runQC
Home Features Pricing Docs About Contact Request access

Data Processing Agreement

Effective Date: June 5, 2026 · Last Updated: September 14, 2026 · Syntaxa LLC

This Data Processing Agreement ("DPA") is entered into between Syntaxa LLC ("Processor," "Company," "we," or "us") and the customer identified in the associated runQC Account ("Controller," "Customer," or "you"). This DPA supplements the runQC Terms of Service ("ToS") and forms part of the agreement between the parties.

This DPA applies to the extent that Company processes Personal Data on behalf of Customer in the course of providing the runQC Service.


1. Definitions

For purposes of this DPA, the following terms have the meanings set forth below. Terms not defined herein have the meanings given in the ToS or, where applicable, under Data Protection Laws.

"Data Protection Laws" means all applicable laws and regulations relating to the processing of Personal Data, including: (a) the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"); (b) the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"); (c) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); (d) the Swiss Federal Act on Data Protection ("FADP"); and (e) any other applicable privacy or data protection legislation.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Company on behalf of Customer through the Service. For the purposes of this DPA, Personal Data may include email addresses, names, IP addresses, or any personal information contained in test interactions between the Service and Customer's Target Agent.

"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.

"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Company on behalf of Customer.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission (Commission Implementing Decision (EU) 2021/914).

"Sub-Processor" means any third party engaged by Company to process Personal Data on behalf of Customer.


2. Scope and Roles

2.1 Roles

Customer is the Controller of Personal Data processed through the Service. Company is the Processor, processing Personal Data on Customer's behalf and in accordance with Customer's documented instructions.

2.2 Scope of Processing

Company processes Personal Data solely to provide the Service as described in the ToS and this DPA. The details of processing are:

ElementDescription
Subject MatterProvision of AI agent testing and quality control services
DurationFor the term of the ToS plus the data retention/deletion period
Nature and PurposeExecuting test runs against Customer's Target Agents; storing and presenting test results; managing Customer Accounts; processing payments
Categories of Data SubjectsCustomer personnel (Authorized Users); individuals whose personal data may be contained in Target Agent responses
Categories of Personal DataAccount information (email, name); usage data (IP address, login records); test interaction data (to the extent it contains personal data); billing information

2.3 Customer Obligations

Customer shall: (a) ensure it has a valid legal basis for providing Personal Data to Company; (b) inform Data Subjects about the processing as required by Data Protection Laws; (c) ensure that any personal data included in test interactions with Target Agents is processed in compliance with applicable law; (d) not submit to the Service any special categories of personal data (as defined under GDPR Article 9) or sensitive personal information unless expressly agreed in writing.


3. Processing Instructions

3.1 Documented Instructions

Company shall process Personal Data only on Customer's documented instructions, unless required to do so by applicable law (in which case Company shall, to the extent permitted by law, inform Customer of such legal requirement before processing).

3.2 Scope of Instructions

Customer's instructions for processing are documented in: (a) the ToS and this DPA; (b) Customer's configuration of the Service (endpoint settings, suite definitions, user permissions); (c) any additional written instructions agreed upon by the parties; and (d) the Beta Participant's consent under Section 5 of the Beta Program Agreement, which constitutes a documented instruction for the duration of the Beta Program.

3.3 Additional Instructions

If Customer issues instructions that Company reasonably believes violate Data Protection Laws, Company shall promptly notify Customer. Company is not required to comply with instructions that would result in a violation of applicable law.

3.4 Anonymized Data

Company may process Personal Data to create anonymized, aggregated data that no longer identifies the Customer or any Data Subject; such anonymized data is no longer Personal Data and may be used to improve the Service.


4. Security

4.1 Technical and Organizational Measures

Company shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

Encryption:

  • Data at rest: MongoDB Atlas storage-layer encryption at rest (Atlas platform default; Company has not configured customer-managed encryption keys), AWS KMS encryption (Secrets Manager)
  • Data in transit: TLS 1.2+ for all connections

Access Control:

  • Role-based access control for Company personnel
  • Optional time-based one-time-password (TOTP) multi-factor authentication for end-user accounts. Company does not currently enforce multi-factor authentication, and does not represent that multi-factor authentication gates administrative or infrastructure access.
  • API key authentication with SHA-256 hashing
  • JWT-based authentication via AWS Cognito

Tenant Isolation:

  • All database queries scoped by tenant_id
  • Isolated compute containers (ECS Fargate) per test run
  • Tenant-specific encryption key paths in AWS Secrets Manager

Network Security:

  • Private subnets for compute workloads
  • Security groups restricting network access
  • SSRF protection with DNS re-validation
  • Rate limiting on all endpoints

Monitoring:

  • CloudWatch logging and alerting
  • Automated stale-run detection and cleanup

Personnel:

  • Confidentiality obligations for all personnel with data access
  • Principle of least privilege for system access

4.2 Security Review

Company shall regularly review and update its security measures to ensure continued appropriateness in light of the current state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.


