Data Processing Agreement (GDPR Article 28)
Last updated: 14 August 2026 · Effective: 31 August 2026
This Data Processing Agreement ("DPA") is entered into between:
- Queuey AS, a company registered in Norway (organisation number 937 342 977; registered business address: c/o Sverre Senneset, Skjermvegen 66, 7023 Trondheim, Norway), operating the website queuey.ai ("Queuey", "we", "us", "our"); and
- the business or organisation identified in the Order that has entered into the Agreement with Queuey ("Customer", "you", "your").
Queuey and Customer are each a "party" and together the "parties".
This DPA forms part of, and is annexed to, the agreement between the parties for Customer's use of the Service, comprising the applicable Order, these terms, the Cloud Service Agreement (the Queuey Cover Page incorporating the Common Paper CSA Standard Terms, version 2.1), and the Acceptable Use Policy (together, the "Agreement"). The Queuey client SDKs are licensed separately under the MIT License and are not part of the Agreement. This DPA reflects the parties' agreement on the processing of Personal Data in connection with the Service, as required by Article 28 of the GDPR. Capitalised terms used but not defined in this DPA have the meanings given to them in the Cloud Service Agreement.
Where there is a conflict between this DPA and any other part of the Agreement in respect of the processing of Personal Data, this DPA prevails, save that an executed Order Form takes precedence over this DPA. The order of precedence for all other matters is as set out in the Cloud Service Agreement.
The Service is offered exclusively to businesses and organisations acting in the course of a trade, business, craft or profession, and is not offered to consumers. This DPA is entered into on that basis.
1. Definitions
1.1. In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given in the Cloud Service Agreement.
- "Controller", "Processor", "Data Subject", "Personal Data Breach", "Processing" (and "process", "processed", "processing"), and "Supervisory Authority" have the meanings given to them in the Data Protection Laws.
- "Customer Personal Data" means any Personal Data contained within Customer Data that Queuey processes on behalf of Customer under the Agreement, including Personal Data contained in Event payloads and in Endpoint configuration.
- "Data Protection Laws" means the EU General Data Protection Regulation 2016/679 ("GDPR") as incorporated into the Agreement on the European Economic Area (the "EEA Agreement") and as applicable in Norway, the Norwegian Personal Data Act (personopplysningsloven), and all other data protection and privacy laws applicable to the processing of Personal Data under the Agreement, in each case as amended, replaced or superseded from time to time.
- "EEA" means the European Economic Area.
- "SCCs" or "Standard Contractual Clauses" means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission in its Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced or superseded from time to time.
- "Sub-processor" means any third party engaged by Queuey (or by another Sub-processor of Queuey) to process Customer Personal Data on Queuey's behalf in connection with the provision of the Service.
1.2. The terms "Event", "Endpoint", "Integration Tenant", "Partner", "Authorised User", "SDK", "Documentation", "Order", "Subscription Plan", "Subscription Term", "Fees", and "Confidential Information" have the meanings given to them in the Cloud Service Agreement.
2. Roles of the parties
2.1. Controller / Processor relationship. The parties acknowledge and agree that, with regard to the processing of Customer Personal Data:
- (a) where Customer is a Controller of Customer Personal Data, Queuey is a Processor acting on behalf of Customer; and
- (b) where Customer is itself a Processor of Customer Personal Data (that is, where Customer processes such data on behalf of one or more third-party controllers), Queuey is a Sub-processor.
2.2. Customer's warranties as to role. Where Customer acts as a Processor, Customer warrants that its instructions to Queuey, including its authorisation of Queuey as a Sub-processor and of Queuey's own Sub-processors, have been authorised by the relevant Controller(s). Customer is solely responsible for the accuracy, quality and lawfulness of Customer Personal Data and of the means by which Customer acquired it, and for maintaining the relationship, and complying with the applicable data processing terms, between Customer and any such Controller.
