Skip to content

Records of processing activities

InnoQualis LTD (England and Wales, company number 17066029) keeps this record under Article 30 of the UK GDPR and, where it applies, the EU GDPR. It is published so that customers’ data-protection officers can read it without asking, and it is reviewed with every sub-processor change and at least once a year. Last reviewed: 13 September 2026.

Contact for this record: dpo@innoqualis.com. There is no separately appointed Data Protection Officer or EU representative today; the founders answer the mailbox. Whether an Article 27 EU representative is required is under legal review (KAN-820).

#Processing activityPurposeCategories of data subjectsCategories of personal dataLawful basisRecipients / sub-processorsTransfers outside UK/EURetentionSecurity measures
A1Platform accountsOperate user accounts, apply permissions, send service messages (sign-in codes, notifications)Customer workforce members and invited auditorsName, work email, role, workspace membership, authentication eventsContract (Art. 6(1)(b))Hosting (OVHcloud), backups (Hetzner, Backblaze), email (Microsoft 365 via GoDaddy)None for the data itself; email transits Microsoft EULife of the account; deleted with the workspace (30-day window + 30 days)Passwordless single-use codes, http-only refresh cookie, RBAC, audit log
A2Billing and subscriptionsCharge for paid plans, issue invoices, keep accounting recordsCustomer billing contactsBilling name and email, VAT number, subscription state, invoice history; card data is entered on Stripe’s pages onlyContract; legal obligation (accounting records)Stripe Payments Europe Ltd.Stripe may process in the US under its own SCCsAccounting records 6 years after the financial year (UK Companies Act)Stripe-hosted payment pages; webhook signature verification
A3AI usage meteringEnforce plan limits and bill accuratelyPlatform usersRequest metadata: model, token counts, cost, workspace and user identifiers — never the prompt textContract; legitimate interests (plan enforcement)Hosting and backups as A1NoneLife of the workspaceTenant-scoped rows; audit log
A4Support and contactAnswer messages sent through the in-app help form, the feedback widget or emailAnyone who contacts usName, email, message content and any attachments the sender includesLegitimate interests (answering a request the person made)Email (Microsoft 365 via GoDaddy); Jira (Atlassian) where a ticket is raisedAtlassian: EU-hosted site; provider DPA on file24 months after the last messageAccess limited to the founders; attachments scanned on upload
A5Server access logsSecurity and troubleshooting of the hub and the websiteVisitors and usersIP address, browser type, page requested, timeLegitimate interests (security)Hosting; Hetzner (Germany) for the encrypted off-host log archive; Cloudflare once traffic is proxiedNoneOn the hub host: application and access logs 30 days in the system journal; the remaining container logs are size-capped (5 × 50 MB each), time-based rotation for those tracked (KAN-874). Off-host archive: 90 days, then deleted automaticallyRoot-only access to the host; an hourly copy is encrypted on the host before it leaves, to a key that is not stored on the host (Spec 42.2 / KAN-803)
A6Website enquiries and marketing emailReply to early-access and contact requests; send product news to people who asked for itProspects and customers who opted inWork email, name, company, role; open/click events on campaign emailConsent; legitimate interests for repliesListmonk (self-hosted, our own tools box), Twenty CRM (self-hosted), Microsoft 365 via GoDaddyNoneUntil consent is withdrawn (unsubscribe link in every email) or 24 months of inactivitySelf-hosted tools behind the host firewall; no third-party analytics
A7Website analyticsUnderstand how innoqualis.com is usedWebsite visitorsNot active today. If enabled it will record page views and interaction events only after consent through the cookie notice; nothing is recorded on declineConsent (cookie notice)Payload CMS on our own hostNone12 monthsConsent-gated; no third-party analytics provider
A8Platform operatorsAuthenticate InnoQualis staff to the control panelInnoQualis staffWork email, TOTP secret (encrypted), IP address, every control-panel request (hash-chained audit log)Legitimate interests (security of the service)Hosting and backupsNoneLife of the staff account; audit rows kept with the platform audit logPlatform-only account type, email-domain check, TOTP, optional IP allow-list
#Processing carried out on behalf of the controllerControllerCategories of processingCategories of data subjects and dataSub-processorsTransfers outside UK/EURetentionSecurity measures
B1Hosting and operating each customer workspace of the eQMSEach customer organisation (the workspace owner)Storage, retrieval, display, transmission, backup and deletion of quality records; generation of immutable audit trails; email delivery of notificationsWorkforce members, invited auditors, and individuals appearing in quality records as decided by the controller (complainants, supplier and customer contacts, trainees) — identification data, role, record content, audit-trail entries, signature eventsOVHcloud (hosting), Hetzner and Backblaze (encrypted backups), Microsoft 365 via GoDaddy (email), Cloudflare (DNS; edge once proxied)NoneSubscription term + 30-day retention-and-return window, then deletion within 30 days; backups age out on their rolling cycleTenant scoping on every query (commit-time guard + tests), RBAC, hash-chained audit trails, soft-invalidated signatures, encrypted off-site backups
B2AI features on the controller’s contentEach customer organisation that uses AI featuresSending prompts and record passages for inference; embedding document text for searchAs B1, for the content a user submits to an AI featureOpenAI, L.L.C. (United States)Yes — EU Standard Contractual Clauses and the UK Addendum in OpenAI’s DPA; OpenAI retains API data up to 30 days for abuse monitoring, no trainingEmbeddings for the life of the workspace; OpenAI ≤ 30 daysPer-workspace vector collection for licensed standards; per-workspace filter on the shared document collection; AI can be switched off for a workspace on request
B3Optional SharePoint integrationCustomer organisations that connect itIngest of documents and metadata from the controller’s SharePointAs B1Microsoft (Graph API)None (EU tenant)OAuth tokens until disconnected (encrypted at rest); ingested content as B1Encrypted tokens; tenant-scoped ingest

General description of technical and organisational measures

Section titled “General description of technical and organisational measures”

Summarised on the Trust Centre (security overview, security assurance, isolation model) and in the Data Processing Agreement §5. Procedures that support this record: the personal-data breach procedure, the tenant erasure runbook and the incident response guide.

DateChange
2026-09-13First published version (KAN-822). Sub-processors aligned with the Trust Centre and DPA of the same date.
2026-09-13A5 server access logs: hourly encrypted off-host archive to the existing Hetzner Storage Box, kept 90 days (Spec 42.2 / KAN-803). No new sub-processor.