5. Sub-Processors

5.1 Authorized Sub-Processors

Customer hereby provides general written authorization for Company to engage Sub-Processors. The current list of Sub-Processors is set forth in Annex B.

5.2 Sub-Processor Obligations

Company shall: (a) enter into a written agreement with each Sub-Processor that imposes data protection obligations no less protective than those in this DPA; (b) remain liable for the acts and omissions of its Sub-Processors.

5.3 Changes to Sub-Processors

Company shall notify Customer at least thirty (30) days before engaging a new Sub-Processor or making material changes to existing Sub-Processor arrangements. Notification will be provided via email to the Account contact.

5.4 Objection Right

If Customer has a reasonable, documented objection to a new Sub-Processor based on data protection concerns, Customer shall notify Company in writing within fifteen (15) days of receiving notice. The parties shall discuss the objection in good faith and Company shall use commercially reasonable efforts to address Customer's concerns, which may include: (a) offering an alternative Sub-Processor; (b) modifying data flows to avoid the objected-to Sub-Processor; or (c) providing additional safeguards. If the parties cannot resolve the objection within thirty (30) days, Customer may terminate the ToS and this DPA without penalty.


6. Data Subject Rights

6.1 Assistance

Company shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligations to respond to Data Subject requests under Data Protection Laws, including requests for access, rectification, erasure, restriction, portability, and objection.

6.2 Notification

If Company receives a request directly from a Data Subject, Company shall promptly redirect the Data Subject to Customer and notify Customer of the request, unless prohibited by law.

6.3 Costs

Assistance beyond what is reasonably required may be subject to additional fees at Company's then-current professional services rates.


7. Security Incidents

7.1 Notification

Company shall notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Security Incident affecting Customer's Personal Data.

7.2 Notification Content

The Security Incident notification shall include, to the extent reasonably available:

(a) A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and records affected;

(b) The name and contact details of the point of contact;

(c) A description of the likely consequences of the Security Incident;

(d) A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.

7.3 Cooperation

Company shall cooperate with Customer and take reasonable measures to assist in the investigation, mitigation, and remediation of the Security Incident.

7.4 No Admission

Notification of a Security Incident shall not be construed as an acknowledgment of fault or liability by Company.


8. International Data Transfers

8.1 Transfer Mechanisms

Customer's Personal Data is processed in the United States. To the extent that the processing constitutes a transfer of Personal Data from the EEA, UK, or Switzerland to a jurisdiction that does not provide an adequate level of data protection, the parties agree that the Standard Contractual Clauses (Module Two: Controller to Processor) shall apply, incorporated by reference into this DPA.

8.2 SCC Annexes

The information required to complete the SCCs is set forth in the Annexes to this DPA.

8.3 UK and Swiss Addendum

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs shall apply. For transfers subject to the Swiss FADP, the SCCs shall apply with the modifications required by the Swiss Federal Data Protection and Information Commissioner.

8.4 Alternative Transfer Mechanisms

If the SCCs are invalidated, replaced, or supplemented by a new transfer mechanism, the parties shall cooperate in good faith to implement the applicable replacement mechanism.


9. Audits and Compliance

9.1 Audit Rights

Customer may, upon thirty (30) days' prior written notice and no more than once per year, request an audit of Company's compliance with this DPA. Audits shall be: (a) conducted during normal business hours; (b) limited in scope to Company's processing of Customer's Personal Data; (c) subject to reasonable confidentiality obligations; and (d) conducted at Customer's expense.

9.2 Alternative Compliance Evidence

At Company's option, Company may satisfy Customer's audit rights by providing: (a) a copy of a relevant third-party audit report (e.g., SOC 2 Type II) or certification; (b) responses to a reasonable written questionnaire; or (c) other compliance documentation.

9.3 Regulatory Audits

Company shall cooperate with audits conducted by Customer's supervisory authority to the extent required by Data Protection Laws.


10. Data Impact Assessments

Company shall provide reasonable assistance to Customer in conducting data protection impact assessments and related consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the nature of the processing and the information available to Company.