2.3. Queuey's role. Queuey processes Customer Personal Data only as a Processor (or Sub-processor) on behalf of Customer and does not determine the purposes and means of processing Customer Personal Data. Nothing in this DPA is intended to make Queuey a Controller of Customer Personal Data. To the extent Queuey processes any Personal Data as a Controller (for example, account, billing and administrative contact data of Authorised Users processed to operate Queuey's business, or usage, security and operational telemetry processed solely for the security, integrity and operational monitoring of the Service), such processing is governed by Queuey's privacy notice and not by this DPA. Such Queuey-controller telemetry is limited to security, integrity and operational metrics of the Service and does not extend to the contents of Event payloads or otherwise to Customer Personal Data processed on Customer's behalf under this DPA.
2.4. Webhooks-as-a-Service (WaaS). Under the Webhooks-as-a-Service feature, a producing Customer publishes Event "streams" that subscribing Integration Tenants receive. In respect of Customer Personal Data contained in such distributed Events:
- (a) Queuey ingests, queues, deduplicates, retries, rate-limits and delivers those Events to the Endpoints of the subscribing Integration Tenants, in each case as a Processor acting on the documented instructions of the producing Customer, which are constituted by the producing Customer's configuration of the streams, subscriptions, packages and delivery policies within the Service;
- (b) the producing Customer remains responsible, as between the parties and as against Data Subjects, for determining which Events (and which Personal Data within them) are distributed to which Integration Tenants, and for ensuring it has a valid legal basis and any required consents and notices for that distribution;
- (c) the onward relationship between the producing Customer and an Integration Tenant (including whether that Integration Tenant is a further controller, joint controller or processor in respect of the distributed Personal Data, and any controller-to-controller or controller-to-processor terms required between them) is a matter to be determined and documented between the producing Customer and the Integration Tenant; Queuey is not a party to that relationship and is not responsible for it; and
- (d) Queuey enforces strict per-tenant data isolation between tenants (including between the producing Customer and its Integration Tenants) as described in Schedule 2, and delivers a distributed Event to an Integration Tenant only where the producing Customer's configuration authorises that delivery.
2.5. Details of processing. The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Schedule 1 (Details of Processing).
3. Scope and instructions
3.1. Processing on documented instructions. Queuey shall process Customer Personal Data only on, and in accordance with, Customer's documented instructions, unless required to do otherwise by Union or Member State law (including Norwegian law) to which Queuey is subject; in such a case, Queuey shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2. What constitutes instructions. Customer's documented instructions are constituted by this DPA and the Agreement, together with Customer's configuration and use of the Service through its permitted interfaces (including the console, the API, the SDK, and the configuration of Endpoints, streams, subscriptions, retention settings, retry, rate-limiting and delivery policies). Customer may issue additional written instructions consistent with the Agreement; Queuey is not obliged to comply with additional instructions that are inconsistent with the Agreement or that would require changes to the Service, unless the parties agree in writing (including as to any Fees for implementing them).
3.3. Lawfulness of instructions. Queuey shall inform Customer without undue delay if, in Queuey's reasonable opinion, an instruction infringes the Data Protection Laws. In that event, Queuey may (without liability) suspend performance of the affected instruction until Customer confirms, amends or withdraws it, save that this paragraph does not oblige Queuey to carry out a legal assessment of Customer's instructions.
3.4. Purpose limitation. Queuey shall not process, retain, use or disclose Customer Personal Data for any purpose other than providing, maintaining, securing and supporting the Service under the Agreement and as instructed by Customer, and shall not sell Customer Personal Data or process it for Queuey's own independent commercial purposes.
3.5. Compliance. Each party shall comply with its respective obligations under the Data Protection Laws. Customer, as Controller, is responsible for ensuring that there is a lawful basis for the processing of Customer Personal Data, for providing all required information to, and obtaining all required consents from, Data Subjects, and for the lawfulness of the delivery of Events to Endpoints and Integration Tenants.
4. Confidentiality of personnel
4.1. Queuey shall ensure that persons authorised to process Customer Personal Data:
- (a) are subject to an appropriate obligation of confidentiality (whether a contractual duty or a statutory obligation) with respect to Customer Personal Data;
- (b) are granted access to Customer Personal Data only on a need-to-know basis and only to the extent necessary to perform their duties in connection with the Service; and
- (c) receive appropriate training on their responsibilities in respect of the processing and protection of Personal Data.
