Skip to content
Quantummycos

Legal

Data processing agreement

When a company uses Quantummycos, its staff data is its own: the company decides what it is used for and Quantummycos processes it on the company’s behalf. This agreement sets out how.

Updated:

01Subject, parties and acceptance

This agreement governs the personal data processing that [[RAZÓN SOCIAL, S.L.]] (Quantummycos, the “processor”) carries out on behalf of the customer company (the “controller”) when providing it with the Quantummycos service, under article 28 of Regulation (EU) 2016/679 (GDPR) and article 33 of Spanish Organic Law 3/2018 (LOPDGDD).

It is part of the Terms and conditions. It is accepted when the company signs up in the application, and the date of acceptance is recorded. Companies that contract through another channel accept it when they place their order.

02Description of the processing

The processing entrusted is as follows.

ItemDetail
PurposeProviding the Quantummycos service: time tracking, absences, shifts, reviews, documents, reports, email notices and the AI assistant.
NatureRecording, storage, organisation, consultation, sending communications and erasure, by automated means.
DurationThat of the service contract, plus the retention period in the section “End of the processing”.
Data subjectsThe customer company’s employees and anyone else the company gives access to the application.
Types of dataIdentification and contact data; employment data (job title, department, contract, working hours, clock-ins, absences, shifts, reviews, documents, joining and leaving tasks); pay data, where the company enters it; sex, date of birth, national ID number and social security number, where the company enters them; location at clock-in, where the company switches it on; voluntary mood indicator; questions to the AI assistant; access and activity records; emails sent by the platform.
Special categoriesThe service does not need them. If the company enters them (a sick note attached to an absence, for instance), it does so under its own responsibility.

03Processor obligations

Quantummycos undertakes to:

  • Process the data only on the controller’s documented instructions, which are this agreement, the Terms and the way the company configures the service. If an instruction infringes data protection law, we will tell it straight away.
  • Not use the data for its own purposes, not disclose it except to authorised sub-processors, and not use it to train artificial intelligence models.
  • Ensure that anyone authorised to process the data has committed to confidentiality.
  • Apply the article 32 GDPR security measures described in the “Security measures” section of the Privacy policy.
  • Help the controller respond to data subjects’ requests, through the application’s own features (viewing, correcting, exporting and erasing) and by passing on without delay any request that reaches us directly.
  • Help the controller comply with articles 32 to 36 GDPR (security, breaches, impact assessments and prior consultation) with the information available to us.
  • Notify it without undue delay of any personal data breach we become aware of, with the information it needs to meet its own obligations.
  • Make available to it the information needed to demonstrate compliance with this agreement, and allow the audits described below.

04Sub-processors and international transfers

The controller gives Quantummycos general authorisation to use the providers listed in the “Who we share data with” section of the Privacy policy, insofar as they process the company’s data to provide the service.

Before adding or replacing a sub-processor, we will update that list and tell the company by email, at its contact address, at least fifteen days in advance. The controller may object within that period; if we cannot find an alternative, it may terminate the contract without penalty.

Each sub-processor is bound by contract to the same data protection obligations this agreement places on Quantummycos, which remains liable for their compliance. Transfers outside the European Economic Area always rely on a Chapter V GDPR safeguard: an adequacy decision or standard contractual clauses.

05Controller obligations

The customer company, as controller, undertakes to:

  • Have a legal basis for the data it enters and have informed its staff about it, including what article 90 LOPDGDD and article 20.3 of the Spanish Workers’ Statute require if it switches on location at clock-in.
  • Enter only the data needed for the purposes it pursues.
  • Assign the application’s roles and permissions appropriately and safeguard its staff’s access credentials.
  • Give its instructions in writing and oversee the processing.

06End of the processing

While the account is active, the company can export its data from the application.

When the contract ends, the data is kept blocked for four years, the period for which article 34.9 of the Spanish Workers’ Statute requires the company to keep its time records, so that it can meet that obligation. During that time it is accessed only to respond to the company itself, the competent authorities or the courts. The company can ask at any time for the data to be returned or erased sooner. Once the period is over, it is deleted securely.

07Audits, term and applicable law

The controller may request the information it needs to verify compliance with this agreement by writing to info@quantummycos.com. If it also wishes to carry out an audit, itself or through an independent auditor bound by confidentiality, it will give thirty days’ notice, bear the cost, and not repeat it more than once a year unless there has been a security breach.

This agreement lasts as long as the service contract, and its confidentiality and retention obligations survive it. It is governed by Spanish law and by the GDPR.