Data Processing Agreement
Last updated
Template — countersigned on request, not yet reviewed by counsel. This Data Processing Agreement is a plain-English draft prepared by the Quordo product team so a customer can see the terms we intend to offer. It is a starting point, not legal advice, and it must be reviewed and adapted by a qualified lawyer (and aligned with the final Quordo agreement, our current sub-processor list, and the regulations that apply to you, including GDPR and CCPA/CPRA) before either side relies on it. To put a signed DPA in place, email [email protected] — we will countersign a negotiated version.
This is the Data Processing Agreement (DPA) template Quordo offers to customers. It sets out how we process the personal data you connect on your behalf: we act as your processor, we only process on your documented instructions, we keep a defined list of sub-processors, and we return or delete your data when the service ends. It is a template — we countersign a negotiated version on request. To execute one, email [email protected].
Status of this document
This is a template DPA, not a signed contract. It shows the terms Quordo is willing to agree so you can assess us before you buy. It becomes binding only when both parties sign a negotiated version — we countersign on request. Until then, nothing here creates obligations, and the Terms of Service and Privacy Policy govern your use of Quordo. To put a signed DPA in place, email [email protected] and tell us which entity will sign.
Parties and roles
In this DPA, the "Customer" is the organization that subscribes to Quordo, and "Quordo" is the provider of the service. For the personal data contained in the AI usage records, cost data, mission context, and agent-activity traces the Customer connects, the Customer is the data controller and Quordo is the data processor acting on the Customer's behalf. For the Customer's own account and billing data, Quordo is a controller as described in the Privacy Policy — that data is outside the scope of this processor DPA. Where the Customer is itself a processor for its own end customers, Quordo acts as a sub-processor and the same terms apply down the chain.
Scope, nature and purpose of processing
Quordo processes personal data only to provide the service: reading AI usage and cost data using credentials the Customer supplies, attributing spend to teams, coordinating agent activity, and producing the audit trail and traces the Customer relies on. The subject matter is the operation of the Quordo control plane for the duration of the subscription. The nature of the processing is storage, organization, aggregation, and display of the connected estate data. Quordo does not use the Customer's estate data for any other purpose, and in particular does not use it to train its own or anyone else's general-purpose models.
Categories of data and data subjects (Annex I)
Data subjects: the Customer's workspace users (employees and contractors who sign in) and, incidentally, any individuals a Customer chooses to reference inside mission context or agent traces. Categories of personal data: names, work email addresses, organization and team membership, role, and pseudonymous usage identifiers; plus any personal data the Customer elects to include in the content it connects, which the Customer controls. Special-category data is not requested and should not be sent; the Customer is responsible for what it puts into the service. Retention follows the Customer's configuration and the term of the agreement, as described under "Return and deletion" below.
Customer instructions
Quordo processes personal data only on the Customer's documented instructions, including the instructions embodied in the configuration choices the Customer makes in the product and in the parties' agreement. If Quordo believes an instruction infringes applicable data-protection law, it will inform the Customer. If a law requires Quordo to process data beyond the Customer's instructions, Quordo will tell the Customer first unless that law prohibits it.
Confidentiality
Quordo ensures that people authorised to process the Customer's personal data are bound by an appropriate duty of confidentiality and access it only as needed to provide and support the service.
Security measures
Quordo maintains technical and organizational measures appropriate to the risk, described plainly on the Security page: encryption in transit (TLS) and at rest; provider credentials encrypted at rest and never returned to the browser; row-level isolation so one organization cannot read another's data; role-based access within a workspace; and an append-only audit log of mutations. Quordo is not SOC 2 certified today — SOC 2 is on our roadmap and we are building toward it; we do not claim a certification we do not hold. The measures may evolve, but Quordo will not materially reduce the overall level of security during the term.
Sub-processors
The Customer authorises Quordo to engage the sub-processors listed at quordo.com/subprocessors, each bound by data-protection terms no less protective than this DPA. Quordo will keep that list current and give the Customer a reasonable opportunity to object to a new sub-processor before it starts processing the Customer's personal data. If the Customer reasonably objects on data-protection grounds and Quordo cannot offer a reasonable alternative, the Customer may terminate the affected part of the subscription. Quordo remains responsible for its sub-processors' performance of the applicable obligations.
International transfers
Where providing the service involves transferring personal data outside the Customer's region, Quordo relies on an appropriate transfer mechanism — the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) — together with each sub-processor's own safeguards. Quordo prefers region-appropriate hosting and EU-hosted tenants of its processors where available. Details of the current transfer mechanisms are available on request.
Assisting the Customer
Taking into account the nature of the processing, Quordo will assist the Customer, by appropriate technical and organizational measures and insofar as possible, to respond to data-subject requests (access, correction, deletion, portability, restriction, and objection) and to meet the Customer's obligations around security, breach notification, data-protection impact assessments, and prior consultation. Workspace users should ordinarily exercise their rights through the Customer as controller.
Personal data breach
Quordo will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide the information the Customer reasonably needs to meet its own notification duties. Quordo will take reasonable steps to mitigate and, where possible, remedy the breach. A notification is not an acknowledgement of fault.
Audits
Quordo will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, security, scheduling, and frequency limits. Where available, Quordo may satisfy an audit request by providing current documentation, security summaries, or third-party reports rather than an on-site inspection.
Return and deletion
On expiry or termination of the subscription, Quordo will, at the Customer's choice, return or delete the Customer's personal data processed under this DPA, and delete existing copies, unless applicable law requires storage. A limited wind-down period lets the Customer export or reactivate before deletion, as described in the Privacy Policy. Append-only audit and trace records are retained only as long as needed as a security and accountability record and are then deleted or anonymised.
How to execute a DPA
This template is countersigned on request. If your procurement process needs a signed DPA, email [email protected] with the signing entity and any changes you need, and a real person will work through it with you and countersign a negotiated version. We will tell you honestly where we stand — including that we are not SOC 2 certified yet — rather than sign up to something we cannot deliver.