Data Processing Agreement

Terms for processing Customer Personal Data through AlwaysQA.

Last updated: July 9, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer using AlwaysQA (“Customer”, “you”) and Maciej Chmura IdeaUnlock, operating the AlwaysQA service (“AlwaysQA”, “we”, “us”, “our”), when AlwaysQA processes Customer Personal Data on behalf of Customer.

AlwaysQA is operated by:

Maciej Chmura IdeaUnlock
ul. Tadeusza Kosciuszki 1
32-020 Wieliczka
Poland
NIP / VAT ID: 8652425764
REGON: 18070444800000
Email: hello@alwaysqa.com

This DPA is intended to satisfy the requirements of Article 28 of the GDPR where Customer is the controller and AlwaysQA acts as processor. If Customer acts as a processor for another controller, AlwaysQA acts as Customer’s sub-processor.


1. Definitions

“Agreement” means the Terms & Conditions, order form, subscription agreement, statement of work, or other agreement governing Customer’s use of AlwaysQA.

“Customer Personal Data” means personal data included in Customer Content and processed by AlwaysQA on behalf of Customer.

“Customer Content” means data submitted to, generated by, or processed through AlwaysQA by or on behalf of Customer, including URLs, critical-flow instructions, generated check definitions, check versions, deployment history, screenshots, videos, logs, browser traces, reports, prompts, issue data, uploaded bug lists or CSVs, and related QA materials.

“Data Protection Laws” means the GDPR, applicable Polish data protection laws, and any other privacy or data protection laws that apply to the processing of Customer Personal Data.

“GDPR” means Regulation (EU) 2016/679.

“Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by AlwaysQA.

Terms such as “controller”, “processor”, “sub-processor”, “personal data”, “processing”, and “data subject” have the meanings given to them in the GDPR.


2. Roles of the parties

For Customer Personal Data, Customer is the controller and AlwaysQA is the processor, unless Customer acts as a processor on behalf of another controller. In that case, AlwaysQA is Customer’s sub-processor.

Customer determines the purposes and means of processing Customer Personal Data. AlwaysQA processes Customer Personal Data only to provide, secure, support, maintain, and improve the Service as permitted by the Agreement, this DPA, and Customer’s documented instructions.

Customer is responsible for ensuring that it has a lawful basis and all required notices, permissions, and rights to submit Customer Personal Data to AlwaysQA.


3. Subject matter, duration, nature, and purpose of processing

3.1 Subject matter

AlwaysQA processes Customer Personal Data to provide agent-first post-deploy QA, critical-flow checks, deployment history, failure diagnosis, check versioning, fix-and-rerun workflows, regression bug validation, reporting, integrations, and related support.

3.2 Duration

AlwaysQA processes Customer Personal Data for the duration of the Agreement and any post-termination retention period required to provide the Service, comply with law, resolve disputes, enforce agreements, preserve security, or follow Customer deletion instructions.

3.3 Nature and purpose

Processing may include hosting, storing, transmitting, accessing, reading, generating, analyzing, structuring, displaying, recording, testing, debugging, securing, deleting, and returning Customer Personal Data.

The purposes include:

  • running critical-flow checks after deployments;
  • reproducing, verifying, or validating reported issues;
  • processing uploaded bug lists or CSVs where Customer uses regression validation workflows;
  • generating and storing QA reports;
  • creating screenshots, videos, logs, traces, and evidence;
  • integrating with Customer tools such as issue trackers, repositories, CI/CD tools, MCP clients, APIs, and coding agents;
  • providing support and troubleshooting;
  • securing, monitoring, and maintaining the Service;
  • complying with legal obligations.

4. Categories of data subjects and personal data

4.1 Categories of data subjects

Depending on Customer’s configuration and tested application, Customer Personal Data may relate to:

  • Customer’s users and employees;
  • developers, QA engineers, product managers, support staff, and administrators;
  • Customer’s customers, prospects, end users, contractors, or business contacts;
  • people whose personal data appears in screenshots, logs, traces, test environments, issue reports, or tested application screens.

4.2 Categories of personal data

Customer Personal Data may include:

  • names, email addresses, usernames, roles, account IDs, team or organization details;
  • application content visible during post-deploy QA checks;
  • URLs, page content, form labels, metadata, logs, browser traces, screenshots, videos, and network information;
  • issue descriptions, reproduction steps, comments, ticket metadata, and QA reports;
  • test credentials, test account information, or session data provided by Customer;
  • any other personal data Customer chooses to submit or expose to AlwaysQA through the Service.

AlwaysQA is not designed to process special categories of personal data, criminal offence data, payment card data, medical data, government identifiers, bank credentials, or other highly sensitive data unless expressly agreed in writing.


5. Customer instructions

Customer instructs AlwaysQA to process Customer Personal Data as necessary to provide the Service and as further documented through:

  • the Agreement;
  • this DPA;
  • Customer’s product configuration;
  • Customer’s use of dashboards, APIs, MCP integrations, CLI tools, coding-agent workflows, issue imports, uploaded bug lists or CSVs, check instructions, prompts, and support requests;
  • any written instructions agreed by the parties.

AlwaysQA will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, unless prohibited from doing so by law.


6. AlwaysQA processor obligations

AlwaysQA will:

  • process Customer Personal Data only on documented instructions from Customer, unless required by law;
  • ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations;
  • implement appropriate technical and organizational measures to protect Customer Personal Data;
  • assist Customer with data subject requests where reasonably possible and taking into account the nature of processing;
  • assist Customer with security, breach notification, data protection impact assessments, and prior consultation obligations where required by Data Protection Laws and taking into account the information available to AlwaysQA;
  • make information reasonably necessary to demonstrate compliance with this DPA available to Customer;
  • delete or return Customer Personal Data after the end of the Service as described in this DPA, unless law requires continued storage.

