Data Processing Agreement

Standard Data Processing Agreement · QSai LLC as processor · Last updated: July 4, 2026

Executed as an addendum to the Master Services Agreement. For EEA/UK vendors, this DPA incorporates the EU Standard Contractual Clauses (Module 2, controller → processor) and the UK Addendum by reference for transfers to the United States.

1. Roles and scope

The Vendor is the controller of end-customer personal data; QSai LLC (Custody) processes it solely to provide fulfillment services under the MSA: receiving, storage, order fulfillment, shipping, tracking, and returns.

2. Processing details (Art. 28(3) GDPR)

Subject matter Order fulfillment and returns logistics
Duration Term of the MSA + statutory retention
Data subjects Vendor's end customers and business contacts
Data categories Name, shipping address, email, phone (optional), order contents, device serials, return reasons, shipment tracking events
Special categories None (and none may be submitted)

3. Processor obligations

4. Sub-processors

General authorization with 30-day advance notice of changes. Current list: Cloudflare, Inc. (infrastructure, global); EasyPost + selected carriers (shipping, US/EU); Stripe (vendor billing — no end-customer data); Resend (transactional email).

5. International transfers

Transfers from the EEA/UK rely on the EU SCCs (Module 2) and the UK Addendum, incorporated by reference and executed with the MSA.

6. Audit

Once annually and on reasonable notice, the controller may audit compliance via written questionnaire or, where required, a supervised review. Our chain-of-custody records provide per-device evidentiary trails.

← cisomarketplace fulfillment · Privacy · Terms