EvaliQA
PricingAbout us
Sign inStart free Start→

Data Processing Addendum

Effective Date: September 19, 2026

This Data Processing Addendum (the "DPA") forms part of the agreement between QA Mentor, Inc. ("QA Mentor," "we," "our," or "us"), operator of the EvaliQA platform, and the customer that has entered into the EvaliQA Terms and Conditions or another written ordering agreement ("Customer," "you," or "your") (together, the "Agreement"). This DPA governs the Processing of Personal Data by QA Mentor on Customer's behalf in connection with the Services.

This DPA applies to the extent QA Mentor Processes Personal Data on Customer's behalf that is subject to European Data Protection Law, the laws of the United Kingdom or Switzerland, applicable United States state privacy laws, or another law requiring a data processing agreement. In the event of a conflict concerning the Processing of Customer Personal Data, the order of precedence is set out in Section 15.2.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement.

"Applicable Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as incorporated into the law of the United Kingdom ("UK GDPR"), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other United States state privacy laws.

"Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach," and "Special Categories of Personal Data" have the meanings given in Applicable Data Protection Law. For United States state privacy laws, "Controller" includes "Business," and "Processor" includes "Service Provider" or "Contractor."

"Customer Evaluation Data" has the meaning given in the Agreement and, to the extent it contains Personal Data, is Processed under this DPA.

"Customer Personal Data" means Personal Data contained in Customer Evaluation Data or otherwise Processed by QA Mentor on Customer's behalf under the Agreement.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Decision 2021/914 of 4 June 2021.

"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018.

"Sub-processor" means any third party engaged by QA Mentor to Process Customer Personal Data.

2. Roles of the Parties

2.1 As between the parties, Customer is the Controller (or, where Customer is itself a Processor, the Processor) of Customer Personal Data, and QA Mentor is the Processor (or Sub-processor). For United States state privacy laws, Customer is the Business and QA Mentor is the Service Provider.

2.2 Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for having the rights, notices, consents, and other lawful authority required to provide that data to QA Mentor and to authorize the Processing described in this DPA. Customer will promptly inform QA Mentor if it discovers that it submitted Customer Personal Data without the required authority or contrary to the agreed restrictions, and will cooperate in stopping or remediating the affected Processing.

2.3 QA Mentor acts as an independent Controller for Personal Data it Processes for its own account administration, billing, security, and direct communications purposes. That Processing is described in the EvaliQA Privacy Policy and is outside this DPA. Where the same Authorized User's information is included in Customer Evaluation Data or is Processed solely to provide the Services on Customer's behalf, this DPA applies to that Processing.

3. Scope and Instructions

3.1 QA Mentor will Process Customer Personal Data only on Customer's documented instructions, including as set out in this DPA and the Agreement and as necessary to provide and support the Services, unless Applicable Data Protection Law requires otherwise, in which case QA Mentor will inform Customer of that legal requirement before Processing unless the law prohibits it.

3.2 Customer's instructions are documented in the Agreement, this DPA, Annex I, the configuration and features Customer selects, and Customer's use of the Services. Customer may issue additional reasonable written instructions consistent with the Agreement.

3.3 QA Mentor will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. QA Mentor is not obligated to make a legal assessment of Customer's instructions. If QA Mentor reasonably believes an instruction is unlawful, exceeds the agreed scope, or requires Processing of Special Categories of Personal Data without the authorization and safeguards described in Annex I, QA Mentor may suspend the affected Processing, promptly notify Customer unless legally prohibited, and seek a revised instruction. Any suspension will be limited to what is reasonably necessary and will not limit QA Mentor's mandatory duties under Applicable Data Protection Law or the SCCs.

4. Restrictions on Processing

QA Mentor will Process Customer Personal Data only to provide, support, and secure the Services on Customer's documented instructions, including any evaluation requested by Customer. QA Mentor will not:

  • sell Customer Personal Data or "share" it for cross-context behavioral advertising as those terms are defined under United States state privacy laws;
  • use Customer Personal Data to train or fine-tune any public, general-purpose, third-party, or EvaliQA-specific AI or machine-learning model, or to test or improve a model for QA Mentor's or another party's benefit;
  • use Customer Personal Data to prepare proposals, market services, train staff, develop services for other customers, or perform cross-customer benchmarking;
  • disclose one customer's Customer Personal Data, evaluation results, reports, scores, or artifacts to another customer; or
  • retain, use, or disclose Customer Personal Data outside the direct business relationship or for a purpose other than providing the Services under the Agreement, except as required by Applicable Data Protection Law.

QA Mentor certifies that it understands these restrictions and will comply with them.