5. Security (Article 32)
5.1. Technical and organisational measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Queuey shall implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to that risk. Those measures are described in Schedule 2 (Technical and Organisational Measures).
5.2. Changes to measures. Queuey may update or modify the measures in Schedule 2 from time to time, provided that any such update or modification does not materially reduce the overall level of security of the Service during the Subscription Term.
5.3. Customer's responsibility. Customer is responsible for its own security in connection with its use of the Service, including securing its Endpoints, its API keys, HMAC signing secrets and other credentials, configuring IP allow-listing where available, managing its Authorised Users, and assessing whether the measures in Schedule 2 meet Customer's requirements and legal obligations for the Customer Personal Data it chooses to submit to the Service.
6. Sub-processors
6.1. General authorisation. Customer gives Queuey a general written authorisation to engage Sub-processors to process Customer Personal Data in connection with the provision of the Service. Queuey's current Sub-processors as at the effective date of this DPA are listed in Schedule 3 (Sub-processors).
6.2. Notice of changes. Queuey shall maintain the list of Sub-processors in Schedule 3 and shall give Customer at least thirty (30) days' prior notice of any addition or replacement of a Sub-processor before that Sub-processor begins processing Customer Personal Data, in each case by the notification mechanism identified in Schedule 3 (e-mail notice to the Customer's registered administrative contact).
6.3. Right to object. Customer may object to the appointment or replacement of a Sub-processor on reasonable grounds relating to data protection, by giving Queuey written notice within the thirty (30) day notice period. The parties shall discuss such objection in good faith with a view to achieving a commercially reasonable resolution. If no such resolution can be reached, Queuey may, at its option, either not appoint or replace the Sub-processor, or permit Customer to suspend or terminate the affected part of the Service (and, if the affected part cannot reasonably be separated, the Agreement) in accordance with the termination provisions of the Cloud Service Agreement, as Customer's sole and exclusive remedy.
6.4. Sub-processor obligations and liability. Where Queuey engages a Sub-processor, Queuey shall impose on that Sub-processor, by way of a written contract, data-protection obligations that are substantially the same as, and in any event no less protective than, those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Queuey remains fully liable to Customer for the performance of each Sub-processor's data-protection obligations, to the same extent as if Queuey were performing the relevant processing itself, subject to the limitations of liability set out in clause 12.
7. International transfers
7.1. Primary processing location. Queuey hosts the Service, including its managed databases, on Microsoft Azure in the Norway East region, which is within the EEA. Queuey's primary processing of Customer Personal Data takes place within the EEA.
7.2. Transfers outside the EEA. Queuey shall not transfer Customer Personal Data to a country outside the EEA, and shall not permit a Sub-processor to do so, except where the transfer is subject to appropriate safeguards under the Data Protection Laws, namely:
- (a) the recipient country, territory, sector or organisation is the subject of an adequacy decision of the European Commission (or an equivalent decision applicable in Norway) that remains in force; or
- (b) the transfer is governed by the Standard Contractual Clauses, incorporated by reference and completed as described in Schedule 4 (International transfers), together with any supplementary technical, organisational and contractual measures reasonably necessary to ensure an essentially equivalent level of protection; or
- (c) another lawful transfer mechanism recognised under the Data Protection Laws applies.
7.3. Cooperation on transfers. The parties shall reasonably cooperate to give effect to, and to keep current, the transfer mechanism(s) applicable under this clause 7, including executing any updated version of the SCCs or additional documentation reasonably required to maintain lawful transfers.
7.4. Standing safeguard. No Sub-processor will process Customer Personal Data outside the EEA unless and until an appropriate Chapter V transfer mechanism for that Sub-processor is in place and recorded in Schedule 4.
8. Assistance with Data-Subject requests
8.1. Taking into account the nature of the processing, Queuey shall assist Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR (including rights of access, rectification, erasure, restriction, portability and objection).
8.2. Where Queuey receives a request directly from a Data Subject in respect of Customer Personal Data, Queuey shall not respond to the request itself (except to confirm that the request should be directed to Customer, or as legally required) and shall, without undue delay, notify Customer of the request, unless prohibited by law.
