Data Processing Agreement

Effective June 6, 2026

This Data Processing Agreement (“DPA”) supplements and is incorporated into the Terms of Service between Qualityiris LLC (“Qualityiris”) and the Customer entity that accepts the Terms. It applies whenever Qualityiris processes Customer Personal Data on Customer’s behalf. By using the Service, Customer accepts this DPA on behalf of itself and its authorized affiliates. No counter-signature is required. If your procurement process requires a counter-signed PDF, email privacy@qualityiris.com.

See also: Terms of Service · Privacy Policy.

1. Parties & Scope

This DPA governs the processing of Customer Personal Data by Qualityiris in connection with the Service. For the purposes of this DPA, Customer is the controller of Customer Personal Data and Qualityiris is the processor. Where Customer is itself a processor acting on behalf of a third-party controller, Qualityiris acts as a sub-processor and the same obligations apply. This DPA applies in addition to the Terms; in the event of a conflict regarding the processing of Customer Personal Data, this DPA controls.

2. Definitions

  • Applicable Data Protection Law — the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK Data Protection Act 2018 and UK GDPR, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act / CPRA, in each case as amended.
  • Customer Personal Data — personal data contained in Customer Content that Qualityiris processes on Customer’s behalf to deliver the Service.
  • Controller, Processor, Personal Data, Data Subject, Processing, Sub-processor, Personal Data Breach — as defined in GDPR Article 4 (and the equivalent terms in UK GDPR and CCPA).
  • Standard Contractual Clauses or “SCCs” — the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 of 4 June 2021 (Module 2: Controller-to-Processor), together with the UK International Data Transfer Addendum and the Swiss FDPIC amendments where applicable.

3. Details of Processing

The full description of the processing is set out in Annex 1 below.

  • Subject matter: provision of the QualityIris garment quality assurance and inspection management platform.
  • Duration: the term of Customer’s subscription plus the 90-day post-termination export window.
  • Nature & purpose: hosting, transmitting, displaying, processing and analyzing Customer Content so Customer’s authorized users can plan, execute and report garment inspections.
  • Categories of data subjects: Customer’s authorized users (admins, managers, inspectors), buyer and factory representatives invited by Customer, and any natural persons identified in inspection notes, photos, signatures or order data.
  • Categories of personal data: name, work email, work phone, job role and company, signed-in IP address and session metadata, hand-drawn signature images, defect photos that may incidentally depict individuals, and any personal data Customer chooses to record in free-text fields.
  • Special categories: none required by the Service. Customer must not submit special-category data (GDPR Art. 9) unless agreed in writing.

4. Processor Obligations

  • 4.1 Documented instructions. Qualityiris processes Customer Personal Data only on Customer’s documented instructions. The Terms, this DPA and Customer’s configuration and use of the Service constitute Customer’s complete and final instructions. Qualityiris will notify Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
  • 4.2 Confidentiality. Qualityiris personnel authorized to process Customer Personal Data are bound by written confidentiality obligations.
  • 4.3 Security. Qualityiris implements the technical and organizational measures set out in Annex 2, designed to ensure a level of security appropriate to the risk under GDPR Art. 32.
  • 4.4 Personal Data Breach. Qualityiris will notify Customer without undue delay and in any event within 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, via privacy@qualityiris.com, including the information required by GDPR Art. 33(3) to the extent then known.
  • 4.5 Assistance. Taking into account the nature of the processing, Qualityiris will provide reasonable assistance to Customer in fulfilling its obligations under GDPR Art. 32–36 (security, breach notification, data protection impact assessments and prior consultation).

5. Sub-processors

Customer provides a general written authorization for Qualityiris to engage the sub-processors listed in Annex 3. Each sub-processor is bound by data-protection obligations no less protective than those in this DPA.

Qualityiris will provide at least 30 days’ prior notice of any intended addition or replacement of a sub-processor by updating this page (the “Last updated” effective date above is the canonical change marker) and, where Customer has subscribed to administrator email notifications, by email to the tenant administrator. Customer may object in writing within that period on reasonable data-protection grounds; if the parties cannot agree on a remedy, Customer’s sole remedy is to terminate the affected portion of the Service for convenience and receive a pro-rata refund of pre-paid, unused fees.

6. International Transfers

Where Customer Personal Data is transferred from the EEA, the UK or Switzerland to Qualityiris in the United States, or onward to any sub-processor in a third country, the parties incorporate the Standard Contractual Clauses by reference (Module 2, controller-to-processor), together with the UK IDTA Addendum and the Swiss amendments where applicable. For the SCC Annexes, the parties rely on the corresponding sections of this DPA: Annex I.A — the parties and contact points; Annex I.B — the details of processing in §3 and Annex 1; Annex II — the technical and organizational measures in Annex 2; Annex III — the sub-processor list in Annex 3.

