Data Processing Agreement
This Data Processing Agreement ("DPA") supplements the terms set forth in the primary service contract between That Is A Q ("Processor") and the Client ("Controller"). It governs the processing of personal data in compliance with applicable data protection laws, including but not limited to the GDPR, CCPA, and UK GDPR.
1. Introduction & Scope
This DPA applies to all personal data processed by That Is A Q on behalf of the Controller in the course of providing design, development, hosting, or consulting services. It reflects the obligations required under Article 28 of the GDPR and equivalent local regulations. Where this DPA conflicts with the primary agreement, the DPA shall govern matters specific to data processing.
2. Definitions
- Controller: The client or entity that determines the purposes and means of processing personal data.
- Processor: That Is A Q, or any subprocessor engaged by That Is A Q to process data on the Controller's behalf.
- Personal Data: Any information relating to an identified or identifiable natural person.
- Data Subject: The individual to whom the personal data relates.
- Processing: Any operation performed on personal data, including collection, storage, modification, or deletion.
3. Processing Instructions
That Is A Q shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law. In the event of a conflict between processing instructions and applicable legal requirements, That Is A Q will notify the Controller prior to processing, where legally permissible.
Processing activities are strictly limited to the scope defined in the Statement of Work (SOW) or service specifications provided by the Controller.
4. Data Protection Measures
That Is A Q implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include, but are not limited to:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Strict access controls and role-based authentication
- Regular security audits, penetration testing, and vulnerability assessments
- Employee training on data protection and confidentiality obligations
- Secure development lifecycle (SDLC) practices for all custom software
- Automated backups with geographically redundant storage
That Is A Q will assist the Controller in maintaining these standards and will promptly notify of any material changes to security infrastructure.
5. Subprocessors
That Is A Q may engage third-party subprocessors to assist in fulfilling service obligations. Current approved subprocessors include cloud infrastructure providers, CI/CD platforms, and analytics services. A complete list is maintained at thatisaq.com/subprocessors.
The Controller retains the right to object to specific subprocessors. That Is A Q will provide 30 days' advance notice of new or modified subprocessor relationships. All subprocessors are bound by written data processing agreements containing equivalent or stricter data protection obligations.
6. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), UK, or other restricted jurisdictions, That Is A Q ensures adequate safeguards are in place, including Standard Contractual Clauses (SCCs), Transfer Impact Assessments (TIAs), and compliance with local export restrictions. Data transfer mappings are available upon request.
7. Data Subject Rights Assistance
That Is A Q will assist the Controller in fulfilling requests from data subjects regarding their rights under applicable law (access, rectification, erasure, restriction, portability, objection). Assistance includes technical implementation, API integrations, and secure data retrieval workflows. That Is A Q will respond to such requests within 10 business days of receiving documented instructions from the Controller.
8. Security Incidents & Breach Notification
In the event of a personal data breach, That Is A Q will notify the Controller without undue delay, and no later than 24 hours after becoming aware of the incident. The notification will include the nature of the breach, categories of data affected, approximate number of records, contact details of the DPO, and proposed mitigation measures. That Is A Q will cooperate fully with the Controller's investigation and regulatory reporting obligations.
9. Audit & Compliance
The Controller may conduct annual audits or request compliance certifications (e.g., SOC 2 Type II, ISO 27001) upon reasonable notice. Audits will be conducted in a manner that minimizes disruption to That Is A Q's operations and protects confidential business information. Costs are borne by the Controller unless the audit reveals a material breach of this DPA.
10. Term & Termination
This DPA remains in effect for the duration of the primary service agreement and until all processed personal data has been securely deleted or returned. Upon termination, That Is A Q will, at the Controller's direction, return or securely destroy all personal data and certify destruction in writing within 30 days. Retention of archival copies for legal or regulatory obligations remains permitted, subject to ongoing confidentiality protections.
11. Liability & Governance
That Is A Q assumes liability for breaches of its processing obligations under this DPA, subject to standard professional services liability caps. Disputes arising from this DPA shall be resolved under the governing law and jurisdiction specified in the primary agreement. This DPA constitutes the entire understanding between the parties regarding data processing and supersedes prior verbal or written communications on the subject.
12. Contact Information
For questions regarding this DPA, data processing activities, or to exercise contractual rights, please contact our Data Protection Officer:
Data Protection Officer
That Is A Q
Email: dpo@thatisaq.com
Phone: +1 (555) 019-2834
Address: 42 Innovation Blvd, Suite 300, Austin, TX 78701, USA
This contact channel is monitored for compliance inquiries and data subject requests.
Document Control: This DPA is reviewed biannually. Updates will be communicated via official client portal notifications. By continuing to use services, the Controller acknowledges acceptance of the current version.