8.3. Customer acknowledges that, given the architecture of the Service, Customer is generally able to access, correct, delete, export and restrict Customer Personal Data itself through the console, the API and the SDK. Queuey's obligation to assist under this clause 8 applies to the extent Customer cannot reasonably achieve the required outcome through those self-service capabilities. Queuey may charge a reasonable fee for assistance that requires material effort beyond the standard functionality of the Service, having first notified Customer.
9. Assistance with the Controller's obligations (Articles 32–36)
9.1. Taking into account the nature of the processing and the information available to Queuey, Queuey shall provide reasonable assistance to Customer in ensuring compliance with Customer's obligations under Articles 32 to 36 of the GDPR, namely:
- (a) the security of processing (Article 32), including by maintaining the measures described in Schedule 2 and making available the information described in clause 13;
- (b) notification of a Personal Data Breach to the Supervisory Authority (Article 33) and communication of a Personal Data Breach to affected Data Subjects (Article 34), as further described in clause 10;
- (c) carrying out data protection impact assessments (Article 35); and
- (d) prior consultation with the Supervisory Authority (Article 36).
9.2. Queuey may charge a reasonable fee for assistance under clause 9.1(c) and 9.1(d) that requires material effort beyond making available its standard documentation and information about the Service, having first notified Customer.
10. Personal Data Breach
10.1. Notification to Customer. Queuey shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware.
10.2. Content of notification. The notification shall, to the extent then known to Queuey and permitted by law, describe: (a) the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and of Personal Data records concerned; (b) the likely consequences of the Personal Data Breach; (c) the measures taken or proposed to be taken by Queuey to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects; and (d) a contact point from whom more information can be obtained. Where, and insofar as, it is not possible to provide all such information at the same time, the information may be provided in phases without further undue delay.
10.3. Cooperation. Queuey shall reasonably cooperate with Customer and take such reasonable commercial steps as are directed by Customer to assist in the investigation, mitigation and remediation of the Personal Data Breach.
10.4. No admission. Queuey's notification of, or response to, a Personal Data Breach under this clause 10 is not, and shall not be construed as, an acknowledgement by Queuey of any fault or liability with respect to the Personal Data Breach. Customer is solely responsible for determining whether the Personal Data Breach must be notified to any Supervisory Authority or Data Subject, and for making any such notification.
11. Return and deletion of Customer Personal Data
11.1. During the Subscription Term. During the Subscription Term, Customer may access, export and delete Customer Personal Data through the Service, and may configure the data-retention settings made available by the Service (including metrics/observability retention). Queuey shall retain and delete Customer Personal Data in accordance with those retention settings and Customer's instructions.
11.2. On termination or expiry. On termination or expiry of the Agreement, at Customer's choice, Queuey shall delete or return Customer Personal Data. Unless Customer elects and completes a return by another agreed method within the export window, Customer Personal Data will be available for export by Customer for thirty (30) days after the effective date of termination or expiry, after which Queuey shall delete Customer Personal Data from the production systems of the Service and shall delete existing copies.
11.3. Backups and legal retention. Deletion of Customer Personal Data from encrypted backups occurs in accordance with Queuey's backup rotation cycle seven (7) days — the point-in-time-recovery window (verified against the production Azure PostgreSQL configuration on 14 August 2026), after which the data is overwritten or destroyed. Queuey may retain Customer Personal Data to the extent, and for so long as, required by Union or Member State law (including Norwegian law) to which Queuey is subject, in which case Queuey shall protect the confidentiality of, and shall not further process, the retained Customer Personal Data except as required by that law.
11.4. Certification. Queuey shall, on Customer's written request made within thirty (30) days after the export window closes, certify in writing that it has complied with its deletion obligations under this clause 11, subject to clause 11.3.
12. Liability
12.1. The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Cloud Service Agreement, to the maximum extent permitted by the Data Protection Laws and other applicable law. The limitations and exclusions of liability in the Cloud Service Agreement apply to the parties' aggregate liability arising out of or related to the Agreement and this DPA taken together, and not per agreement.
12.2. Nothing in this DPA or the Cloud Service Agreement limits or excludes either party's liability where such limitation or exclusion is not permitted by applicable law, including liability which under mandatory Norwegian law cannot be excluded or limited (which includes liability caused by intent (forsett) or gross negligence (grov uaktsomhet), and liability for death or personal injury), or the rights of Data Subjects under the Data Protection Laws.
