This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Agreement (as defined in the Quant Flow Terms and Conditions) between Quant Network Limited (“Quant”) (also “we”, “us”, “our” and “ours”) and the Customer (also “you”, “your”, “yours) (each a “Party” and together the “Parties”).
Quant will provide the Customer with the Services (including certain API technology and open banking services, as set out in the Agreement), and may process personal data on behalf of the Customer in doing so. This DPA sets out the requirements of processing this data under applicable Data Protection Legislation.
This DPA is effective on the Effective Date (as defined in the other documents comprising the Agreement), unless this DPA expressly states otherwise. This DPA must be read in conjunction with the other documents comprising the Agreement, including the Quant Flow Terms and Conditions.
1. Definitions and Interpretation
Definitions
1.1 In this DPA capitalised terms shall have the following meanings:
-
-
“Adequate Country” means a country or territory recognised as providing an adequate level of protection for Personal Data under an adequacy decision made, from time to time, by (as applicable) (i) the Secretary of State, the Information Commissioner’s Office (“ICO”) and/or under applicable UK law (including the UK GDPR), or (ii) the European Commission under EU GDPR.
-
“Data Protection Legislation” means all data protection and privacy laws applicable to any Personal Data, including:
(a) in the EEA, the General Data Protection Regulation 2016/679 (“EU GDPR”) and the Privacy and Electronic Communications Directive 2002/58/EC, and
(b) in the United Kingdom (the “UK”), the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”); the Data Protection Act 2018; the Data (Use and Access) Act 2025; and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“ePrivacy Regulation”), as amended from time to time, including their transposition into the national law of the states in the EEA; -
“Data Subject Request” means a request from or on behalf of a data subject to exercise any rights in relation to their Personal Data under Data Protection Legislation;
-
“EEA” means the European Economic Area (the area which currently comprises the EU Member States together with Iceland, Liechtenstein and Norway);
-
“EU SCCs” means Commission Decision 2021/914/EU of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (set out at http://data.europa.eu/eli/dec_impl/2021/914/oj);
-
“Personal Data” means all personal data which Quant accesses, stores or otherwise processes on behalf of the Customer as part of its provision of the Services to the Customer under the Agreement;
-
“Security Breach” means any breach of security or other action or inaction leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data by Quant or its sub-processors or any other identified or unidentified third party;
-
“Services” has the meaning given to it in the Agreement;
-
“Supervisory Authority” means:
(a) in the EEA, the General Data Protection Regulation 2016/679 (“EU GDPR”) and the Privacy and Electronic Communications Directive 2002/58/EC, and
(b) in the EEA, an independent public authority established pursuant to EU GDPR;
“UK Addendum” means the EU SCCs as amended and incorporated into the International Data Transfer Addendum approved by the UK Information Commissioner and adopted by the UK under section 119A(1) of the Data Protection Act 2018; and
“controller”, “data subject”, “personal data”, “personal data breach”, “process/processing”, “processor” have the meanings given to them in the Data Protection Legislation.
“Yapily” means:
(a) Yapily Connect UAB, a limited liability company registered in Lithuania, registration number 305602679 and registered office at Palangos st. 4-101, 01402, Vilnius, the Republic of Lithuania (“Yapily EU”);
(b) Yapily Connect Ltd, a limited liability company registered in England and Wales, with company number 11598433 and registered office at 86-90 Paul Street, London, England, EC2A 4NE, United Kingdom (“Yapily UK”); and
(c) Yapily Limited, a limited liability company registered in England and Wales under company number 10842280 having its registered office at 86-90 Paul Street, London, England, EC2A 4NE, United Kingdom (“Yapily Limited”).
-
1.2 In this DPA (including the introduction and schedules) unless the context otherwise requires:
(a) any defined terms not defined in this DPA are as defined in the Agreement;
(b) references to legislation or guidance are to that legislation or guidance as amended, supplemented or replaced;
(c) reference to “including” or any similar terms are by way of example and do not limit the general applicability of any preceding words;
(d) references to recitals, clauses, paragraphs or schedules are to recitals, clauses, paragraphs or schedules of this DPA;
(e) clause headings do not affect the interpretation of this DPA;
(f) reference to a person includes a legal person (such as a limited company) as well as a natural person;
(g) reference to a gender is to any gender; and
(h) the singular includes the plural and vice versa.
