Data Processing Agreement
Effective Date: 25 November 2025
This Data Processing Agreement ("DPA") is between Qaxal s.r.o. ("Qaxal", "we", "us") and the business that subscribes to the Digital Identity Platform ("Customer", "you"). It governs our processing of personal data on your behalf in connection with the Digital Identity Platform ("DIP" or "the Service").
This DPA forms part of the Terms of Service at dip.qaxal.com/legal/terms and is binding on Customer upon Customer's acceptance of those Terms. No separate signature is required. Qaxal records the same acceptance evidence as for the Terms (namely the accepting user's name and email, business identified, timestamp, IP address and user agent, and the version of the Terms and this DPA accepted, by URL and document hash) to evidence formation of this DPA. The only contact address for any matter under this DPA is legal@qaxal.com.
Qaxal s.r.o. is a Slovak limited liability company, IČO 55 900 526, DIČ 2122126281, VAT ID SK2122126281, with registered seat at Ulica Adama Štrekára 8131/19, 917 08 Trnava, Slovakia, registered in the Commercial Register of the District Court Trnava (Obchodný register Okresného súdu Trnava), Section Sro, Insert No. 55543/T.
1. Definitions
Capitalised terms not defined below have the meaning given to them in the Terms or in the GDPR.
- "GDPR" means Regulation (EU) 2016/679. References to "Controller", "Processor", "Personal Data", "Personal Data Breach", "Processing", "Data Subject", "Supervisory Authority", and "Special Categories of Personal Data" have the meanings given in Article 4 GDPR.
- "Applicable Data Protection Law" means the GDPR, the UK GDPR and Data Protection Act 2018 where they apply, the Swiss Federal Act on Data Protection where it applies, the ePrivacy Directive 2002/58/EC and its national implementations (including Slovak Act No. 452/2021 Coll.), and Slovak Act No. 18/2018 Coll. on the Protection of Personal Data.
- "Customer Personal Data" means Personal Data that Qaxal processes on Customer's behalf in connection with the Service.
- "Sub-processor" means a third party engaged by Qaxal to process Customer Personal Data on Customer's behalf, as listed at dip.qaxal.com/legal/sub-processors.
- "SCCs" means the standard contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "Terms" means the Terms of Service at dip.qaxal.com/legal/terms.
2. Roles
In respect of Customer Personal Data, Customer is the Controller and Qaxal is the Processor. This DPA satisfies Article 28 GDPR.
Where Customer configures the Service to transmit event data to third-party platforms (for example Meta Conversions API, Google Ads, LinkedIn Conversions API, Google Analytics 4, or any other destination Customer enables) using Customer's own accounts with those platforms, Customer is the Controller for that onward transmission and each destination is an independent Controller (or Customer's own Processor under Customer's direct contract with the destination). Qaxal is not a Joint Controller with Customer and is not a Sub-processor of any such destination.
This DPA does not cover Personal Data that Qaxal processes in its own Controller capacity (for example, Customer account contacts, billing, marketing, and prospect data). That processing is described in Qaxal's Privacy Policy at dip.qaxal.com/legal/privacy.
3. Scope and Customer Instructions
The subject matter, duration, nature and purpose of the processing, types of Personal Data, and categories of Data Subjects are set out in Annex I.
Qaxal processes Customer Personal Data only on Customer's documented instructions, unless required to do so by Union or Member State law. Where Qaxal is required by law to process otherwise, Qaxal will inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
Customer's documented instructions consist of:
(a) the Terms; (b) this DPA; (c) Customer's configuration of the Service through its admin dashboard, including selection and configuration of destinations, sub-domains, retention controls, and event schemas; and (d) any subsequent written instructions sent to legal@qaxal.com.
If Qaxal considers that an instruction infringes Applicable Data Protection Law, Qaxal will inform Customer without undue delay.
