Data Processing Agreement
The processor terms that apply to every RainerQMS subscription — readable by humans, signable by counsel. Executed copies with the named subprocessor schedule are available on request.
§ 1Roles and scope
This Data Processing Agreement ("DPA") forms part of the agreement between Rainer Technologies ("Rainer", the processor) and the Customer (the controller) and governs Rainer's processing of personal data contained in Customer's RainerQMS workspace ("Service Data") under Article 28 GDPR and equivalent laws.
§ 2Nature and purpose of processing
Hosting, storage, transmission and display of quality-management records; execution of workflows and notifications; audit logging; backup and recovery; support on Customer's request. Duration: the subscription term plus the wind-down period in § 13.
§ 3Categories of data and data subjects
| Data subjects | Typical categories of personal data |
|---|---|
| Customer's personnel and contractors | Name, work contact details, role, training and competency records, e-signature events, audit-trail entries |
| Customer's clients' contacts | Name, business contact details in complaints and correspondence records |
RainerQMS is not designed for special categories of data; Customer agrees not to store them unless the parties agree safeguards in writing.
§ 4Documented instructions
Rainer processes Service Data only on Customer's documented instructions — the agreement, this DPA, and configuration through the Service — unless required by law, in which case Rainer informs Customer before processing (unless the law forbids it). Rainer will flag instructions it believes infringe data protection law.
§ 5Confidentiality of personnel
Persons authorized to process Service Data are bound by contractual or statutory confidentiality and receive data protection training. Access follows least privilege and is logged.
§ 6Security measures (Art. 32)
- Strict tenant separation — each customer's Service Data is isolated from every other customer's at every layer of the platform
- Encryption in transit (TLS) and at rest; credentials stored only in industry-standard hashed form; signed, expiring access tokens with revocation
- Role-based access control, MFA, account lockout and strong password policy
- Append-only audit logging of processing activity
- Security headers, input validation, malware scanning of uploads
- Backups with documented recovery objectives (RPO/RTO per plan); recovery tested
§ 7Assistance to the controller
Taking into account the nature of processing, Rainer assists Customer with data subject requests (access, rectification, erasure, restriction, portability, objection), and with Articles 32–36 (security, breach notification, DPIAs, prior consultation), providing the information reasonably needed.
§ 8Subprocessors
Customer grants general authorization for the subprocessors below. Rainer will give at least 30 days' notice of additions or replacements; Customer may object on reasonable data-protection grounds, and if no resolution is found may terminate the affected service pro rata.
| Function | Data touched | Location |
|---|---|---|
| Cloud infrastructure (compute, storage, backup) | All Service Data, encrypted volumes | Customer-selected region (EU or US) |
| Transactional email delivery | Recipient name, email, notification content | EU/US |
| Payment processing (billing only — never Service Data) | Billing contact and payment details | EU/US |
The named, current subprocessor list is maintained in the signed DPA schedule and available at any time from privacy@rainerqms.com.
§ 9Personal data breaches
Rainer notifies Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Service Data, with the information required for Customer's Article 33/34 obligations, and cooperates in the response.
§ 10International transfers
Service Data is hosted in the region selected at provisioning. Where processing involves a transfer out of the EEA/UK/Switzerland without an adequacy decision, the EU Standard Contractual Clauses (2021/914, Module 2) — and the UK Addendum where applicable — are incorporated into this DPA.
§ 11Audits
Rainer makes available the information necessary to demonstrate compliance with Article 28: documentation, third-party attestations and audit summaries as they become available. Where these are insufficient, Customer may audit — once per 12 months, on 30 days' notice, at its cost, under confidentiality, without access to other customers' data.
§ 12Deletion and return
On termination, Customer may export all Service Data in open formats free of charge for 60 days. After the export window, Rainer deletes Service Data — including the tenant database — within 30 days, and backup copies within the backup rotation period (maximum 90 days), unless law requires longer retention.
§ 13Precedence
For personal data processing, this DPA prevails over conflicting terms of the agreement. Nothing in the agreement limits either party's liability to data subjects.