TRUST AND SECURITY

Data processing agreement

Qity’s standard terms under Article 28 of the GDPR, published in full so a reviewer can read them before asking for a signed copy.

STANDARD TERMS, VERSION 1

Effective 10 August 2026. Published for review. A signed, counter-signed copy is issued on request and prevails over this page.

Request a signed copy
BEFORE YOU RELY ON THIS

This page reproduces Qity's standard processor terms for review. It is not legal advice, and it does not by itself form a contract. Where a Qity service agreement, statement of work, or a customer's own DPA is in place, that signed instrument governs. Contact dpo@qity.be to execute these terms or to review a customer paper alternative.

Which role Qity holds, and when

Qity delivers two things, and the data protection position differs between them. Getting this right at the start avoids a DPA that covers the wrong processing.

ActivityQity's roleWhy
Quality records created in the Qity appsNot a processor of that dataThe apps run on Atlassian Forge. Documents, records, approvals, and audit trails are created and stored inside the customer's own Atlassian Cloud site, under the customer's admin controls and data residency setting. Qity operates no separate backend holding them. The customer's agreement with Atlassian governs that hosting.
Support tickets, diagnostics, and attachments a customer sends to QityProcessorWhere a customer sends Qity personal data to investigate an issue, Qity processes it on the customer's instructions under these terms.
Consultancy, migration, validation, and outsourced DPO servicesProcessorQity personnel act on the customer's documented instructions under a statement of work and these terms.
Website visits, contact and demo requests, commercial correspondenceControllerQity determines the purposes and means. Governed by the privacy policy, not by this agreement.

This agreement applies to the rows marked processor. Where Qity is a controller, the privacy policy applies instead.

The terms

1Definitions and interpretation

Controller, processor, data subject, personal data, personal data breach, processing, and supervisory authority have the meanings given in the GDPR. "Data Protection Law" means Regulation (EU) 2016/679, the UK GDPR and Data Protection Act 2018 where applicable, the Belgian Act of 30 July 2018, and any other applicable data protection legislation. "Customer Personal Data" means personal data processed by Qity on behalf of the Customer under the Principal Agreement. "Principal Agreement" means the service agreement, statement of work, or order under which Qity provides services to the Customer. Where this agreement conflicts with the Principal Agreement on the subject of processing personal data, this agreement prevails.

2Roles and scope

  1. The Customer is the controller and Qity is the processor in respect of Customer Personal Data, except where the Customer is itself a processor, in which case Qity is a sub-processor and the Customer warrants that it has the controller’s authority to appoint Qity.
  2. Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects, as required by Article 28(3).
  3. This agreement does not apply to personal data for which Qity is the controller, including website, marketing, and commercial contact data.

3Processing on documented instructions

  1. Qity shall process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country or an international organisation, unless required to do so by Union or Member State law to which Qity is subject. In that case Qity shall inform the Customer of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  2. The Principal Agreement, this agreement, and the Customer’s use and configuration of the services constitute the Customer’s complete documented instructions. Additional instructions must be agreed in writing and may be subject to charges where they require a change to the services.
  3. Qity shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
  4. Qity shall not sell Customer Personal Data, and shall not use it to train artificial intelligence models. Where Qity apps invoke Atlassian AI capabilities, including Rovo and Forge LLM, that processing occurs within the Atlassian platform under the Customer’s Atlassian agreement and settings.

4Confidentiality

  1. Qity shall ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that the obligation survives the end of their engagement.
  2. Access is limited to personnel who need it to deliver the services or to comply with law, is granted on the principle of least privilege, and is reviewed under Qity’s Access Control Policy.

5Security of processing

  1. Qity shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32. The measures in force are described in Annex 2.
  2. Qity operates an Information Security Management System aligned to ISO/IEC 27001, adopting ISO/IEC 27002, ISO/IEC 27017 and ISO/IEC 27018 as codes of practice. Details are published at Security controls and the ISMS.
  3. Qity may update the measures in Annex 2 from time to time provided that the updates do not materially reduce the overall level of security.

6Sub-processors

  1. The Customer grants Qity general written authorisation to engage sub-processors. The sub-processors engaged at the effective date are listed in Annex 3 and maintained at qity.be/trust.
  2. Qity shall inform the Customer of any intended addition or replacement of a sub-processor at least 30 days before that sub-processor begins processing, giving the Customer the opportunity to object on reasonable data protection grounds.
  3. Where the Customer objects on reasonable grounds and the objection cannot be resolved, the Customer may terminate the affected part of the services without penalty, on written notice.
  4. Qity shall impose on each sub-processor, by contract, data protection obligations no less protective than those in this agreement, and shall remain fully liable to the Customer for the performance of each sub-processor’s obligations.

