← DLQ Technos

Data Processing Addendum

Version 0.3-draft · Effective 31/07/2026

Draft — under legal review. This text has not yet been reviewed by a lawyer and is published for review purposes only. It does not yet form a binding agreement. Please check back before relying on it.
Lawyer consent requiredthis document was EXPANDED from the version supplied to us, and must be signed off before it leaves draft. What changed and why: the supplied version was a two-sentence summary. A Data Processing Addendum normally states the subject matter, duration, categories of data and data subjects, the processor obligations and the subprocessor position — otherwise it does not do the job it exists for. Those sections have been added. A signable version for enterprise customers is still needed.

Effective Date: July 28, 2026

This Addendum forms part of the Terms of Service.

1. Roles

Customer acts as Data Controller / Data Fiduciary. DL Quantum Technos Private Limited acts as Data Processor. Processing occurs only on the Customer's documented instructions.

2. Scope of processing

Subject matter — provision of HR, payroll, attendance and related SaaS services. Duration — for the term of the subscription, plus the retention period in the Privacy Policy. Categories of data subjects — the Customer's employees, contractors and workers. Categories of personal data — as listed in the Privacy Policy, including government identifiers, bank details, salary and attendance data.

3. Customer responsibilities

The Customer warrants it has a lawful basis for the personal data it uploads, including any consent required from employees for identity documents, biometric processing and location capture.

4. Our obligations

5. Subprocessors

The Customer authorises the subprocessors listed on our Subprocessors page. We will give notice before adding a new one, and remain responsible for their performance.

6. Audits

On reasonable written request and no more than once a year, we will provide the information reasonably necessary to demonstrate compliance with this Addendum.

7. Transfers

Where personal data crosses borders, we rely on appropriate safeguards.

8. Support access

Our personnel may access Customer Data by signing in to the Customer's workspace where reasonably necessary to provide support or investigate a fault. Such access is restricted by role and by assigned region, is written to the Customer's own audit trail before it begins, and uses a one-time sign-in link — passwords are never read, reset or stored.

[Lawyer: confirm whether support access must be itemised as a documented instruction under section 1, or whether describing it here satisfies the processor obligation.]

[Lawyer: this is a summary Addendum published on the site. Enterprise customers will require a signed DPA with their own terms — please confirm whether this published version is sufficient for smaller customers, and prepare a signable version for larger ones. Also confirm the cross-border position under the DPDP Act once subprocessor regions are established.]

Contact: admin@dlqtechnos.com