13. Audits
13.1. Information. Queuey shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA.
13.2. Audits and inspections. Queuey shall allow for and contribute to audits, including inspections, conducted by Customer or an independent third-party auditor mandated by Customer, subject to the following:
- (a) Customer may exercise its audit right no more than once in any twelve (12) month period, save where an audit is required following a Personal Data Breach affecting Customer Personal Data or is expressly required by a Supervisory Authority or applicable law;
- (b) Customer shall give Queuey at least thirty (30) days' prior written notice of any audit, and shall conduct the audit during Queuey's normal business hours, in a manner that does not disrupt Queuey's business or compromise the security or confidentiality of the data of Queuey's other customers;
- (c) the auditor (and, where the auditor is Customer, Customer) must be bound by obligations of confidentiality at least as protective as those in the Agreement, and must not be a competitor of Queuey; and
- (d) Customer bears its own costs of any audit, and shall reimburse Queuey's reasonable costs of providing assistance beyond making available the information and reports described in clause 13.3.
13.3. Third-party reports and certifications. Queuey may satisfy the audit obligations in clause 13.2 by making available to Customer, on a confidential basis, its then-current third-party audit reports, certifications and attestations (for example, ISO/IEC 27001 certification or SOC 2 reports, when available) Queuey does not currently hold ISO/IEC 27001 certification or SOC 2 reports; independent reviews and certifications will be listed at queuey.ai/security as they are obtained, together with responses to a reasonable number of Customer's written security questionnaires. Where such reports and responses reasonably enable Customer to verify Queuey's compliance, Customer shall accept them in satisfaction of an audit request in place of an on-site inspection.
14. General
14.1. Term. This DPA takes effect on the effective date of the Agreement and continues in force for as long as Queuey processes Customer Personal Data on behalf of Customer, notwithstanding any expiry or termination of the Agreement, until all Customer Personal Data has been deleted or returned in accordance with clause 11.
14.2. Governing law and venue. This DPA is governed by the laws of Norway, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods (CISG). The parties submit to the exclusive jurisdiction of Trøndelag District Court (Trøndelag tingrett, Trondheim) as legal venue (verneting), subject to any mandatory rules of the Data Protection Laws. Where the SCCs apply, the governing law and forum provisions of the SCCs prevail in respect of matters governed by the SCCs to the extent of any conflict.
14.3. Language. English is the governing language of this DPA.
14.4. Order of precedence. In the event of a conflict between this DPA and the SCCs (where the SCCs apply), the SCCs prevail in respect of the transfer to which they relate. Otherwise, the order of precedence set out in the preamble and in the Cloud Service Agreement applies.
14.5. Severability. If any provision of this DPA is or becomes invalid or unenforceable, the remaining provisions remain in full force and effect, and the parties shall replace the invalid or unenforceable provision with a valid and enforceable provision that most closely reflects the parties' original intention.
14.6. Changes to this DPA. Queuey may amend this DPA from time to time where reasonably necessary to reflect changes in the Data Protection Laws, guidance from a Supervisory Authority, or changes to the Service, provided that no such amendment materially reduces the protections afforded to Customer Personal Data. Queuey shall give Customer reasonable prior notice of any material amendment.
14.7. Contacts. Data-protection matters under this DPA may be addressed to Queuey at privacy@queuey.ai. Abuse reports may be sent to abuse@queuey.ai, and other legal matters to legal@queuey.ai. Customer's data-protection contact is as set out in the Order or as notified by Customer to Queuey in writing [To be completed per Order: Customer data-protection contact / DPO details, where applicable].
Schedule 1 — Details of Processing
A. Parties
- Controller / Data exporter: Customer, as identified in the Order (acting as Controller, or as Processor on behalf of its own controller(s)).
- Processor / Data importer: Queuey AS — organisation number 937 342 977, registered address c/o Sverre Senneset, Skjermvegen 66, 7023 Trondheim, Norway.