7. Data Subject Rights Assistance

If Qualityiris receives a data-subject access, deletion, rectification, restriction, portability or objection request relating to Customer Personal Data, Qualityiris will, unless legally required to respond directly, promptly forward the request to Customer and not respond itself. Taking into account the nature of the processing, Qualityiris will provide reasonable assistance to Customer in responding within applicable statutory deadlines (generally 30 days). Customer may submit assistance requests to privacy@qualityiris.com.

8. Audits & Information Rights

Once per twelve (12) months, Customer may request from Qualityiris a written response to a reasonable security questionnaire, together with a summary of Qualityiris’s then-current security posture and any third-party attestations or sub-processor compliance documentation that Qualityiris is contractually permitted to share. Qualityiris will respond within thirty (30) days. On-site audits are not offered. This clause is intended to satisfy the audit assistance obligation under GDPR Art. 28(3)(h) for a mid-market SaaS context; nothing in this DPA limits any audit right that a supervisory authority may exercise by law.

9. Return & Deletion

On expiry or termination of the Service, Customer may request a full export of Customer Personal Data (CSV / JSON for structured data and signed download URLs for photos, signatures and PDF reports) during a 90-day export window. After that window, Qualityiris will permanently delete Customer Personal Data from production systems, subject to encrypted backup-retention cycles of up to 14 days, after which backups are overwritten. On written request, Qualityiris will provide written certification of deletion. Qualityiris may retain Customer Personal Data to the extent and for the period required by law.

10. Liability

Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service, §18.

11. Governing Law & Venue

This DPA is governed by the same governing law and venue as the Terms of Service, except that, where required by Applicable Data Protection Law, the SCCs are governed by the law and subject to the courts designated in the SCCs themselves.

12. Acceptance

Customer’s continued use of the Service constitutes acceptance of this DPA on behalf of the Customer entity and its authorized affiliates. No counter-signature is required. For a counter-signed PDF version, email privacy@qualityiris.com.


Annex 1 — Details of Processing

  • Subject matter & nature: hosting, transmission, display and processing of Customer Content in the QualityIris platform to enable garment quality assurance workflows (inline inspections, final audits, measurement specifications, defect photos, production progress, digital signatures, PDF reports and transactional email notifications).
  • Purpose: deliver the Service as described in the Terms and Customer’s configuration.
  • Duration: the subscription term plus the 90-day post-termination export window and up to 14 days of encrypted backup retention.
  • Categories of data subjects: Customer’s authorized users (admin, manager, inspector roles); buyer and factory representatives invited by Customer; natural persons identified in free-text inspection notes, photos, signatures or order data.
  • Categories of personal data: name, work email, work phone, job role, company, signed-in IP address, session and authentication metadata, hand-drawn signature images, defect photos (which may incidentally depict individuals), and any personal data Customer chooses to record in free-text fields.
  • Frequency of processing: continuous for the duration of the subscription.
  • Recipients: Qualityiris’s authorized personnel and the sub-processors in Annex 3.

Annex 2 — Technical & Organizational Measures

  • Encryption in transit: TLS 1.2 or higher for all client and inter-service traffic.
  • Encryption at rest: AES-256 for database, object storage and backups.
  • Tenant isolation: strict Postgres Row-Level Security (RLS) policies on every customer-data table; signed, short-lived URLs for private object storage.
  • Access control: role-based access control (Admin, Manager, Inspector, Buyer, Factory); least-privilege staff access; multi-factor authentication for administrative access.
  • Authentication: passwords checked against the “Have I Been Pwned” corpus; rate-limited login; bot-protection on sign-up.
  • Audit logging: authentication events, administrative actions and email-delivery events are logged and retained for diagnostic and security purposes.
  • Backups: automated daily encrypted backups with up to 14-day retention.
  • Secure SDLC: code review, automated tests, dependency scanning, periodic security review and an ignore-with-justification policy for security findings.
  • Vendor management: sub-processors are vetted, contractually bound, and listed publicly in Annex 3.
  • Incident response: documented breach-notification process targeting notification to affected customers within 72 hours of confirmation.

Annex 3 — Sub-processor List

The following sub-processors are authorized as of the effective date above. The canonical list is also reflected in the Privacy Policy §7.

Sub-processorPurposeProcessing location
SupabaseManaged Postgres, authentication, object storage, edge functions (Lovable Cloud)United States (AWS)
StripeSubscription billing, checkout, customer portal, tax calculationUnited States & EU
CloudflareTurnstile bot-protection challenge on sign-upGlobal edge
ResendTransactional email delivery from notify.qualityiris.comUnited States & EU
PostHogFirst-party product analytics (no advertising identifiers)European Union
SentryApplication error monitoring and diagnosticsUnited States
Lovable AI Gateway (with downstream Google Gemini and OpenAI GPT)LLM and vision inference for Iris AI features; no customer data used for model trainingUnited States

Contact

Qualityiris LLC
Wylie, Texas, USA
Privacy & DPA: privacy@qualityiris.com
General: info@qualityiris.com

Questions about how we handle your data?

Every tenant’s inspection data is isolated at the database level. Read the wider picture, or ask us directly.