Client projects
Data Processing
This page summarises QELVIRO's intended approach when building or supporting a client system that processes personal data. It is not a signed Data Processing Agreement (“DPA”). A project-specific DPA should be completed where legally required.
1. Roles
The client will normally act as data controller for personal data entered into its system. The individual operating under the QELVIRO name may act as a processor where it hosts, maintains, migrates, accesses or supports that data on the client's documented instructions. Exact roles must be confirmed for each project.
2. Processing instructions
QELVIRO will process client personal data only as necessary to provide the agreed services and in accordance with the signed agreement, documented client instructions and applicable data-protection law.
3. Security and confidentiality
Project controls may include role-based access, authentication, encryption where appropriate, logging, backups, vulnerability management and confidentiality commitments. The final control set depends on the system's data, risk and agreed scope and must be documented before launch.
4. Service providers and transfers
Any hosting, email, database, monitoring or other subprocessors used for a client project should be listed in the applicable DPA or project documentation. International transfers must use appropriate safeguards where required.
5. Assistance and incidents
The project agreement should describe how QELVIRO assists with data-subject requests, security incidents, impact assessments, audits and regulatory enquiries, including relevant notification contacts and response times.
6. End of service
At the end of services, client personal data should be returned, exported or securely deleted as agreed, subject to legal retention obligations and documented backup cycles.
7. Request a DPA
To discuss data protection for a project or request a project-specific DPA, contact martynas@qelviro.tech.