B. Subject matter of the processing
The provision of the Service to Customer under the Agreement, namely a hosted webhooks-as-a-service and event-distribution platform through which Customer Personal Data contained in Events is ingested, queued, deduplicated, retried, rate-limited and delivered to Customer-configured Endpoints and, under the Webhooks-as-a-Service feature, distributed to subscribing Integration Tenants.
C. Nature and purpose of the processing
Processing operations performed by Queuey on Customer Personal Data include: receipt and ingestion of Events over HTTP or via the SDK; validation and idempotency-based deduplication; queuing and buffering; application of Customer-configured retry, rate-limiting and delivery policies; HMAC signing of delivery requests; delivery of Events to Endpoints; dead-letter handling of failed deliveries; distribution of published Event streams to subscribing Integration Tenants under the WaaS feature; storage of Event payloads and Endpoint/stream configuration; generation of metrics and observability data subject to configurable retention; encrypted backup; and related support, security, monitoring and troubleshooting activities. The purpose of the processing is to provide, maintain, secure and support the Service in accordance with Customer's documented instructions.
D. Duration of the processing
For the duration of the Subscription Term and thereafter until Customer Personal Data is deleted or returned in accordance with clause 11 of this DPA, subject to the retention configuration selected by Customer and to any legally required retention.
E. Types of Personal Data
Customer determines the content of Events and Endpoint configuration and therefore the categories of Personal Data submitted to the Service. These may include, without limitation and depending on Customer's use: identifiers and contact details (for example names, email addresses, telephone numbers, usernames, account and customer identifiers); organisation and role information; transaction, order, billing and product-usage data; technical identifiers (for example IP addresses, device identifiers, tokens); Endpoint URLs, headers and configuration values; and any other Personal Data that Customer chooses to include within Event payloads or configuration.
None intended: the Customer agrees not to submit special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) through the Service unless separately agreed in writing. [To be confirmed per Order.]
F. Categories of Data Subjects
Data Subjects whose Personal Data is contained in Events or Endpoint configuration, as determined by Customer, which may include: Customer's own customers, clients and end users; Customer's employees, contractors and Authorised Users; Customer's suppliers and business contacts; and, under the WaaS feature, the individuals whose Personal Data is contained in the Event streams that Customer publishes to Integration Tenants.
G. Frequency of the processing
Continuous and/or event-driven, for the duration of the Subscription Term, according to the volume and timing of Events submitted by Customer and delivered by the Service.
Schedule 2 — Technical and Organisational Measures (Article 32)
Queuey implements and maintains appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, including the measures set out below. The word "including" in this Schedule is used illustratively and not exhaustively. Queuey may update these measures in accordance with clause 5.2.
- Encryption in transit. Encryption of Customer Personal Data in transit using Transport Layer Security (TLS) (TLS 1.2 or higher), including for Event ingestion, delivery to Endpoints, and access to the console and API.
- Encryption at rest. Encryption of Customer Personal Data at rest in the managed database and in backups, using platform-provided encryption on Microsoft Azure (AES-256 with Azure service-managed keys).
- Strict per-tenant isolation. Strict logical isolation of tenant data, including a separate database schema per tenant, with access scoped per tenant so that one tenant cannot access another tenant's Customer Personal Data. Under the WaaS feature, delivery of a distributed Event from a producing Customer to an Integration Tenant occurs only where the producing Customer's configuration authorises that delivery.
- Access controls and least privilege. Role-based access controls and the principle of least privilege for personnel and systems; access to production systems and Customer Personal Data restricted to authorised personnel on a need-to-know basis; multi-factor authentication is required for administrative and production access (Microsoft Entra ID).
- Authentication of Customer traffic. API-key authentication for Customer access to the Service, with support for IP allow-listing to restrict the source addresses permitted to use a given API key.
- Request signing. HMAC request signing of delivery requests, enabling Endpoints to verify the authenticity and integrity of delivered Events.
- Audit logging. Logging of relevant security and administrative events to support monitoring, investigation and accountability (retained for thirty (30) days — verified against the production Log Analytics workspace configuration on 14 August 2026).
- Encrypted backups. Regular, encrypted backups of the managed database to support resilience and recovery (automated continuous backups with a seven (7)-day point-in-time-recovery window; backup restoration is tested periodically through environment rebuilds, and formally verified at least annually).
