This Data Processing Agreement ("DPA") forms part of the agreement between:
Qelta ApS, CVR 46661885, Strandvejen 73B, st. tv, 2100 København Ø, Denmark ("Processor", "Qelta")
and
the customer identified in the applicable order form or services agreement ("Controller", "Customer")
(together, the "Parties"), and governs Qelta's processing of personal data on the Customer's behalf in connection with the Qelta platform (the "Service").
1. Definitions
Terms defined in Regulation (EU) 2016/679 ("GDPR") have the same meaning here. "Customer Data" means personal data contained in case material, documents, review criteria, and related records that the Customer or its authorised users submit to, or that is generated within, the Service.
2. Roles of the Parties
The Customer is the controller and Qelta is the processor in respect of Customer Data. The Customer determines the purposes and means of processing, including which case material is submitted and which review criteria are applied.
Qelta is an independent controller for the limited data described in its Privacy Policy (business contacts, authorised-user account records, and platform access logs used for security and service administration).
The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided any required information to data subjects, and that its submission of Customer Data to the Service is consistent with its own regulatory obligations, including obligations of confidentiality applicable to financial institutions.
Scope of this DPA. This DPA governs Qelta's processing of Customer Data in the Service (app.qelta.ai). It does not govern personal data that Qelta processes as controller in its own right — including data collected from visitors to the qelta.ai website, enquiry and demo-request forms, and general business correspondence — which is described in Qelta's Privacy Policy. Nothing in this DPA is intended to characterise that processing as processing on the Customer's behalf.
3. Subject matter, duration, nature and purpose
Set out in Annex I. Processing continues for the term of the services agreement and the limited post-termination period described in section 12.
4. Processing only on instructions
Qelta shall process Customer Data only:
(a) as necessary to provide the Service in accordance with the services agreement; (b) in accordance with the Customer's documented instructions, including configuration choices made in the Service; and (c) as required by Union or Member State law, in which case Qelta shall inform the Customer before processing unless legally prohibited.
Qelta shall inform the Customer without undue delay if, in its opinion, an instruction infringes applicable data protection law.
Qelta shall not:
(d) use Customer Data for its own purposes; (e) use Customer Data to train, fine-tune, or improve any Qelta model or any third party's model; or (f) disclose Customer Data to any third party except as permitted under section 6 or required by law.
5. Confidentiality and personnel
Qelta shall ensure that persons authorised to process Customer Data are bound by confidentiality obligations, are informed of the confidential nature of the data, receive appropriate data protection and security awareness training, and have access only to the extent necessary for their role.
Access to Customer environments by Qelta personnel shall be limited, logged, and — where technically feasible — subject to Customer-visible records. Access to production case data is always subject to prior customer approval.
6. Sub-processors
The Customer provides general authorisation for Qelta to engage the sub-processors listed at qelta.ai/legal/sub-processors and in Annex II.
Qelta shall:
(a) impose data protection obligations on each sub-processor no less protective than those in this DPA; (b) remain fully liable to the Customer for the performance of its sub-processors; (c) give the Customer at least 30 days' prior notice of the intended addition or replacement of a sub-processor, or of a change to the region in which Customer Data is processed; and (d) where the Customer objects on reasonable data-protection or regulatory grounds within the notice period, work in good faith to provide an alternative; failing which the Customer may terminate the affected part of the Service without penalty.
7. International transfers
Qelta shall not transfer Customer Data outside the EU/EEA except where an adequacy decision applies, the European Commission's Standard Contractual Clauses (Decision 2021/914) are in place together with any necessary supplementary measures, or another valid Article 46 mechanism applies. Transfer arrangements applicable to each sub-processor are stated in Annex II.
8. Security
Qelta shall implement and maintain appropriate technical and organisational measures, including access controls, tenant separation, encryption in transit and at rest, logging and monitoring, backups, vulnerability management, incident response, staff confidentiality, and supplier oversight. Measures shall reflect the risks associated with Customer Data, including data relating to suspected criminal offences (see section 13).
Qelta shall not materially reduce the overall level of security during the term.
9. Assistance with data subject rights
Taking into account the nature of the processing, Qelta shall assist the Customer in responding to data subject requests, including by providing functionality within the Service to search, export, correct, and delete Customer Data. Where Qelta receives a request directly from a data subject relating to Customer Data, it shall not respond substantively but shall refer the request to the Customer without undue delay.
The Customer acknowledges that rights of access and erasure may be restricted where the Customer is subject to anti-money-laundering record-keeping or tipping-off provisions, and that the Customer determines how such restrictions apply.
10. Personal data breach
Qelta shall notify the Customer without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting Customer Data, and shall provide the information reasonably available to enable the Customer to meet its obligations under Articles 33–34 GDPR, together with reasonable assistance in investigation, mitigation, and remediation.
11. Data protection impact assessments and audits
Qelta shall provide the Customer with information reasonably necessary to conduct a data protection impact assessment and, where required, prior consultation with a supervisory authority.