7. Security measures

AlwaysQA will maintain appropriate technical and organizational security measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

These measures may include, as appropriate to the nature of the Service:

  • access controls and authentication safeguards;
  • role-based access or least-privilege practices;
  • encryption in transit and, where appropriate, at rest;
  • logging, monitoring, and audit trails;
  • secure development and deployment practices;
  • backup, resilience, and recovery measures;
  • vulnerability management and security review processes;
  • internal confidentiality requirements;
  • separation between customer workspaces where technically applicable;
  • incident response procedures.

Customer is responsible for configuring the Service securely, limiting submitted data to what is necessary, protecting credentials, and controlling access to Customer accounts, integrations, test environments, and connected tools.


8. Sub-processors

Customer gives AlwaysQA general authorization to engage sub-processors to provide the Service.

AlwaysQA may use sub-processors for hosting, infrastructure, storage, databases, authentication, email, analytics, payments, support, AI processing, logging, monitoring, security, and other operational functions.

AlwaysQA will:

  • impose data protection obligations on sub-processors that are no less protective, in substance, than those in this DPA;
  • remain responsible for the performance of sub-processors’ data protection obligations;
  • provide information about current sub-processors on request or through the Privacy Policy, website, dashboard, or other customer notice mechanism;
  • give Customer reasonable notice of material changes to sub-processors where required by Data Protection Laws.

Customer may object to a new sub-processor on reasonable data protection grounds. If the parties cannot resolve the objection, Customer may stop using the affected part of the Service or terminate the affected Service according to the Agreement.


9. International transfers

AlwaysQA is established in Poland. Customer Personal Data may be processed in the European Economic Area and in other countries where AlwaysQA or its sub-processors operate.

Where Customer Personal Data is transferred outside the EEA, AlwaysQA will use appropriate safeguards required by Data Protection Laws, such as adequacy decisions, Standard Contractual Clauses, transfer risk assessments, supplementary measures, or another lawful transfer mechanism.

Customer authorizes AlwaysQA to enter into such transfer mechanisms on Customer’s behalf where necessary to provide the Service.


10. Security incidents

AlwaysQA will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

The notification will include information reasonably available to AlwaysQA, such as the nature of the incident, affected data, likely consequences, mitigation steps, and contact point for follow-up. AlwaysQA may provide information in phases as the investigation develops.

Customer is responsible for determining whether it must notify supervisory authorities, data subjects, customers, users, or other parties.


11. Data subject requests

If AlwaysQA receives a request from a data subject relating to Customer Personal Data, AlwaysQA will, where reasonably possible, direct the requester to Customer or notify Customer, unless prohibited by law.

AlwaysQA will provide reasonable assistance to Customer in responding to data subject requests, taking into account the nature of processing and the information available to AlwaysQA.


12. Deletion and return

Upon termination or expiration of the Agreement, or upon Customer’s documented request, AlwaysQA will delete or return Customer Personal Data in accordance with the Agreement, product functionality, backup cycles, and applicable law.

AlwaysQA may retain Customer Personal Data where required by law, necessary for legitimate records, security, fraud prevention, dispute resolution, enforcement of agreements, or backup integrity, provided that retained data remains protected under this DPA and is not processed for other purposes.


13. Audits and compliance information

AlwaysQA will make available information reasonably necessary to demonstrate compliance with this DPA.

Customer may request audits or inspections where required by Data Protection Laws. The parties will agree on reasonable scope, timing, confidentiality, security, and cost controls. Audits must not compromise the security, confidentiality, availability, or privacy of AlwaysQA, other customers, systems, or sub-processors.

AlwaysQA may satisfy audit requests by providing security documentation, summaries, certifications, questionnaires, or third-party reports where available.


14. AI processing

AlwaysQA may use AI systems to generate, execute, analyze, summarize, or triage QA tests, issue reports, screenshots, videos, logs, traces, prompts, and related Customer Content.

AlwaysQA will process Customer Personal Data through AI systems only as necessary to provide the Service, follow Customer instructions, maintain security, provide support, or as otherwise permitted by the Agreement and Privacy Policy.

Customer is responsible for deciding what personal data may be submitted to AI-enabled features and for avoiding unnecessary submission of sensitive data.


15. Customer responsibilities

Customer is responsible for:

  • complying with Data Protection Laws as controller or processor;
  • providing all required notices to data subjects;
  • obtaining all required consents, permissions, and rights;
  • ensuring that Customer’s use of AlwaysQA is lawful;
  • limiting Customer Personal Data submitted to AlwaysQA to what is necessary;
  • configuring test environments, integrations, credentials, and user permissions securely;
  • ensuring that production testing does not create unlawful, unsafe, or unintended effects;
  • responding to data subject and supervisory authority requests unless AlwaysQA is legally required to respond directly.

16. Order of precedence

If there is a conflict between this DPA and the Agreement, this DPA controls only with respect to the processing of Customer Personal Data.

If there is a conflict between this DPA and mandatory Data Protection Laws, the mandatory law controls.


17. Changes to this DPA

AlwaysQA may update this DPA from time to time. If we make material changes, we will take reasonable steps to notify customers, such as by posting an updated version on the website, updating the “Last updated” date, or sending notice where appropriate.

Continued use of the Service after the effective date of an updated DPA means the updated DPA applies to Customer’s use of the Service, unless a separate signed DPA states otherwise.


18. Contact

For DPA questions, privacy requests, security issues, or sub-processor information, contact:

Maciej Chmura IdeaUnlock
ul. Tadeusza Kosciuszki 1
32-020 Wieliczka
Poland
NIP / VAT ID: 8652425764
REGON: 18070444800000
Email: hello@alwaysqa.com