written confirmation of the performance of the obligations set out in this Section 15.
16. Exclusions from Scope
This DPA does not govern the following Processing activities, with respect to which Quantum Neuron acts as an independent controller in accordance with its privacy notice:
- Processing of billing, payment and administrative data of the Client's account for the purposes of contract performance, invoicing and compliance with financial and tax obligations;
- Processing of support communications initiated by the Client or its authorized personnel for the purposes of providing support, troubleshooting and service quality improvement;
- Processing of security telemetry, access logs, audit logs and related operational data for the purposes of protecting the security, integrity and availability of the Services, preventing and detecting abuse and fraud, and complying with Quantum Neuron's legal and regulatory obligations; and
- Processing of aggregated, de-identified or technical product analytics for the purposes of operating, maintaining and improving the Services.
To the extent such Processing involves Personal Data, Quantum Neuron Processes such data in accordance with the Applicable Data Protection Laws and on the basis of an appropriate legal basis under Article 6 EU GDPR or the equivalent provisions of other Applicable Data Protection Laws.
17. AI Act Compliance
17.1 Scope of AI Act references
References to Regulation (EU) 2024/1689 (the "EU AI Act") in this DPA apply only to the extent the relevant use, deployment, output, placing on the market or legal obligation falls within the territorial or extraterritorial scope of the EU AI Act.
17.2 Provider and deployer roles
To the extent the EU AI Act applies, Quantum Neuron acts as the "provider" of the AI system vis-a-vis the Client, and the Client acts as the "deployer" of the AI system within the meaning of the EU AI Act. The Services are classified in their default configuration as a limited-risk AI system under the EU AI Act.
17.3 AI transparency and disclosure
The AI Persona has a built-in and by-default active AI disclosure to the extent required by law. The AI-interaction disclosure is a Quantum Neuron product standard active in all communication channels regardless of the Client's region. The Client may not disable or weaken it to the extent the disclosure is required by law, platform rules or the contractual documents; the content of the disclosure notice may be agreed with Quantum Neuron within the limits of applicable law and platform rules. The Client is responsible for its own context of use, its own deployer obligations and for ensuring that End Users receive the legally required information notices and disclosures beyond the built-in notice, unless the Parties expressly agree otherwise in the Order Form or an Enterprise AI compliance addendum.
17.4 High-Risk AI Use Cases
The Client shall not use the Services for any High-Risk AI Use Case, except in accordance with the Main Agreement and an Enterprise High-Risk AI Addendum entered into by the Parties.
18. Liability
18.1 Limitation of liability
Each Party's liability arising out of or relating to this DPA, of any kind, whether in contract, tort or otherwise, is subject to the aggregate limitations of liability set out in the Main Agreement.
18.2 Administrative fines
Administrative fines imposed on a Party by a competent supervisory authority under the Applicable Data Protection Laws are borne by the Party on which they are imposed, except to the extent the other Party caused or materially contributed to the circumstances giving rise to the fine.
19. Term and Termination
This DPA takes effect on the effective date of the Main Agreement or the applicable Order Form and remains in force for the term of the Main Agreement and for such further period during which Quantum Neuron Processes Client Personal Data after termination, including the retention periods set out in Section 15.
20. Amendments to this DPA
Quantum Neuron may update this DPA from time to time, provided that non-material amendments may be made by publication of an updated version, and material amendments take effect no earlier than thirty (30) days after Quantum Neuron gives notice to the Client. All versions of this DPA are maintained in a version control system, and previous versions remain available to the Client upon request.
21. Precedence
In the event of any conflict or inconsistency: (a) between this DPA and the Main Agreement - this DPA prevails in matters concerning privacy, data protection and the Processing of Personal Data; (b) between this DPA and the EU SCCs or the UK Addendum with respect to a transfer governed by those instruments - the EU SCCs or the UK Addendum prevail; (c) between this DPA and any other document incorporated by reference - this DPA prevails, unless expressly provided otherwise.
22. Miscellaneous
22.1 Governing law
This DPA is governed by and construed in accordance with the law governing the Main Agreement or the applicable Order Form. Notwithstanding the foregoing, the mandatory provisions of the Applicable Data Protection Laws of the Client's jurisdiction apply where required, and the governing law and jurisdiction of the EU SCCs and the UK Addendum are as set out in those instruments and in Section 9 of this DPA.
22.2 Severability
If any provision of this DPA is held invalid, unlawful or unenforceable, the remaining provisions remain in full force and effect.
22.3 Notices
Notices under this DPA are given in accordance with the notice provisions of the Main Agreement. In matters concerning data protection, notices to Quantum Neuron are additionally sent to privacy@quantumneuron.ai and to the Data Protection Officer at ido@quantumneuron.ai, with a copy to legal@quantumneuron.ai.
22.4 Electronic acceptance
The Client accepts this DPA by entering into the Main Agreement or the Order Form into which this DPA is incorporated by reference. A signed counterpart of this DPA may be executed by the Parties upon the Client's request.
Annex I - Description of the Processing
A. List of Parties
Data Exporter / Controller: the Client, as identified in the Main Agreement or the Order Form.
