DPA
Data Processing Agreement
How CloudQuell processes personal data on your behalf. Incorporated into the Terms of Service — it applies automatically when you accept them.
Effective: 2026-07-03
Summary
This summary highlights the key points; the full agreement below governs. This DPA forms part of the CloudQuell Terms of Service (or a signed Master Service Agreement, where one exists — the "Agreement") between ADLAB Solutions, LLC, the Utah limited liability company operating CloudQuell ("CloudQuell" or "Processor"), and the customer entity that has accepted the Agreement ("Customer" or "Controller").
- This DPA applies automatically: it is incorporated into the Terms and takes effect when you accept them (for example, by creating an account or organization). No signature is required. Countersigned copies are available from privacy@cloudquell.com.
- You are the controller of your data; CloudQuell is the processor.
- Standard Contractual Clauses (Module Two) and the UK Addendum are incorporated for EEA, UK, and Swiss data transferred to our US infrastructure.
- We notify you of a personal data breach without undue delay, and in any event within 72 hours of becoming aware.
- Sub-processor changes are published at /subprocessors with a 30-day objection window.
- In case of conflict between this DPA and the Agreement, this DPA controls with respect to its subject matter.
1. Definitions
- "Data Protection Laws" means all laws applicable to the Processing of Personal Data under the Agreement, including as applicable: Regulation (EU) 2016/679 ("GDPR"), the GDPR as incorporated into UK law ("UK GDPR"), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other US state privacy laws.
- "Personal Data" means any information relating to an identified or identifiable natural person that CloudQuell Processes on behalf of Customer in connection with the Service.
- "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority", and "Personal Data Breach" have the meanings given in the GDPR. "Sub-processor" means any third party engaged by CloudQuell to Process Personal Data on Customer's behalf.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in decision 2021/914/EU (Module Two: Controller to Processor), as supplemented for UK transfers by the UK International Data Transfer Addendum issued by the ICO.
2. Roles and scope of processing
- As between the parties, Customer is the Controller and CloudQuell is the Processor of the Personal Data described in Annex A. Customer's instructions to CloudQuell are: (a) Processing as necessary to provide the Service as described in the Agreement and the product documentation; and (b) any further written instructions agreed by the parties.
- CloudQuell shall Process Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which CloudQuell is subject; in such a case, CloudQuell shall inform Customer of that legal requirement before Processing, unless the law prohibits doing so. CloudQuell shall promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
- Customer is responsible for the accuracy and lawfulness of the Personal Data it provides, for its own compliance as Controller (including any required notices and legal bases), and for the permissions it configures — including the read-only cross-account IAM role and the cost-attribution tags it chooses to apply in its cloud accounts (see Annex A).
3. Confidentiality
CloudQuell shall ensure that persons authorized to Process Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and Process Personal Data only as needed to provide the Service.
4. Security
CloudQuell shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex B. CloudQuell may update Annex B from time to time, provided the updates do not materially reduce the overall protection of Personal Data. Taking into account the nature of the Processing and the information available to it, CloudQuell shall assist Customer in ensuring compliance with Customer's obligations regarding security of Processing, breach notification, data protection impact assessments, and prior consultation under Articles 32–36 GDPR.
5. Personal Data Breach
CloudQuell shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification shall include, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. CloudQuell shall provide reasonable cooperation with Customer's investigation and any legally required notifications. Notifications are sent to the email address of Customer's account owner unless Customer designates a different contact in writing.
6. Data Subject requests
Taking into account the nature of the Processing, CloudQuell shall assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If a Data Subject request is made directly to CloudQuell, CloudQuell shall promptly forward it to Customer and shall not respond substantively except to direct the Data Subject to Customer, unless legally required.
7. Sub-processors
- Customer provides general written authorization for CloudQuell to engage Sub-processors to provide the Service. The current list is published at www.cloudquell.com/subprocessors.
- CloudQuell shall: (a) impose data protection obligations on each Sub-processor that are materially no less protective than those in this DPA; (b) remain liable for each Sub-processor's performance; and (c) update the published list before adding or replacing a Sub-processor. Customers may subscribe to change notifications as described on the Sub-processors page.
- Customer may object on reasonable data-protection grounds to a new Sub-processor within 30 days of the list update by emailing privacy@cloudquell.com. The parties will discuss in good faith; if no resolution is reached (including pinning Customer's organization to a subset of AI model providers, where applicable), Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period.
8. International transfers
CloudQuell Processes and stores Customer Data in AWS data centers in the United States. To the extent Customer transfers Personal Data subject to the GDPR, UK GDPR, or Swiss law to CloudQuell in the United States, the SCCs (Module Two) are incorporated into this DPA by reference, with: Customer as data exporter; CloudQuell as data importer; Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 30-day notice); Clause 17 governed by the law of Ireland; Clause 18 courts of Ireland; and Annexes I and II of the SCCs populated by Annex A and Annex B of this DPA. For UK transfers, the UK Addendum applies with the same information. Acceptance of the Agreement constitutes execution of the SCCs by both parties.
