Legal
Data Processing Addendum
This Data Processing Addendum (DPA) applies only where QASA Solutions processes personal data on a business customer's behalf in connection with Sendvelo Self-Hosted support or related vendor-operated services.
- Effective:
- October 1, 2026
- Last updated:
- October 1, 2026
1. Parties, scope, and priority
This DPA forms part of the Terms of Service & Sale or another agreement between the customer ("Customer") and QASA Solutions ("QASA"). It applies when QASA acts as a processor or service provider for Customer Personal Data.
Sendvelo Self-Hosted runs in Customer-controlled infrastructure. QASA does not become a processor merely because Customer uses the Software. This DPA does not apply to data that remains solely in that environment or is sent directly to providers selected and contracted by Customer. QASA is an independent controller for account, transaction, fraud-prevention, licensing, and legal-compliance data processed for its own purposes under the Privacy Policy.
If this DPA conflicts with the main agreement on processing Customer Personal Data, this DPA controls. Mandatory data-protection law controls over both.
2. Definitions
"Customer Personal Data" means personal data QASA processes on Customer's behalf under the main agreement. "Data Protection Law" means privacy and data-protection law applicable to that processing, including where applicable Ghana's Data Protection Act, 2012 (Act 843), GDPR, UK GDPR, and US state privacy laws. "controller," "processor," "personal data," "processing," and "personal data breach" have the meanings given by applicable Data Protection Law. "Subprocessor" means a processor engaged by QASA to process Customer Personal Data.
3. Customer instructions and responsibilities
QASA will process Customer Personal Data only on Customer's documented instructions, including the main agreement, this DPA, support requests, and lawful configuration or use of a vendor-operated service. QASA may process data as required by law after notice to Customer unless law prohibits notice.
Customer is responsible for the lawfulness, accuracy, quality, and minimization of Customer Personal Data; providing required notices; obtaining any consent; responding to individuals; and ensuring its instructions comply with Data Protection Law. QASA will notify Customer if, in its reasonable opinion, an instruction violates Data Protection Law and may suspend the affected processing while the parties resolve the concern.
4. Confidentiality and security
QASA will ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed. QASA will maintain appropriate technical and organizational measures proportionate to the limited processing, nature of the data, state of the art, cost, and risk.
Measures include, as appropriate:
- access controls, least privilege, authentication, and secret management;
- transport encryption for production services and cryptographic protection of relevant credentials or tokens;
- logging, rate limiting, vulnerability and dependency management, and incident response;
- availability, backup, recovery, and provider-resilience procedures for QASA-operated systems; and
- data minimization, redaction guidance, and secure deletion processes.
Customer remains responsible for security of its self-hosted installation and for redacting logs and support materials before submission.
5. Subprocessors
Customer generally authorizes QASA to engage the Subprocessors identified on the Third-Party Services page for applicable services. QASA will impose data-protection obligations materially consistent with this DPA and remains responsible for a Subprocessor's performance to the extent required by law.
QASA will post intended material additions or replacements to that page at least 15 days before the new Subprocessor begins processing Customer Personal Data where reasonably practicable. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected service.
6. Individual rights and compliance assistance
Taking into account the nature of processing and information available, QASA will provide reasonable assistance for Customer to respond to verified requests from individuals and to meet applicable security, breach-notification, impact-assessment, and regulator consultation duties.
If QASA receives a request concerning Customer Personal Data, it will refer the requester to Customer where feasible and will not respond substantively except on Customer's instruction or as required by law. Customer is responsible for reasonable costs of unusually burdensome assistance not caused by QASA's breach.
7. Personal data breaches
QASA will notify Customer without undue delay after confirming a personal data breach affecting Customer Personal Data. Notification will include information reasonably available about the nature of the breach, affected data and individuals, likely consequences, measures taken or proposed, and a contact for follow-up.
QASA will take reasonable steps to contain, investigate, and mitigate the breach and cooperate with Customer. Notification is not an admission of fault or liability. Customer is responsible for notices to individuals, regulators, or others unless law assigns that duty to QASA.
8. Return and deletion
On termination of the relevant service or Customer's written request, QASA will delete or return Customer Personal Data within its control unless law requires retention. Copies in routine backups may remain until overwritten under normal cycles and will stay protected and isolated from further use. This section does not require deletion of QASA controller records described in the Privacy Policy.
9. Information and audits
QASA will make information reasonably necessary to demonstrate compliance available on request, subject to confidentiality and security restrictions. Customer should first use current documentation, questionnaires, and independent reports QASA makes available.
If that material is insufficient, Customer may conduct one audit per year through an independent, non-competitor auditor on at least 30 days' notice, during normal business hours, and without access to other customers' data or systems. Customer bears its audit costs unless an audit identifies QASA's material breach. More frequent audits are allowed where required by a regulator or following a substantiated breach.
10. International data transfers
Customer authorizes processing in Ghana and other locations used by approved Subprocessors. If Customer Personal Data subject to GDPR is transferred to a country without an applicable adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914, Module Two (controller to processor), with Customer as exporter and QASA as importer.
The docking clause applies; Clause 7 optional wording is included; Option 2 in Clause 9 applies with the notice period in this DPA; the optional language in Clause 11 does not apply; Ghana law governs Clause 17 to the extent permitted, otherwise the law of Ireland; and courts determined under Clause 18 have jurisdiction. Annexes I through III are completed by the processing details and security terms in this DPA.
For restricted transfers under UK GDPR, the then-current UK International Data Transfer Addendum to the EU SCCs is incorporated and completed using the same information. If a new lawful transfer mechanism replaces these terms, that mechanism applies to the extent necessary.
11. US state privacy terms
Where QASA processes personal information as a "service provider," "contractor," or "processor" under applicable US state law, QASA will not sell or share it for cross-context behavioral advertising, retain/use/disclose it outside the direct business relationship or specified purposes, or combine it with personal information from other sources except as law permits.
QASA will notify Customer if it can no longer meet these obligations. Customer may take reasonable steps to stop and remediate unauthorized use after notice and an opportunity for QASA to address the concern.
12. Processing details (Annex I)
Subject and duration: limited support, troubleshooting, account administration, secure delivery, or other services where QASA processes data on Customer's documented instructions, for the term of those services and required deletion period.
Nature and purpose: receiving, reviewing, storing, transmitting, redacting, securing, troubleshooting, and deleting information as needed to provide requested support or service.
Data subjects: Customer personnel, users, prospects, customers, recipients, or other individuals whose data Customer chooses to submit.
Data types: business contact details, account and technical identifiers, support correspondence, redacted logs, configuration details, and content or personal data Customer includes in a request. Special-category or highly sensitive data is not intended and must not be submitted unless separately agreed.
Controller contact: the Customer account contact. Processor contact: support@thesendvelo.com, 5th Mankralo Link, Mataheko, Accra, Ghana.
13. Liability and termination
Liability under this DPA is subject to the exclusions and aggregate cap in the main agreement, except where Data Protection Law prohibits that limitation. This DPA ends when QASA no longer processes Customer Personal Data, but confidentiality, deletion, transfer, and liability terms survive as necessary.
Questions about this document?
Contact support@thesendvelo.com. QASA Solutions is located at 5th Mankralo Link, Mataheko, Accra, Ghana.