Data Processing Agreement

Effective July 24, 2026 · Allinners LLC

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Allinners LLC ("Processor", "we") and the organization using QS Calls ("Controller", "you") whenever the Controller determines the purposes and means of processing personal data of its own end users, contacts, or customers through the Service. It applies to the extent the Controller's processing of personal data is subject to the EU/UK General Data Protection Regulation ("GDPR") or a substantially similar data protection law.

1. Definitions

  • Controller, Processor, Data Subject, Personal Data, Processing — as defined in the GDPR.
  • Sub-processor — a third party engaged by the Processor to process personal data on the Controller's behalf.
  • Personal Data Breach — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data processed under this DPA.
  • Service — the QS Calls web dashboard and Android application described in the Terms of Service.

2. Subject matter and duration

The Processor processes personal data on behalf of the Controller for as long as the Controller's account with the Service is active, and for the retention period described in Section 4, unless instructed otherwise.

3. Processor obligations

The Processor will:

  • Process personal data only on the Controller's documented instructions, including as set out in the Terms of Service, unless required to do otherwise by law.
  • Ensure persons authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to protect personal data (see Section 8).
  • Assist the Controller, at the Controller's cost where the assistance is significant, in responding to Data Subject requests and in complying with security, breach-notification, and impact-assessment obligations under applicable law.
  • Not engage a Sub-processor without the general authorization described in Section 5.

4. Data deletion or return

On termination of the Controller's account, the Processor will delete or, on the Controller's written request made before termination, return the Controller's personal data within a reasonable period, except to the extent retention is required by law. See Account Deletion for how to request this.

5. Sub-processors

The Controller provides general authorization for the Processor to engage the Sub-processors listed in Annex 1. The Processor will impose data protection terms on each Sub-processor no less protective than those in this DPA, and remains liable for a Sub-processor's performance. The Processor will give reasonable notice before adding or replacing a Sub-processor where doing so materially changes how personal data is processed, and the Controller may object on reasonable data protection grounds.

6. International transfers

The Processor is based in the United Arab Emirates; the Service's infrastructure is hosted in the Netherlands (European Union) via the Processor's hosting Sub-processor. Where a Sub-processor is located outside the EU/EEA/UK (see Annex 1), the Processor relies on that Sub-processor's own compliance mechanisms (such as the EU Standard Contractual Clauses or an adequacy decision) to safeguard the transfer.

7. Audits

On reasonable written request, no more than once per year (or more frequently if required following a Personal Data Breach), the Processor will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for an audit, including inspection, conducted by the Controller or an independent auditor, subject to reasonable confidentiality and scheduling constraints.

8. Security measures

The Processor maintains technical and organizational measures including:

  • Encryption of data in transit (HTTPS/TLS) between clients, the application, and the database.
  • Password hashing (passwords are never stored in plain text).
  • Authenticated, token-based access to the API and dashboard, scoped per Organization.
  • Access to production infrastructure limited to personnel who need it.
  • Regular review of dependencies and infrastructure configuration.

9. Personal Data Breach notification

The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's personal data, and will provide information reasonably available to help the Controller meet its own notification obligations.

10. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations of liability in the Terms of Service. Sections 4, 6, and 9 survive termination of this DPA to the extent necessary for their purpose.

Annex 1 — Processing specification

Subject matter and nature of processing

Hosting, storage, and processing of account, call-metadata, contact, and (optionally) call-recording data submitted by the Controller's Users to operate the Service, including syncing call activity to a CRM the Controller connects.

Duration

For the term of the Controller's use of the Service, per Section 2 above.

Categories of Data Subjects

  • The Controller's Users (employees/representatives with a QS Calls account).
  • Contacts — individuals called by the Controller's Users.

Categories of personal data

  • User account data: name, email, phone number, role.
  • Call metadata: phone numbers, call direction, duration, outcome, timestamps.
  • Call recordings, where the Controller has enabled this optional feature.
  • Contact name, where available.

Sub-processors

Sub-processorPurposeLocation
Railway CorporationApplication hosting and database infrastructureNetherlands (EU)
HighLevel Inc. (GoHighLevel)CRM sync — only for Organizations that connect their own GHL accountUnited States
ResendTransactional email delivery (password resets, invitations)United States

This list may be updated from time to time as described in Section 5. The current version of this page reflects the Sub-processors in effect as of the date above.

Contact

Questions about this DPA can be sent to finance@allinners.com.