Legal
Data processing agreement
Last updated 2026-09-25 · CS Cloud Ltd
This Data processing agreement (“DPA”) forms part of the Terms of service between the Customer and CS Cloud Ltd (“Provider”). It applies whenever the Provider processes personal data on the Customer’s behalf in the course of providing QueuePower. Customers who require a countersigned copy may request one at privacy@queuepower.com.
1. Roles and scope
For personal data contained in support tickets, customer records, and related communications that the Customer or its end-customers submit to the Service (“Customer Personal Data”), the Customer is the controller and the Provider is the processor. For data about the Customer’s own staff accounts and billing, the Provider is an independent controller as described in the Privacy policy. “Data protection law” means the UK GDPR, the Data Protection Act 2018, and, where applicable, the EU GDPR.
2. Details of processing
- Subject matter and purpose: receiving, triaging, drafting responses to, and resolving or escalating customer support requests, and producing operational reporting on that activity.
- Nature: storage, retrieval, automated classification and text generation by large language models, transmission by email and to systems the Customer connects, and deletion.
- Duration:the term of the Customer’s subscription plus the 30-day recovery period in section 8.
- Categories of data subject:the Customer’s end-customers and prospective customers, and the Customer’s staff insofar as they appear in tickets.
- Categories of personal data: name, email address, contents of support conversations, and any account context the Customer chooses to attach (for example plan tier or account age). The Service is not designed for special-category data; where an end-customer includes such data in a ticket body, it is processed under the same controls.
3. Provider obligations
The Provider shall:
- process Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA, and the configuration choices the Customer makes in the Service, unless required to do otherwise by law, in which case the Provider will inform the Customer unless prohibited;
- ensure that persons authorised to process Customer Personal Data are bound by confidentiality;
- implement the technical and organisational measures in section 5;
- assist the Customer, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and data protection impact assessments;
- delete or return Customer Personal Data at the end of the services as set out in section 8;
- make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits as set out in section 7;
- inform the Customer immediately if, in its opinion, an instruction infringes data protection law.
4. Customer obligations
The Customer warrants that it has a lawful basis for the processing, has given any notices required to data subjects, and that its instructions comply with data protection law. The Customer is responsible for its configuration of the Service, including which categories of request may be resolved by AI without human review, and for the content of communications sent from its workspace.
5. Security measures
The Provider maintains at least the following measures:
- Logical tenant isolation enforced by PostgreSQL row-level security on every tenant-scoped table, with the application database role unable to bypass the policies.
- Application-layer AES-256-GCM encryption of end-customer email addresses and of stored third-party credentials, in addition to provider disk encryption; lookups by email use a one-way hash.
- Replacement of names and email addresses with placeholders before any content is sent to the AI provider; original values are re-inserted only after the response returns.
- TLS for all data in transit; HTTP security headers including HSTS and frame denial on every response.
- Role-based access within each workspace; administrative actions and every AI action recorded in an immutable audit log exportable by the Customer.
- Signature verification and replay protection on every inbound webhook and public endpoint; per-tenant rate limiting.
- Secrets held only in deployment environment configuration; production refuses to start with insecure defaults.
- Periodic internal security reviews covering the OWASP Top 10, multi-tenant isolation, and dependency vulnerabilities.
A fuller description is published on the security page and may be updated from time to time, provided the overall level of protection is not reduced.
6. Subprocessors
The Customer gives general authorisation for the Provider to engage the subprocessors listed at /legal/subprocessors. The Provider will give at least 30 days’ notice by email to workspace administrators before adding or replacing a subprocessor. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected services and receive a pro-rata refund of prepaid fees.
The Provider imposes data protection obligations on each subprocessor that are no less protective than this DPA and remains liable for their performance. Services that process data only because the Customer chose to connect them (for example the Customer’s own Microsoft 365 or Google Workspace mailbox) act under the Customer’s own agreement with that provider.
7. Audits and breach notification
The Provider will make available, on request and no more than once a year unless required by a supervisory authority or following a breach, its security documentation and the results of any third-party assessment it holds. Where this does not reasonably satisfy the Customer’s obligations, the Customer may conduct an audit on 30 days’ notice, during business hours, at its own cost, and subject to confidentiality.
The Provider will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably required for the Customer to meet its own notification obligations.
8. Return and deletion
On termination or expiry of the services, Customer Personal Data is retained in a recoverable state for 30 days. During that period the Customer may request a structured export, which the Provider will supply in a commonly used machine-readable format. After that period the Provider deletes Customer Personal Data from live systems, unless retention is required by law, and confirms deletion on request. Copies in encrypted backups are overwritten on the backup provider’s rolling schedule and are not restored except for disaster recovery.
9. International transfers
The Customer authorises transfers of Customer Personal Data to the locations listed for each subprocessor. Where a transfer leaves the United Kingdom or the European Economic Area to a country without an adequacy decision, the parties rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the UK IDTA) and the EU Standard Contractual Clauses (module two, controller to processor), which are incorporated by reference, with the Customer as data exporter and the Provider as data importer.
10. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms. In the event of conflict between this DPA and the Terms, this DPA prevails in respect of the processing of Customer Personal Data. In the event of conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.