Qaxal will not (i) process Customer Personal Data for any purpose other than the provision of the Service, (ii) sell, share for advertising, or otherwise commercialise Customer Personal Data, (iii) combine Customer Personal Data with data from any other customer or with Qaxal's own Controller-side data, or (iv) use Customer Personal Data to train or improve any artificial-intelligence, machine-learning, or analytics model, whether Qaxal's own or a third party's. Qaxal will impose the same restriction on its Sub-processors.
4. Confidentiality
Qaxal will ensure that persons authorised to process Customer Personal Data have committed to confidentiality in writing or are under an appropriate statutory obligation of confidentiality. Access is restricted on a least-privilege, need-to-know basis and reviewed periodically.
5. Security
Qaxal will implement and maintain the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk in accordance with Article 32 GDPR. Qaxal may update those measures from time to time provided that any update does not materially reduce the overall level of security.
6. Sub-processors
General authorisation. Customer grants Qaxal a general written authorisation to engage Sub-processors. The current list of Sub-processors is published at dip.qaxal.com/legal/sub-processors and identifies each Sub-processor, its processing location, and the applicable transfer mechanism where relevant.
Notice of changes. Qaxal will notify Customer of any addition or replacement of a Sub-processor by emailing the address Customer has provided for legal notices, at least 30 days before the change takes effect. Customer may also subscribe to general sub-processor change notices at legal@qaxal.com to receive notifications in addition to the legal-notice email.
Objection and remedy. Within 30 days of notice, Customer may object in writing to legal@qaxal.com on reasonable data-protection grounds. The parties will discuss the objection in good faith. If Qaxal cannot address Customer's objection within a reasonable period, Customer may terminate the affected portion of the Service by written notice to legal@qaxal.com, and Qaxal will refund any prepaid Fees for the unused portion of the term on a pro-rata basis.
Flow-down. Qaxal will impose on each Sub-processor, by written contract, data-protection obligations no less protective than those set out in this DPA. Qaxal remains liable to Customer for the performance of each Sub-processor's obligations.
7. Data Subject Requests
If Qaxal receives a request from a Data Subject directed to Qaxal that relates to Customer Personal Data, Qaxal will notify Customer within 5 business days of receipt and will not respond to the Data Subject directly, except to confirm that Customer is the Controller and to refer the Data Subject to Customer.
Taking into account the nature of the processing, Qaxal will assist Customer by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling Customer's obligations to respond to requests for the exercise of Data Subject rights under Articles 15 to 22 GDPR.
8. Personal Data Breach
Qaxal will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of the breach. For these purposes, "becoming aware" means the point at which Qaxal has a reasonable degree of certainty that a security incident has occurred which has led to Customer Personal Data being compromised, applying the standard set out in EDPB Guidelines 9/2022 on Personal Data Breach notification under GDPR.
The notification will include, to the extent then known: the nature of the breach including the categories and approximate number of Data Subjects and records concerned; the likely consequences of the breach; and the measures taken or proposed to address the breach and mitigate its possible adverse effects. Where not all information is available at the time of initial notification, Qaxal will provide further information in phases as it becomes available.
Qaxal will reasonably assist Customer in any communication to Data Subjects required under Article 34 GDPR. The decision and content of any communication to Data Subjects remain Customer's.
9. Assistance with Articles 32 to 36 GDPR
Taking into account the nature of processing and the information available to Qaxal, Qaxal will assist Customer with Customer's compliance obligations under Articles 32 to 36 GDPR. This includes:
- assisting Customer with implementing appropriate technical and organisational measures under Article 32, including by providing the security information described in Annex II and any reasonably necessary updates;
- assisting Customer with Customer's Article 33 notifications to the competent Supervisory Authority by providing the information described in Section 8 (Personal Data Breach) within the timelines required to support Customer's notification deadlines;
- assisting with Customer's Article 34 communications to Data Subjects where the breach is likely to result in a high risk to their rights and freedoms, as further set out in Section 8;
- assisting with any data-protection impact assessment Customer must carry out under Article 35 GDPR and any prior consultation with a Supervisory Authority under Article 36 GDPR, by making available information about Qaxal's processing that is reasonably available to Qaxal. Qaxal does not commit to bespoke DPIA drafting.
