Acuerdo de procesamiento de datos

Última actualización: 1 de enero de 2025

Nuestro DPA regula el procesamiento de datos personales en nombre de nuestros clientes.

1. Parties and Scope

This Data Processing Agreement ("DPA") forms part of the agreement between QualityProxy Inc. ("Processor") and the customer ("Controller") when Controller processes personal data subject to GDPR, UK GDPR, or similar laws using QualityProxy Services.

This DPA applies to personal data QualityProxy processes on behalf of Controller in connection with account management, billing, support, and service delivery. It does not cover data Controller collects from third parties through proxy traffic—that remains Controller's responsibility.

2. Definitions

"Personal Data", "Processing", "Data Subject", "Sub-processor", and "Supervisory Authority" have meanings under applicable Data Protection Laws.

"Data Protection Laws" means GDPR, UK GDPR, CCPA where applicable, and other privacy laws governing the processing.

3. Processor Obligations

Process Personal Data only on documented instructions from Controller, including regarding transfers, unless required by law.

Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.

Implement appropriate technical and organizational measures as described in our security documentation.

Assist Controller with data subject requests, DPIAs, and breach notifications as reasonably required.

Delete or return Personal Data upon termination of Services, subject to legal retention requirements.

4. Sub-processors

Controller authorizes QualityProxy to engage Sub-processors for cloud hosting, payment processing, analytics, and support tools. A current list of Sub-processors is available upon request.

We notify Controller of new Sub-processors with thirty days to object on reasonable grounds. Objections may require alternative arrangements or termination without penalty if unresolved.

5. International Transfers

Where Personal Data is transferred outside the EEA or UK, QualityProxy relies on Standard Contractual Clauses, UK IDTA addendum, or other approved mechanisms. Supplementary measures are applied as assessed.

6. Security Incidents

QualityProxy notifies Controller without undue delay upon becoming aware of a Personal Data breach affecting Controller data, providing information reasonably available for Controller's regulatory obligations.

7. Audit Rights

Upon reasonable notice, Controller may request information necessary to demonstrate compliance. Enterprise customers may conduct audits under confidentiality agreements no more than once annually unless required by Supervisory Authority.

8. Execution

This DPA is incorporated into the Terms of Service upon account creation. Enterprise customers may execute a countersigned version by contacting legal@qualityproxy.com.