HyperBridge Platformhyperbridge.digital ↗
QuantumOS X3
Book a demo
Legal

Data Processing Addendum

Last updated: May 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between QuantumOS X3 (“Processor”) and the customer (“Controller”) and governs the processing of personal data by QuantumOS X3 on behalf of the customer in connection with the Service.

1. Definitions

Controller means the customer entity that determines the purposes and means of processing personal data. Processor means QuantumOS X3, which processes personal data on behalf of the Controller. Personal Data, Data Subject, Processing, and Supervisory Authority have the meanings given in the GDPR (Regulation (EU) 2016/679). Standard Contractual Clauses (SCCs) means the clauses adopted by the European Commission Decision 2021/914.

2. Roles of the parties

The Controller determines the purposes and means of processing customer end-user personal data stored and processed via the Service. QuantumOS X3 acts as Processor for that data. For data relating to the Controller's own account (billing contacts, admin users), QuantumOS X3 acts as an independent Controller under its Privacy Policy.

3. Processing details

Subject matter: provision of the QuantumOS X3 commerce platform. Duration: the term of the Agreement. Nature: storage, retrieval, structuring, transmission, and deletion of personal data. Purpose: operating the storefront, POS, OMS, WMS, loyalty, marketplace sync, and analytics features on behalf of the Controller. Types of personal data: names, email addresses, postal addresses, phone numbers, payment instrument tokens, purchase history, and loyalty/subscription data submitted by the Controller's end users.

4. Processor obligations

QuantumOS X3 will: (a) process personal data only on documented instructions from the Controller; (b) ensure that all personnel authorized to process personal data are bound by appropriate confidentiality obligations; (c) implement the technical and organizational security measures described in Section 6; (d) assist the Controller in fulfilling data subject rights requests; (e) delete or return all personal data upon termination of the Agreement, as directed by the Controller; (f) make available all information necessary to demonstrate compliance with this DPA; and (g) notify the Controller promptly of any instruction it believes infringes applicable data protection law.

5. Sub-processors

QuantumOS X3 maintains a current list of sub-processors at trust.qosx3.com. Prior to engaging any new sub-processor, QuantumOS X3 will provide at least 30 days' written notice. The Controller may object to the appointment of a new sub-processor within that notice period; if the parties cannot resolve the objection in good faith, the Controller may terminate the Agreement with a full pro-rata refund of prepaid fees. QuantumOS X3 imposes data protection obligations on sub-processors equivalent to those in this DPA via back-to-back data processing agreements.

6. Security measures

QuantumOS X3 implements and maintains the following technical and organizational security measures:

  • Encryption of personal data in transit (TLS 1.3) and at rest (AES-256)
  • Tenant-isolated row-level security (RLS) enforced at the database level
  • Least-privilege access controls and role-based authentication for all personnel
  • Annual SOC 2 Type II audit by an accredited third-party auditor
  • PCI DSS Level 1 compliance for payment data processing
  • Continuous vulnerability scanning and annual penetration testing
  • Immutable audit logging of all access to personal data
  • Business continuity and disaster recovery plan with tested RTO/RPO targets

7. Data subject requests

QuantumOS X3 will promptly notify the Controller of any data subject requests received directly by QuantumOS X3. QuantumOS X3 will provide the Controller with self-service tools to fulfill access, erasure, portability, and restriction requests from end users. The Controller is responsible for responding to data subject requests within applicable legal timeframes. QuantumOS X3 will assist with requests that require processing-level intervention within 5 business days of receiving a written request.

8. Personal data breach notification

QuantumOS X3 will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Controller data. Notification will include: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. QuantumOS X3 will cooperate with the Controller in any investigation, mitigation, and regulatory notifications required under applicable law.

9. International transfers

Where personal data of EU/EEA data subjects is transferred to a country not recognized as providing an adequate level of data protection, such transfers are made under the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 (Module Two: Controller to Processor). By entering into the Agreement, the parties are deemed to have executed the SCCs with QuantumOS X3 as data importer and the Controller as data exporter. A copy of the applicable SCCs is available on request from privacy@qosx3.com.

10. Audit rights

QuantumOS X3 will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA, including making available its most recent SOC 2 Type II report under NDA. In the event the Controller requires a dedicated audit or inspection, QuantumOS X3 will accommodate this at most once per year upon 30 days' written notice, at the Controller's cost, during normal business hours and in a manner that does not unreasonably disrupt operations.

11. Return and deletion of data

Upon termination of the Agreement, QuantumOS X3 will provide the Controller with a full data export in machine-readable format within 5 business days of written request. Following the 90-day post-termination window (or earlier if instructed), QuantumOS X3 will securely delete all personal data from all systems, including backups, and provide written confirmation of deletion upon request.

12. Contact

For DPA-related inquiries, to request a signed copy, or to contact our Data Protection Officer, email privacy@qosx3.com with the subject line “DPA Request”.