Data Processing Addendum (DPA)
Processor terms for QNSI Cloud - GDPR Article 28, UK GDPR, and Singapore PDPA. Includes the current sub-processor list and notification commitments.
Last updated: June 1, 2026
This page summarises the Data Processing Addendum (DPA) that applies when HEOSSI (PTE.) LTD processes personal data on your behalf as a data processor through QNSI Cloud. The DPA is incorporated into the Terms of Service and is available as a counter-signed agreement on request.
Parties and roles
Controller: you (or your organization), as the entity that determines the purposes and means of processing Customer Data.
Processor: HEOSSI (PTE.) LTD ("HEOSSI"), a company incorporated in Singapore with Unique Entity Number 202532790K. Our registered office is recorded against that UEN on the public ACRA register.
For personal data HEOSSI collects directly - for example, your account-holder data when you sign up - HEOSSI acts as a controller under the Privacy Policy.
Scope and subject matter
This DPA governs processing of Customer Data that you submit to QNSI Cloud - secrets, encrypted objects, search indexes, audit events, key material handles, and metadata generated by your applications.
The duration of processing is the duration of your subscription, plus any retention period required by law or your plan's audit-trail-retention configuration.
Purposes of processing
- Provide the QNSI Cloud services you have subscribed to.
- Operate, maintain, secure, and improve QNSI - including capacity management, performance monitoring, and security incident detection.
- Respond to your support requests.
- Comply with legal obligations and lawful requests from authorities.
Categories of data subjects and personal data
Customer Data may include personal data of your employees, contractors, customers, or end users, depending on how you use QNSI. HEOSSI does not direct the contents of Customer Data and does not inspect Customer Data except as required to provide the services or as authorised by you.
Processor obligations
HEOSSI will:
- Process Customer Data only on documented instructions from you (the controller) - your QNSI Cloud configuration constitutes documented instructions for the standard processing required to deliver the services.
- Ensure personnel authorised to process Customer Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures (see Security below).
- Engage sub-processors only under the conditions described under "Sub-processors".
- Assist you with data-subject requests, security incident notifications, data protection impact assessments, and consultations with supervisory authorities, taking into account the nature of processing and the information available to HEOSSI.
- At the end of the provision of services, delete or return all Customer Data, subject to any retention required by law.
- Make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you. Audits are subject to reasonable confidentiality and scheduling terms.
Security
HEOSSI implements technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include, at a minimum:
- Encryption in transit (TLS 1.3, with hybrid post-quantum key exchange on the edge-gateway).
- Encryption at rest with managed and customer-controlled keys (KMS, vault, SSE-X storage).
- Hardware-backed key management for enterprise and government tiers (CloudHSM, BYO HSM, air-gapped enclaves).
- SPIFFE-based service identity, mTLS for all inter-service traffic, JWT audience validation on every protected route, tenant isolation enforced at the proxy layer.
- Tamper-evident audit trails (PQC-signed Merkle-tree audit chain), immutable retention per plan configuration.
- Continuous monitoring, intrusion detection, and a published incident-response procedure (see the Security page).
Sub-processors
You authorise HEOSSI to engage the sub-processors listed below to process Customer Data on behalf of HEOSSI in connection with the provision of QNSI. HEOSSI will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA.
The continuously maintained disclosure is also available at /legal/sub-processors.
| Sub-processor | Purpose | Hosting region | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary cloud infrastructure for QNSI Cloud - compute (ECS, Lambda), storage (S3, RDS), networking (CloudFront, ELB), key management (KMS, Secrets Manager). | Singapore (ap-southeast-1) | EU SCCs + UK IDTA in place for EU/UK customer data routed through AWS edges. |
| Stripe | Subscription billing, payment processing, tax calculation, and invoicing for self-serve plans. | Global (controller-to-processor) | Stripe's published SCCs; cardholder data is tokenised and never touches QNSI infrastructure. |
| Namecheap (PrivateEmail) | Transactional email delivery for account verification, invoices, support correspondence, and incident notifications. | United States | EU SCCs in place for EU/UK recipient addresses. |
| Cloudflare | DNS authoritative resolution and DDoS protection for heossi.com and qnsi.heossi.com zones. | Global edge network | Cloudflare's data processing addendum + EU SCCs. |
| GitHub (Microsoft) | Source-code hosting and CI/CD orchestration for QNSI build pipelines. Customer Data is never stored in GitHub. | United States | Microsoft EU Data Boundary commitments + SCCs. |
| npm, Inc. (GitHub Packages) | Public SDK distribution. No Customer Data is processed; only published artifact metadata. | United States | Not applicable - public package registry. |
Notification of changes
HEOSSI will provide reasonable advance notice (typically 30 days) before engaging a new sub-processor that processes Customer Data, via update to this page and, for enterprise customers, via your designated administrative contact. You may object on reasonable, documented grounds; if the objection cannot be resolved, you may terminate the affected services as your sole remedy.
