This Data Processing Agreement ("DPA") is entered into between Syntaxa LLC ("Processor," "Company," "we," or "us") and the customer identified in the associated runQC Account ("Controller," "Customer," or "you"). This DPA supplements the runQC Terms of Service ("ToS") and forms part of the agreement between the parties.
This DPA applies to the extent that Company processes Personal Data on behalf of Customer in the course of providing the runQC Service.
For purposes of this DPA, the following terms have the meanings set forth below. Terms not defined herein have the meanings given in the ToS or, where applicable, under Data Protection Laws.
"Data Protection Laws" means all applicable laws and regulations relating to the processing of Personal Data, including: (a) the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"); (b) the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"); (c) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); (d) the Swiss Federal Act on Data Protection ("FADP"); and (e) any other applicable privacy or data protection legislation.
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Company on behalf of Customer through the Service. For the purposes of this DPA, Personal Data may include email addresses, names, IP addresses, or any personal information contained in test interactions between the Service and Customer's Target Agent.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Company on behalf of Customer.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission (Commission Implementing Decision (EU) 2021/914).
"Sub-Processor" means any third party engaged by Company to process Personal Data on behalf of Customer.
Customer is the Controller of Personal Data processed through the Service. Company is the Processor, processing Personal Data on Customer's behalf and in accordance with Customer's documented instructions.
Company processes Personal Data solely to provide the Service as described in the ToS and this DPA. The details of processing are:
| Element | Description |
|---|---|
| Subject Matter | Provision of AI agent testing and quality control services |
| Duration | For the term of the ToS plus the data retention/deletion period |
| Nature and Purpose | Executing test runs against Customer's Target Agents; storing and presenting test results; managing Customer Accounts; processing payments |
| Categories of Data Subjects | Customer personnel (Authorized Users); individuals whose personal data may be contained in Target Agent responses |
| Categories of Personal Data | Account information (email, name); usage data (IP address, login records); test interaction data (to the extent it contains personal data); billing information |
Customer shall: (a) ensure it has a valid legal basis for providing Personal Data to Company; (b) inform Data Subjects about the processing as required by Data Protection Laws; (c) ensure that any personal data included in test interactions with Target Agents is processed in compliance with applicable law; (d) not submit to the Service any special categories of personal data (as defined under GDPR Article 9) or sensitive personal information unless expressly agreed in writing.
Company shall process Personal Data only on Customer's documented instructions, unless required to do so by applicable law (in which case Company shall, to the extent permitted by law, inform Customer of such legal requirement before processing).
Customer's instructions for processing are documented in: (a) the ToS and this DPA; (b) Customer's configuration of the Service (endpoint settings, suite definitions, user permissions); (c) any additional written instructions agreed upon by the parties; and (d) the Beta Participant's consent under Section 5 of the Beta Program Agreement, which constitutes a documented instruction for the duration of the Beta Program.
If Customer issues instructions that Company reasonably believes violate Data Protection Laws, Company shall promptly notify Customer. Company is not required to comply with instructions that would result in a violation of applicable law.
Company may process Personal Data to create anonymized, aggregated data that no longer identifies the Customer or any Data Subject; such anonymized data is no longer Personal Data and may be used to improve the Service.
Company shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
Encryption:
Access Control:
Tenant Isolation:
Network Security:
Monitoring:
Personnel:
Company shall regularly review and update its security measures to ensure continued appropriateness in light of the current state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.
Customer hereby provides general written authorization for Company to engage Sub-Processors. The current list of Sub-Processors is set forth in Annex B.
Company shall: (a) enter into a written agreement with each Sub-Processor that imposes data protection obligations no less protective than those in this DPA; (b) remain liable for the acts and omissions of its Sub-Processors.
Company shall notify Customer at least thirty (30) days before engaging a new Sub-Processor or making material changes to existing Sub-Processor arrangements. Notification will be provided via email to the Account contact.
If Customer has a reasonable, documented objection to a new Sub-Processor based on data protection concerns, Customer shall notify Company in writing within fifteen (15) days of receiving notice. The parties shall discuss the objection in good faith and Company shall use commercially reasonable efforts to address Customer's concerns, which may include: (a) offering an alternative Sub-Processor; (b) modifying data flows to avoid the objected-to Sub-Processor; or (c) providing additional safeguards. If the parties cannot resolve the objection within thirty (30) days, Customer may terminate the ToS and this DPA without penalty.
Company shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligations to respond to Data Subject requests under Data Protection Laws, including requests for access, rectification, erasure, restriction, portability, and objection.
If Company receives a request directly from a Data Subject, Company shall promptly redirect the Data Subject to Customer and notify Customer of the request, unless prohibited by law.
Assistance beyond what is reasonably required may be subject to additional fees at Company's then-current professional services rates.
Company shall notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Security Incident affecting Customer's Personal Data.
The Security Incident notification shall include, to the extent reasonably available:
(a) A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and records affected;
(b) The name and contact details of the point of contact;
(c) A description of the likely consequences of the Security Incident;
(d) A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.
Company shall cooperate with Customer and take reasonable measures to assist in the investigation, mitigation, and remediation of the Security Incident.
