Legal

Data Processing Addendum

This addendum governs our processing of personal information contained in Customer Data on your behalf. It forms part of the agreement between you and QSolve Inc. and applies where data protection law governs that processing. In it, "we" is the processor and "you" is the controller.

Version 1.0 Effective August 21, 2026 Processor QSolve Inc.

01Definitions

  • Customer Data — ledger, sub-ledger, banking, and operational data you or your integrations submit to the platform, including any personal information within it.
  • Data Protection Law — the GDPR, the UK GDPR and Data Protection Act 2018, the CCPA as amended, and any other privacy law applicable to processing under the agreement.
  • Personal Data — information within Customer Data relating to an identified or identifiable person.
  • Processing, controller, processor, data subject, and personal data breach have the meanings given in Data Protection Law.
  • Subprocessor — a third party we engage to process Personal Data on our behalf.

02Roles and scope

You are the controller of Personal Data within Customer Data. We are your processor and will process it only on your documented instructions. Your instructions comprise the agreement, this addendum, your configuration of the platform, and any further written instruction you give.

We are an independent controller for the limited information described in our Privacy Policy, such as account administrator contact details and website analytics. This addendum does not apply to that processing.

If we believe an instruction breaches Data Protection Law, we will tell you promptly and may pause the affected processing until the instruction is resolved.

03Our obligations as processor

  • Process Personal Data only for the purposes in Annex I and on your instructions, not for our own purposes.
  • Not sell Personal Data, and not disclose it for cross-context behavioral advertising or targeted advertising.
  • Implement and maintain the security measures in Annex II.
  • Ensure personnel with access are bound by confidentiality and trained appropriately.
  • Assist you, at your cost where the effort is material, with data protection impact assessments, regulator consultations, and your own compliance obligations, so far as the assistance relates to our processing.
  • Make available the information reasonably necessary to demonstrate our compliance with this addendum.
  • Notify you without undue delay if we receive a legally binding demand for Personal Data, unless prohibited by law, and challenge demands that appear unlawful or overbroad.

04Your obligations as controller

  • Ensure you have a lawful basis to submit Personal Data to the platform and to instruct us to process it.
  • Provide any notices and obtain any consents required from data subjects, including tenants, vendors, and employees whose details appear in ledger or sub-ledger data.
  • Configure roles, permissions, thresholds, approval paths, and retention settings appropriately for your control environment.
  • Not submit Personal Data the platform is not designed to hold, including payment card data, government identifiers beyond what a ledger ordinarily contains, or special category data, unless separately agreed in writing.
  • Keep account credentials secure and promptly deprovision users who leave your organization.

05Confidentiality and personnel

We limit access to Personal Data to personnel who need it to deliver or support the service. Those personnel are subject to written confidentiality obligations that survive their engagement, receive security and privacy training, and are subject to background screening where permitted by law. Access is granted on a least-privilege basis, reviewed periodically, and revoked on role change or departure.

06Security measures

We maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, as described in Annex II. We may update those measures provided the level of protection is not materially reduced.

07Subprocessors

You give general authorization for us to engage the subprocessors listed in Annex III. We impose data protection obligations on each subprocessor that are no less protective than this addendum, and we remain responsible for their performance.

We will give you at least 30 days' notice before a new subprocessor begins processing Personal Data. If you object on reasonable data protection grounds within that period, we will work with you to find an alternative. If none is available, you may terminate the affected part of the service without penalty for the unused portion of the term.

08International transfers

We host Personal Data in Microsoft Azure US East and process it in the United States. We apply encryption in transit and at rest to all Personal Data regardless of origin.

QSolve currently serves customers in the United States. If processing under the agreement would involve a transfer from the EEA, UK, or Switzerland, contact us at info@qsolve.app before submitting Personal Data so that the appropriate transfer mechanism, including Standard Contractual Clauses where required, can be executed as a schedule to this addendum.

09Data subject requests

The platform gives you the means to access, correct, export, and delete Personal Data within your environment, so that you can respond to data subject requests directly.

If we receive a request that relates to your Customer Data, we will not respond to it substantively. We will redirect the individual to you and notify you without undue delay, unless we are legally required to respond. Where you need assistance we cannot provide through the platform, we will help at your reasonable cost.

Audit records

Audit logs and evidence records are immutable by design, because their integrity is what makes them useful to your auditors. Where a deletion request conflicts with an audit record you are required to retain, we will tell you so that you can assess the applicable exemption, and we will act on your written instruction.

10Incident notification

We will notify you without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting your Personal Data. The notice will describe, to the extent known: the nature of the breach, categories and approximate number of records and data subjects affected, likely consequences, measures taken or proposed, and a contact point for further information.