International transfers
QNSI Cloud is operated from Singapore by default. Where Customer Data is transferred to a jurisdiction without an adequacy decision (e.g. transfers from the EU/EEA to the United States via a sub-processor), HEOSSI relies on:
- EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), where applicable.
- UK International Data Transfer Addendum (IDTA), where applicable.
- Equivalent contractual safeguards under the Singapore PDPA and other applicable privacy laws.
Personal data breach notification
HEOSSI will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, providing the information you reasonably need to meet your own notification obligations under GDPR Article 33, PDPA, or equivalent laws.
Controller obligations
You warrant that your instructions and processing of Customer Data comply with applicable law; that you have provided required notices and established a lawful basis; and that you have authority to disclose Customer Data to HEOSSI. You are responsible for responding to data subjects and regulators as controller and for configuring QNSI consistently with your retention, localisation, minimisation, and security duties.
Unlawful instructions
HEOSSI will inform you if, in its reasonable opinion, an instruction infringes applicable data-protection law, unless prohibited from doing so. HEOSSI may suspend the affected processing while the parties resolve the issue and is not required to follow an unlawful instruction.
Audit procedure
HEOSSI may satisfy routine audit requests with current third-party reports, certifications, questionnaires, and other relevant evidence. If that evidence is insufficient, you may request one additional audit per year on at least 30 days' notice, during normal business hours, by an independent auditor bound by confidentiality. Audits must avoid access to other customers' data and unreasonable disruption. You bear audit costs unless an audit identifies a material breach by HEOSSI, or applicable law requires otherwise.
Schedule 1 - Processing details
- Subject matter: provision, security, support, and administration of QNSI Cloud.
- Duration: the subscription term plus deletion, backup, legal-hold, and statutory-retention periods.
- Nature and purpose: storage, encryption, retrieval, transmission, search, access control, audit logging, monitoring, support, and deletion as instructed through QNSI.
- Data subjects: customer personnel, contractors, end users, customers, suppliers, and any other persons whose data the controller submits.
- Personal data: identifiers, contact and account data, authentication and access metadata, device/network data, audit events, support content, and any personal data included in Customer Data.
- Sensitive data: only categories expressly authorised by the agreement and configured service; the controller must not submit prohibited or unsupported regulated data.
Schedule 2 - Technical and organisational measures
The measures described in the Security section above and the current Security, Incident Response, Business Continuity, Customer Security Responsibilities, and Sub-processor policies form Schedule 2. Measures are risk-based and may evolve, provided HEOSSI does not materially reduce overall protection during the subscription term.
Schedule 3 - Restricted transfers
Where legally required for a restricted transfer, the applicable 2021 EU Standard Contractual Clauses are incorporated by reference using the controller-to-processor or processor-to-processor module appropriate to the parties' roles, together with the UK Addendum where UK law applies. The parties will complete required annex information using this DPA, the Order Form, and the Sub-processor list. A supervisory-authority or local-law requirement prevails over a conflicting commercial term to the extent required.
Liability, precedence, and termination
The Terms' liability limits and dispute-resolution provisions apply to this DPA unless a signed agreement states otherwise or applicable data-protection law prohibits the result. If this DPA conflicts with the Terms on personal-data processing, this DPA controls. If a Standard Contractual Clause conflicts with this DPA, that Clause controls for the restricted transfer. This DPA terminates when HEOSSI has deleted or returned Customer Data as required, except for provisions that must survive.
Requesting a counter-signed DPA
If your procurement process requires a counter-signed Data Processing Addendum, contact qnsi-legal@heossi.com with your legal entity name, registered address, and jurisdiction. We will return a signed copy of the standard DPA within 5 business days for most cases. Customers on enterprise and government tiers may negotiate bespoke terms.
Contact
Privacy or DPA questions: qnsi-legal@heossi.com.