1. Definitions
Terms not defined in this DPA have the meaning given in the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) or, where the Controller is established in jurisdictions with parallel regimes (UK GDPR, Federal Law No. 45 of 2021 of the United Arab Emirates, California Consumer Privacy Act, etc.), the equivalent term in the applicable law. “Personal Data” means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller through the Service.
2. Roles and scope
Controller determines the purposes and means of processing. Processor processes Personal Data only on documented instructions from Controller and only to the extent necessary to deliver the Service. The categories of data subjects and Personal Data processed are described in Schedule A below.
3. Processor obligations
Processor shall:
- process Personal Data only on documented instructions from Controller, including with regard to transfers to a third country, unless applicable law requires otherwise (in which case Processor will inform Controller before such processing unless the law prohibits disclosure);
- ensure that persons authorised to process Personal Data are bound by confidentiality;
- implement and maintain the technical and organisational measures described in Schedule B (Security Measures);
- assist Controller, taking into account the nature of processing and the information available, in fulfilling Controller’s obligations to respond to data-subject requests, conduct data-protection impact assessments, and notify supervisory authorities of personal-data breaches;
- on termination of the Services, and at the choice of Controller, delete or return all Personal Data, save where applicable law requires storage of Personal Data; and
- make available to Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as described in Section 9.
4. Sub-processors
Controller authorises Processor to engage sub-processors to provide infrastructure, monitoring, communication, and AI-inference services in support of the Service. The current list of sub-processors is published at /subprocessors and notified in-app. Processor will notify Controller at least 30 days in advance of any addition or replacement of a sub-processor that processes Personal Data, providing Controller a reasonable opportunity to object. If Controller objects on reasonable data-protection grounds and the parties cannot agree a remedy within 30 days, Controller may terminate the affected portion of the Service.
Processor remains responsible for sub-processors’ compliance with obligations equivalent to those in this DPA and for any breach by a sub-processor of those obligations.
5. International transfers
Personal Data is hosted in the US-East region with a tier-1 cloud provider by default. For Controllers established in the European Economic Area, the United Kingdom, or Switzerland whose data may transfer outside that jurisdiction, the parties incorporate the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914) and, where applicable, the UK International Data Transfer Addendum, by reference into this DPA. Processor will, on request, assist Controller in completing the relevant Schedules of the SCCs based on the actual processing performed under the Service.
6. Security breach notification
Processor shall notify Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any Personal-Data breach affecting Controller’s Personal Data. The notification shall include, to the extent known at the time:
- the nature of the breach and the categories and approximate number of data subjects affected;
- the categories and approximate number of records affected;
- the likely consequences of the breach; and
- the measures taken or proposed to address the breach and mitigate its possible adverse effects.
Processor will follow up with reasonable detail as further information becomes available and will cooperate with Controller’s investigation and any regulator notifications.
7. Data-subject rights
Processor provides Controller with administrator tools to export the Personal Data of an individual data subject and to delete or anonymise a user account on request from that data subject. Where Controller requires Processor’s assistance to respond to a data-subject request beyond those tools, Processor will provide such assistance within ten (10) business days of receiving a written request, at no additional cost.
8. Retention and deletion
Customer Content is retained for the period configured by Controller (default seven (7) years to align with ISO 13485 record-retention expectations). Compliance audit-log records are retained for ten (10) years and are stored on an append-only basis (no UPDATE, no DELETE) at the database layer. On termination of the Services, Processor will, at Controller’s election within thirty (30) days, return all Personal Data to Controller in a structured commonly used machine- readable format and then delete it from active systems within sixty (60) days, save for copies retained in operational backups for up to ninety (90) days and then expunged.
9. Audit rights
Once per twelve-month period, Controller (or an independent third-party auditor bound to confidentiality and selected by Controller) may audit Processor’s compliance with this DPA on at least thirty (30) days written notice. Audits will be conducted during business hours, with minimal disruption to Processor’s operations, and at Controller’s cost unless the audit identifies a material non-compliance, in which case Processor bears reasonable costs. Processor may, at its discretion, satisfy Controller’s audit rights by providing copies of relevant third-party audit reports (e.g. SOC 2 Type II, ISO 27001).
10. Liability
Each party’s liability under this DPA is subject to the limitations of liability set out in the Master Services Agreement. Nothing in this DPA limits or excludes either party’s liability where such limitation or exclusion is prohibited by applicable law.
11. Term and termination
This DPA is effective from the date the corresponding Master Services Agreement is executed and continues until the end of the Services. Sections that by their nature should survive termination (including confidentiality, deletion, audit, and liability) will so survive.
Schedule A — Subject matter and categories of data
Subject matter of processing: provision of the Spell QMS Pro Service, including quality-management workflows (objectives, risks, audits, findings, CAPAs, change requests, management reviews, controlled documents, computer-system validation, and AI-assisted drafting).
Duration: for the term of the Services.
Nature and purpose of processing: hosting, storage, retrieval, computation, and presentation of Controller’s records; generation of AI drafts on instruction; transmission of notification emails to identified recipients.
Categories of data subjects: employees, contractors, auditors, suppliers, and other natural persons identified by Controller in the course of using the Service.
Categories of Personal Data: name, professional email, job title, organisation, role assignments, profile preferences, electronic signatures, audit-trail entries (including timestamps and actor identification), and any Personal Data Controller includes in Customer Content (e.g. names referenced in findings or audit reports). The Service is not intended to be used to process special-category (sensitive) Personal Data; Controller is responsible for any such use.
Schedule B — Security measures
Processor maintains, at minimum, the following technical and organisational measures:
- Encryption. TLS 1.2+ in transit; AES-256 at rest across the database, container image registry, and attachment storage, using managed encryption keys.
- Access control. Least-privilege platform permissions, role-based access in the application, JWT-based authentication with refresh-token rotation, and break-glass access logged through centralized audit logging.
- Multi-tenant isolation. Tenant scoping enforced at the application layer via per-tenant filters on every server-side query; cross-tenant access available only to authorised platform operators and logged in the compliance audit log.
- Append-only audit log. Regulatory events (record approvals, electronic signatures, status transitions, administrative actions) are written to a hash-chained log with database-level UPDATE and DELETE permissions revoked from the application user.
- Backup and recovery. Multi-zone resilient database with automated daily snapshots retained for thirty (30) days and on-demand manual snapshots retained per release; documented restore procedure.
- Monitoring. Centralised log aggregation and metrics; intrusion and anomaly detection; vulnerability scanning of container images on push; documented incident-response playbook.
- Personnel. Confidentiality undertakings from all personnel with access; security and privacy training; access reviews on a defined cadence.
- Sub-processors. Bound by data-protection terms equivalent to those in this DPA.
12. Contact
Privacy enquiries, audit requests, and data-subject assistance requests: privacy@spell.solutions.
Spell Solutions LLC.