Data Processing Agreement
May 9, 2026
This Data Processing Agreement (DPA) forms part of the service agreement between QAWave s.r.o. (Processor) and the customer (Controller).
1. Scope of Processing
QAWave processes customer data solely for the purpose of delivering the contracted QA agent services. Processing activities include: reading source code to generate tests, analyzing CI/CD logs for triage, and accessing test environments to validate agent outputs.
2. Sub-processors
QAWave uses a limited set of sub-processors, listed at qawave.ai/legal/subprocessors. Customers will be notified 30 days before any new sub-processor is added.
3. Security Measures
All data is encrypted in transit and at rest. Access is restricted on a need-to-know basis. QAWave maintains security incident response procedures and will notify the customer within 72 hours of any confirmed data breach.
4. Data Transfers
All processing occurs within the EU (Frankfurt, Germany). If any processing requires transfer outside the EU, QAWave will ensure appropriate safeguards (Standard Contractual Clauses) are in place.
5. Audit Rights
Customers may audit QAWave's compliance with this DPA upon reasonable notice. QAWave will provide all necessary documentation and access to demonstrate compliance.
6. Data Deletion
Upon termination of the service agreement, QAWave will delete all customer data within 90 days unless retention is required by law. Customers may request earlier deletion at any time.