2. Roles and Compliance with Data Protection Legislation
2.1 Each Party will comply with Data Protection Legislation applicable to Personal Data.
2.2 The Customer is the controller of Personal Data, and Quant is the processor of Personal Data.
2.3 The Customer acknowledges that: (i) this DPA solely relates to Quant’s processing of Personal Data; (ii) this DPA does not relate to Quant’s processing of personal data on behalf of Yapily, where Yapily is controller of such personal data; and (iii) the Customer may separately enter into the Yapily End User Terms (as referenced in the Quant Flow Terms and Conditions) or other agreements with third parties, and that this DPA does not address the processing of personal data under or in relation to the Yapily End User Terms, or such other agreements with third parties.
3. Description of Processing
3.1 The subject matter, duration, nature and purpose of the processing, categories of data subjects, and the types of Personal Data processed under this DPA are as described in Schedule 1 (Description of Processing) to this DPA.
4. Processing by Quant
4.1 Quant will:
(a) only process Personal Data in order to provide the Services in accordance with the Agreement (which includes this DPA) and the Customer‘s written instructions, each as updated from time to time by written agreement of the Parties, unless otherwise required under Applicable Law (including EEA and UK laws);
(b) if Applicable Law requires Quant to process Personal Data other than on the Customer‘s instruction, Quant will notify the Customer (unless prohibited from so doing by Applicable Law); and
(c) promptly inform the Customer if, in Quant’s opinion, any of the Customer’s instructions under clause 4.1(a) infringe applicable Data Protection Legislation.
5. Technical and Organisational Security Measures
5.1 Quant will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks of processing Personal Data, in particular protection against any Security Breach. Such measures include, without limitation, the security measures set out in Schedule 2 (Security Measures).
5.2 Quant will ensure that only authorised personnel have access to Personal Data and that any such authorised personnel are under appropriate obligations of confidentiality.
6. Security Breaches, Data Subject Requests, and Further Assistance
6.1 Security Breaches. Quant will notify the Customer of any Security Breach without undue delay, and within forty-eight (48) hours of becoming aware of any such Security Breach.
(a) Quant will promptly provide the Customer with reasonable cooperation and assistance in respect of a Security Breach and with all reasonable information in Quant’s possession concerning the Security Breach, including:
(i) the possible cause and consequences for the data subjects of the Security Breach;
(ii) the categories of Personal Data involved;
(iii) a summary of the unauthorised recipients of the Personal Data; and
(iii) the measures taken by Quant to mitigate any damage.
6.2 Data Subject Requests. Quant will promptly notify the Customer if it receives a Data Subject Request. Quant may respond to a Data Subject Request solely to confirm that such request relates to the Customer.
6.3 Further Assistance. Taking into account the nature of processing and the information available to Quant, Quant will provide such assistance as the Customer reasonably requests in relation to the Customer’s obligations under Data Protection Legislation with respect to:
(a) data protection impact assessments;
(b) in response to a Security Breach, notifications to a Supervisory Authority under Data Protection Legislation and/or communications to data subjects by the Customer; or
(c) the Customer’s compliance with its obligations under the Data Protection Legislation with respect to the security of processing and Data Subject Requests.
7. Sub-processing
7.1 The Customer grants a general authorisation to Quant to appoint sub-processors to support the performance of the Services, including “know your client” (KYC) or “know your business” (KYB) providers, open banking service providers, payment services providers (as defined in Payment Services Legislation), data centre operators, cloud-based software providers (including CRM software), and outsourced support and service providers.
7.2 Quant’s sub-processors are set out at Schedule 3 (Processors) and Quant will notify the Customer of any new or replacement sub-processors to this list prior to them processing Personal Data.
(a) If the Customer objects to any new or replacement sub-processor, it will notify Quant of such objections in writing within ten (10) days of the notification, and the Parties will seek to resolve the matter in good faith.
(b) If the Customer does not provide a timely objection to any new or replacement sub-processor in accordance with this clause 7.2, the Customer will be deemed to have consented to the sub-processor and waived its right to object.