5. Confidentiality

QA Mentor will ensure that personnel authorized to Process Customer Personal Data are subject to a duty of confidentiality and Process Customer Personal Data only as needed to perform their duties. Access is restricted through appropriate access controls to authorized personnel, and access may be logged or monitored where appropriate.

6. Security

6.1 QA Mentor will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing. Those measures are described in Annex II.

6.2 QA Mentor may update its security measures from time to time, provided the updates do not materially reduce the overall level of protection of Customer Personal Data.

7. Sub-processors

7.1 Customer provides QA Mentor with general written authorization to engage Sub-processors to Process Customer Personal Data, subject to this Section. A current list of Sub-processors is set out in Annex III.

7.2 QA Mentor will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, including the relevant obligations of Article 28 GDPR. QA Mentor remains responsible for each Sub-processor's performance of its obligations.

7.3 QA Mentor will specifically notify Customer in writing, at the designated account contact email or through a written notice addressed to Customer in the Services, at least thirty (30) days before an intended addition or replacement of a Sub-processor. QA Mentor will also update the Sub-processor list. Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith to resolve the objection. If they cannot, Customer may terminate the affected Service and receive a prorated refund of prepaid fees for the unused subscription period, without limiting any rights or remedies that cannot be excluded under Applicable Data Protection Law or the SCCs.

8. Assistance to Customer

8.1 Data Subject requests. Taking into account the nature of the Processing, QA Mentor will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law. If QA Mentor receives such a request directly, it will not respond except on Customer's documented instructions or as required by law, and will refer the requester to Customer where appropriate.

8.2 Compliance obligations. Taking into account the nature of the Processing and the information available to QA Mentor, QA Mentor will assist Customer in ensuring compliance with its obligations relating to security of Processing, notification of Personal Data Breaches, data protection impact assessments, and prior consultation with a supervisory authority under Articles 32 to 36 GDPR.

9. Personal Data Breach

9.1 QA Mentor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2 The notification will describe, to the extent known and reasonably available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. QA Mentor will provide further information in phases as it becomes available.

9.3 QA Mentor's notification is not an acknowledgment of fault or liability. Customer is responsible for notifying supervisory authorities and Data Subjects where required in its role as Controller, without relieving QA Mentor of any notification duty imposed directly on it by Applicable Data Protection Law.

10. Deletion and Return

10.1 During the term, Customer may use the available export and deletion features. Customer Personal Data remains subject to Customer's selected retention settings, if available, and otherwise is retained only while needed to provide the Services during the subscription term. QA Mentor will provide the applicable setting or schedule to Customer through the Services, the Order Form, or a written request before it is applied. On expiry of that period, QA Mentor will delete active records, subject to Section 10.2 for backups and any retention required by law.

10.2 On expiration or termination of the Services, QA Mentor will, at Customer's choice, return or delete Customer Personal Data and delete existing active copies, unless Applicable Data Protection Law requires storage. If available export functionality is insufficient, Customer may request return in a commonly used electronic format. Residual copies in routine backups will remain protected, inaccessible for ordinary service use, and subject to this DPA until overwritten or deleted under the backup rotation schedule that QA Mentor makes available on request. If a backup is restored, Customer Personal Data that was due for deletion will be deleted again.

11. Audits and Records

11.1 QA Mentor will make available to Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, which may be satisfied through up-to-date certifications, audit reports, or completed security questionnaires.

11.2 Where the information under Section 11.1 is not sufficient to demonstrate compliance, Customer may conduct an audit on reasonable prior written notice, ordinarily no more than once per year, during business hours and subject to reasonable confidentiality, security, and operational safeguards. Additional audits are permitted where required by a supervisory authority, following a Personal Data Breach, or where required by Applicable Data Protection Law or the SCCs. The audit must not compromise the security or confidentiality of another customer's data. Customer bears its own audit costs, without limiting mandatory audit rights.

12. International Transfers

12.1 QA Mentor and its Sub-processors may Process Customer Personal Data in the United States and other locations used by authorized hosting and infrastructure providers to operate, secure, maintain, or support the Services.

12.2 Where a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland is subject to Applicable Data Protection Law governing international transfers, the parties agree that the transfer is made under a legally recognized mechanism, in the following order: (a) an adequacy decision; (b) the EU-US Data Privacy Framework and its UK and Swiss extensions, where the relevant importer is certified; or (c) the Standard Contractual Clauses, which are hereby incorporated into this DPA by reference and completed as set out in Section 12.3.

12.3 For the purposes of the SCCs:

  • Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor;
  • in Clause 7, the optional docking clause applies;
  • in Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 7.3 of this DPA;
  • in Clause 11, the optional redress language does not apply;
  • in Clause 17, the SCCs are governed by the law of Ireland;
  • in Clause 18, disputes are resolved before the courts of Ireland;
  • Annexes I and II of the SCCs are populated by Annexes I and II of this DPA. The list in Annex III of this DPA identifies the generally authorized Sub-processors for purposes of Clause 9, Option 2; Annex III of the SCCs is required for specific authorization under Clause 9, Option 1.