10. Records of Processing
Qaxal maintains its records of processing under Article 30(2) GDPR and will make relevant extracts available to Customer on reasonable written request to legal@qaxal.com.
11. Audit Rights
Qaxal will make available to Customer all information necessary to demonstrate Qaxal's compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer, subject to the procedural controls below.
Customer may verify Qaxal's compliance with this DPA as follows.
(a) Annual security questionnaire. Customer may submit, once per 12-month period, an industry-standard written security questionnaire (for example SIG Lite or CAIQ). Qaxal will respond within 30 business days.
(b) Third-party assessments. Where Qaxal holds them, Qaxal will provide recent third-party security assessments (penetration test summaries, certification reports, audit reports) under a confidentiality undertaking, in place of an on-site audit. Qaxal holds no formal certification at the date of this DPA.
(c) On-site audits. On-site audits are available on reasonable cause (for example, a confirmed material breach by Qaxal affecting Customer Personal Data), with at least 30 days' written notice, during normal business hours, no more than once per 12-month period, at Customer's cost, conducted by Customer or by an independent auditor mandated by Customer and reasonably acceptable to Qaxal, and subject to appropriate confidentiality obligations. If the audit reveals material non-compliance by Qaxal with this DPA or applicable data-protection law, Qaxal will reimburse Customer's reasonable, documented audit costs in addition to remedying the non-compliance.
(d) Supervisory Authority access. Qaxal will accommodate audits and inspections by the Slovak Office for Personal Data Protection (UOOÚ) or any other competent Supervisory Authority as required by Applicable Data Protection Law.
12. International Transfers
Where Qaxal transfers Customer Personal Data outside the European Economic Area to a country that is not covered by an adequacy decision of the European Commission, the transfer is supported by the SCCs, Module Two (Controller to Processor). The SCCs are incorporated into this DPA by reference and are available at https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en. The SCC clause elections agreed by the parties are set out in Annex III.
Where Customer Personal Data is subject to UK data-protection law, the transfer is supported by the UK International Data Transfer Addendum to the EU SCCs (Version B1.0, in force 21 March 2022), incorporated by reference and available at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-data-transfers/international-data-transfer-agreement-and-guidance/.
Where Customer Personal Data is subject to Swiss data-protection law, the transfer is supported by the SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner (FDPIC) in its statement of 27 August 2021, incorporated by reference.
In the event of any conflict between this DPA and the SCCs, the SCCs prevail.
13. Return or Deletion
On termination or expiry of the Service, Customer may export Customer Personal Data during a 30-day export window using the export functionality made available through the Service. Within a further 30 days after the end of the export window, Qaxal will delete Customer Personal Data from active systems and from backups, except where retention is required by Union or Member State law (for example, accounting records under Slovak Act No. 431/2002 Coll. on Accounting). Qaxal will, on Customer's written request, document any data retained under this exception and the basis for retention.
During the term, Customer may instruct Qaxal in writing at legal@qaxal.com to delete identified Customer Personal Data; Qaxal will give effect to the instruction without undue delay.
14. Liability
The parties' respective liabilities under this DPA are subject to and form part of the limitation of liability set out in Section 12 (Limitation of Liability) of the Terms. There is no separate liability cap under this DPA. Customer's payment, refund, and indemnity obligations are not subject to that cap, as set out in the Terms.
Nothing in this DPA limits or excludes any liability of either party to a Data Subject under Article 82 GDPR where that liability cannot be limited or excluded as a matter of mandatory law.
15. Term, Survival, and Conflicts
This DPA takes effect on Customer's acceptance of the Terms and continues for as long as Qaxal processes Customer Personal Data on Customer's behalf. Sections 3 (no further processing), 8 (breach notification, to the extent of incidents that occurred during the term), 13 (return or deletion), 14 (liability), and any provisions intended by their nature to survive, survive termination.
