Questa
  • Product
  • How it works
  • The app
  • Pricing
  • FAQ
Sign inStart for free
Legal · Organizations

Version 2026-10-09

Data Processing Agreement (DPA)

Version: 2026-10-09

This Data Processing Agreement ("Agreement" or "DPA") is entered into between the customer Organization ("Controller") and Questa ("Processor"), identified in Annex I, and forms an integral part of the Terms of Service for Organizations.

The Agreement is structured on the standard contractual clauses between controllers and processors adopted by the European Commission in Implementing Decision (EU) 2021/915 of 4 June 2021, under Article 28(7) of Regulation (EU) 2016/679 (GDPR), supplemented by annexes specific to the Questa service.

Section I

Clause 1 — Purpose and scope

a) This Agreement ensures compliance with Article 28(3) and (4) GDPR.

b) The Controller and the Processor listed in Annex I have accepted these clauses for that purpose.

c) The clauses apply to the processing of personal data described in Annex II.

d) Annexes I to IV are an integral part of the clauses.

e) The clauses are without prejudice to the obligations to which the Controller is subject under the GDPR.

f) The clauses do not, on their own, ensure compliance with the rules on international transfers in Chapter V GDPR.

Clause 2 — Invariability of the clauses

a) The parties will not modify the clauses, except to complete or update the information in the annexes.

b) The parties may include the clauses in a wider contract (the Terms of Service) or add further safeguards, provided these do not contradict the clauses or reduce the fundamental rights or freedoms of data subjects.

Clause 3 — Interpretation

a) Terms defined in the GDPR have the same meaning in these clauses.

b) The clauses are read and interpreted in light of the GDPR.

c) The clauses must not be interpreted in a way that runs counter to the rights and obligations in the GDPR or that prejudices the fundamental rights or freedoms of data subjects.

Clause 4 — Hierarchy

If these clauses conflict with any related agreement between the parties, whether existing or entered into later, these clauses prevail.

Clause 5 — Docking clause

Not applicable.

Section II — Obligations of the parties

Clause 6 — Description of processing

The details of the processing, including the categories of personal data and the purposes for which they are processed on behalf of the Controller, are set out in Annex II.

Clause 7 — Obligations of the parties

7.1. Instructions

a) The Processor processes personal data only on documented instructions from the Controller, unless required to do otherwise by Union or Member State law. In that case, the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Controller may give further instructions throughout the processing; they must always be documented.

b) The Controller's documented instructions are: the Terms of Service, this Agreement, and the way the Controller configures and uses the Platform through the backoffice (for example, creating events, importing or removing participants, publishing content, sending surveys or deleting data).

c) The Processor informs the Controller immediately if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

7.2. Purpose limitation

The Processor processes personal data only for the specific purposes set out in Annex II, unless it receives further instructions from the Controller.

7.3. Duration of the processing

Processing by the Processor takes place only for the period set out in Annex II.

7.4. Security of processing

a) The Processor implements at least the technical and organisational measures in Annex III to ensure the security of the personal data, including protection against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to the data (a personal data breach). In assessing the appropriate level of security, the parties take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks for data subjects.

b) The Processor gives its staff access to the personal data only to the extent strictly necessary to perform, manage and monitor the contract, and ensures that everyone authorised to process the data is bound by confidentiality.

7.5. Sensitive data

If the processing involves data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data used to uniquely identify a person, data concerning health, sex life or sexual orientation, or data relating to criminal convictions and offences ("sensitive data"), the Processor applies specific restrictions and/or additional safeguards. The service does not require sensitive data, and the Controller undertakes not to enter such data on the Platform without prior agreement.

7.6. Documentation and compliance

a) The parties must be able to demonstrate compliance with these clauses.

b) The Processor deals promptly and adequately with the Controller's enquiries about the processing under these clauses.

c) The Processor makes available to the Controller all information needed to demonstrate compliance with these clauses and with the GDPR. At the Controller's request, the Processor allows for and contributes to audits of the processing at reasonable intervals or where there are indications of non-compliance. In deciding on a review or audit, the Controller may take into account relevant certifications held by the Processor.

d) The Controller may carry out the audit itself or appoint an independent auditor. Audits may include inspections of the Processor's premises and are carried out with reasonable notice of at least 30 days, during business hours, without disrupting the service provided to other customers and under a confidentiality undertaking. Each party bears its own costs, unless the audit reveals a material breach by the Processor.

e) The parties make the information referred to in this clause, including audit results, available to the competent supervisory authorities on request.