(c) If the Parties cannot resolve the matter in good faith within sixty (60) days of such notification, the Customer’s sole and exclusive remedy is the option to terminate the Agreement only in relation to the Services to which the proposed new sub-processor’s processing of Personal Data relates or would relate by providing written notice to Quant having effect thirty (30) days after receipt by Quant.
(d) Quant may use a new or replacement sub-processor whilst the objection procedure in this clause 7.2 is in process.
7.3 Quant will enter into a written contract, which imposes terms no less protective of Personal Data than those imposed on Quant in this DPA, with any sub-processor it engages in connection with this DPA, subject to the standard data processing terms sub-processors may impose on Quant (the “Relevant Terms”). Quant will ensure sub-processors’ performance of the Relevant Terms. Quant will be liable to the Customer for any breach of the Relevant Terms by a sub-processor, to the extent required under Data Protection Legislation.
7.4 To the extent that Quant transfers any Personal Data to a sub-processor that processes Personal Data outside the UK or EEA (except if in an Adequate Country), Quant shall in advance of such transfer take steps to implement a legal mechanism to achieve adequacy in respect of that processing under Data Protection Legislation (such as reliance on the sub-processor’s binding corporate rules, the EU SCCs, or the UK Addendum).
8. International Transfers
8.1 The Customer agrees that its use of the Services may involve the transfer of Personal Data to, and processing of Personal Data in, locations outside of the UK and/or EEA from time to time, including processing in the UK, the EEA and United States and any country in which Quant and authorised sub-processors perform the Services. Quant will ensure any such transfer or other processing complies with Data Protection Legislation, including implementing a transfer safeguard (such as the EU SCCs or UK Addendum, or reliance on an adequacy decision made under applicable EU/EEA or UK law).
(a) To the extent Quant processes Personal Data subject to EU GDPR in the UK, the Customer acknowledges that the UK is an Adequate Country.
(b) To the extent Quant processes Personal Data subject to UK GDPR in the EEA (including the Republic of Lithuania), the Customer acknowledges that the relevant importing country is an Adequate Country.
8.2 If the UK ceases to be an Adequate Country for the purposes of EU GDPR or if any EU member state ceases to be an Adequate Country for the purposes of UK GDPR, the Parties agree to make such changes to this clause 8 as are reasonably necessary under Data Protection Legislation, by written agreement between the Parties specifying the new transfer mechanism.
9. Audit and Records
9.1 Quant will permit the Customer’s third party representatives to audit Quant’s compliance with its obligations under this DPA, on at least 30 days’ written notice. Quant will make available to the Customer such information in Quant’s possession or control as the Customer may reasonably request with a view to demonstrating Quant’s compliance with this DPA, and give the Customer and its third party representatives all necessary assistance to conduct such audits at no additional cost to the Customer. The Customer must conduct its audit during normal business hours, and ensure its auditors have agreed to appropriate confidentiality obligations.
9.2 Notwithstanding clause 9.1, in the event of any Security Breach, or upon the instruction of a Supervisory Authority, Quant will permit the Customer’s appointed third party auditors to carry out an audit of Quant’s premises and operations to the extent reasonably required to confirm Quant’s compliance with this DPA.
10. Deletion or Return of Data
10.1 Quant will, as soon as reasonably practicable following, and in any event within sixty (60) days of, termination or expiry of the Agreement or completion of the Services, delete or return to Customer (at the Customer’s direction) all Personal Data.
11. General
11.1 Conflicts. This DPA is without prejudice to other rights and obligations of the Parties under the Agreement (including the Order Schedule or the Quant Flow Terms and Conditions )which will continue to have full force and effect. In the event of any conflict between the terms of this DPA and other terms of the Agreement (including the Order Schedule or the Quant Flow Terms and Conditions), the terms (including definitions) of this DPA will prevail so far as the subject matter concerns the processing of personal data.
11.2 Limitation of liability. Quant’s maximum aggregate liability to the Customer under or in connection with this DPA will not under any circumstances exceed the maximum aggregate liability of Quant to Customer as set out in the Quant Flow Terms and Conditions. Nothing in this DPA will limit Quant’s liability in respect of personal injury or death in negligence or for any other liability or loss which may not be limited by agreement under Applicable Law.
