Data Processing Agreement

Draft — not in force

Informis Labs · P.IVA 05049350266 · Treviso, Veneto, Italia

Version 1.0.0 · Last updated 2026-07-27 · Effective date: not yet in force — pending legal approval

Legal status: this page is an informative copy of the DPA template pending legal review. It is not binding contractual text and it is not an offer to contract. The binding Data Processing Agreement is the one signed between the parties, available on request at enterprise@quvant.app.

Art. 1. Subject matter and duration

This Agreement governs the processing of personal data carried out by Informis Labs (VAT 05049350266, established in Treviso, Veneto, Italy) as Processor under Art. 28 GDPR, on behalf of the Customer as Controller, in the context of providing the Quvant service. The Agreement lasts for the term of the underlying service contract.

Art. 2. Nature and purpose of processing

Processed data include: incident reports, documentary evidence and audit configurations uploaded by the Customer. The exclusive purpose is delivery of the contracted service. No data is used to train AI models or disclosed to third parties for Informis Labs' own purposes.

Art. 3. Pseudonymisation and AI models

Before any transmission to third-party AI providers, data are subject to pseudonymisation: direct identifiers (names, emails, tax codes) are removed or replaced with neutral tokens. Data transmitted to extra-EU providers are reduced to the technical-functional content necessary. The Customer is responsible for not including unnecessary personal data in free-text fields.

Art. 4. Security measures

  • TLS 1.3 encryption in transit
  • AES-256 encryption at rest on MongoDB Atlas
  • Data access limited to technical personnel with documented operational need
  • Retention periods by data category are stated in the Trust Center at https://www.quvant.app/en/trust, which is the unique public source of the schedule.
  • Daily backups with 30-day retention

Art. 5. Sub-processors

The following entities act as sub-processors under Art. 28(2) GDPR, on instructions from Informis Labs:

Sub-processorServiceLocationTransfer safeguard
MongoDB, Inc.Primary application databaseUnited StatesDPA
Railway CorporationBackend application hostingUnited StatesSCC
Redis (Railway plugin and/or Upstash per docs)Cache / rate-limit / session helpersUnited StatesSCC
Vercel Inc.Landing + dashboard CDN / hostingUnited StatesSCC
Lemon Squeezy (Sold through Link, LLC) — Stripe affiliateMerchant of Record / self-serve paymentsUnited StatesSCC
Resend Inc.Transactional emailUnited StatesSCC

Art. 6. Transfers outside the EU

Transfers to USA and other extra-EEA providers occur on the basis of the SCCs adopted by the European Commission under Decision 2021/914. Railway Corp. does not publish a dedicated public DPA; the DPA is available on request at hello@quvant.app.

Art. 7. Data-subject rights

Informis Labs assists the Controller in responding to data-subject requests without undue delay, and in any event in time for the Controller to meet the deadlines under Art. 12 GDPR. Requests: hello@quvant.app

Art. 8. Personal data breach notification

In the event of a breach, Informis Labs notifies the Controller within 36 hours of discovery with the information available under Art. 33 GDPR.

Art. 9. Governing law

Italian law. Exclusive venue: Treviso (TV).

Disclaimer: this text is informative. The contractually binding DPA is the one digitally signed between the parties, available on request for Team and Professional plans.

Request the signed DPA

The binding Data Processing Agreement is the one signed between the parties. Write to us and we will send you the version to countersign for your plan.