Data Processing Agreement

Last updated: 29 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Elqar (Procity Innovations)("Processor", "we", "us") and the customer organisation using the Elqar platform ("Controller", "you"). It governs the processing of personal data by Elqar on behalf of the Controller in accordance with UK GDPR and the Data Protection Act 2018.

By using Elqar, the Controller agrees to the terms of this DPA. This DPA supplements and is incorporated into the Terms of Service.

1. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person processed through the Elqar platform
  • Controller — the customer organisation that determines the purposes and means of processing personal data
  • ProcessorElqar (Procity Innovations), which processes personal data on behalf of the Controller
  • Sub-processor — a third party engaged by the Processor to assist in processing personal data
  • Data Subject — an individual whose personal data is processed

2. Subject matter and nature of processing

Subject matterOperation of the Elqar inventory management platform
DurationFor the term of the customer's subscription, plus 30 days post-termination
NatureCollection, storage, retrieval, use, and deletion of personal data
PurposeProviding the Elqar service as described in the Terms of Service
Types of dataNames, email addresses, job titles, activity logs, IP addresses
Categories of data subjectsCustomer's employees and team members using the platform

3. Processor obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller (including as set out in this DPA and the Terms of Service)
  • Ensure that persons authorised to process the data are under appropriate confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Assist the Controller in responding to Data Subject rights requests
  • Notify the Controller without undue delay upon becoming aware of a personal data breach
  • Delete or return all personal data at the end of the service relationship, as directed by the Controller
  • Make available all information necessary to demonstrate compliance with this DPA

4. Controller obligations

The Controller warrants and represents that:

  • It has a valid legal basis for processing personal data and for instructing the Processor
  • It has provided all required notices to Data Subjects regarding processing by Elqar
  • It will only submit personal data to Elqar that is necessary for the use of the platform
  • It will comply with applicable data protection law in relation to its use of the service

5. Sub-processors

The Controller provides general authorisation for the Processor to engage sub-processors. The Processor currently uses the following sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase hostingEU (Ireland)
VercelApplication hostingGlobal (US primary)
StripePayment processingUS
ResendTransactional emailUS
SentryError monitoringUS

The Processor will notify the Controller of any intended changes to sub-processors by updating this DPA. The Controller may object to such changes within 14 days of notification.

6. Security measures

The Processor implements the following technical and organisational measures:

  • Encrypted connections (HTTPS/TLS) for all data in transit
  • Passwords stored as bcrypt hashes — never in plaintext
  • Row-level security and strict per-organisation data isolation at database level
  • JWT-based authentication with short-lived tokens
  • Regular security reviews and penetration testing
  • Rate limiting on all write API endpoints
  • Audit logging of all data access and modifications

7. International data transfers

Where personal data is transferred outside the UK or EEA (for example, to US-based sub-processors), such transfers are protected by Standard Contractual Clauses approved by the UK ICO, or another valid transfer mechanism under UK GDPR.

8. Data Subject rights

The Processor will assist the Controller in fulfilling Data Subject rights requests (access, rectification, erasure, portability, objection, restriction) within a reasonable timeframe. Controllers may also use the self-serve export and deletion tools in Settings → Data.

9. Data breach notification

In the event of a personal data breach, the Processor will notify the Controller without undue delay and no later than 72 hours after becoming aware of it. Notification will include the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed.

10. Audit rights

The Controller may request, no more than once per year and with 30 days' written notice, information necessary to demonstrate compliance with this DPA. The Processor will provide relevant documentation and, where required, allow for audits conducted by the Controller or a mutually agreed third-party auditor.

11. Termination and deletion

Upon termination of the service, the Processor will delete all personal data within 30 days, unless retention is required by law. The Controller may export their data at any time before termination via Settings → Data.

12. Governing law

This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.

13. Contact

For any questions about this DPA, contact us at hello@elqar.com.