Data Processing Agreement (DPA)
Last updated: June 11, 2026
This DPA forms part of your CosmoQuick HRM Terms when you act as Data Controller and we act as Data Processor under GDPR / UK GDPR / CCPA equivalents.
1. Scope. Personal data of your employees, candidates, contractors processed in CosmoQuick HRM.
2. Roles. You = Controller. CosmoQuick = Processor. Sub-processors below = Sub-processor.
3. Processing purposes. Strictly to deliver the HRM service per your instructions.
4. Sub-processors. Lovable Cloud (hosting/storage, US/EU/IN), Resend (email), Google (Gemini AI), OpenAI (GPT), Sentry (error tracking). We notify of new sub-processors 30 days in advance and you may object.
5. Security. AES-256 at rest, TLS 1.3 in transit, RBAC, MFA via SSO, immutable audit logs, annual SOC2 Type II.
6. International transfers. SCCs (2021/914) + UK addendum. Choose data residency in Settings.
7. Breach notification. We notify you within 72 hours of confirmed breach affecting your data.
8. Audits. SOC2 report on request under NDA. On-site audits with 30 days notice, once per year.
9. Deletion. On termination, deletion within 90 days unless legal hold.
10. Liability. Per the main Terms.
Request a signed DPA: legal@cosmoquick.com.
Questions? Email legal@cosmoquick.com or visit help.cosmoquick.com.