Records of processing activities
InnoQualis LTD (England and Wales, company number 17066029) keeps this record under Article 30 of the UK GDPR and, where it applies, the EU GDPR. It is published so that customers’ data-protection officers can read it without asking, and it is reviewed with every sub-processor change and at least once a year. Last reviewed: 13 September 2026.
Contact for this record: dpo@innoqualis.com. There is no separately appointed Data Protection Officer or EU representative today; the founders answer the mailbox. Whether an Article 27 EU representative is required is under legal review (KAN-820).
Part A — InnoQualis as controller
Section titled “Part A — InnoQualis as controller”| # | Processing activity | Purpose | Categories of data subjects | Categories of personal data | Lawful basis | Recipients / sub-processors | Transfers outside UK/EU | Retention | Security measures |
|---|---|---|---|---|---|---|---|---|---|
| A1 | Platform accounts | Operate user accounts, apply permissions, send service messages (sign-in codes, notifications) | Customer workforce members and invited auditors | Name, work email, role, workspace membership, authentication events | Contract (Art. 6(1)(b)) | Hosting (OVHcloud), backups (Hetzner, Backblaze), email (Microsoft 365 via GoDaddy) | None for the data itself; email transits Microsoft EU | Life of the account; deleted with the workspace (30-day window + 30 days) | Passwordless single-use codes, http-only refresh cookie, RBAC, audit log |
| A2 | Billing and subscriptions | Charge for paid plans, issue invoices, keep accounting records | Customer billing contacts | Billing name and email, VAT number, subscription state, invoice history; card data is entered on Stripe’s pages only | Contract; legal obligation (accounting records) | Stripe Payments Europe Ltd. | Stripe may process in the US under its own SCCs | Accounting records 6 years after the financial year (UK Companies Act) | Stripe-hosted payment pages; webhook signature verification |
| A3 | AI usage metering | Enforce plan limits and bill accurately | Platform users | Request metadata: model, token counts, cost, workspace and user identifiers — never the prompt text | Contract; legitimate interests (plan enforcement) | Hosting and backups as A1 | None | Life of the workspace | Tenant-scoped rows; audit log |
| A4 | Support and contact | Answer messages sent through the in-app help form, the feedback widget or email | Anyone who contacts us | Name, email, message content and any attachments the sender includes | Legitimate interests (answering a request the person made) | Email (Microsoft 365 via GoDaddy); Jira (Atlassian) where a ticket is raised | Atlassian: EU-hosted site; provider DPA on file | 24 months after the last message | Access limited to the founders; attachments scanned on upload |
| A5 | Server access logs | Security and troubleshooting of the hub and the website | Visitors and users | IP address, browser type, page requested, time | Legitimate interests (security) | Hosting; Hetzner (Germany) for the encrypted off-host log archive; Cloudflare once traffic is proxied | None | On the hub host: application and access logs 30 days in the system journal; the remaining container logs are size-capped (5 × 50 MB each), time-based rotation for those tracked (KAN-874). Off-host archive: 90 days, then deleted automatically | Root-only access to the host; an hourly copy is encrypted on the host before it leaves, to a key that is not stored on the host (Spec 42.2 / KAN-803) |
| A6 | Website enquiries and marketing email | Reply to early-access and contact requests; send product news to people who asked for it | Prospects and customers who opted in | Work email, name, company, role; open/click events on campaign email | Consent; legitimate interests for replies | Listmonk (self-hosted, our own tools box), Twenty CRM (self-hosted), Microsoft 365 via GoDaddy | None | Until consent is withdrawn (unsubscribe link in every email) or 24 months of inactivity | Self-hosted tools behind the host firewall; no third-party analytics |
| A7 | Website analytics | Understand how innoqualis.com is used | Website visitors | Not active today. If enabled it will record page views and interaction events only after consent through the cookie notice; nothing is recorded on decline | Consent (cookie notice) | Payload CMS on our own host | None | 12 months | Consent-gated; no third-party analytics provider |
| A8 | Platform operators | Authenticate InnoQualis staff to the control panel | InnoQualis staff | Work email, TOTP secret (encrypted), IP address, every control-panel request (hash-chained audit log) | Legitimate interests (security of the service) | Hosting and backups | None | Life of the staff account; audit rows kept with the platform audit log | Platform-only account type, email-domain check, TOTP, optional IP allow-list |
Part B — InnoQualis as processor
Section titled “Part B — InnoQualis as processor”| # | Processing carried out on behalf of the controller | Controller | Categories of processing | Categories of data subjects and data | Sub-processors | Transfers outside UK/EU | Retention | Security measures |
|---|---|---|---|---|---|---|---|---|
| B1 | Hosting and operating each customer workspace of the eQMS | Each customer organisation (the workspace owner) | Storage, retrieval, display, transmission, backup and deletion of quality records; generation of immutable audit trails; email delivery of notifications | Workforce members, invited auditors, and individuals appearing in quality records as decided by the controller (complainants, supplier and customer contacts, trainees) — identification data, role, record content, audit-trail entries, signature events | OVHcloud (hosting), Hetzner and Backblaze (encrypted backups), Microsoft 365 via GoDaddy (email), Cloudflare (DNS; edge once proxied) | None | Subscription term + 30-day retention-and-return window, then deletion within 30 days; backups age out on their rolling cycle | Tenant scoping on every query (commit-time guard + tests), RBAC, hash-chained audit trails, soft-invalidated signatures, encrypted off-site backups |
| B2 | AI features on the controller’s content | Each customer organisation that uses AI features | Sending prompts and record passages for inference; embedding document text for search | As B1, for the content a user submits to an AI feature | OpenAI, L.L.C. (United States) | Yes — EU Standard Contractual Clauses and the UK Addendum in OpenAI’s DPA; OpenAI retains API data up to 30 days for abuse monitoring, no training | Embeddings for the life of the workspace; OpenAI ≤ 30 days | Per-workspace vector collection for licensed standards; per-workspace filter on the shared document collection; AI can be switched off for a workspace on request |
| B3 | Optional SharePoint integration | Customer organisations that connect it | Ingest of documents and metadata from the controller’s SharePoint | As B1 | Microsoft (Graph API) | None (EU tenant) | OAuth tokens until disconnected (encrypted at rest); ingested content as B1 | Encrypted tokens; tenant-scoped ingest |
General description of technical and organisational measures
Section titled “General description of technical and organisational measures”Summarised on the Trust Centre (security overview, security assurance, isolation model) and in the Data Processing Agreement §5. Procedures that support this record: the personal-data breach procedure, the tenant erasure runbook and the incident response guide.
Change log
Section titled “Change log”| Date | Change |
|---|---|
| 2026-09-13 | First published version (KAN-822). Sub-processors aligned with the Trust Centre and DPA of the same date. |
| 2026-09-13 | A5 server access logs: hourly encrypted off-host archive to the existing Hetzner Storage Box, kept 90 days (Spec 42.2 / KAN-803). No new sub-processor. |