Data Processing Agreement
Data Processing Agreement
Last Updated: July 27, 2026
This Data Processing Agreement ("DPA") applies when you use qretro.com (the "Service") to run sessions with other people, and the content of those sessions contains personal data of individuals other than yourself.
It forms part of the Terms of Service and takes effect automatically when you create a session and invite participants. You do not need to sign a separate copy. If your organisation requires a countersigned document, write to [email protected].
1. Roles
You are the Controller of the content created in sessions you host: the cards, comments, votes, survey answers and health check ratings submitted by your participants. You decide what the session is about, who takes part, and how long the content is kept.
We are the Processor of that content. We process it on your documented instructions, which are given by your use of the Service's features.
For your own account data — your email address, authentication and security logs — we act as Controller. That processing is described in the Privacy Policy and is outside the scope of this DPA.
2. Subject Matter, Duration, Nature and Purpose
Subject matter: hosting and displaying session content, and generating summaries, highlights and suggestions from it.
Duration: for as long as you use the Service, and until the content is deleted.
Nature and purpose: storage, real-time synchronisation between participants, structuring into groups and votes, and generation of text summarising the session.
3. Categories of Data and Data Subjects
Categories of personal data: display names, and any personal data your participants choose to include in the text they submit.
Categories of data subjects: participants of your sessions — typically members of your team.
Special categories of data must not be processed through the Service. Do not use it for health data, biometric data, or other data falling under Article 9 GDPR. If such data is submitted, you remain responsible for it.
4. Our Obligations
We will:
- Process the content only on your instructions, including for transfers, unless required otherwise by law — in which case we will inform you before processing, unless that law forbids it.
- Ensure that people authorised to access the content are bound by confidentiality.
- Apply the technical and organisational measures described in section 6.
- Respect the conditions in section 5 for engaging sub-processors.
- Assist you, as far as reasonably possible, in responding to requests from data subjects exercising their rights. Where a participant contacts us directly about your session content, we will forward the request to you rather than act on it ourselves.
- Assist you with your obligations regarding security, breach notification and impact assessments, taking into account the information available to us.
- Notify you without undue delay after becoming aware of a personal data breach affecting your content.
- At your choice, delete or return the content when the Service is no longer provided to you, unless we are required to keep it by law. Deleting a board or an account in the Service performs that deletion.
- Make available the information necessary to demonstrate compliance with this DPA, and allow for an audit no more than once per year, on reasonable notice, at your cost, and in a way that does not compromise other customers' data.
5. Sub-processors
You give general authorisation for us to engage sub-processors. The current list is published at Sub-processors.
We will publish any addition to that list before the new sub-processor starts processing, so that you have the opportunity to object. If you object on reasonable data protection grounds, you may stop using the Service and delete your content.
We remain responsible for the performance of our sub-processors' obligations.
6. Security Measures
We apply measures appropriate to the risk, including:
- Encryption of data in transit (TLS).
- Passwords stored only as hashes; sign-in links that expire.
- Access to production data limited to those who need it.
- Personally identifiable information disabled in our error-monitoring tooling, and text masked in any session recordings captured for diagnostics.
- Guest participation under an automatically generated display name, with no email or password collected.
- Separation of environments, with development and testing performed on non-production data.
We may update these measures over time, provided the level of protection is not reduced.
7. International Transfers
Our sub-processors operate in different countries, so content may be processed outside the country you are in. Where a sub-processor is located in a country without an adequacy decision, we rely on the terms in place with that provider. Details for a specific provider are available on request at [email protected].
8. Your Obligations
You confirm that:
- You have a lawful basis for processing the personal data your participants submit, and for inviting them to the session.
- Your instructions to us comply with applicable data protection law.
- You have informed your participants about the processing as required by law.
- You will handle requests from your participants regarding session content.
9. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service.
10. Changes
We may update this DPA. Material changes will be published on this page, and the date above will be updated. If a change materially reduces your rights, you may stop using the Service and delete your content.
11. Contact
- Email:
[email protected]