Back to Privacy policy

Data Processing Agreement

Last updated: September 8, 2026

When this applies

This DPA applies where a business customer ("Customer") uses QuantRidge to process personal data on behalf of its organization or its own clients — for example where the EU or UK GDPR, the Swiss FADP, or a U.S. state privacy law requires a written agreement covering processing instructions, subprocessors, security measures, breach notification, and international transfers.

It is incorporated by reference into our Terms & Conditions (together, the "Agreement") and takes effect automatically when a business customer accepts them — no signature is required for it to bind us, though we will countersign on request.

Individuals using the Service for personal purposes should rely on our Privacy policy and California notice.

1. Roles of the parties

For Customer Personal Data processed under the Agreement, Customer is the controller (or, where Customer is itself a processor for its own clients, the processor) and QuantRidge is the processor (or subprocessor, correspondingly). QuantRidge processes Customer Personal Data only on Customer's documented instructions, which comprise the Agreement, this DPA, and Customer's use of the Service's features.

Under the CCPA/CPRA, QuantRidge is a service provider. QuantRidge does not sell or share Personal Information, does not retain, use, or disclose it for any purpose other than performing the Service, and does not combine it with personal information from other sources except as permitted for a service provider.

2. Scope and subject matter of processing

Subject matter: provision of the QuantRidge wealth management and financial intelligence platform. Duration: the term of the Agreement, plus the deletion period in clause 8.

Nature and purpose: hosting, storage, aggregation, analysis, and display of financial and account data; document storage; report generation; AI-assisted research; support and billing.

Categories of data subjects: Customer's personnel and authorized users, and where Customer is a firm, its clients and their household members whose records Customer enters into the Service.

Categories of personal data: identifiers and contact details; professional information; financial account, holding, transaction, and tax-lot data; documents Customer uploads; beneficiary and fiduciary designations; usage and device data. Customer must not submit special-category data or protected health information unless separately agreed in writing.

3. QuantRidge obligations

  • Process Customer Personal Data only on documented instructions, including for transfers.
  • Notify Customer without undue delay if, in QuantRidge's opinion, an instruction infringes applicable data protection law, and pause the affected processing.
  • Ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations that survive their engagement, and limit access to those who need it.
  • Implement and maintain the technical and organizational measures described in clause 5.
  • Make available information reasonably necessary to demonstrate compliance with this DPA, and support Customer's data protection impact assessments and prior consultations.

4. Subprocessors

Customer grants QuantRidge general written authorization to engage subprocessors. The current list is published at quantridge.net/subprocessors.

Notice. QuantRidge will update that page at least 30 days before a new subprocessor begins processing Customer Personal Data. Updating the page is the agreed method of notice; Customer is responsible for checking it, and may additionally subscribe to email notification by writing to support@quantridge.net.

Exceptions to the notice period. Advance notice is not required, and QuantRidge will instead update the page as soon as reasonably practicable, where: (a) a provider must be replaced urgently to maintain the security, integrity, or availability of the Service, or because the existing provider ceases operating or materially breaches its obligations; (b) the change is a successor entity of an existing subprocessor, or an affiliate of one, and the categories of personal data and processing location do not materially change; or (c) the new provider does not process Customer Personal Data.

Objection. Customer may object to a new subprocessor on reasonable grounds relating to data protection by writing to support@quantridge.net within 30 days of the change being posted. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected subscription without early-termination penalty, with termination effective at the end of the period already paid for. Fees already paid are not refunded and no credit is issued, except where applicable law requires otherwise. Termination on this basis is Customer's sole and exclusive remedy for an objection to a subprocessor, and for any failure to give notice within the period above. This does not limit the time Customer has to bring a claim, which is governed by the Terms.

QuantRidge imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to Customer for each subprocessor's performance.

5. Security measures

QuantRidge maintains technical and organizational measures appropriate to the risk, including: encryption of Customer Personal Data in transit (TLS) and at rest; role-based access control and least-privilege access; multi-factor authentication for administrative access; session review and revocation; network isolation and hardened HTTP headers; rate limiting and abuse controls; audit logging; secure development practices and dependency monitoring; and documented backup and restoration procedures.

Measures may be updated as technology and threats evolve, provided the level of protection is not materially reduced. Current detail is published at quantridge.net/security. QuantRidge does not currently hold its own SOC 2 or ISO 27001 certification and does not represent otherwise; infrastructure providers maintain their own.

6. Personal data breach

QuantRidge will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — to the extent known, with further information provided in phases as the investigation proceeds. QuantRidge will reasonably cooperate with Customer's own notification obligations. Notification is not an acknowledgement of fault or liability.

7. Data subject rights

The Service provides features allowing Customer to access, correct, export, and delete Customer Personal Data itself. Taking account of the nature of the processing, QuantRidge will provide reasonable assistance to help Customer respond to data subject requests it cannot fulfil through those features. If a data subject contacts QuantRidge directly regarding Customer Personal Data, QuantRidge will refer them to Customer rather than respond substantively, unless legally required to do so.

8. Return and deletion

Customer may export Customer Personal Data at any time during the term. On termination or expiry, QuantRidge will, at Customer's election, return or delete Customer Personal Data within 90 days, except where retention is required by law. Encrypted backups age out on a rolling schedule, typically within 35 days, during which deleted data is not restored to production or used for any purpose.

9. International transfers

QuantRidge processes Customer Personal Data in the United States. For transfers of personal data from the EEA, the UK, or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor, or Module Three, processor-to-processor, as applicable), together with the UK International Data Transfer Addendum and the Swiss adaptations. Where they conflict with this DPA, the Standard Contractual Clauses prevail. QuantRidge will notify Customer if it becomes subject to a legal requirement that would prevent it from meeting those obligations.

10. Audit

On written request, no more than once in any twelve-month period and subject to reasonable confidentiality terms, QuantRidge will provide information reasonably necessary to demonstrate compliance with this DPA, including responses to a standard security questionnaire. Where a regulator or applicable law requires an on-site audit, the parties will agree scope, timing, and cost in advance so as not to disrupt the Service or compromise other customers' confidentiality.

11. AI processing

Where Customer uses AI-assisted features, the text submitted to an assistant and the recent turns of that conversation are transmitted to the AI subprocessor identified on the subprocessors page for the sole purpose of generating a response. Customer Personal Data is not used to train, fine-tune, or otherwise improve any machine-learning model, by QuantRidge or by any subprocessor. QuantRidge does not carry out automated decision-making producing legal or similarly significant effects on data subjects. Use of these features is additionally governed by the AI Acceptable Use Policy.

12. Order of precedence and term

This DPA forms part of the Agreement. In the event of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms & Conditions as to the processing of Customer Personal Data. It takes effect when Customer accepts the Agreement and continues until QuantRidge has deleted or returned all Customer Personal Data. Liability under this DPA is subject to the limitations in the Agreement.

Download or countersign

The published DPA above is the operative version. A PDF is available for your legal and procurement teams, and we will countersign a copy for your records on request.

Include your company name, contact details, the entity that will sign, and any order reference. QuantRidge, 5830 E 2nd St, Ste 7000, Casper, WY 82609, United States.