12.4 For restricted transfers subject to the UK GDPR, the UK Addendum is incorporated with Tables 1 to 3 completed using this DPA, the Agreement, and its Annexes. In Table 4, the data importer is selected as the party that may end the UK Addendum if the Approved Addendum changes, in accordance with Section 19 of that Addendum. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection where applicable, and the competent authority is the Swiss Federal Data Protection and Information Commissioner. The parties will complete any additional particulars required for an applicable transfer before relying on the SCCs or UK Addendum.

13. United States State Privacy Laws

13.1 To the extent United States state privacy law applies to Customer Personal Data, QA Mentor acts as a Service Provider or Contractor. The specified business purposes are hosting, storing, transmitting, testing and evaluating Customer Evaluation Data at Customer's direction, delivering the resulting reports and artifacts, providing support, and securing the Services. QA Mentor will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship or for another purpose, or combine it with Personal Data from other sources, except as permitted by Applicable Data Protection Law. The independent Controller activities described in Section 2.3 are outside this service-provider Processing.

13.2 QA Mentor will notify Customer if it determines it can no longer meet its obligations under Applicable Data Protection Law. Customer may take reasonable steps to stop and remediate unauthorized Processing.

14. Liability

14.1 As between the parties, a claim arising out of or relating to this DPA is a claim under the Agreement and counts toward the Agreement's single aggregate liability cap, rather than a separate cap. The exclusions, limitations, and express exceptions in the Agreement, including its treatment of indemnification, apply to such claims subject to Section 14.2. The indemnification obligations and procedures in the Agreement remain in effect for third-party claims arising from Customer Evaluation Data (including Customer Personal Data) or Customer's unlawful or unauthorized use of the Services, in each case according to their terms.

14.2 Nothing in this DPA or the Agreement restricts a Data Subject's rights or remedies, liability to a Data Subject, or a regulator's powers to the extent they cannot lawfully be restricted under Applicable Data Protection Law. Where the SCCs apply, no exclusion or cap applies to an obligation or remedy to the extent it would contradict the SCCs, including their liability provisions.

15. Term, Conflict, and Governing Law

15.1 This DPA takes effect on the Effective Date and continues for as long as QA Mentor Processes Customer Personal Data under the Agreement.

15.2 In the event of a conflict concerning the Processing of Personal Data, the order of precedence is: (1) the Standard Contractual Clauses, where they apply; (2) this DPA; and (3) the remainder of the Agreement.

15.3 Except for the SCCs, which are governed as set out in Section 12, this DPA is governed by the law that governs the Agreement.

Annex I. Description of the Processing

A. List of the Parties

Data exporter (Controller / Processor): the Customer legal entity identified in its accepted Order Form or account registration record, together with the business address and designated privacy contact recorded there. That record is incorporated into this Annex. Activities relevant to the transfer: use of the Services to evaluate, test, and validate AI systems. Role: Controller, or Processor where Customer acts on behalf of its own controller. The account registration or Order Form must contain these details before reliance on the SCCs.

Data importer (Processor / Sub-processor): QA Mentor, Inc., 1441 Broadway, 3rd Floor, New York, NY 10018, USA (published business contact address). Privacy contact: EvaliQA Privacy Team, support@qamentor.com. Activities relevant to the transfer: providing the EvaliQA platform and related Services. Role: Processor or Sub-processor, as applicable. If the parties specify a different legal service address in the Order Form, that address controls for this Annex.

B. Description of the Processing

Categories of Data Subjects: individuals whose Personal Data is included in Customer Evaluation Data, as determined by Customer. These may include Customer's end users, customers, employees, contractors, and individuals referenced in prompts, responses, transcripts, recordings, documents, or other submitted content. Authorized Users are included only to the extent their Personal Data is Processed by QA Mentor on Customer's behalf under this DPA.

Categories of Personal Data: Personal Data included by Customer in Customer Evaluation Data, such as names, contact details, identifiers, prompts, responses, test cases, chatbot or agent outputs, transcripts, voice recordings, logs, screenshots, and documents. Identifiers and technical data concerning Authorized Users, including IP addresses, device and browser information, and usage logs, are included only to the extent Processed on Customer's behalf. Personal Data processed for QA Mentor's independent purposes under Section 2.3 is excluded.

Special Categories of Personal Data: not intended to be submitted by default. Because Customer determines the content of evaluations, incidental inclusion in prompts, transcripts, recordings, or documents is possible. Customer must not intentionally submit Special Categories of Personal Data unless expressly authorized under the Agreement and subject to documented additional safeguards appropriate to the data and use case. Where authorized, the categories, safeguards, and any applicable restrictions must be recorded in the Agreement or Order Form.