In the event of a conflict between the Terms and this DPA on data-protection matters, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
16. Governing Law and Forum
This DPA is governed by the law of the Slovak Republic. Disputes arising out of or in connection with this DPA are subject to the exclusive jurisdiction of the competent Slovak court at Qaxal's registered seat. The competent Supervisory Authority for Qaxal is the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov Slovenskej republiky, UOOÚ), Hraničná 12, 820 07 Bratislava 27, Slovak Republic, dataprotection.gov.sk.
Annex I: Description of Processing
Controller (Data Exporter). Customer, as identified in Customer's account at sign-up to the Service. Customer's activities relevant to the processing are the operation of Customer's websites and applications and the use of the Service for first-party event collection, identity stitching, and server-side fan-out to destinations Customer enables.
Processor (Data Importer). Qaxal s.r.o., IČO 55 900 526, DIČ 2122126281, VAT ID SK2122126281, Ulica Adama Štrekára 8131/19, 917 08 Trnava, Slovakia, registered in the Commercial Register of the District Court Trnava, Section Sro, Insert No. 55543/T, legal@qaxal.com. Qaxal's activities relevant to the processing are the operation of the Digital Identity Platform as described below.
Subject matter. Provision of the Digital Identity Platform, namely server-side tag-management hosting and first-party identity services.
Duration. The term of Customer's subscription to the Service, plus the 30-day export window described in Section 13.
Nature and purpose of the processing. Hosting Customer's server-side tag containers; receiving event data from Customer's web and application properties; transmitting events to destinations Customer has configured in the Service; identity resolution across sessions and (where Customer enables it) across authenticated and anonymous identifiers for Customer's end-users; logging and warehousing of event data for Customer's analytics, advertising-measurement, and customer-data purposes.
Types of Personal Data.
- Technical identifiers: IP address (truncated by default), device identifiers, user-agent string, browser and operating-system metadata, approximate geolocation derived from IP.
- Online identifiers set by Customer or by the Service on Customer's behalf: first-party cookies (including the Service's visitor identifier and session identifier), Customer-defined user identifiers, hashed contact identifiers (for example SHA-256 hashes of email addresses) where Customer's tags transmit them, click identifiers and campaign parameters.
- Event metadata: page and screen views, interactions, e-commerce events, custom dimensions and custom events that Customer chooses to send through the Service.
- Consent state where Customer's tags transmit it.
- Any other Personal Data that Customer chooses to transmit through the Service in accordance with Customer's documented instructions.
Categories of Data Subjects. Customer's website and application end-users, including visitors, leads, account holders, and customers.
Special Categories of Personal Data. None by default. Customer must not configure the Service to process Special Categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) on a systematic basis without prior written notice to Qaxal.
Frequency of the transfer. Continuous, in real time, for the duration of the Service.
Sub-processors. As listed at dip.qaxal.com/legal/sub-processors.
Competent Supervisory Authority. For Customer (where Customer is established in the EU), the Supervisory Authority of the Member State in which Customer is established. For Qaxal, the Slovak Office for Personal Data Protection (UOOÚ).
Annex II: Technical and Organisational Measures
This Annex describes the technical and organisational measures Qaxal applies to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. Qaxal holds no formal security certification at this time; the measures listed below are Qaxal's current Article 32 baseline and may be updated provided that any update does not materially reduce the overall level of security.
Access control. Access to production systems and to Customer Personal Data is restricted to authorised Qaxal personnel on a least-privilege, need-to-know basis. Access is reviewed periodically and revoked promptly on role change or departure.
Authentication. Administrative access requires single sign-on with multi-factor authentication. Service accounts used by automated systems are scoped to least privilege and rotated on a documented schedule.
Encryption in transit. TLS 1.2 or higher is enforced on Service endpoints, between Qaxal and its Sub-processors, and on administrative access. Insecure ciphers are disabled.