Notification of a Security Incident shall not be construed as an acknowledgment of fault or liability by Company.
Customer's Personal Data is processed in the United States. To the extent that the processing constitutes a transfer of Personal Data from the EEA, UK, or Switzerland to a jurisdiction that does not provide an adequate level of data protection, the parties agree that the Standard Contractual Clauses (Module Two: Controller to Processor) shall apply, incorporated by reference into this DPA.
The information required to complete the SCCs is set forth in the Annexes to this DPA.
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs shall apply. For transfers subject to the Swiss FADP, the SCCs shall apply with the modifications required by the Swiss Federal Data Protection and Information Commissioner.
If the SCCs are invalidated, replaced, or supplemented by a new transfer mechanism, the parties shall cooperate in good faith to implement the applicable replacement mechanism.
Customer may, upon thirty (30) days' prior written notice and no more than once per year, request an audit of Company's compliance with this DPA. Audits shall be: (a) conducted during normal business hours; (b) limited in scope to Company's processing of Customer's Personal Data; (c) subject to reasonable confidentiality obligations; and (d) conducted at Customer's expense.
At Company's option, Company may satisfy Customer's audit rights by providing: (a) a copy of a relevant third-party audit report (e.g., SOC 2 Type II) or certification; (b) responses to a reasonable written questionnaire; or (c) other compliance documentation.
Company shall cooperate with audits conducted by Customer's supervisory authority to the extent required by Data Protection Laws.
Company shall provide reasonable assistance to Customer in conducting data protection impact assessments and related consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the nature of the processing and the information available to Company.
Customer may export Personal Data through the Service's API and web interface at any time during the term, subject to the viewing limits described in Section 7.4 of the ToS. Customer may request from Company a copy of any other Personal Data.
Upon termination of the ToS, Company shall, at Customer's election (communicated in writing within thirty (30) days of termination): (a) return all Personal Data in a commonly used, machine-readable format; or (b) delete all Personal Data in accordance with Company's standard data deletion practices. If Customer does not provide instructions, Company shall delete Personal Data within ninety (90) days of termination.
Company may retain Personal Data to the extent required by applicable law, provided that Company shall: (a) limit such retention to the minimum required; (b) protect retained data in accordance with this DPA; and (c) delete retained data when the legal obligation ceases.
This DPA takes effect on the effective date of the ToS and remains in effect until the later of: (a) termination of the ToS; or (b) Company's cessation of all processing of Customer's Personal Data.
The liability of each party under this DPA is subject to the limitations and exclusions of liability set forth in the ToS, except where Data Protection Laws require otherwise.
In the event of a conflict between this DPA and the ToS, this DPA shall prevail with respect to the processing of Personal Data. In the event of a conflict between this DPA and the SCCs, the SCCs shall prevail.
| Element | Description |
|---|---|
| Controller | Customer, as identified in the runQC Account |
| Processor | Syntaxa LLC |
| Categories of Data Subjects | Customer's Authorized Users; individuals whose personal data may appear in Target Agent test interactions |
| Types of Personal Data | Email addresses, names, IP addresses, usage metadata, authentication tokens (hashed), billing contact information, and any personal data incidentally contained in Target Agent request/response payloads |
| Special Categories (Art. 9 GDPR) | None (Customer shall not submit special category data without prior written agreement) |
| Purpose of Processing | Providing AI agent testing and quality control services; Account management; billing; support |
| Duration | Term of the ToS plus retention/deletion period |
| Frequency | Continuous during the term |
| Retention | Journals, Test Results, and metadata retained for the Account lifetime, subject to Section 11 and the deletion provisions of the ToS; Journals and Test Results are not deleted on a Subscription Plan retention schedule. Subscription Plan viewing limits described in Section 7.4 of the ToS restrict access in the Service and do not affect retention |
| Sub-Processor | Purpose | Location | Data Processed |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure (compute, storage, networking, authentication, email, secrets management) | United States (us-east-1) | All Service data |
| MongoDB, Inc. (Atlas) | Managed database hosting | United States (AWS us-east-1) | All persistent Service data (journals, accounts, suites, billing) |
| OpenAI, Inc. | Large language model API services for test generation, response grading, and analysis | United States | Test interaction data (prompts and responses processed during test runs) |
| Anthropic PBC | Large language model API services for test generation, response grading, and analysis | United States | Test interaction data (prompts and responses processed during test runs) |
| Stripe, Inc. | Payment processing and billing | United States | Billing information (payment methods, subscription data, invoices) |
| Cloudflare, Inc. | DNS management, CDN, DDoS protection | Global (edge network) | Technical data (IP addresses, domain routing) |
| Google LLC | Authentication (Google Sign-In OAuth) | United States | Email address |
| GitHub, Inc. | Source-control integration (GitHub App: repository configuration, check runs, pull-request comments) | United States | Repository metadata; test summaries and result links posted to Customer-connected repositories |
Company will update this list and provide notice in accordance with Section 5.3.
See Section 4.1 of this DPA for the current technical and organizational measures implemented by Company.
This Data Processing Agreement was last updated on September 14, 2026.