9. CCPA and US state privacy laws
To the extent CloudQuell Processes Personal Data subject to the CCPA or similar US state laws, CloudQuell acts as Customer's "service provider" / "processor". CloudQuell shall not: sell or share the Personal Data; retain, use, or disclose it for any purpose other than performing the Service (or as permitted by law); or combine it with personal information from other sources except as permitted for service providers. CloudQuell certifies that it understands and will comply with these restrictions.
10. Deletion and return
Upon termination or expiration of the Agreement, CloudQuell shall, at Customer's choice, return or delete Customer's Personal Data. Consistent with the Terms: Customer may request an export within 30 days after termination; after that window Personal Data is deleted in accordance with the retention schedule in the Privacy Policy (Customer Data after the 30-day window; account data within 90 days of termination; backups within 30 days of deletion from active systems), unless retention is required by law. Aggregated or anonymized data that no longer identifies Customer or any Data Subject is not Personal Data and may be retained.
11. Audits and information
CloudQuell shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including (when available) its most recent SOC 2 report and security documentation under NDA. Where Data Protection Laws grant Customer an audit right that cannot be satisfied by those materials, CloudQuell shall allow an audit by Customer or its independent auditor, no more than once per 12 months, on at least 30 days' written notice, during business hours, at Customer's expense, subject to reasonable confidentiality and scope controls, and without access to other customers' data.
12. Liability and general
- Each party's liability arising out of or related to this DPA (including the SCCs, to the extent permitted) is subject to the exclusions and limitations of liability in the Agreement.
- This DPA terminates automatically with the Agreement. Obligations that by their nature survive (Sections 3, 10, and 12) survive termination.
- This DPA is governed by the law governing the Agreement (Utah), except where the SCCs require otherwise for transferred data.
Annex A — Description of processing
- Subject matter and duration: Processing of Personal Data as necessary to provide the CloudQuell cloud cost management service, for the term of the Agreement plus the post-termination deletion window (Section 10).
- Nature and purpose: hosting, ingestion, storage, analysis, and display of cloud and AI-provider cost and usage data; account administration and authentication; alerting and notifications; customer support; billing.
- Categories of Data Subjects: Customer's authorized users of the Service (owners, admins, members); incidentally, natural persons identifiable from resource metadata Customer sends (see the tag caveat below).
- Categories of Personal Data — account and profile data: name, work email address, role, organization membership, authentication identifiers.
- Categories of Personal Data — usage and device data: product telemetry, IP address, browser metadata, audit log entries.
- Categories of Personal Data — support and communications data: messages sent to support channels and the chat widget.
- Categories of Personal Data — billing contact data (when paid billing is enabled): billing name, email, address. Payment card data is processed by Stripe, not stored by CloudQuell.
- Categories of Personal Data — cloud billing metadata: AWS account IDs and names, resource identifiers (ARNs), usage types, costs, regions, and cost-attribution tags.
- Tag caveat: cloud billing line items are primarily non-personal machine and financial metadata. However, resource names and cost-attribution tags are free-form fields controlled by Customer and may incidentally contain Personal Data (for example, a tag like owner=jane.doe@example.com). Customer controls what its tags contain; CloudQuell Processes them as opaque attribution metadata.
- Special categories of data: none intended or required. Customer shall not submit special-category data to the Service.
- Frequency: continuous, for the duration of the Agreement.
Annex B — Technical and organizational measures
- Access model: Customer cloud data is accessed exclusively via a customer-provisioned, read-only cross-account IAM role scoped to Cost & Usage Reports and Cost Explorer, protected against confused-deputy attacks with an ExternalId. No agents in Customer environments; no write access. Customer can revoke the role at any time.
- Encryption: TLS 1.3 in transit; AES-256 at rest (AWS-managed keys).
- Tenant isolation: logical isolation per organization enforced at the application and query layer; org-scoped authorization on every API route.
- Access control: least-privilege IAM for production systems; MFA on production and administrative access; role-based access in the product (owner/admin/member) controlled by Customer.
- Audit logging: role assumptions logged in Customer's CloudTrail; application and infrastructure audit trails retained on the CloudQuell side.
- Infrastructure: AWS (United States regions), inheriting AWS physical and environmental controls; managed database services with automated backups (30-day maximum backup retention after deletion).
- Secure development: code review before production deployment; secrets held in AWS Secrets Manager, never in source control; dependency and vulnerability management.
- Incident response: monitoring and error tracking; documented breach notification path (Section 5); security contact security@cloudquell.com.
- Personnel: confidentiality obligations for all personnel with production access; access revoked promptly on role change.
- Sub-processor management: vetting against security and privacy standards before engagement; flow-down of data protection obligations; published list with change notification (Section 7).
- Certifications: SOC 2 Type I in progress (target Q4 2026); report available under NDA once issued.
Where you have signed a Master Service Agreement or a separately executed Data Processing Agreement with CloudQuell, that document governs in case of conflict with this page.