This DPA governs the processing of personal data by Quandry Labs on behalf of our clients, in accordance with applicable data protection legislation including the GDPR.
For the purposes of this Data Processing Agreement ("DPA"), the following definitions apply:
The Client entity that determines the purposes and means of the processing of Personal Data and enters into a service agreement with Quandry Labs.
Quandry Labs LLC, which processes Personal Data on behalf of the Controller pursuant to the service agreement and this DPA.
An identified or identifiable natural person whose Personal Data is processed under this DPA.
Any information relating to a Data Subject that is processed by the Processor on behalf of the Controller in connection with the services.
Any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
Any third party engaged by Quandry Labs to process Personal Data on behalf of the Controller.
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed.
This DPA applies to all processing of Personal Data by Quandry Labs in connection with the consulting, integration, and automation services provided under the applicable service agreement.
The processing of Personal Data necessary for Quandry Labs to deliver the services described in the Statement of Work, which may include access to, analysis of, and integration with client security systems containing Personal Data.
Processing continues for the duration of the service agreement, plus any retention period required by law or specified herein.
Quandry Labs, as Processor, shall:
The Controller provides general written authorization for Quandry Labs to engage Sub-Processors. Quandry Labs shall:
If the Controller objects to a new Sub-Processor on reasonable grounds related to data protection, the parties shall discuss the concern in good faith. If no resolution is reached within 30 days, the Controller may terminate the affected services without penalty.
Quandry Labs shall impose on each Sub-Processor, by way of contract, data protection obligations no less protective than those set out in this DPA. Quandry Labs remains fully liable for the performance of each Sub-Processor's obligations.
Quandry Labs shall assist the Controller in fulfilling its obligations to respond to Data Subject requests exercising their rights under GDPR, including:
If a Data Subject contacts Quandry Labs directly, we shall promptly redirect the request to the Controller and not respond directly unless authorized.
Quandry Labs shall respond to Controller assistance requests within 10 business days, or sooner where required by applicable law.
Quandry Labs implements and maintains technical and organizational security measures appropriate to the risk, including:
For full details of our security practices, see our Security Practices page.
Quandry Labs shall regularly assess and update these measures to account for evolving risks, technology changes, and regulatory requirements.
In the event of a Data Breach affecting Personal Data processed under this DPA, Quandry Labs shall:
72-hour notification — notify the Controller without undue delay and in any event within 72 hours of becoming aware of the Data Breach.
The notification shall include, to the extent available:
Where information is not immediately available, it shall be provided in phases without undue delay. Quandry Labs shall cooperate fully with the Controller's investigation and regulatory notification obligations.
Quandry Labs shall document all Data Breaches, including facts, effects, and remedial actions taken, regardless of whether notification to the Controller is required.
Quandry Labs is based in the United States. Where Personal Data originating from the EEA, UK, or Switzerland is transferred to the US for processing, the following safeguards apply:
Quandry Labs shall not transfer Personal Data to any country outside the EEA without appropriate safeguards and without informing the Controller.
Sub-Processors located outside the EEA are subject to equivalent transfer mechanisms before any Personal Data is shared with them.
This DPA is effective from the date of the applicable service agreement and remains in force for as long as Quandry Labs processes Personal Data on behalf of the Controller.
Upon termination or expiration of the service agreement, Quandry Labs shall, at the Controller's election:
Quandry Labs may retain Personal Data only to the extent required by applicable law, and only for the duration required. Any retained data remains subject to this DPA.
Confidentiality obligations and data protection commitments survive termination for as long as any Personal Data remains in Quandry Labs' possession.
The Controller has the right to verify Quandry Labs' compliance with this DPA through:
Quandry Labs shall cooperate with and provide reasonable assistance for audits. The Controller shall bear the costs of any audit it initiates, except where the audit reveals material non-compliance, in which case Quandry Labs shall bear the costs.
Quandry Labs LLC — Data Protection
Registered in the State of Delaware
Email: [email protected]
Response time: within 10 business days
We can provide a countersigned DPA for your engagement. Reach out and we'll send an executable version within 48 hours.
Request signed DPA →