1. Purpose
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service or any agreement between Quality Group Pty Ltd (“Quality Group”) and the Client.
This DPA applies where Quality Group processes personal data on behalf of the Client in connection with services provided by Quality Group (“Service”).
In this DPA, the terms "controller", "data subject", "personal data", "processing", "processor", "pseudonymisation" and "supervisory authority" have the meanings given to them in the UK GDPR, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), or any equivalent applicable data protection legislation. Where a term is not specifically defined, it will have the meaning of the analogous term under the UK GDPR or EU GDPR, as applicable.
Other capitalised terms used but not defined in this DPA have the meaning given in Quality Group’s Terms of Service.
2. Roles of the Parties
- The Client is the “controller”; and
- Quality Group acts as a “processor”.
The Client determines the purposes and means of processing personal data. Quality Group processes personal data solely on behalf of the Client.
Quality Group will process personal data in a manner consistent with this DPA, the instructions of Client, and/or to the extent necessary to provide the Services to the Client and in accordance with applicable laws.
Each party undertakes to comply with its obligations under the UK GDPR and is solely responsible for compliance with the UK GDPR that apply to them.
3. Nature and Purpose of Processing
Processing is limited to what is necessary to provide the Service, including:
- analysis of uploaded reports and materials
- generation of structured outputs
- storage, transmission, and deletion of data
Processing is carried out only in accordance with the Client’s instructions as set out in this DPA and the main agreement (if any). Any main agreement and this DPA constitute the Client’s instructions to the Quality Group for processing personal data. The Client is responsible for ensuring those instructions comply with applicable laws. Quality Group will notify the Client if it reasonably believes an instruction may breach applicable laws, but any failure to do so does not affect the Client’s responsibility for its instructions.
Quality Group will notify the Client if it is legally required to process personal data other than in accordance with the Client's instructions, unless prohibited by law from doing so.
4. Types of Personal Data
Personal data processed may include:
- information contained within client reports and materials
- professional or business-related personal information
- any other personal data submitted by the Client
Quality Group does not control the categories of personal data submitted.
5. Obligations of the Processor
Quality Group will:
- process personal data only on documented instructions from the Client
- ensure personnel with access to personal data are subject to confidentiality obligations
- implement appropriate technical and organisational measures to protect personal data in accordance with applicable laws
Quality Group will not use client data to train shared models or improve systems across organisations unless expressly agreed.
6. Data Subjects
Quality Group has no direct relationship with data subjects and will direct them to the Client.
If Quality Group receives a data subject request, privacy complaint, or legal demand relating to personal data, it will promptly notify the Client (unless prohibited by law).
Quality Group will reasonably assist the Client in handling such requests or complaints, taking into account practicality, cost and available information.
Where the Client can access the required information directly through Quality Group’s systems, the Client is expected to do so.
7. Security Measures
Quality Group will develop, implement and maintain adequate technical and organisational security measures to safeguard the security of the personal data in accordance with applicable laws. These measures will take into account the risks involved with the processing and the nature of the personal data, prevailing industry standards and mandatory security requirements applicable to Quality Group.
Quality Group implements reasonable security measures, including:
- encryption in transit and at rest
- access controls and authentication mechanisms
- system monitoring and safeguards
Security measures are designed to protect against unauthorised access, disclosure, alteration, or destruction of personal data.
8. Subprocessors
Quality Group may engage third-party subprocessors to support delivery of the Service. Our primary subprocessor is Amazon Web Services (AWS), which provides cloud infrastructure and AI model inference services via AWS Bedrock.
The Client hereby provides Quality Group with a general authorisation to engage sub-processors including those set out in this DPA.
Quality Group will:
- ensure subprocessors are bound by data protection obligations no less protective than those in this DPA
- remain responsible for their performance
- provide the Client with at least 14 days' prior written notice of any intended change to subprocessors
9. International Data Transfers
Personal data is currently processed in the AWS London region (eu-west-2) within the United Kingdom. Quality Group may support additional regions in future to meet specific client requirements, subject to appropriate data transfer mechanisms.
The Client understands and agrees that for the fulfilment of the Services, personal data may be accessed by employees of the Quality Group and/or sub-processors, who might be located outside of the UK.
10. Assistance to the Client
Taking into account the nature of processing, Quality Group will provide reasonable assistance to the Client:
- to respond to data subject requests
- to comply with applicable data protection obligations
- in relation to data protection impact assessments, consultations with supervisory authorities and investigations, to the extent required by applicable law and taking into account the nature of the processing and information available to Quality Group.
11. Data Breach Notification
Quality Group will notify the Client without undue delay upon becoming aware of a data breach affecting personal data processed on behalf of the Client under this DPA.
Notification will include available information to assist the Client in meeting its obligations.
12. Data Retention and Deletion
Personal data is retained while the Client account is active.
Quality Group will, upon termination or expiration of this DPA, return or delete any personal data on the Client’s request, unless retention is required by law.
13. Audit and Information Rights
Quality Group will make available information reasonably necessary to demonstrate compliance with this DPA.
Quality Group may agree to an audit to demonstrate the foregoing.
Any audit must:
- be conducted no more than once in any 12-month period
- be subject to reasonable prior notice
- be limited to what is necessary and proportionate
- not unreasonably interfere with Quality Group’s operations or other clients
14. Liability
Liability arising under this DPA is subject to the limitations set out in the Terms of Service or applicable agreement.
15. Governing Law
This DPA is governed by the laws of Victoria, Australia, except that:
- where the Client is established in the European Economic Area, the data protection obligations in this DPA shall be interpreted in accordance with applicable EU law, including the GDPR; and
- where the Client is established in the United Kingdom, the data protection obligations in this DPA shall be interpreted in accordance with UK data protection law, including the UK GDPR and the Data Protection Act 2018.
In the event of any conflict between Victorian law and applicable EU or UK data protection law in relation to data protection obligations, the applicable EU or UK data protection law prevails.
Quality Group Pty Ltd
Melbourne, Australia