Skip to content

For institutions

Data Processing Agreement

For schools, clinics, retreats, and employers deploying Q Origin to their members.

If you are introducing Q Origin to a defined group — students, patients, staff, retreat guests — and you are the data controller for those individuals, we sign a Data Processing Agreement with you as your processor under GDPR Article 28.

What the DPA covers

  • Subject matter, duration, nature and purpose of processing
  • Categories of data subjects and personal data
  • Technical and organisational security measures (mirrors our security page)
  • Sub-processor list and notification of changes
  • International transfer safeguards (Standard Contractual Clauses + UK IDTA where applicable)
  • Audit rights, breach notification timelines (within 72 hours), and end-of-contract data return / deletion

How to get it

Email institutions@qorigin.app with your organisation name, the country of your controller entity, and the rough size of the cohort. We send a PDF of our standard DPA the same working day. Counter-signing typically takes us 2–3 working days from receipt of your version.

Other documents on request

  • Information security policy summary
  • Latest penetration-test attestation
  • Data protection impact assessment (DPIA) template, pre-completed for our processing
  • Sub-processor list with locations

See also: Security · Privacy · For practitioners