7.7. Use of sub-processors

a) The Processor has the Controller's general authorisation to engage the sub-processors on an agreed list, set out in Annex IV. The Processor informs the Controller in writing of any intended addition or replacement of sub-processors at least 30 days in advance, so that the Controller has enough time to object. If the Controller objects on reasonable data protection grounds and the parties cannot find a solution, the Controller may terminate the Terms of Service without penalty. The Processor provides the information the Controller needs to exercise this right.

b) Where the Processor engages a sub-processor to carry out specific processing on behalf of the Controller, it does so by a contract that imposes on the sub-processor, in substance, the same data protection obligations as those imposed on the Processor under these clauses, and ensures that the sub-processor complies with them and with the GDPR.

c) At the Controller's request, the Processor provides a copy of that sub-processor agreement and any later amendments. To the extent necessary to protect business secrets or other confidential information, including personal data, the Processor may redact the text before sharing it.

d) The Processor remains fully responsible to the Controller for the performance of the sub-processor's obligations, and notifies the Controller of any failure by the sub-processor to fulfil them.

e) The Processor agrees with the sub-processor a third-party beneficiary clause under which, if the Processor has factually disappeared, ceased to exist in law or become insolvent, the Controller has the right to terminate the sub-processor contract and instruct the sub-processor to erase or return the personal data.

7.8. International transfers

a) Any transfer of data to a third country or international organisation by the Processor takes place only on documented instructions from the Controller, or to fulfil a specific requirement under Union or Member State law to which the Processor is subject, and in compliance with Chapter V GDPR. The Controller authorises the transfers resulting from the sub-processors listed in Annex IV, under the conditions described there.

b) Where a sub-processor engaged under Clause 7.7 carries out processing that involves a transfer within the meaning of Chapter V GDPR, the Processor and the sub-processor may ensure compliance by using standard contractual clauses adopted by the Commission under Article 46(2) GDPR, where the conditions for their use are met, or another valid mechanism such as an adequacy decision.

Clause 8 — Assistance to the Controller

a) The Processor promptly notifies the Controller of any request received from a data subject. It does not respond to the request itself unless the Controller has authorised it to do so.

b) Taking into account the nature of the processing, the Processor assists the Controller in responding to data subjects' requests to exercise their rights, following the Controller's instructions. The Platform gives the Controller tools to view, correct and remove participants and their content, and gives participants the ability to edit their profile and privacy settings and to delete their own account.

c) Taking into account the nature of the processing and the information available to it, the Processor also assists the Controller with:

  1. carrying out a data protection impact assessment where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons;
  2. consulting the competent supervisory authority before processing where such an assessment indicates a high risk that the Controller has not mitigated;
  3. keeping personal data accurate and up to date, by informing the Controller without delay if it becomes aware that data it processes is inaccurate or outdated;
  4. the obligations in Article 32 GDPR.

d) The appropriate technical and organisational measures through which the Processor provides this assistance are set out in Annex III.

Clause 9 — Notification of personal data breaches

In the event of a personal data breach, the Processor cooperates with and assists the Controller so that it can meet its obligations under Articles 33 and 34 GDPR, taking into account the nature of the processing and the information available to the Processor.

9.1. Breach concerning data processed by the Controller

Where the breach concerns data processed by the Controller, the Processor assists the Controller:

a) in notifying the breach to the competent supervisory authority without undue delay after the Controller becomes aware of it, where relevant (unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons);

b) in obtaining the information that the notification must contain under Article 33(3) GDPR, including at least the nature of the data, the categories and approximate number of data subjects and records concerned where possible, the likely consequences of the breach, and the measures taken or proposed to address it and mitigate its possible adverse effects. Where not all of this information can be provided at once, the initial notification contains what is available and the rest follows without undue delay as it becomes available;

c) in complying with the obligation under Article 34 GDPR to communicate the breach without undue delay to the data subject, where it is likely to result in a high risk to the rights and freedoms of natural persons.

9.2. Breach concerning data processed by the Processor

Where the breach concerns data processed by the Processor, the Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of it. The notification contains at least:

a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and records concerned);

b) the details of a contact point where more information about the breach can be obtained;

c) its likely consequences and the measures taken or proposed to address the breach, including to mitigate its possible adverse effects.

Where not all of this information can be provided at once, the initial notification contains what is available and the rest follows without undue delay as it becomes available. Notifications are sent to the email address of the Organization's owner registered on the Platform.

Any other information the Processor must provide when assisting the Controller under Articles 33 and 34 GDPR is set out in Annex III.

Section III — Final provisions

Clause 10 — Non-compliance and termination

a) Without prejudice to the GDPR, if the Processor breaches its obligations under these clauses, the Controller may instruct it to suspend the processing until it complies or the contract is terminated. The Processor promptly informs the Controller if it is unable to comply with these clauses for any reason.

b) The Controller may terminate the contract insofar as it concerns processing under these clauses if:

  1. the processing has been suspended under point (a) and compliance is not restored within a reasonable time, and in any event within one month of the suspension;
  2. the Processor is in substantial or persistent breach of these clauses or of its obligations under the GDPR;
  3. the Processor fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these clauses or the GDPR.

c) The Processor may terminate the contract insofar as it concerns processing under these clauses if, after informing the Controller that its instructions infringe applicable legal requirements under Clause 7.1(c), the Controller insists on compliance with those instructions.

d) After termination, the Processor, at the Controller's choice, either deletes all personal data processed on the Controller's behalf and certifies that it has done so, or returns all the personal data to the Controller and deletes existing copies, unless Union or Member State law requires the data to be retained. Until the data is deleted or returned, the Processor continues to ensure compliance with these clauses. If the Controller makes no choice within 30 days of termination, the data is deleted.

