For institutions
Data Processing Agreement
For schools, clinics, retreats, and employers deploying Q Origin to their members.
If you are introducing Q Origin to a defined group — students, patients, staff, retreat guests — and you are the data controller for those individuals, we sign a Data Processing Agreement with you as your processor under GDPR Article 28.
What the DPA covers
- Subject matter, duration, nature and purpose of processing
- Categories of data subjects and personal data
- Technical and organisational security measures (mirrors our security page)
- Sub-processor list and notification of changes
- International transfer safeguards (Standard Contractual Clauses + UK IDTA where applicable)
- Audit rights, breach notification timelines (within 72 hours), and end-of-contract data return / deletion
How to get it
Email institutions@qorigin.app with your organisation name, the country of your controller entity, and the rough size of the cohort. We send a PDF of our standard DPA the same working day. Counter-signing typically takes us 2–3 working days from receipt of your version.
Other documents on request
- Information security policy summary
- Latest penetration-test attestation
- Data protection impact assessment (DPIA) template, pre-completed for our processing
- Sub-processor list with locations
See also: Security · Privacy · For practitioners