11.3 Entire agreement. Without prejudice to clause 11.1, this DPA sets out all of the terms that have been agreed between the Parties in relation to the subjects covered by it. Other than in respect of statements made fraudulently, no other representations or terms apply or form part of this DPA.
11.4 Third Party Rights. A person who is not a party to this DPA will not have any rights under the Contracts (Rights of Third Parties) Act 1999 of the UK or otherwise to enforce any term of this DPA.
11.5 Governing Law and Jurisdiction. This DPA is governed by the laws which govern the Quant Flow Terms and Conditions, and the venue(s) for disputes and claims under the Quant Flow Terms and Conditions apply to disputes and claims under this DPA.
Schedule 1: Description of Processing
The subject matter, duration, nature and purpose of the processing, categories of data subjects, and the types of Personal Data processed under this DPA are as follows:
(a) Subject Matter of the Processing: Quant’s provision of the Services to the Customer, other than the provision of Account Information Services (or AIS) and Payment Initiation Services (or PIS). As set out in the Agreement, AIS and PIS are provided subject to the Yapily End User Terms.
(b) Nature and Purpose of the Processing: the collection, analysis, storage, duplication, deletion and disclosure as necessary to provide the Services and as may be further instructed by the Customer in writing.
(c) Duration of Processing: Quant will process Personal Data for the duration of the Agreement, or until Personal Data is no longer necessary for the purposes of either Party performing its obligations under the Agreement (to the extent applicable), unless otherwise agreed between the Parties in writing.
(d) Categories of Data Subjects: data subjects may include the Customer’s end-users, payors, payees, employees/staff, and suppliers about whom Personal Data is provided to Quant via the Services by (or at the direction of) the Customer.
(e) Types of Data: data relating to individuals provided to Quant via the Services, by (or at the direction of) the Customer, including:
(i) Identification and contact details: first name, last name, email address, phone number, address, log-in details or other online user credentials;
(ii) Account data: sort code/account number, IBAN, SWIFT, account name, account nickname, type, balance, currency;
(iii) Transaction data: transaction ID, amount, currency, reference, payee, other transaction details;
(iv) Automatically collected information: Internet Protocol (IP) address, technical information including hardware model, operating system, browser data, time zone setting, location, device ID, and network/browsing activity; and
(v) Special category data: N/A. Customer will not provide special categories of personal data to Quant.
Schedule 2: Security Measures
-
Purpose and Scope
Quant shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing of personal data under the Agreement. These measures shall take into account Quant’s role in the provision of Account Information Services (AIS) and Payment Initiation Services (PIS) under the Agreement and Yapily End User Terms, including Quant’s role in the UK as a PSD Agent of Yapily UK in respect of AIS. Quant shall ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, and shall comply with all applicable obligations under data protection and financial services regulations. -
Organisational Governance and Compliance
Quant shall maintain robust organisational controls, including designation of a senior individual responsible for information security. All personnel authorised to access personal data shall be subject to appropriate confidentiality obligations and shall receive regular training in data protection, secure payment handling, and cybersecurity. A formal risk management process shall be in place, covering technological, operational, and data protection risks, including those specific to AIS and PIS. Quant shall ensure that any sub-processors or service providers are subject to appropriate due diligence and are bound by contractual terms that impose equivalent data protection and security obligations. -
Physical and Environmental Security
Personal data shall be hosted in secure, access-controlled environments. Quant shall use cloud infrastructure or data centres that are certified to ISO/IEC 27001, or equivalent. Access to physical premises where data is stored or processed shall be restricted using badge or biometric authentication, with appropriate monitoring and logging. All hardware or storage media containing personal data shall be securely erased or destroyed prior to disposal to prevent any data recovery. -
Identity and Access Management
Quant shall implement strict access control mechanisms to ensure that personal data is only accessible to authorised individuals. Role-based access controls and the principle of least privilege shall be enforced across all systems. Multi-factor authentication (MFA) shall be required for all administrative and privileged access. Quant shall maintain detailed audit logs of access to AIS and PIS systems, and these logs shall be retained for a period of at least five (5) years. Access logs shall be subject to regular monitoring and review to detect unauthorised activity. -