Encryption at rest. Customer Personal Data stored by Qaxal's Sub-processors is encrypted at rest using the Sub-processor's default server-side encryption (for example AES-256). Where the data warehouse is provisioned in Customer's own cloud project, the encryption-key arrangement applicable to that project applies.
Network security. Qaxal relies on its hosting Sub-processor's DDoS protection, web-application firewall, and bot-management features. Service endpoints validate event payloads against the configured schema; rate-limiting is applied per source and endpoint.
Segregation. Customer Personal Data is segregated logically by Customer-scoped namespaces and datasets. Cross-Customer access is prevented at the application layer.
Logging. Administrative access to production systems and changes to Customer configuration are logged centrally. Logs are retained for at least 12 months and protected against unauthorised modification.
Incident response. Qaxal maintains a documented incident-response process covering detection, triage, containment, eradication, recovery, and notification, including the breach-notification commitment in Section 8 of this DPA. An on-call point of contact is designated.
Backup and restore. Customer event data is backed up by Qaxal's data-warehouse Sub-processor on a daily snapshot basis with a 30-day rolling retention by default. Restore is tested periodically as part of Qaxal's continuity exercises.
Change control. Production code and configuration changes are peer-reviewed before deployment. Infrastructure is managed as code and versioned.
Vulnerability management. Dependencies are scanned periodically. Critical vulnerabilities are addressed promptly, high-severity within 30 days of disclosure, and others on a risk-prioritised basis.
Vendor management. Sub-processors are onboarded under written data-protection terms and reviewed periodically. The current list is published at dip.qaxal.com/legal/sub-processors.
Personnel security. Qaxal personnel and contractors with access to Customer Personal Data are bound by written confidentiality undertakings, complete security-awareness orientation, and follow Qaxal's acceptable-use, device-security, and clean-desk policies. Qaxal does not operate on-premises infrastructure for processing Customer Personal Data; personnel access production systems from company-controlled or managed devices with full-disk encryption.
Data minimisation and retention. Service defaults favour minimisation: IP truncation is on by default; the Service stores only fields Customer has configured to send. Retention is enforced through partitioned storage and configured expiries; Customer controls retention extensions through the Service interface.
Annex III: SCC Clause Elections
Where the SCCs apply under Section 12, the parties have agreed the following clause elections.
| SCC element | Election |
|---|---|
| Module | Module Two (Controller to Processor) for Customer-to-Qaxal transfers. Module Three (Processor to Processor) applies between Qaxal and any Sub-processor located outside the EEA, under Qaxal's separate contracts with each Sub-processor. |
| Clause 7 (Docking clause) | Does not apply. |
| Clause 9 (Use of Sub-processors) | Option 2 (General written authorisation), with the 30-day advance notice set out in Section 6 of this DPA. |
| Clause 11 (Redress) | The optional independent dispute-resolution body is not selected; Data Subjects retain the right to lodge a complaint with a Supervisory Authority and to seek judicial redress under Clause 11(1). |
| Clause 17 (Governing law) | The law of the Slovak Republic. |
| Clause 18 (Choice of forum and jurisdiction) | The courts of the Slovak Republic in Bratislava. |
| Annexes to the SCCs | Annex I.A (parties), Annex I.B (description of transfer), Annex I.C (competent Supervisory Authority), and Annex II (technical and organisational measures) of the SCCs are populated by the corresponding sections of Annex I and Annex II of this DPA. The list of Sub-processors at dip.qaxal.com/legal/sub-processors serves as Annex III of the SCCs. |
| Frequency of Sub-processor changes (where the SCCs require it) | As notified under Section 6 of this DPA. |
For UK transfers, the UK International Data Transfer Addendum is incorporated as set out in Section 12. For Swiss transfers, the SCCs apply as adapted by the FDPIC's statement of 27 August 2021.
Last updated: 29 May 2026