> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Processing Agreement (DPA)

> Standard contractual clauses and terms governing customer data processing under GDPR.

# Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") supplements the [Terms of Service](/legal/terms) between **Foalk, Inc.** ("Processor", "we", "us") and the customer entity agreeing to these terms ("Controller", "Customer", "you"). It applies where and to the extent that Processor processes Personal Data on behalf of Controller in the course of providing the Qumo Deploy service.

***

## 1. Roles and Scope of Processing

* **Controller & Processor**: Customer acts as the Data Controller (or Processor acting on behalf of a third-party Controller), and Foalk, Inc. acts as the Data Processor.
* **Subject Matter & Purpose**: The subject matter of data processing is the performance of the Qumo Deploy relay network orchestration, ephemeral token generation, usage telemetry metering, and tenant workspace management.
* **Duration**: The term of this DPA corresponds to the duration of your active subscription or account registration.

***

## 2. Customer Instructions

Processor shall process Personal Data exclusively upon documented instructions from Controller, including with respect to transfers of Personal Data to third countries or international organizations, unless required to do so by applicable European Union or Member State law.

***

## 3. Confidentiality & Personnel

Processor ensures that all personnel authorized to process Customer Personal Data:

1. Have committed themselves to strict confidentiality or are under an appropriate statutory obligation of confidentiality.
2. Receive recurring training on information security, privacy protocols, and credential handling.
3. Access systems only via least-privilege role-based access control (RBAC) and hardware-backed multi-factor authentication.

***

## 4. Technical and Organizational Measures (TOMs)

Processor maintains industry-standard technical and organizational measures to ensure a level of security appropriate to the operational risk, including:

* **Data In Transit**: Mandatory TLS 1.3 encryption across all HTTP/3, WebTransport, and REST API connections.
* **Data At Rest**: AES-256 server-side encryption across CockroachDB storage volumes, database backups, and Cloudflare R2 audit archives.
* **Credential Protection**: One-way SHA-256 salted hashing for API keys; short-lived asymmetric JWT issuance for relay sessions.
* **Vulnerability Scanning**: Automated continuous static analysis, dependency auditing, and container vulnerability scanning.

***

## 5. Approved Sub-Processors

Controller grants Processor general written authorization to engage the following sub-processors for infrastructure operations:

| Sub-Processor                 | Role & Purpose                                     | Corporate Headquarters | Processing Regions  |
| :---------------------------- | :------------------------------------------------- | :--------------------- | :------------------ |
| **Amazon Web Services, Inc.** | Core cloud infrastructure, relay compute instances | United States          | US, Japan, EU       |
| **Cloudflare, Inc.**          | R2 object storage, global DNS, DDoS protection     | United States          | Global Edge Network |
| **Cockroach Labs, Inc.**      | Managed distributed relational database            | United States          | United States       |
| **Stripe, Inc.**              | Credit card processing, subscription management    | United States          | United States       |
| **GitHub, Inc.**              | Developer OAuth login integration                  | United States          | United States       |

Processor shall notify Controller at least 30 days in advance of adding or replacing any sub-processor by updating this page and notifying designated administrative contacts.

***

## 6. Personal Data Breach Notification

Processor shall notify Controller without undue delay (and in any event within **48 hours**) upon becoming aware of a confirmed Personal Data Breach affecting Controller's data. The notification shall describe:

1. The nature of the breach, including categories and approximate numbers of data subjects and records concerned.
2. The name and contact details of our Data Protection Officer or security representative.
3. The likely consequences of the incident and remediation measures taken or planned.

***

## 7. Audit & Data Subject Rights

* **Data Subject Requests**: Processor provides self-service REST endpoints (`/admin/v1/users/me/export` and `DELETE /admin/v1/users/me`) allowing Controllers to fulfill data portability and erasure requests directly.
* **Compliance Audits**: Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with GDPR Article 28, allowing for audits and reviews conducted by Controller or an independent auditor.

***

## 8. Execution of a Signed DPA

Customers requiring an individually executed, signed copy of this DPA (including standard contractual clauses for international data transfers) may contact our legal compliance team at:

```text theme={null}
Foalk, Inc.
Attn: Legal & Privacy Compliance
Email: compliance@qumo-deploy.com
Subject: Request for Executed DPA - [Your Tenant Name]
```
