Polyq.ai Inc. offers a Data Processing Addendum that governs our handling of personal data you process through PolyQ Intake. The summary below is plain-English; the counter-signed agreement is the binding document.
Last updated · April 21, 2026Version · 2026.04 · GDPR Art. 28
Form
Standalone addendum, incorporated into the Master Services Agreement.
Roles
You are the Controller; Polyq.ai Inc. is the Processor.
Applicable law
EU GDPR · UK GDPR · California Consumer Privacy Act (as Service Provider)
Transfer mechanism
EU SCCs (2021/914) Module Two · UK IDTA · Data Privacy Framework (where certified)
Encryption in transit and at rest · access control · logging · incident response · backup and recovery
Breach notice
Without undue delay and in any event within 72 hours of confirmation
Turnaround
Counter-signed within one business day of receipt
What the DPA covers
Scope and subject-matter. Defines PolyQ Intake as the service, enumerates the categories of data subjects (your clients, interviewees, staff) and personal data (transcripts, audio, contact info, and any categories you voluntarily collect in your interview prompts).
Processing instructions. We process personal data only on your documented instructions, which include the product configuration you set (bot prompts, retention, approval gating) and any ad-hoc support requests you make in writing.
Confidentiality. Every person authorized to process your data is bound by confidentiality obligations, either by contract or statutory duty.
Security measures. An Annex describing the measures we operate today: encryption in transit and at rest, identity-verified operator access checked against company ownership, an audit log of administrative actions, alerting on application failures, and point-in-time database backups.
Sub-processors. General authorization with the current list published at polyq.ai/subprocessors, 30-day advance notice of material changes, and a right to object for enterprise customers.
Data-subject requests. We will assist you in responding to access, rectification, erasure, restriction, portability, and objection requests within the timelines your law requires.
International transfers. EU SCCs Module Two (Controller-to-Processor), with the UK Addendum where applicable. Supplementary technical measures include AES-256 at rest and TLS 1.2+ in transit.
Audit rights. We answer a written security questionnaire once per twelve months, and will tell you exactly which audit evidence exists at the time you ask. We hold no third-party security certification today; on-site audits are available to enterprise customers with reasonable notice.
Breach notification. Without undue delay and in any event within 72 hours of confirming a Personal Data Breach, we will notify your designated security contact with available details, impact assessment, and mitigation steps.
Deletion on termination. On written request, we return or delete Customer Data within 30 days of contract termination, with a certificate of destruction on request.
How to get a signed DPA
If your organization can execute our standard form unmodified, the fastest path is the self-serve flow below. For custom redlines or enterprise terms, send your questions or preferred markup to privacy@polyq.ai.
Need a counter-signed DPA?
Reply with your legal entity, jurisdiction, and the email of the signatory. We’ll send back a counter-signed PDF within one business day.