Data Processing Agreement
Last updated 16 August 2026
1. Purpose and scope
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service or applicable Order Form between Customer and Max Kugland, trading as Quinta ("Quinta") (together, "the Agreement"). It applies whenever Quinta processes personal data contained in Customer Data on Customer's behalf in the course of providing the Service, and reflects the parties' obligations under Art. 28 of Regulation (EU) 2016/679 ("GDPR"). In this relationship, Customer is the controller and Quinta is the processor.
2. Definitions
"Personal data," "processing," "controller," "processor," "data subject," "personal data breach," and "supervisory authority" have the meanings given in Art. 4 GDPR. "Sub-processor" means a third party engaged by Quinta to process personal data in order to provide the Service. "Customer Data" has the meaning given in the Terms of Service.
3. Subject matter, duration, nature, and purpose
The subject matter, duration, nature and purpose of processing, the categories of data subjects, and the types of personal data are set out in Annex 1. This DPA remains in effect for as long as Quinta processes personal data on Customer's behalf under the Agreement.
4. Customer's instructions
Quinta will process personal data only on Customer's documented instructions, including as necessary to provide the Service in the ordinary course (e.g. storage, search, and AI-assisted analysis of records Customer or its users add), unless required to do otherwise by EU or member state law, in which case Quinta will inform Customer of that legal requirement before processing, unless the law prohibits doing so. Quinta will inform Customer if, in its opinion, an instruction infringes the GDPR or another data protection provision.
5. Confidentiality
Quinta ensures that persons authorized to process personal data under this DPA have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6. Security of processing
Quinta implements the technical and organizational measures set out in Annex 2, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, consistent with Art. 32 GDPR.
7. Sub-processors
Customer authorizes Quinta to engage the sub-processors listed in Annex 3. Quinta will give Customer at least 30 days' notice before engaging a new sub-processor, so Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, either party may terminate the affected part of the Service. Quinta will impose data protection obligations substantially similar to those in this DPA on each sub-processor, and remains liable to Customer for a sub-processor's performance of those obligations.
8. International transfers
Where a sub-processor is located, or processes personal data, outside the EU/EEA, Quinta ensures the transfer is subject to appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another legally recognized transfer mechanism.
9. Assistance to Customer
Taking into account the nature of the processing, Quinta will reasonably assist Customer, insofar as this is possible, in fulfilling Customer's obligations to respond to requests from data subjects exercising their rights under Chapter III GDPR, and with Customer's obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the information available to Quinta.
10. Personal data breaches
Quinta will notify Customer without undue delay, and in any event within 72 hours of becoming aware, after confirming a personal data breach affecting Customer Data, and will provide the information reasonably available to it to help Customer meet its own notification obligations under Art. 33 and 34 GDPR.
11. Audits
Quinta will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including by providing a written summary of its technical and organizational measures on request. Customer may request an on-site or third-party audit of Quinta's relevant processing activities on reasonable prior written notice (at least 30 days), no more than once per 12-month period absent a specific concern, conducted during business hours in a manner that avoids unnecessary disruption and preserves the confidentiality of Quinta's other customers.
12. Deletion and return of data
At Customer's choice, and upon termination of the Agreement or on earlier request, Quinta will delete or return all personal data processed on Customer's behalf, and delete existing copies, unless EU or member state law requires continued storage of that personal data.
13. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations of liability set out in the Terms of Service, except where GDPR itself assigns liability directly to a party (e.g. Art. 82 GDPR).
14. Order of precedence and term
This DPA applies for as long as Quinta processes personal data on Customer's behalf under the Agreement. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.
Annex 1 — Details of processing
- Subject matter
- Hosting, storage, search, and AI-assisted analysis of records (briefs, CVs, interview notes, and related material) that Customer or its users upload to or generate within Quinta, in order to provide the Service.
- Duration
- For the term of the Agreement, plus any retention period agreed with Customer or required by law, followed by deletion or return per Section 12.
- Nature of processing
- Collection, storage, organization, structuring, retrieval, search (including AI-assisted semantic search), and AI-assisted analysis and drafting (e.g. embeddings and language-model-based report generation).
- Purpose of processing
- To provide the Service to Customer as instructed, and for no other purpose (including no use of Customer Data to train general-purpose AI models).
- Categories of data subjects
- Customer's own users; and individuals referenced in Customer Data that Customer uploads, which may include candidates, referees, interviewees, and other third parties Customer chooses to include.
- Types of personal data
- Contact and identification details, professional/employment history, interview and assessment notes, and any other personal data Customer includes in the material it uploads. Customer determines what personal data it includes and is responsible for ensuring it has a lawful basis to do so; special categories of data (Art. 9 GDPR) should only be included where Customer has confirmed a lawful basis and appropriate safeguards apply.
Annex 2 — Technical and organizational measures
- Encryption in transit: connections to the Service are encrypted using TLS.
- Tenant isolation: Customer Data is logically separated per customer at the database level (row-level security), so one customer's data cannot be accessed through another customer's account or credentials.
- Access control: access to Customer Data within Quinta is limited to what is necessary to operate and support the Service, and is tied to individually attributable accounts.
- Hosting location: infrastructure is located within the EU (Germany).
- Sub-processor due diligence: sub-processors are engaged under data processing terms consistent with this DPA, including appropriate international-transfer safeguards where applicable.
Annex 3 — Approved sub-processors
- OpenAI
- AI-assisted analysis of Customer Data (e.g. embeddings and language-model-based drafting of assessments and reports). Located outside the EU/EEA; transfers are subject to the EU Standard Contractual Clauses or another appropriate safeguard.
- United Domains AG
- Email delivery. Used solely to deliver transactional sign-in emails; does not receive Customer Data. Located in the EU (Germany); no international transfer.
- Hetzner Online GmbH
- Infrastructure hosting. Located in the EU (Germany); no international transfer.
Contact
Questions about this DPA can be sent to maxtrainbombing. Our full legal contact details are listed in the imprint.