Frequency of the transfer: continuous, for the duration of the Services.

Nature and purpose of the Processing: hosting, storing, transmitting, evaluating, testing, validating, and supporting Customer Evaluation Data to provide the Services and the outputs Customer requests, including where a third-party or platform AI model is used to perform a Customer-requested evaluation.

Duration of the Processing: the term of the Agreement, plus the retention and deletion periods described in Section 10 and the EvaliQA Privacy Policy.

C. Competent Supervisory Authority

The competent supervisory authority for EEA transfers is determined under Clause 13 of the SCCs based on the data exporter identified in the Order Form or account registration record and must be identified in the relevant transfer record before relying on the SCCs. For UK transfers, the competent authority is the Information Commissioner's Office. For Swiss transfers, it is the Swiss Federal Data Protection and Information Commissioner.

Annex II. Technical and Organizational Measures

QA Mentor maintains the following measures, which it may update provided the overall level of protection is not materially reduced:

Encryption. QA Mentor will protect Customer-supplied model-provider credentials using encryption at rest and protect Customer Personal Data in transit using industry-standard encrypted transport. Access to provider credentials is restricted to the functions and personnel necessary to provide the Services; such credentials will not be disclosed to another customer. QA Mentor will maintain documented key-management and access procedures.

Access control. QA Mentor will maintain role-based, least-privilege access for systems that Process Customer Personal Data. Personnel access is limited to authorized roles and subject to authentication and access logging, with periodic review of access rights.

Tenant isolation. Logical separation of workspaces and tenants so that one customer's Customer Evaluation Data, evaluation results, and artifacts are not disclosed to another customer.

Network and application security. Access to client-facing endpoints through a controlled API gateway; input validation; protection against common web application risks; segregation of internal services.

Logging and monitoring. Security and audit logging, including administrative access review; monitoring for misuse, unauthorized access, and other security threats.

Retention and deletion. QA Mentor will apply Customer's selected retention settings where available, delete or return Customer Personal Data as described in Section 10, and keep backup copies protected until their scheduled deletion or overwrite. The applicable retention and backup schedule will be made available to Customer through the Services or on request.

Organizational measures. Confidentiality obligations for personnel; security reviews; vendor and Sub-processor due diligence and contractual data-protection terms; an information security program aligned with recognized frameworks.

Sub-processor controls. QA Mentor will impose written data-protection obligations on Sub-processors. For platform-model evaluations using a third-party AI provider, QA Mentor will use service terms and available privacy controls that prohibit use of Customer Personal Data to train the provider's general-purpose models and restrict retention to providing the requested evaluation, subject to any mandatory legal requirement.

Annex III. List of Sub-processors

The following generally authorized Sub-processors may Process Customer Personal Data only for the described service functions. The list identifies the providers QA Mentor engages, including providers used only when the corresponding feature is enabled. QA Mentor will maintain a current list with the applicable contracting entity, functions, and processing locations and provide it to Customer on request. Additions or replacements are subject to Section 7.3.

ProviderFunctionWhen applicable
Hetzner Online GmbHHosting, storage, database and infrastructureCore service
OpenAI, L.L.C.Model processing for customer-requested evaluationsPlatform model feature
Twilio Inc.Telephony and media processing for voice evaluationsVoice feature
Resend, Inc.Delivery of service messages containing Customer Personal DataOnly if that notification feature is enabled

Payment processing and website or product analytics are separate account and business operations under Section 2.3. QA Mentor will not disclose Customer Evaluation Data to payment or analytics providers for those purposes. Where an email service carries Customer Personal Data as part of an enabled Service feature, that email provider is included as a Sub-processor in the list above. Other providers processing only QA Mentor's independent Controller data are addressed in the Privacy Policy, rather than this Annex.

Where Customer connects a third-party AI provider using Customer-supplied credentials, the provider's legal role depends on the applicable contracts, instructions, and data flow. If QA Mentor engages that provider to Process Customer Personal Data on its behalf, QA Mentor will treat it as a Sub-processor and give notice under Section 7.3. If Customer contracts directly with the provider and directs a separate transfer, Customer is responsible for that provider relationship and any required transfer mechanism. Supplying credentials alone does not determine the provider's role.

Platform

  • AI Evaluation
  • Red teaming
  • Voicebot evaluation
  • Online evaluation and observability

Resources

  • Docs
  • Blog
  • Guides

Company

  • About us
  • Pricing

Legal

  • Privacy
  • Terms
  • DPA
  • Subprocessors
  • Cookies
EvaliQAThe AI evaluation workspace.
© 2026 QA Mentor · Best Software Testing Company in USA