Data Encryption and Security in Transit and at Rest
All personal data shall be encrypted in transit using strong TLS protocols (TLS 1.2 or higher), and at rest using AES-256 or equivalent encryption. Encryption keys shall be stored securely using a key management system (KMS) with access restricted to authorised personnel only. Quant shall ensure that all Quant Flow APIs and communication interfaces used for AIS and PIS are protected using mutual TLS, OAuth 2.0 with PKCE, and other authentication and authorisation mechanisms as required under applicable open banking frameworks or Payment Services Legislation. -
Consent Management and Authorisation
Quant shall obtain, record, and manage user consents in a manner consistent with Payment Services Legislation and applicable open banking requirements. Consent mechanisms shall clearly specify the scope, duration, and purpose of access. AIS consents shall not be retained for longer than the maximum permitted period (e.g. ninety (90) days under the UK open banking standards), and PIS consents shall be strictly single-use or purpose-limited. Consent revocation functionality shall be provided to users, and any revoked access tokens shall be immediately invalidated within Quant’s systems. Quant shall not access or retain personal or financial data in the absence of a valid and current user consent. -
Data Minimisation and Retention
Quant shall ensure that only the minimum necessary personal data is accessed or stored to fulfil each specific Payment Transaction (as defined in the Quant Flow Terms and Conditions). Payment and account information shall be limited to the required scope, and unnecessary data shall not be collected. Sensitive data, such as payment authentication details, shall never be stored after authorisation. Where personal data must be retained for compliance or audit purposes, it shall be pseudonymised or tokenised where feasible. Quant shall implement a documented retention schedule to ensure that data is deleted or anonymised when no longer necessary for the stated purpose. -
Business Continuity and System Resilience
Quant shall maintain a business continuity and disaster recovery plan to ensure the resilience of critical services. Systems shall be designed for high availability, including redundancy, automatic failover, and load balancing where appropriate. Encrypted backups shall be performed on a regular basis and tested periodically to ensure recoverability. Quant shall define and maintain recovery point objectives (RPO) and recovery time objectives (RTO) that are proportionate to the importance of the services provided. -
Incident Detection and Breach Notification
Quant shall implement real-time monitoring tools and maintain an incident response plan that includes procedures for containing, investigating, and reporting personal data breaches or payment-related security incidents. Any such breach shall be reported to the Customer (the controller) without undue delay and, where applicable, to the competent Supervisory Authority within seventy two (72) hours of becoming aware. In the case of payment service-related incidents, Quant shall comply with reporting obligations under Payment Services Legislation and shall notify the relevant Authority as required. Incident logs and root cause analyses shall be documented and retained. -
Security Testing and Independent Assurance
Quant shall conduct regular internal and external assessments of its information security measures. This shall include vulnerability assessments, static and dynamic code analysis, and at least one independent penetration test annually. All material findings from such assessments shall be tracked and remediated promptly. -
Review and Continuous Improvement
Quant shall review and update its security measures at regular intervals to ensure continued effectiveness in light of technological advancements, changes in regulatory requirements, and evolving threats. Quant shall also ensure that all measures described in this Schedule 2 remain proportionate to the nature, scope, and context of the data processing and the risks to the rights and freedoms of data subjects.
Schedule 3: Processors
| Processor entity | Services | Location | Transfer safeguard |
| Yapily Limited | Open Banking API aggregation | EU/UK-hosted | No transfers outside EEA |
| Sum and Substance Limited | KYC/KYB onboarding verification | EU and other possible locations | SCCs apply; must verify data storage regions |
| Stripe Payments UK Limited | Billing, subscriptions, and payments | U.S. and EU options | SCCs apply; EU data residency option available |
| HubSpot (unspecified entity, UK terms apply) | CRM, email marketing, customer support, User support (tickets, chat, logs) | U.S. (some EU modules possible) | SCCs apply; EU data hosting possible for modules |
| Google LLC | Website and onboarding analytics | U.S. | SCCs with additional safeguards; consent platform required |
| Microsoft Ireland Operations Limited | Session replay and heatmaps | U.S. | SCCs may apply; disable sensitive session capture |