Data Processing Terms

Last updated: October 2026

These terms summarize how Qcorp AI Technology Ltd ("Qcorp.ai") processes personal data contained in the advertising, analytics and website data that a customer connects to the Qcorp.ai Beta Service (the "Customer Data"). They form part of the Terms of Service and apply where Qcorp.ai acts as a processor or service provider for the customer.

1. Roles

The customer is the controller (or the equivalent under applicable law) of Customer Data and Qcorp.ai is the processor. For personal data of Site visitors and waitlist applicants, Qcorp.ai is the controller as described in the Privacy Policy.

2. Subject matter and purpose

Qcorp.ai processes Customer Data only to provide the Service as instructed by the customer: analysing sites and campaigns, operating connected ad accounts within the permissions the customer grants, reporting metrics, and supporting and securing the Service. The data may include ad account identifiers, campaign and performance data, conversion and analytics data, website content and metadata, and business contact details of the customer's personnel. Processing lasts for the term of the customer's access and any short period needed to return or delete data.

3. Instructions

We process Customer Data on the customer's documented instructions, which include the customer's configuration of the Service and these terms. We will tell the customer if we believe an instruction breaches data protection law.

4. Confidentiality and security

Personnel with access to Customer Data are bound by confidentiality. We apply technical and organizational measures appropriate to the risk, including encrypted transport, access control, least-privilege access to connected accounts, and logging of agent actions.

5. Sub-processors

We may engage sub-processors such as hosting and infrastructure providers, under written terms that provide protection no less protective than these terms, and remain responsible for them. We will inform customers of material sub-processor changes in advance and customers may object on reasonable data protection grounds.

6. International transfers

Where processing involves transfers of personal data from the EEA, the UK or another jurisdiction that restricts transfers, we will use an appropriate transfer mechanism, such as standard contractual clauses, and will enter into them on request.

7. Assistance and rights

Taking into account the nature of processing, we will reasonably assist the customer in responding to data subject requests and with security, breach notification, impact assessments and consultations with regulators.

8. Personal data breaches

We will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information reasonably available to help the customer meet its obligations.

9. Return and deletion

On termination of access, or on the customer's written request, we will delete or return Customer Data within a reasonable period, unless law requires us to keep it. Disconnecting the customer's accounts stops further access.

10. Audits

On reasonable notice, and no more than once a year unless a breach has occurred, we will make available information necessary to show compliance with these terms and allow for audits conducted under appropriate confidentiality.

11. Customer responsibilities

The customer confirms it has a lawful basis and all required notices and consents to provide Customer Data to us, and is responsible for the lawfulness of its advertising and data collection.

12. Precedence and contact

If these terms conflict with another agreement on data processing signed by both parties, the signed agreement prevails. Data protection requests: cbdo@qcorpai.com. A fuller data processing agreement is available on request.