Data Processing Addendum
Last updated: 2026-07-06
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Quantum League AI ("Processor") and the customer organization — a federation, club, league, or team ("Controller") — and governs Quantum League's processing of personal data on the Controller's behalf under the EU/UK GDPR and comparable laws.
1. Parties & roles
The Controller determines the purposes and means of processing member, player, and guardian data. Quantum League acts as a Processor, processing that personal data only on the Controller's documented instructions (including as configured through the platform) except where required by law. Where Quantum League determines the means and purposes for its own operational data (e.g. account security), it acts as an independent Controller under its Privacy Policy.
2. Scope & purpose of processing
Quantum League processes personal data to provide the platform: account and roster management, registration and payments, scheduling, video capture and highlight generation, chat, and AI features. The subject matter is the provision of the Service; the duration is the term of the agreement; and the nature is storage, transmission, analysis, and display of personal data. Categories of data subjects include admins, coaches, players (including minors), and guardians. Categories of data include identity, contact, profile, participation, video/image, and payment metadata.
3. Subprocessors
The Controller authorizes Quantum League to engage the following subprocessors. We impose data-protection obligations on each and remain responsible for their performance. We will give notice of intended changes so the Controller may object.
- Firebase / Google Cloud
Authentication, database, storage, backend functions.
- Vercel
Web application hosting.
- Stripe
Payment and subscription processing.
- Mux
Video ingest, encoding, storage, streaming.
- Resend
Transactional and notification email delivery.
- OpenRouter / Anthropic
LLM inference for AI features.
- Cloudflare
Network security, DNS, CDN.
- Mixpanel
Product analytics for the web app (opt-in via cookie consent; disabled for known-minor accounts and under GPC/DNT signals).
- Sentry
Error monitoring (web app and backend).
4. Security measures
Quantum League implements appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit and at rest, role-based access control, least-privilege backend security rules, network protection, logging and monitoring, and internal access governance (as summarized in our security documentation). See the Trust Center for our current security posture.
5. Data-subject requests
Quantum League will, taking into account the nature of the processing, assist the Controller with appropriate measures to fulfill data-subject requests (access, rectification, erasure, portability, restriction, objection). Where a data subject contacts Quantum League directly, we will refer them to the relevant Controller unless legally required to act, and provide self-service tools in the platform where possible.
6. Personal data breach notification
Quantum League will notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Controller's data, and will provide the information the Controller needs to meet its own notification obligations. Our internal breach handling follows a documented incident-response runbook.
7. International transfers
Where processing involves transferring personal data outside the EEA/UK, the parties rely on the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary measures where required. These mechanisms are incorporated into this DPA by reference.
8. Audit rights
Quantum League will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates — subject to reasonable notice, confidentiality, and frequency limits. Where available, third-party reports and the Trust Center may satisfy audit requests.
9. Deletion or return on termination
On termination of the Service, Quantum League will, at the Controller's choice, delete or return the personal data it processes on the Controller's behalf, and delete existing copies unless retention is required by law. Backups are purged on a rolling schedule.
10. Contact
To request a countersigned DPA or ask questions, contact: privacy@quantumleagueai.com