Default Data Processing Agreement
Version 1 · 6 July 2026 · Made under Article 28 GDPR
This is the data processing agreement that applies by default whenever Quantum Touch Limited (trading as Strange Materials) processes personal data on your behalf. If you need different processor terms, the onus is on you to propose them in writing before engaging us — unless and until a replacement is agreed in writing by both parties, this DPA governs.
1. When this DPA applies
It applies automatically — with no signature needed — whenever, in the course of the services, we process personal data on your behalf: personal data contained in documents, messages or datasets you (or your guests) provide to the scoping workspace, and personal data processed in systems we design, build, host or support for you under an engagement. By using the workspace or engaging our proposal process you accept this DPA as part of the default agreement described in our Terms of Service.
Two roles, clearly split. For the personal data you give us about yourself — your contact details, consent records, billing — we are the
controller, and our
Privacy Policy governs. For personal data belonging to your customers, staff or other third parties that you put through our services,
you are the controller and we are your processor, and this DPA governs. If you want a negotiated DPA instead, propose it in writing before or during the proposal process; we are not bound by terms in purchase orders, vendor portals or similar unless we expressly accept them in writing.
2. Processing details (Article 28(3))
3. Our commitments as your processor
- (a) Instructions only. We process the data only on your documented instructions — your use of the workspace, the accepted engagement documents, and written instructions you give us — including for international transfers, unless EU or Irish law requires otherwise (we'd tell you first, unless the law prevents it). We will tell you if we believe an instruction infringes data protection law.
- (b) Confidentiality. The people authorised to process the data are bound by confidentiality obligations.
- (c) Security (Article 32). We apply measures appropriate to the risk: encrypted transport (HTTPS), two-factor-protected and role-restricted access, private screened storage of uploads, EU-based hosting, prompt-injection defences on AI inputs, and routine backups.
- (d) Sub-processors. You give general written authorisation for the sub-processors we use to run the service — the current list is in the Privacy Policy (hosting, network security, email, AI, voice, payments). We flow down equivalent obligations, remain responsible for their performance, and post changes to the Privacy Policy; if you object to a change on reasonable data-protection grounds within 14 days, we'll work with you on alternatives, and either party may end the affected services if none is workable.
- (e) Data subject rights. Taking the nature of the processing into account, we assist you with appropriate technical and organisational measures in fulfilling your obligation to respond to data subject requests. If a request reaches us directly, we pass it to you rather than answer for you.
- (f) Breach notice. We notify you of a personal data breach affecting your data without undue delay after becoming aware of it — and in any event within 72 hours — with enough information to support your own notification duties.
- (g) Deletion or return. At the end of the services, at your choice we delete or return the personal data and delete existing copies within 30 days, except where EU or Irish law requires retention (for example, financial records kept for Revenue).
- (h) Information & audit. We make available the information necessary to demonstrate compliance with this DPA and allow audits: once in any 12-month period, on 30 days' written notice, during business hours, remote-first, at your cost, and without access to other clients' data.
- (i) DPIA help. We provide reasonable assistance with data protection impact assessments and prior consultations, insofar as they concern our processing.
4. International transfers
Some sub-processors are US companies; transfers outside the EEA are protected by appropriate safeguards — the EU–US Data Privacy Framework where the provider is certified, and/or the European Commission's Standard Contractual Clauses — as set out in the Privacy Policy.
5. Your obligations as controller
- You are responsible for the lawfulness of the personal data you provide: having a lawful basis, giving the required notices to your data subjects, and providing only what is needed for the services.
- You warrant you have the right to share what you upload — including anything your guests provide — and that your instructions to us comply with data protection law.
- Requests, complaints and regulator engagement belonging to your controller role are yours; we assist as section 3 describes.
6. Liability and precedence
Liability under this DPA is subject to the caps and exclusions in the Terms of Service and forms part of the same single aggregate cap — nothing in this section limits what cannot be limited by law. If a replacement DPA is agreed in writing by both parties, it replaces this one for the work it covers; otherwise this DPA prevails over any conflicting term elsewhere in the default agreement so far as processor obligations are concerned. This DPA is governed by the laws of Ireland.
The short version. If you don't bring your own DPA before engaging us, this one is already in force: we process on your instructions, secure the data, tell you fast if something goes wrong, delete or hand back at the end — and what you feed in, and the notices your own data subjects get, are on you.