Last updated: 16 September 2026.
1. Parties, roles and scope
This Data Processing Agreement (DPA) forms part of the QA Vault Terms of Service. It applies whenever a customer submits personal data to a QA Vault workspace and QA Vault processes that data on the customer's behalf. It takes effect when the customer accepts the Terms; no separate signature is required. A customer who needs a countersigned copy can request one at team@qa-vault.com.
The customer is the organisation or individual that owns the workspace. It determines why and how personal data in workspace content is processed and acts as the controller. QA Vault, operated by Alina Lysenko, registered as an individual entrepreneur (sole proprietor) in Ukraine, processes that data on the customer's documented instructions and acts as the processor.
This DPA does not cover data for which QA Vault decides the purposes itself: account records, billing administration, service security and support communications. That processing is described in the Privacy Policy. Payment data handled by Paddle is processed by Paddle as a separate controller under its own terms.
2. Subject matter, duration, nature and purpose
QA Vault stores, organises, indexes, searches, displays and transmits workspace content so that the customer and its authorised users, including connected MCP clients, can manage test cases, suites, runs, results and defects. Processing lasts for the life of the workspace and ends when the workspace or the relevant content is deleted under section 9.
Processing is automated and includes the search processing described in the Privacy Policy: relevant text from workspace content and search queries is sent to a search and AI provider to compute the information that makes content searchable. This processing runs on every plan and continues after a trial or subscription ends.
3. Types of personal data and data subjects
The customer decides what its workspace contains. QA Vault is designed for test content, and the Terms ask the customer to use synthetic or redacted data where possible. Personal data that typically appears in workspace content includes names and email addresses of the customer's staff and testers as authors, assignees and reporters; names, identifiers or contact details of the customer's own users that appear in test data, defect reports, logs and screenshots; and any other personal data the customer chooses to include.
Data subjects are therefore the customer's employees and contractors, its users and customers, and any other individuals whose data the customer includes. The customer must not submit special categories of data, payment-card data or credentials unless it has confirmed with QA Vault that the processing is appropriate.
4. Customer instructions
QA Vault processes personal data only on the customer's documented instructions. The Terms, this DPA, the customer's use of the service and the actions of its authorised users and connected clients are those instructions. QA Vault informs the customer if, in its opinion, an instruction infringes applicable data-protection law, and may suspend the affected processing until the instruction is clarified.
QA Vault does not use personal data in workspace content for its own purposes, does not sell it and does not use it to train models. The search and AI provider named in section 7 does not use data submitted through the API to train its models unless the API customer opts in; QA Vault has not opted in.
5. Confidentiality
Access to personal data is limited to the operator and any person who needs it to provide, support or secure the service and who is bound by confidentiality obligations. Access to workspace content for support purposes happens only where necessary to handle a request from the customer or to investigate a security issue.
6. Security measures
Taking into account the nature of the processing, QA Vault applies the following measures. Data is encrypted in transit. Storage providers apply encryption at rest. Access to workspace content is enforced by workspace roles, project permissions and database-level access rules. Hosted MCP access requires a personal, workspace-scoped credential that the user or the workspace owner can revoke. Authentication is handled by the account-access provider named in section 7. Operator access to production systems is protected by provider authentication and is not shared.
QA Vault does not hold a third-party security certification and does not claim one. The customer remains responsible for the security of its own devices, connected clients, agents and the credentials it issues.
7. Subprocessors
The customer authorises QA Vault to engage the following subprocessors. Each processes personal data only to provide its part of the service and is bound by a written agreement with data-protection obligations.
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, server-side functions and storage of workspace content and search data | Account records and all workspace content | European Union (Ireland) |
| Cloudflare, Inc. | Website hosting, hosted MCP server execution, MCP session state and waitlist storage | MCP requests and responses, session state, connection metadata, waitlist email addresses | Global edge network; session state is placed near the location of the first request |
| OpenAI, L.L.C. | Computes the search information for workspace text and search queries | Test-case text, search summaries and search queries | Not restricted to a single region; abuse-monitoring records are retained by the provider for up to 30 days |
| Resend, Inc. | Delivery of invitations and operational email | Recipient email addresses, message content and delivery logs | United States; delivery logs are retained by the provider for 30 days |
QA Vault gives at least 30 days' notice before adding or replacing a subprocessor by updating this page and emailing workspace owners. If the customer objects on reasonable data-protection grounds and no solution is found, the customer may terminate the affected subscription before the change takes effect. Cancellation and refund rules are in the Refund & Cancellation Policy.
MCP clients and AI assistants connected by the customer or its users are chosen by the customer and are not QA Vault subprocessors.
8. Assistance with rights requests and incidents
If a data subject contacts QA Vault directly about data in a customer's workspace, QA Vault refers the request to the customer where it can identify the customer, and assists the customer with the information it holds. The customer can edit and delete workspace content itself through the web application and MCP. For deletion of historical records that the application does not expose, the customer contacts team@qa-vault.com.
QA Vault notifies the customer without undue delay after becoming aware of a personal-data breach affecting the customer's workspace, with the information available at the time and further information as it becomes known. Notice goes to the workspace owner's email address. QA Vault provides reasonable assistance with the customer's own obligations, including data-protection impact assessments, taking into account the information available to a processor.
9. Deletion and return
The customer can export test cases, suites, steps and tags from the web application at any time. At the end of the service, the customer requests deletion of the workspace at team@qa-vault.com. QA Vault verifies the requester's authority, then deletes the workspace content, including search data derived from it, and the historical records linked to it, except where applicable law requires retention. Deletion from backups follows the backup retention described in the Privacy Policy. Data the subprocessors retain under their own retention rules, such as email delivery logs, expires under those rules.
10. International transfers
QA Vault is operated from Ukraine and the subprocessors above operate in the locations listed. Where personal data of individuals in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the transfer relies on the subprocessor's standard contractual clauses or an equivalent recognised safeguard in QA Vault's agreement with that subprocessor. The customer can ask for details of the safeguards applicable to its data.
11. Information and audit
QA Vault makes available the information necessary to demonstrate compliance with this DPA, including this page and, on request, the relevant subprocessor terms and a description of the security measures. Where applicable law gives the customer an audit right, an audit is conducted on reasonable notice, no more than once a year unless required by a supervisory authority or following a breach, in a way that does not compromise other customers' data. A written response to a reasonable questionnaire satisfies this right where the law allows.
12. Changes and precedence
This DPA carries a revision date. Changes that reduce the customer's protection require notice before they apply. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. Mandatory data-protection obligations that apply to the customer's data remain in force regardless of the terms here.
Contact: team@qa-vault.com.