We will provide reasonable cooperation with your investigation and any notification you must make to regulators or data subjects. Our notice is not an acknowledgment of fault.

11Audits and assessments

On request, and no more than once a year unless required by a regulator or following a breach, we will provide our then-current SOC 2 Type II report, expected in Q1 2027, a completed security questionnaire, and a summary of our most recent penetration test.

Where those materials are insufficient to demonstrate compliance, you may conduct an audit yourself or through an independent auditor who is not our competitor, on at least 30 days' notice, during business hours, subject to confidentiality, and in a manner that does not disrupt our operations or other customers' data. You bear the cost unless the audit reveals material non-compliance.

12Return and deletion

During the term you may export Customer Data and evidence records at any time through the platform. On termination or expiry we will, at your choice, return Customer Data in a commonly used machine-readable format or delete it.

Absent an instruction, we will delete or de-identify Customer Data within 30 days of termination. We may retain copies where required by law, or in backups that expire on their ordinary cycle of no more than 90 days, and this addendum continues to apply to anything retained. We will certify deletion in writing on request.

13Automated processing and model use

The platform performs automated matching, reconciliation, anomaly detection, and drafting of variance explanations on Customer Data, within the controls you configure. Every output is presented for human review before it can be relied upon or posted to your system of record.

  • We do not use your Customer Data to train, fine-tune, or improve models that serve other customers, unless you instruct us in writing to do so.
  • Where a third-party model provider is used, it is listed in Annex III, is contractually prohibited from training on your data, and processes it only to return a result.
  • Automated processing does not produce decisions with legal or similarly significant effects on individuals.
  • Every automated action, override, and approval is recorded in the audit log with its inputs, so a reviewer or auditor can reconstruct how a result was reached.

14Liability and precedence

Each party's liability under this addendum is subject to the limitations and exclusions in the agreement. Nothing here limits a data subject's rights under Data Protection Law.

If this addendum conflicts with the agreement on the processing of Personal Data, this addendum prevails. If it conflicts with the Standard Contractual Clauses, those clauses prevail.

15Annex I — Processing details

Subject matterProvision of the QSolve financial close and controls platform.
DurationThe subscription term, plus the deletion period in section 12.
Nature and purposeHosting, storage, matching, reconciliation, anomaly detection, drafting of variance explanations, workflow routing, approval recording, audit logging, and reporting.
Categories of data subjectsYour personnel using the platform (preparers, reviewers, approvers, administrators); individuals appearing in ledger and sub-ledger records, which may include tenants, guarantors, vendors, contractors, and payees.
Categories of Personal DataNames, business contact details, role and permission data, authentication metadata, activity and audit records; within ledger data, transaction and account details that may be attributable to an individual, such as tenant balances, receipts, and vendor payments.
Special category dataNone. The platform is not designed to hold it, and it must not be submitted without separate written agreement.
FrequencyContinuous for platform activity; scheduled or on-demand for ledger and sub-ledger ingestion.
RetentionAs configured by you; audit and evidence records default to 7 years.

16Annex II — Security measures

AreaMeasures
EncryptionTLS 1.2 or above in transit; AES-256 at rest, including backups.
Access controlRole-based access, single sign-on, least privilege, periodic access review, prompt deprovisioning, MFA for administrative access.
Segregation of dutiesEnforced for people and for automated processing; preparer and reviewer cannot be the same identity.
Tenant isolationLogical separation of customer environments with access scoped per tenant.
Audit loggingImmutable, timestamped logs of platform activity, including automated actions and overrides, mapped to customer-defined controls.
ResilienceEncrypted backups, documented recovery procedures, and periodic restoration testing.
Vulnerability managementDependency monitoring, patch management, annual third-party penetration testing, remediation tracked to closure.
Secure developmentCode review, separated environments, no production Personal Data in development or test environments.
Incident responseDocumented plan with defined roles, escalation, notification timelines, and post-incident review.
PersonnelBackground screening where permitted, confidentiality agreements, security and privacy training at onboarding and annually.
CertificationSOC 2 Type II report expected Q1 2027, available under NDA on completion.

17Annex III — Subprocessors

SubprocessorProcessingLocation
Microsoft AzurePlatform hosting, storage, and backupUS East
AnthropicInference for matching and drafted explanations; contractually prohibited from training on Customer DataUS East
Microsoft 365Transactional notifications to platform usersUS East
HubSpotCRM and demo requests. Does not process platform Customer Data.United States

Standard Contractual Clauses are not currently in place, as processing is US-only. Where a customer requires them, they will be executed as a schedule to this addendum and referenced here.

Contact

To execute this addendum or request the transfer clauses: info@qsolve.app
Security documentation and questionnaires: info@qsolve.app
QSolve Inc. · 8 The Green, STE R, Dover, DE 19901, USA