11. Return and Deletion of Data

11.1 During the Term

Customer may export Personal Data through the Service's API and web interface at any time during the term, subject to the viewing limits described in Section 7.4 of the ToS. Customer may request from Company a copy of any other Personal Data.

11.2 Upon Termination

Upon termination of the ToS, Company shall, at Customer's election (communicated in writing within thirty (30) days of termination): (a) return all Personal Data in a commonly used, machine-readable format; or (b) delete all Personal Data in accordance with Company's standard data deletion practices. If Customer does not provide instructions, Company shall delete Personal Data within ninety (90) days of termination.

11.3 Retention Exceptions

Company may retain Personal Data to the extent required by applicable law, provided that Company shall: (a) limit such retention to the minimum required; (b) protect retained data in accordance with this DPA; and (c) delete retained data when the legal obligation ceases.


12. Term

This DPA takes effect on the effective date of the ToS and remains in effect until the later of: (a) termination of the ToS; or (b) Company's cessation of all processing of Customer's Personal Data.


13. Liability

The liability of each party under this DPA is subject to the limitations and exclusions of liability set forth in the ToS, except where Data Protection Laws require otherwise.


14. Conflict

In the event of a conflict between this DPA and the ToS, this DPA shall prevail with respect to the processing of Personal Data. In the event of a conflict between this DPA and the SCCs, the SCCs shall prevail.


Annex A: Details of Processing

ElementDescription
ControllerCustomer, as identified in the runQC Account
ProcessorSyntaxa LLC
Categories of Data SubjectsCustomer's Authorized Users; individuals whose personal data may appear in Target Agent test interactions
Types of Personal DataEmail addresses, names, IP addresses, usage metadata, authentication tokens (hashed), billing contact information, and any personal data incidentally contained in Target Agent request/response payloads
Special Categories (Art. 9 GDPR)None (Customer shall not submit special category data without prior written agreement)
Purpose of ProcessingProviding AI agent testing and quality control services; Account management; billing; support
DurationTerm of the ToS plus retention/deletion period
FrequencyContinuous during the term
RetentionJournals, Test Results, and metadata retained for the Account lifetime, subject to Section 11 and the deletion provisions of the ToS; Journals and Test Results are not deleted on a Subscription Plan retention schedule. Subscription Plan viewing limits described in Section 7.4 of the ToS restrict access in the Service and do not affect retention

Annex B: Authorized Sub-Processors

Sub-ProcessorPurposeLocationData Processed
Amazon Web Services (AWS)Cloud infrastructure (compute, storage, networking, authentication, email, secrets management)United States (us-east-1)All Service data
MongoDB, Inc. (Atlas)Managed database hostingUnited States (AWS us-east-1)All persistent Service data (journals, accounts, suites, billing)
OpenAI, Inc.Large language model API services for test generation, response grading, and analysisUnited StatesTest interaction data (prompts and responses processed during test runs)
Anthropic PBCLarge language model API services for test generation, response grading, and analysisUnited StatesTest interaction data (prompts and responses processed during test runs)
Stripe, Inc.Payment processing and billingUnited StatesBilling information (payment methods, subscription data, invoices)
Cloudflare, Inc.DNS management, CDN, DDoS protectionGlobal (edge network)Technical data (IP addresses, domain routing)
Google LLCAuthentication (Google Sign-In OAuth)United StatesEmail address
GitHub, Inc.Source-control integration (GitHub App: repository configuration, check runs, pull-request comments)United StatesRepository metadata; test summaries and result links posted to Customer-connected repositories

Company will update this list and provide notice in accordance with Section 5.3.


Annex C: Technical and Organizational Measures

See Section 4.1 of this DPA for the current technical and organizational measures implemented by Company.


This Data Processing Agreement was last updated on September 14, 2026.

Other Legal Documents

  • Terms of Service
  • Privacy Policy
  • Acceptable Use Policy
  • Cookie Policy
  • DMCA Policy
  • Security Disclosure
  • Service Level Agreement
  • Beta Agreement
runQC

Comprehensive AI agent testing and verification platform for reliable deployments.

Product

  • Features
  • Pricing
  • Documentation
  • API Reference

Company

  • About
  • Contact
  • Blog
  • Careers

Legal

  • Privacy Policy
  • Terms of Service
  • Security
  • Status

© 2026 Syntaxa LLC. All rights reserved.

runQC - AI Agent Quality Control