Qelta shall make available information necessary to demonstrate compliance with this DPA and shall permit audits, including inspections, by the Customer or an auditor it mandates. Audits shall be conducted on reasonable notice, during business hours, subject to confidentiality, and no more than once per year unless required by a supervisory authority or following a personal data breach.
Regulatory access. Qelta shall grant the Customer, its auditors, and its competent supervisory authorities — including any resolution authority — access to information, premises, and systems as necessary for them to exercise their statutory rights in respect of the Service, and shall cooperate with them.
12. Deletion and return
On termination or expiry of the services agreement, Qelta shall, at the Customer's election, return Customer Data in a commonly used machine-readable format and/or delete it, within 30 days, and shall delete existing copies except to the extent Union or Member State law requires storage.
The Customer acknowledges it is responsible for exporting any records it must retain under its own anti-money-laundering or bookkeeping obligations before deletion. Qelta shall provide reasonable export assistance during a transition period of 30 days.
13. Special categories and criminal-offence data
The Parties acknowledge that Customer Data submitted for review may include:
(a) personal data relating to suspicion of criminal offences within the meaning of Article 10 GDPR (for example, suspicious activity assessments, sanctions and adverse-media findings); and (b) in some cases, special categories of personal data under Article 9 (for example, where politically exposed person screening or adverse media reveals political opinions).
The Customer confirms it processes such data under an appropriate legal basis and under the authority of Union or Member State law, in particular anti-money-laundering legislation. Qelta shall apply the measures identified in section 8 to such data and shall not process it for any purpose other than providing the Service.
14. Automated processing and model use
The Service applies automated and AI-based analysis to Customer Data in order to produce review findings against criteria the Customer defines.
(a) Qelta shall not use Customer Data to train or improve any model, whether its own or a third party's, and shall ensure its model sub-processor is contractually bound to the same restriction. (b) Model processing is performed under the retention terms agreed with the applicable model sub-processor. (c) Output of the Service is advisory. The Customer remains responsible for decisions taken in individual cases and for maintaining appropriate human oversight of Service output. (d) Use restriction. The Customer shall not use Service output as the sole or primary basis for decisions concerning an individual employee's promotion, remuneration, disciplinary treatment, or termination. Where the Customer nevertheless uses the Service to monitor or evaluate the performance of individuals, the Customer is responsible for its own obligations as a deployer under Regulation (EU) 2024/1689 (the AI Act) and applicable employment and works-council law.
15. Liability, term and precedence
This DPA takes effect on the effective date of the services agreement and terminates with it. Liability under this DPA is subject to the limitations in the services agreement. In the event of conflict between this DPA and the services agreement in respect of the processing of personal data, this DPA prevails.
Annex I — Description of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Qelta platform for quality assurance and review of compliance case work |
| Duration | Term of the services agreement, plus the period in section 12 |
| Nature and purpose | Storage, retrieval, and automated evaluation of case material against Customer-defined review criteria; generation and storage of review findings and records; provision of reporting |
| Categories of data subjects | (i) the Customer's customers and their representatives and beneficial owners, as referenced in case material; (ii) the Customer's employees and contractors who handle or review cases; (iii) third parties named in case material |
| Categories of personal data | Identification and contact data; identifiers such as customer or case numbers; transaction and account information; risk assessments and scores; screening results (sanctions, PEP, adverse media); free-text analyst narratives; documents and attachments submitted as case material; authorised-user account and activity data |
| Special categories / Art. 10 data | Data relating to suspicion of criminal offences; potentially political opinions via PEP or adverse-media findings (see section 13) |
| Frequency | Continuous, as cases are submitted |
| Retention | As configured by the Customer, and as set out in section 12 |
Annex II — Sub-processors
Current list: qelta.ai/legal/sub-processors, incorporated by reference.
| Sub-processor | Role | Region |
|---|---|---|
| Railway Corp. | Application hosting, storage, compute | EU West (Amsterdam) |
| OpenAI Ireland Ltd. | Language-model inference for automated review | EU |
| Google Cloud (Vertex AI) | Language-model inference for automated review | EU (multi-region) |
| Clerk Inc. | User authentication and identity management — no case content | United States (SCCs) |
| Sentry | Application error tracking and diagnostics — no case content | EU |
Data residency. All Customer Data, including all language-model inference, is processed within the EU/EEA. Qelta shall not transfer Customer Data outside the EU/EEA without the Customer's prior written consent and a valid Chapter V transfer mechanism.
Authentication and diagnostics. Authentication data (user name, business email, session data) is processed by Clerk Inc. in the United States under Standard Contractual Clauses. Error diagnostics are processed by Sentry in the EU; Qelta does not use session recording or replay, and only technical error information is collected. No case content is processed by either provider.
Contact
Qelta ApS · CVR 46661885 · Strandvejen 73B, st. tv, 2100 København Ø, Denmark · contact@qelta.ai