IMSQ · Institute of MedTech Software Quality
Legal

Data Processing Addendum

Version 1.2 · Effective 31 July 2026v1.2

This Data Processing Addendum (DPA) describes how IMSQ LLC ("IMSQ") processes personal data on behalf of subscribing organisations. Your organisation is the controller of the personal data it brings to the service; IMSQ processes it as described here. To execute a countersigned copy for your supplier file, contact privacy@imsq.org.

Scope & roles

This DPA applies to personal data your organisation submits to the IMSQ platform — your users’ account data, learning and engagement records, and related content. For that data, your organisation acts as controller and IMSQ as processor. For IMSQ’s own operations (billing relationships, security telemetry, its Expert registry), IMSQ acts as an independent controller as described in the Privacy Policy.

Processing details

Subject matter: delivery of the IMSQ capability platform. Duration: your subscription term plus the wind-down described in the Privacy Policy’s retention section. Nature and purpose: hosting, structured learning delivery, engagement facilitation, governance-record production, and support. Data subjects: your organisation’s users. Data categories: the categories listed in the Privacy Policy’s "Data we process" section.

IMSQ’s obligations as processor

IMSQ processes your organisation’s data only to operate the service and on your documented instructions; limits access to personnel bound by confidentiality; applies the security measures described in the Privacy Policy (row-level tenant isolation, MFA on privileged roles, encryption in transit and at rest, rate limiting, continuous error monitoring); assists with data-subject requests through the documented rights process; and notifies you without undue delay on becoming aware of a personal-data breach affecting your data.

Sub-processors

IMSQ uses the following sub-processors to operate the service. Changes to this list are versioned in this document; the current list is always published here and on the Trust page.

Supabase — Database, authentication, file storage. Region: United States (us-east-1, AWS).

Stripe — Payment processing. Region: United States (primary), per Stripe's published sub-processor list.

Resend — Transactional email delivery. Region: United States.

Vercel — Hosting, edge network, cookieless analytics. Region: United States (primary).

Microsoft (Teams / Microsoft 365) — Operational notifications, corporate email tenant. Region: United Kingdom (tenant data location).

Sentry — Error monitoring. Region: European Union (Frankfurt).

International transfers

Processing locations are stated per sub-processor above. Where personal data moves between regions, it does so under each named provider’s published data-protection framework (each maintains its own DPA and standard contractual protections).

Deletion, return & audit

At term end (or on verified request), your administrators can obtain an export of your account data, after which data is deleted or de-identified per the Privacy Policy’s retention section. Reasonable information needed for your supplier-governance file — including this DPA, the sub-processor list, and security-posture summaries — is available via privacy@imsq.org.

Executing this DPA

This published DPA states IMSQ’s standard processing terms. To execute a countersigned copy, contact privacy@imsq.org.

This page is a plain-language summary and is not legal advice. For subscribed organisations, the binding contract text is the order form and master agreement executed with your organisation, which take precedence wherever they differ.

Questions about the fine print?

Procurement and legal reviews are welcome. Book a programme review and we’ll walk your team through the terms, the SLA, and the Supplier Qualification Pack.