This Data Processing Agreement ("DPA") forms an integral part of the Organization Subscription Terms (the "Terms") and governs Quorify's processing of personal data on the Organization's behalf under Art. 28 GDPR. Where it conflicts with the Terms on data-protection matters, this DPA prevails.
1. Definitions
1.1. Controller = the Organization. Processor = Quorify. Sub-processors = the third parties in the Sub-processor List. "Personal data", "processing", "data subject", "personal-data breach" have their GDPR meanings.
1.2. "Data Protection Law" means GDPR, Law 190/2018, Law 506/2004 and other applicable rules.
2. Subject matter, duration and instructions
2.1. Quorify processes the Controller's Member data solely to provide the Service, for the term of the Terms and thereafter per Section 11.
2.2. Quorify processes only on the Controller's documented instructions, being the Terms, this DPA, and the configuration/use of the Platform.
2.3. Quorify informs the Controller if, in its opinion, an instruction infringes Data Protection Law (no obligation to give legal advice).
3. Processing details (Annex I)
3.1. Nature and purpose: storage, retrieval, organization, display, aggregate analytics, notification, export and deletion of Member data, to provide the Service. Aggregated and anonymized data that no longer allows identification of a person is not personal data and falls outside this DPA.
3.2. Types of data: name, email, phone, university/faculty, role and membership, attendance, votes, fees and payments, tasks, recruitment data, member documents, admin notes, and, if the Controller uses the 230 feature, donor data (see 230 DPA).
3.3. Categories of data subjects: Organization Members, recruitment applicants, event attendees, and (for 230) donors.
3.4. Special categories: except CNP processed via the 230 feature (governed by the 230 DPA and Art. 4 of Law 190/2018), the Platform is not intended for special-category data.
4. Processor obligations (Art. 28(3))
Quorify: (a) processes only on the Controller's documented instructions, including as to international transfers, save where legally required; (b) ensures authorized persons are under confidentiality; (c) implements the security measures in Section 9 and Annex II; (d) respects the sub-processor conditions (Section 5); (e) assists the Controller, by appropriate technical and organizational measures, with data-subject requests (Arts. 12-22 GDPR); (f) assists the Controller with Arts. 32-36 (security, breach notification, DPIAs and prior consultation), considering the nature of processing and information available; (g) at the Controller's choice, deletes or returns data on termination (Section 11); (h) makes available information to demonstrate compliance and allows audits (Section 12).
5. Sub-processors
5.1. The Controller gives a general authorization for the sub-processors in the Sub-processor List.
5.2. Quorify gives at least 30 days' notice before adding or replacing a sub-processor; the Controller may object within that period on reasonable data-protection grounds, and the parties will seek a solution; if none is possible, the Controller may terminate the affected part of the Service.
5.3. Quorify imposes on sub-processors, by contract, data-protection obligations equivalent to this DPA and remains liable to the Controller for their activity.
6. International transfers
6.1. Data is hosted primarily in the European Union / EEA (Supabase; Upstash - Ireland). For sub-processors outside the EEA (Vercel, Resend, Google, Microsoft, Stripe), transfers rely on the Standard Contractual Clauses (Decision (EU) 2021/914), with the applicable modules and supplementary measures (encryption, minimization, access controls). On request, Quorify provides information on safeguards.
7. Confidentiality
7.1. Quorify treats Member data as confidential and restricts access to personnel who need to know, under confidentiality obligations.
8. Data-subject and authority requests
8.1. If Quorify receives a request directly from a data subject regarding the Controller's data, it forwards it to the Controller and does not respond directly, unless legally required.
8.2. Quorify notifies the Controller of binding authority requests where legally permitted.
9. Security measures (Art. 32 - Annex II)
Considering the state of the art and the risks, Quorify implements appropriate technical and organizational measures, including: AES-256-GCM encryption for CNP (230 feature) and encryption of sensitive data; TLS in transit; row-level security (RLS) and role-based access controls; pseudonymization (IP hashing); audit logging; environment separation; backup and recovery procedures; vulnerability and incident management; two-factor authentication available; minimization and privacy-by-design/by-default principles.
10. Breach notification
10.1. Quorify notifies the Controller without undue delay and in any case within 72 hours of becoming aware of a personal-data breach affecting the Controller's data, providing available information the Controller needs to meet its own notification obligations.
11. Deletion or return of data
11.1. On end of the Service, at the Controller's choice, Quorify deletes or returns the data. The Controller has a 30-day export window; thereafter Quorify securely deletes the data (including at sub-processors), except where retention is legally required, in which case it protects and limits processing.
12. Audit
12.1. Quorify makes available information to demonstrate compliance and allows audits, including inspections, by the Controller or a mandated auditor, on reasonable notice, during business hours, under confidentiality, and no more than once per year (except at an authority's requirement or following an incident). Quorify may respond, in the first instance, by providing relevant reports, certifications or documentation.
13. Liability
13.1. Each party's liability under this DPA is subject to the limitations of liability in the Terms, to the extent permitted by law and without prejudice to data subjects' GDPR rights.
14. Duration, governing law and execution
14.1. This DPA is effective for the term of the Terms and for as long as Quorify processes data on the Controller's behalf.
14.2. It is governed by GDPR and Romanian law.
14.3. Electronic acceptance of this DPA by the Organization's Owner constitutes a valid written agreement under Art. 28(3) and (9) GDPR.