- Secret management. Secure management of secrets and credentials (including API keys, HMAC signing secrets and infrastructure credentials) using appropriate secret-management practices and restricted access.
- Network controls. Network-level controls, including segmentation and restriction of access to production infrastructure, appropriate to a service hosted on Microsoft Azure in the Norway East region.
- Secure development and hardening. A secure software development lifecycle, including mandatory code review via pull requests, automated test gates in CI on every change, dependency updates, and platform-component patching managed by Microsoft Azure and hardening of the Service and its infrastructure.
- Availability and resilience. Measures designed to support the ongoing availability and resilience of the Service, including the retry, dead-letter and backup mechanisms inherent to the platform, and use of Microsoft Azure managed infrastructure. No specific uptime or availability commitment is made under the standard terms; any service-level commitment applies only if separately agreed in writing, as set out in the Cloud Service Agreement.
- Personnel confidentiality and training. Confidentiality obligations binding on personnel and appropriate training on data-protection and information-security responsibilities, as described in clause 4.
- Sandbox separation. A sandbox environment for test traffic that is separated from production processing, enabling Customer to test integrations without affecting production Customer Personal Data.
- Incident response. Procedures for detecting, responding to and managing security incidents and Personal Data Breaches, including the notification process described in clause 10 (see the security overview at queuey.ai/security; security contact: security@queuey.ai).
Schedule 2 was reviewed against Queuey's verified production controls and approved in the final legal review of 14 August 2026 (no deviations). It must be re-reviewed whenever the underlying controls change.
Schedule 3 — Sub-processors
Customer authorises Queuey to engage the following Sub-processors to process Customer Personal Data in connection with the Service. This list is current as at 14 August 2026 and is subject to change in accordance with clause 6.
| Sub-processor (legal entity) | Service provided | Processing location |
|---|---|---|
| Microsoft Azure — Microsoft Ireland Operations Limited | Cloud hosting and managed database | Norway East (EEA) (administration and support performed from Norway, EEA) |
| Stripe — Stripe Payments Europe, Limited | Payment and billing processing | EEA (Ireland); transfers to Stripe, Inc. (United States) under Stripe's intra-group SCCs |
| Resend — Resend, Inc. | Transactional and notification email delivery | United States. Resend processes limited Customer Personal Data: the e-mail addresses of Customer-designated notification recipients, and operational notification content (queue names, issue titles and summaries). Event payloads are never sent by e-mail. Transfer mechanism: Resend, Inc. is certified under the EU-US Data Privacy Framework (including the UK Extension; certification announced 13 March 2025), and Resend's Data Processing Addendum additionally incorporates the EU Standard Contractual Clauses. Recorded in Schedule 4. |
| OpenAI Ireland Limited (EEA contracting entity), with onward transfer to OpenAI, L.L.C. (United States) | AI-assisted failure analysis — engaged only where the Customer’s per-queue AI data control is set to Shape (payload structure only, values masked) or Full; no processing when set to Off; model outputs are not retained by the provider for training | EEA (Ireland); onward transfer to the United States under the Standard Contractual Clauses incorporated in OpenAI's Data Processing Addendum |
The table above is the definitive Sub-processor list as at the date stated.
Notification mechanism for changes: notice by e-mail to the Customer's registered administrative contact, with at least thirty (30) days' prior notice and a right to object as set out in clause 6.3.
Schedule 4 — International transfers / Standard Contractual Clauses
- Primary location. The primary processing of Customer Personal Data takes place within the EEA (Microsoft Azure, Norway East). Where all processing (including by Sub-processors) takes place within the EEA or in a country covered by an adequacy decision, no additional transfer mechanism is required.
- EEA-adapted reading of the SCCs. The parties acknowledge that Queuey, as data exporter, is established in Norway, which is part of the EEA/EFTA but is not an EU Member State. Accordingly, where the SCCs are relied upon under this Schedule, they are entered into and read as adapted for use by an EEA/EFTA exporter in accordance with the guidance of the Norwegian Data Protection Authority (Datatilsynet), such that references in the SCCs to "Member State", to "the GDPR" (Regulation (EU) 2016/679) and to the "supervisory authority" and its powers are read as referring, respectively, to an EEA State, to the GDPR as incorporated into the EEA Agreement and applicable in Norway, and to the Norwegian Data Protection Authority (Datatilsynet), in each case in the EEA context, without expanding or reducing the substantive protections of the SCCs.
