Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) supplements the Terms of Service between Foalk, Inc. (“Processor”, “we”, “us”) and the customer entity agreeing to these terms (“Controller”, “Customer”, “you”). It applies where and to the extent that Processor processes Personal Data on behalf of Controller in the course of providing the Qumo Deploy service.1. Roles and Scope of Processing
- Controller & Processor: Customer acts as the Data Controller (or Processor acting on behalf of a third-party Controller), and Foalk, Inc. acts as the Data Processor.
- Subject Matter & Purpose: The subject matter of data processing is the performance of the Qumo Deploy relay network orchestration, ephemeral token generation, usage telemetry metering, and tenant workspace management.
- Duration: The term of this DPA corresponds to the duration of your active subscription or account registration.
2. Customer Instructions
Processor shall process Personal Data exclusively upon documented instructions from Controller, including with respect to transfers of Personal Data to third countries or international organizations, unless required to do so by applicable European Union or Member State law.3. Confidentiality & Personnel
Processor ensures that all personnel authorized to process Customer Personal Data:- Have committed themselves to strict confidentiality or are under an appropriate statutory obligation of confidentiality.
- Receive recurring training on information security, privacy protocols, and credential handling.
- Access systems only via least-privilege role-based access control (RBAC) and hardware-backed multi-factor authentication.
4. Technical and Organizational Measures (TOMs)
Processor maintains industry-standard technical and organizational measures to ensure a level of security appropriate to the operational risk, including:- Data In Transit: Mandatory TLS 1.3 encryption across all HTTP/3, WebTransport, and REST API connections.
- Data At Rest: AES-256 server-side encryption across CockroachDB storage volumes, database backups, and Cloudflare R2 audit archives.
- Credential Protection: One-way SHA-256 salted hashing for API keys; short-lived asymmetric JWT issuance for relay sessions.
- Vulnerability Scanning: Automated continuous static analysis, dependency auditing, and container vulnerability scanning.
5. Approved Sub-Processors
Controller grants Processor general written authorization to engage the following sub-processors for infrastructure operations:
Processor shall notify Controller at least 30 days in advance of adding or replacing any sub-processor by updating this page and notifying designated administrative contacts.
6. Personal Data Breach Notification
Processor shall notify Controller without undue delay (and in any event within 48 hours) upon becoming aware of a confirmed Personal Data Breach affecting Controller’s data. The notification shall describe:- The nature of the breach, including categories and approximate numbers of data subjects and records concerned.
- The name and contact details of our Data Protection Officer or security representative.
- The likely consequences of the incident and remediation measures taken or planned.
7. Audit & Data Subject Rights
- Data Subject Requests: Processor provides self-service REST endpoints (
/admin/v1/users/me/exportandDELETE /admin/v1/users/me) allowing Controllers to fulfill data portability and erasure requests directly. - Compliance Audits: Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with GDPR Article 28, allowing for audits and reviews conducted by Controller or an independent auditor.