7Assistance with data subject rights

  1. Taking into account the nature of the processing, Qity shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.
  2. Where Qity receives a request directly from a data subject relating to Customer Personal Data, Qity shall not respond to it substantively but shall, without undue delay, notify the Customer and direct the data subject to the Customer.
  3. Where the personal data resides in the Customer’s own Atlassian Cloud site, the Customer retains direct access and administrative control and can generally satisfy a request without Qity’s involvement.

8Personal data breach

  1. Qity shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, so that the Customer can meet its own obligation under Article 33 where applicable.
  2. The notification shall describe, to the extent known, the nature of the breach including the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and the contact point for further information. Information that is not yet available shall be provided in phases without further undue delay, and shall not delay the initial notification.
  3. Qity handles breaches under its controlled Security Incident Management procedure, DOC-836, summarised at How Qity handles security incidents. Reports may be sent to security@qity.be at any time.
  4. Qity shall not notify a supervisory authority or a data subject on the Customer’s behalf in respect of Customer Personal Data unless the Customer instructs it in writing to do so.

9Assistance with DPIA and prior consultation

Taking into account the nature of the processing and the information available to Qity, Qity shall assist the Customer in ensuring compliance with the obligations under Articles 32 to 36, including data protection impact assessments and prior consultation with a supervisory authority, on reasonable request and at the Customer’s cost where the assistance is substantial.

10Deletion and return

  1. At the Customer’s choice, Qity shall delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies, unless Union or Member State law requires storage of the personal data.
  2. Unless the Customer instructs otherwise in writing within 30 days of termination, Qity shall delete Customer Personal Data in its possession within 90 days of termination.
  3. Personal data residing in the Customer’s own Atlassian Cloud site is unaffected by this clause and remains under the Customer’s control.
  4. Backup copies are deleted in accordance with Qity’s Records Retention and Protection Policy, and remain subject to this agreement until deleted.

11Audit and demonstration of compliance

  1. Qity shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28, and shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
  2. Qity shall satisfy this obligation in the first instance by providing its security documentation set, including the Aikido continuous audit report, the Statement of Applicability, the security whitepaper, and the relevant policies and procedures, and by responding to reasonable written security questionnaires.
  3. Where the documentation does not reasonably satisfy the Customer, the Customer may conduct an on-site or remote audit no more than once in any twelve-month period, on at least 30 days’ written notice, during business hours, subject to confidentiality undertakings, and without unreasonably disrupting Qity’s operations. A regulator exercising a statutory power, or an audit following a personal data breach, is not subject to that frequency limit.

12International transfers

  1. Qity shall not transfer Customer Personal Data outside the European Economic Area except in accordance with Chapter V of the GDPR.
  2. Where a transfer to a third country without an adequacy decision is necessary, it shall be made under the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, module two or module three as appropriate, together with any supplementary measures the transfer risk assessment identifies as necessary. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies.
  3. Annex 4 records the current transfer position for each sub-processor.

13Liability, term, and governing law

  1. This agreement takes effect on the effective date of the Principal Agreement and continues for as long as Qity processes Customer Personal Data. Clauses 4, 10, and 11 survive termination.
  2. Each party’s liability under this agreement is subject to the limitations and exclusions of liability in the Principal Agreement, to the extent permitted by Data Protection Law. Nothing in this agreement limits a data subject’s rights or a supervisory authority’s powers.
  3. This agreement is governed by the law of Belgium, and the courts of Belgium have exclusive jurisdiction, unless the Principal Agreement specifies otherwise.

Annex 1, details of the processing

ItemDetail
Subject matterProvision of Qity quality management applications, support, and professional services under the Principal Agreement.
DurationThe term of the Principal Agreement, plus any deletion period under clause 10.
Nature and purposeHosting-adjacent application functionality on the Atlassian platform, technical support and troubleshooting, implementation and configuration, data migration, computer system validation, training delivery, and outsourced data protection officer services where contracted.
Types of personal dataBusiness contact details, Atlassian account identifiers and display names, job titles and organisational roles, training and competence records, electronic signature and approval records, audit trail and system log entries, support ticket content, and any personal data the Customer chooses to include in documents, records, or attachments it sends to Qity.
Categories of data subjectsThe Customer's employees, contractors, and temporary staff; the Customer's suppliers and their personnel; auditors and notified body personnel; and where the Customer chooses to include it, complainant or reporter contact details within quality records.
Special category dataNot required by the services, and not requested by Qity. The Customer should not place special category data or health data of identifiable individuals into support tickets or attachments. Where quality records in the Customer's own Atlassian site contain such data, that data remains in the Customer's tenant and is not transferred to Qity.
FrequencyContinuous for application functionality; occasional and on-demand for support and professional services.