- Where a transfer outside the EEA occurs. To the extent that the provision of the Service involves a transfer of Customer Personal Data to a country outside the EEA that is not covered by an adequacy decision, the parties agree that the Standard Contractual Clauses (EU Commission Implementing Decision (EU) 2021/914), as read in accordance with paragraph 2 above, are incorporated into this DPA by reference and apply to that transfer, completed as follows:
- (a) Module. Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Sub-processor) applies where Customer acts as a Processor.
- (b) Clause 7 (Docking clause): the optional docking clause in Clause 7 shall apply.
- (c) Clause 9 (Use of sub-processors): Option 2 (general written authorisation) applies, with the notice period specified in clause 6.2 of this DPA (at least thirty (30) days).
- (d) Clause 11 (Redress): the optional independent-dispute-resolution language in Clause 11(a) shall not apply.
- (e) Clause 17 (Governing law): the parties acknowledge that Clause 17 of the SCCs, as adopted, refers to the law of an EU Member State, and that Norway is an EEA/EFTA State and not an EU Member State. Accordingly, the governing law of the SCCs is the law of Norway, on the basis that Norway is an EEA/EFTA State that has incorporated the GDPR into national law and recognises third-party beneficiary rights, and that the SCCs are read as adapted for an EEA/EFTA exporter in accordance with the guidance of the Norwegian Data Protection Authority (Datatilsynet). This harmonises the governing law of the SCCs with the governing law of the Agreement.
- (f) Clause 18 (Choice of forum and jurisdiction): any dispute arising from the SCCs shall be resolved by the courts of Norway; the parties agree to submit to the jurisdiction of the Trøndelag District Court (Trøndelag tingrett, Trondheim).
- (g) Annexes. Annex I (parties, description of transfer and competent supervisory authority), Annex II (technical and organisational measures) and Annex III (list of sub-processors) to the SCCs are populated by, respectively, Schedule 1, Schedule 2 and Schedule 3 of this DPA. The competent Supervisory Authority for Annex I.C is the Norwegian Data Protection Authority (Datatilsynet).
- Blocking precondition for non-EEA Sub-processor transfers. For the avoidance of doubt and consistent with clause 7.4, where a Sub-processor listed in Schedule 3 (including Resend) processes Customer Personal Data outside the EEA, the transfer mechanism relied upon for that Sub-processor must be identified and recorded in this Schedule 4 before that Sub-processor processes any Customer Personal Data outside the EEA. Resend's processing of Customer Personal Data is scoped in Schedule 3 (recipient e-mail addresses and operational notification content only). Recorded mechanisms: (i) Resend, Inc. — EU-US Data Privacy Framework certification (including the UK Extension), with the EU SCCs incorporated in Resend's Data Processing Addendum as a fallback; (ii) OpenAI — contracted via OpenAI Ireland Limited (EEA), with onward transfer to OpenAI, L.L.C. (United States) under the SCCs incorporated in OpenAI's Data Processing Addendum. Resend, Inc.'s active DPF certification (including the UK Extension) was confirmed against the dataprivacyframework.gov registry in the final legal review of 14 August 2026.
- UK and Swiss transfers. Where transfers of Customer Personal Data are subject to United Kingdom or Swiss data protection law, the SCCs apply as amended by the UK International Data Transfer Addendum (issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018), and/or with the adaptations required under the Swiss Federal Act on Data Protection, each of which is incorporated into this DPA by reference and applies automatically to the relevant transfer. As the Service is self-serve, these instruments apply proactively without further formality when a UK or Swiss Customer uses the Service.
- Supplementary measures. The parties shall apply such supplementary technical, organisational and contractual measures as are reasonably necessary to ensure that transferred Customer Personal Data enjoys a level of protection essentially equivalent to that guaranteed within the EEA, taking into account the measures in Schedule 2.
- Precedence. In the event of any conflict between the SCCs and this DPA in respect of a transfer governed by the SCCs, the SCCs prevail.