Data Importer / Processor: Quantum Neuron Inc., 169 Madison Ave STE 15768, New York, NY 10016, United States of America, EIN: 30-1448079.
Representative in the European Union (Article 27 EU GDPR): Quantum Neuron Sp. z o.o., ul. Żurawia 6/12/745, 00-503 Warsaw, Poland, KRS: 0001222865.
Representative in the United Kingdom (Article 27 UK GDPR): Kochanowski Consulting Ltd, 151 Picton Road, Liverpool, Merseyside L15 4LG, United Kingdom.
Contact point for data protection matters: privacy@quantumneuron.ai; Data Protection Officer: Krzysztof Kochanowski, ido@quantumneuron.ai.
B. Description of the transfer / Processing
Categories of Data Subjects:
- Employees, contractors and other authorized personnel of the Client who access the Services through a dashboard account.
- Customers, prospects, leads and other End Users interacting with the Client's AI Persona through any text or voice channel made available within the Services.
- Contacts, correspondents and other persons identified in systems integrated with the Services in accordance with the Client's configuration.
- Recipients of Outbound Communication, including leads, prospects, customers, business contacts and other persons whose contact details or identifiers are submitted by or on behalf of the Client to the Services.
Categories of Personal Data:
- Identification and contact data, including name, email address, phone number and similar identifiers.
- Communication content, including text messages, voice audio streams, voice recordings - where recording is enabled - conversation transcripts and conversation history.
- Voice consent metadata, where collected as part of the consent flow for recording a voice interaction.
- Authentication and account data, including hashed credentials, session identifiers and account configuration data.
- Technical data, including IP address, user agent, device information and log data generated as a result of the use of the Services.
- Knowledge base content provided by the Client, to the extent it contains Personal Data.
- Files, documents and attachments shared or sent by the AI Persona on the basis of the Client's materials, configuration or instructions, to the extent they contain Personal Data.
- Data from systems integrated with the Services, for example CRM records, email content, calendar events, in accordance with the Client's configuration.
- Lead Data, prospect data, recipient data, contact list data, phone numbers, email addresses, social media identifiers, messaging identifiers, communication preferences, consent metadata, opt-in records, opt-out records, exclusion lists, do-not-contact designations and campaign metadata.
Special Categories of Personal Data: Not normally processed. Where the Client submits Special Categories of Personal Data, the conditions of Section 4 of this DPA apply.
Frequency of the Processing: Continuous for the term of the Main Agreement or the Order Form.
Nature and purpose of the Processing:
- Provision of the AI Persona platform for automated communication through text and voice channels.
- Retrieval-augmented generation (RAG) processing of the knowledge base content provided by the Client for the purposes of AI Persona responses.
- Integration with the Client's communication, productivity and CRM systems in accordance with the Client's configuration.
- Operational support, service delivery, billing and other purposes reasonable and necessary to deliver the Services.
- Processing of Lead Data and recipient data to enable the Client to conduct, manage, automate, monitor and analyze inbound and outbound communication through the Services.
- Platform maintenance, logging, backups, ensuring availability, reliability and business continuity, security, monitoring, technical support, incident response and cloud and infrastructure operations.
Duration of the Processing: For the term of the Main Agreement or the Order Form and for the post-termination retention and deletion periods set out in Section 15 of this DPA.
C. Competent supervisory authority
For the purposes of Clause 13 of the EU SCCs, the competent supervisory authority is the supervisory authority of the Member State of the European Economic Area in which the relevant Data Subjects are located or - where the Client is established in the European Economic Area - the supervisory authority of the Member State of the Client's main establishment. With respect to Clients subject to the UK GDPR, the competent supervisory authority is the UK Information Commissioner's Office. Where the Client is established outside the European Economic Area and the United Kingdom and the EU SCCs apply to a given transfer, the competent supervisory authority is determined in accordance with Clause 13 of the EU SCCs by reference to the location of the relevant Data Subjects or the Article 27 representative.
Annex II - Technical and Organizational Measures
Quantum Neuron has implemented and maintains the following technical and organizational measures designed to ensure an appropriate level of security of Client Personal Data, in accordance with Article 32 EU GDPR and the equivalent provisions of the UK GDPR. The measures described below are presented in summary form; a more detailed description is contained in the Quantum Neuron Security Annex, made available to the Client upon request subject to appropriate confidentiality obligations.
1. Access control and authentication
Access to systems processing Client Personal Data is restricted on a need-to-know basis through role-based access control (RBAC), least-privilege principles and logical tenant-level separation. Authentication to production environments requires multi-factor authentication (MFA).
2. Encryption
Client Personal Data is encrypted in transit using industry-standard transport layer encryption (TLS 1.2 or higher) and at rest using industry-standard symmetric encryption (AES-256 or equivalent).
3. Network and application security
Production systems are separated from non-production environments and protected by network-layer security controls, including firewalls, traffic filtering and monitoring. Applications are subject to secure development practices, dependency management and vulnerability scanning.
4. Logging, monitoring and audit trails
Security-relevant events, including access to Client Personal Data, authentication events and administrative actions, are logged and retained in accordance with Quantum Neuron's internal retention policies. Logs are monitored for anomalies using automated detection mechanisms.
5. Backups, retention and business continuity
Client Personal Data is subject to regular, encrypted backups, stored within the European Economic Area; any exceptions require a valid transfer mechanism in accordance with Section 9 of this DPA. Quantum Neuron maintains business continuity and disaster recovery procedures.
6. Incident management
Quantum Neuron maintains an incident response procedure covering detection, triage, containment, eradication, recovery and post-incident review.
7. Personnel security, confidentiality and training
Personnel are subject to internal confidentiality commitments surviving the end of their engagement and receive regular data protection and information security training appropriate to their roles.
8. Subprocessor management
Subprocessors are subject to risk-based due diligence before engagement, subprocessor-side access controls and ongoing monitoring. Each Subprocessor is bound by data protection obligations substantially equivalent to those set out in this DPA.
9. Physical security
Physical security of data processing facilities is provided by Quantum Neuron's infrastructure hosting providers, which maintain industry-recognized physical security measures for their data centers.
10. Data minimization, pseudonymization and sensitive field handling
Quantum Neuron applies data minimization principles in the design of the Services and, where appropriate, pseudonymization or anonymization techniques to reduce the risk of unauthorized re-identification.
11. Controls for communication content and outbound channels
Specific controls are applied to voice recordings, transcripts, SMS content, WhatsApp content, email content, call metadata and communication logs generated through the Services, including access restrictions, retention controls and deletion flows.
12. Diagnostic, error monitoring and session replay tools
Where session replay, error monitoring or diagnostic tools are used in connection with the Services, Quantum Neuron configures masking, scrubbing or equivalent controls for sensitive form fields and user-entered content.
Annex III - Authorized Subprocessors
The Subprocessor List published by Quantum Neuron at:
https://quantumneuron.ai/legal/m26/subprocessors
The Subprocessor List is deemed - by reference - to constitute Annex III to the EU SCCs and the equivalent subprocessor list under the UK Addendum.
Annex IV - GCC Data Protection Annex
This Annex IV applies to Clients established in a GCC Jurisdiction (as defined in the Main Agreement) and, to the extent relevant, to the Processing of Personal Data of Data Subjects located in a GCC Jurisdiction. It supplements - and does not reduce - the protections set out in the body of this DPA, which apply to such Clients in full as the universal contractual baseline (Section 2.6).
IV.1 Terminology mapping
For the purposes of applying this DPA under the Applicable Data Protection Laws of a GCC Jurisdiction, the following concepts correspond: "Controller" includes the concept of "controller" under the UAE PDPL and the KSA PDPL and equivalent concepts under other GCC data protection laws; "Processor" includes the concept of "processor" under the UAE PDPL and the KSA PDPL and equivalent concepts; "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" include the corresponding concepts under such laws. Where a GCC data protection law uses a materially different concept for which no direct GDPR equivalent exists, the Parties will interpret this DPA so as to give effect to the protective purpose of both regimes.
IV.2 Protection undertaking
Quantum Neuron undertakes to apply to the Personal Data of Data Subjects located in a GCC Jurisdiction the same protections, technical and organizational measures (Annex II), subprocessor regime (Section 8), transfer safeguards (Section 9), assistance and cooperation machinery (Sections 10-13) and AI-training safeguards (Section 14) as apply to data subject to the EU GDPR under this DPA, which the Parties acknowledge to be a standard of protection at least equivalent in substance to the requirements of the UAE PDPL and the KSA PDPL at the level of principles.
IV.3 Breach notification consistency
The forty-eight (48) hour notification obligation in Section 11.1 is intended to enable the Client to comply with its own breach notification obligations under the Applicable Data Protection Laws of its jurisdiction, including any notification deadlines under the UAE PDPL or the KSA PDPL. Quantum Neuron's cooperation under Section 11.3 extends to the information reasonably required by the Client to notify the competent GCC data protection authority.
IV.4 Local registration and notification duties
Quantum Neuron will reasonably cooperate with the Client's registration, notification, record-keeping or appointment duties under the Applicable Data Protection Laws of the Client's GCC Jurisdiction, to the extent such duties concern the Services, by providing information, records and security descriptions reasonably available to Quantum Neuron, mirroring the cooperation machinery of Sections 12 and 13. Quantum Neuron does not undertake to perform any local registration or filing in the Client's jurisdiction on its own behalf.
IV.5 Cross-border transfer conditions and localization
The Client is responsible for confirming that its submission of Personal Data to the Services complies with the cross-border transfer conditions of the Applicable Data Protection Laws of its jurisdiction (including any consent, notification, contractual or adequacy-style conditions under the UAE PDPL or the KSA PDPL) and with any data localization requirements applicable to the Client, in accordance with Section RT-8 of the Regional Terms. The exclusion of health data, patient data and government-classified data set out in Section RT-8.3 of the Regional Terms applies to all Processing under this DPA.
IV.6 Free zones
Where the Client is established in the DIFC or the ADGM, references in this Annex IV to the UAE PDPL are read as references to the DIFC Data Protection Law or the ADGM Data Protection Regulations, as applicable, and the terminology mapping in Section IV.1 applies accordingly.