Annex 2, technical and organisational measures

The measures below are those in force at the effective date, implemented under the policy set described at Security controls and the ISMS.

AreaMeasures
Data minimisation by architectureQity applications run on Atlassian Forge. Customer quality data remains in the Customer's Atlassian Cloud tenant. Qity operates no separate production datastore holding Customer quality records, which removes an entire class of exposure rather than mitigating it.
Access controlLeast privilege, named accounts, multifactor authentication, documented joiner, mover and leaver process, and periodic access review under the Access Control Policy and User Password Policy.
EncryptionPersonal data encrypted in transit using current TLS. Data at rest within the Atlassian platform is encrypted by Atlassian. Cryptographic use governed by the Records Retention and Protection Policy.
Secure developmentVersion control, peer code review, protected branches, secrets scanning, dependency and licence scanning, container and infrastructure-as-code scanning, and software bills of materials per release. Continuous scanning by Aikido, with a publicly available audit report.
Vulnerability managementContinuous detection, severity-based triage, and remediation to the published targets at Vulnerability management: 10 days Critical, 4 weeks High, 12 weeks Medium, 25 weeks Low.
Change controlChanges affecting released software, production configuration, customer environments, or validation status pass through the controlled change process with verification evidence.
Logging and monitoringAdministrative actions, application errors, code and configuration changes, and system start and stop events are logged with date and time. Log access is restricted to personnel with a business need and is itself recorded.
Incident managementControlled procedure DOC-836 with defined roles, severity classification, containment, personal data breach assessment, customer advisory, remediation verification, and post-incident review.
Business continuityBusiness Continuity and Disaster Recovery Policy and plan, with recovery arrangements proportionate to the service.
PersonnelConfidentiality undertakings, background screening where lawful and proportionate, security awareness training with recorded competence, and a documented disciplinary process.
Physical and remote workingPhysical Security Policy, Clear Desk and Clear Screen Policy, Remote Working Policy, BYOD Policy, and device management for company-provided equipment.
Supplier assuranceDue diligence, contractual data protection terms, monitoring and review, and end-of-contract handling under the Information Security Policy for Supplier Relationships.
GovernanceISMS aligned to ISO/IEC 27001 with a Statement of Applicability, risk assessment and treatment, documented objectives, internal review, and management review. Named data protection officer reachable at dpo@qity.be.

Annex 3, authorised sub-processors

Sub-processorPurposeProcessing location
AtlassianPlatform hosting for the applications and application data, Marketplace distribution, and the customer's own Cloud tenant.EU, UK, US per the customer's Atlassian residency setting
MicrosoftEmail, business communication, productivity, and document collaboration.EU
Xray, SembiTest management and quality tooling used in the development and validation of the applications.EU

Qity notifies customers of changes to this list at least 30 days before a new sub-processor begins processing. To receive those notifications, write to dpo@qity.be.

Annex 4, international transfers

Sub-processorTransfer position
AtlassianData residency is selected by the customer in its own Atlassian site. Where a customer selects an EU realm, application data remains in the EEA. Where processing outside the EEA occurs, it is covered by the Standard Contractual Clauses in Atlassian's own data processing addendum, to which Qity is bound as a Marketplace Partner.
MicrosoftEU-hosted tenant. Any support processing outside the EEA is covered by the Standard Contractual Clauses in the Microsoft Products and Services Data Protection Addendum.
Xray, SembiEU processing. No transfer outside the EEA is required for the services.

Qity does not transfer Customer Personal Data to a third country without an adequacy decision except under the Standard Contractual Clauses and, where the transfer risk assessment requires them, supplementary measures.

Further reading

The reasoning behind how Qity structures data protection accountability, as controlled records and decisions rather than a shelf of privacy documents, is set out in the open-access paper below. It is the closest thing Qity publishes to a security whitepaper on data protection, and it is the method Qity applies to itself.

SECURITY WHITEPAPER, DATA PROTECTION

A systematic approach for the protection of personal data and privacy

Miguel Azevedo, Qity, 2026 · 21 pages, open access, no form

Read the paper

The privacy policy covers the processing for which Qity is the controller. The trust overview summarises where data lives and which role Qity holds across every activity.

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA