Data Processing Agreement
Last updated: 29 June 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Elqar (Procity Innovations)("Processor", "we", "us") and the customer organisation using the Elqar platform ("Controller", "you"). It governs the processing of personal data by Elqar on behalf of the Controller in accordance with UK GDPR and the Data Protection Act 2018.
By using Elqar, the Controller agrees to the terms of this DPA. This DPA supplements and is incorporated into the Terms of Service.
1. Definitions
- Personal Data — any information relating to an identified or identifiable natural person processed through the Elqar platform
- Controller — the customer organisation that determines the purposes and means of processing personal data
- Processor — Elqar (Procity Innovations), which processes personal data on behalf of the Controller
- Sub-processor — a third party engaged by the Processor to assist in processing personal data
- Data Subject — an individual whose personal data is processed
2. Subject matter and nature of processing
| Subject matter | Operation of the Elqar inventory management platform |
| Duration | For the term of the customer's subscription, plus 30 days post-termination |
| Nature | Collection, storage, retrieval, use, and deletion of personal data |
| Purpose | Providing the Elqar service as described in the Terms of Service |
| Types of data | Names, email addresses, job titles, activity logs, IP addresses |
| Categories of data subjects | Customer's employees and team members using the platform |
3. Processor obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller (including as set out in this DPA and the Terms of Service)
- Ensure that persons authorised to process the data are under appropriate confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the Controller in responding to Data Subject rights requests
- Notify the Controller without undue delay upon becoming aware of a personal data breach
- Delete or return all personal data at the end of the service relationship, as directed by the Controller
- Make available all information necessary to demonstrate compliance with this DPA
4. Controller obligations
The Controller warrants and represents that:
- It has a valid legal basis for processing personal data and for instructing the Processor
- It has provided all required notices to Data Subjects regarding processing by Elqar
- It will only submit personal data to Elqar that is necessary for the use of the platform
- It will comply with applicable data protection law in relation to its use of the service
5. Sub-processors
The Controller provides general authorisation for the Processor to engage sub-processors. The Processor currently uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting | EU (Ireland) |
| Vercel | Application hosting | Global (US primary) |
| Stripe | Payment processing | US |
| Resend | Transactional email | US |
| Sentry | Error monitoring | US |
The Processor will notify the Controller of any intended changes to sub-processors by updating this DPA. The Controller may object to such changes within 14 days of notification.
6. Security measures
The Processor implements the following technical and organisational measures:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Passwords stored as bcrypt hashes — never in plaintext
- Row-level security and strict per-organisation data isolation at database level
- JWT-based authentication with short-lived tokens
- Regular security reviews and penetration testing
- Rate limiting on all write API endpoints
- Audit logging of all data access and modifications
7. International data transfers
Where personal data is transferred outside the UK or EEA (for example, to US-based sub-processors), such transfers are protected by Standard Contractual Clauses approved by the UK ICO, or another valid transfer mechanism under UK GDPR.
8. Data Subject rights
The Processor will assist the Controller in fulfilling Data Subject rights requests (access, rectification, erasure, portability, objection, restriction) within a reasonable timeframe. Controllers may also use the self-serve export and deletion tools in Settings → Data.
9. Data breach notification
In the event of a personal data breach, the Processor will notify the Controller without undue delay and no later than 72 hours after becoming aware of it. Notification will include the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed.
10. Audit rights
The Controller may request, no more than once per year and with 30 days' written notice, information necessary to demonstrate compliance with this DPA. The Processor will provide relevant documentation and, where required, allow for audits conducted by the Controller or a mutually agreed third-party auditor.
11. Termination and deletion
Upon termination of the service, the Processor will delete all personal data within 30 days, unless retention is required by law. The Controller may export their data at any time before termination via Settings → Data.
12. Governing law
This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.
13. Contact
For any questions about this DPA, contact us at hello@elqar.com.