Clause 11 — Changes and acceptance

a) This Agreement is accepted electronically by the Organization's owner at registration or in the backoffice. Questa keeps a record of the acceptance (version, date and time, user and IP address).

b) Changes to the annexes, in particular to the list of sub-processors in Annex IV, follow Clause 7.7. A new version of the Agreement is announced in the backoffice and must be accepted within 30 days, as set out in the Terms of Service.


Annex I — List of parties

Controller: the Organization identified in the Platform account (organization name given at registration), represented by its owner, who accepts this Agreement on the Organization's behalf. Its identification and contact details are those registered on the Platform and are stored in the acceptance record.

Processor: Questa, VAT no. 240600070, Porto, Portugal. Data protection contact: info@questa.pt.

Annex II — Description of the processing

Categories of data subjects

  • Participants in the Controller's events (invited, imported or registered);
  • Administrators and members of the Organization with access to the backoffice.

Categories of personal data processed

  • Identification and contact: name, email and, if provided, phone number;
  • Profile: photo, institution, job title, social media links and language preference, as filled in by the data subject;
  • Event participation: registration, points and ranking, completed challenges, quiz answers, check-ins by QR code or challenge location, feed posts and comments, likes and reports;
  • Networking: connections between participants and the privacy settings that control what each one shares;
  • Event surveys: answers stored anonymously, with no link to the data subject; only whether the invitation was answered is recorded;
  • Technical data: device identifiers for push notifications, access and security logs.

Sensitive data processed: none intended (see Clause 7.5).

Nature of the processing: hosting, storage, organisation, consultation, display to participants and administrators, sending transactional emails (invitations, codes, surveys) and push notifications, backup and deletion.

Purpose(s): providing the Controller with the gamified events platform described in the Terms of Service, including technical support and service security.

Duration of the processing: for as long as the Terms of Service are in force. After termination, the data remains available for export for 30 days and is then deleted; backups are deleted in the normal rotation cycle, within 30 days at most. The Controller can remove participants, events and content at any time through the backoffice.

Sub-processors: see Annex IV.

Annex III — Technical and organisational measures

  • Confidentiality in transit: all communication with the Platform uses HTTPS (TLS).
  • Credentials: passwords are stored only as a hash (bcrypt); verification and recovery codes expire after 15 minutes and have an attempt limit.
  • Access control: role-based access to the backoffice (owner, admin); logical separation between organizations in every query; administrative access to servers limited to authorised staff, with key-based authentication.
  • Abuse protection: rate limiting, anti-bot verification at registration and manual approval of new organizations.
  • Data minimisation and privacy by default: participants control which profile fields they share in networking (by default, only name and photo); survey answers are anonymous by design.
  • Availability and resilience: periodic backups of the database and files, and the ability to restore them.
  • Updates: regular security updates to the operating system, web server and application dependencies.
  • Logging: error and access logs to detect and investigate incidents.
  • Staff: confidentiality undertaking by everyone with access to the data.
  • Assistance to the Controller: backoffice tools to view, correct and remove participants and content; requests handled through info@questa.pt; breach notification as set out in Clause 9.

Annex IV — Authorised sub-processors

Sub-processor Location Service Data involved
OVH SAS France (EU) Hosting of the server, database and files; email delivery All categories in Annex II
Google Ireland Limited (Firebase Cloud Messaging) Ireland (EU); may involve Google LLC, USA Delivery of push notifications to the apps Device identifier and notification content
Apple Distribution International Ltd. (Apple Push Notification service) Ireland (EU); may involve Apple Inc., USA Delivery of push notifications on iOS devices Device identifier and notification content

Any transfers to the USA resulting from the Google and Apple services rely on the adequacy decision for the EU-U.S. Data Privacy Framework and, in the alternative, on the European Commission's standard contractual clauses entered into by those providers.

In case of discrepancy between language versions, the Portuguese version prevails.

See also: Terms of Service for Organizations

Questa

The event gamification platform built for teams who care about engagement. Quests, leaderboards and live insights — all in one.

info@questa.pt+351 938 353 294
Product
FeaturesPricingThe appCreate a free accountSign in
Solutions
ConferencesUniversitiesHackathonsTrade showsCorporate eventsAssociations
Company
Resources & guidesBook a demoFAQContact
Legal
Terms & ConditionsPrivacy PolicyTerms for organizationsData Processing AgreementCookie preferences
© 2026 Questa. All rights reserved.Built in Portugal with

We use cookies

We use essential cookies to make the site work and, with your permission, analytics cookies to understand how it is used. You can change your mind at any time. Read the Privacy Policy