Legal · DPA

Data Processing Addendum

This Addendum forms part of the Terms of Service between Sonicium Quantum Lab Ltd (Processor) and Customer (Controller), and reflects Article 28 GDPR requirements.

Version 2.1 · Effective 1 May 2026.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", and "Data Subject" carry the meanings given in the GDPR (Regulation (EU) 2016/679).

2. Scope of processing

Subject matter: provision of the Kepler Q-Max quantum-AI platform.
Duration: for the term of the underlying agreement.
Nature & purpose: hosted inference, account management, billing, support.
Data categories: identifiers, contact data, usage logs, content submitted to API.
Data subjects: Customer's authorized users and end-users.

3. Processor obligations

We will: (a) process Personal Data only on documented Customer instructions; (b) ensure personnel are bound by confidentiality; (c) implement the technical and organizational measures described on the Security page; (d) assist Customer with DSARs, DPIAs, and breach notifications.

4. Sub-processors

Customer authorizes the sub-processors listed at trust.sonicium.ltd/subprocessors. We provide 30 days' notice before adding a new sub-processor; Customer may object on reasonable data-protection grounds.

5. International transfers

Where Personal Data is transferred outside the EEA, UK, or Switzerland, the EU Standard Contractual Clauses (Module 2 / Module 3) and the UK International Data Transfer Addendum are incorporated by reference.

6. Security & breach

We maintain a written information security program aligned with ISO 27001. We will notify Customer without undue delay (and within 72 hours) of any confirmed Personal Data breach affecting Customer Data.

7. Audit

Customer may, no more than once per year, request third-party audit reports (SOC 2, ISO 27001) under NDA. On-site audits are available for Enterprise customers with reasonable notice.

8. Return & deletion

On termination, Customer Data is exported on request and deleted within 30 days, except where retention is required by law.

Signing the DPA

Enterprise customers may countersign this DPA by emailing legal@sonicium.ltd with their company details. A counter-signed PDF will be returned within 5 business days.