Data Processing Addendum
Last updated: 24 August 2026
This page states the data-processing commitments supported by the current Quantara implementation for customer project data processed through the service.
It is intended to be incorporated into an applicable written customer agreement. The verified legal entity, contract particulars and transfer terms must be completed before it can operate as a final signed addendum.
Roles and instructions
A business customer normally determines why authorized project personal data is processed and acts as controller or equivalent decision-maker. Quantara processes that customer data to provide the selected service and may separately control account, security, billing and business-contact records.
Documented instructions consist of the customer's use of supported features, settings, requests and the applicable written agreement. Quantara will not use customer project data for an unrelated purpose without a valid legal basis or instruction.
Subject matter and data categories
Processing covers hosting, organizing, extracting, reviewing, validating, generating, supporting, securing and deleting authorized Quantara records for the service term and any justified retention period.
- Authorized user names, business contact details, company identifiers, roles and access records.
- Project files, extracted content, BOQ records, quantities, units, rates, templates, revisions, findings and generated documents.
- Client, supplier, project-team or other business contact data the customer chooses to include.
- Selected integration metadata, encrypted OAuth credentials and imported content when an optional integration is enabled.
- Subscription and billing identifiers required for configured commercial services.
Categories of people
Data may relate to customer users, employees, contractors, clients, suppliers, consultants and other project stakeholders whose information the customer is authorized to process.
Confidentiality and security
Access to customer data must be limited to authorized personnel and service operations. Customers are responsible for assigning appropriate users and protecting their own credentials.
Implemented measures include hashed passwords and session tokens, role and company authorization, private production object-storage configuration, audit records and encryption of stored OAuth credentials. The Security page describes limitations and does not claim certification.
Subprocessors and transfers
Quantara may use infrastructure and optional service providers only for documented operational purposes. The Subprocessors page distinguishes conditional provider paths from production facts that still require confirmation.
Before customer data is processed outside the UAE, the active provider, region and appropriate transfer safeguard must be identified in the applicable terms. No safeguard is inferred from a software dependency alone.
Security incidents and assistance
Quantara will investigate suspected unauthorized access affecting customer personal data, take reasonable containment steps, preserve relevant records and provide information needed for the customer's obligations when the facts and applicable law require it.
Reasonable assistance will be provided for valid data-subject requests, security assessments and regulatory enquiries in light of the available information and the agreed service. No unverified response or notification deadline is promised here.
Return, deletion and retention
On a valid customer instruction or service closure, supported data will be returned or deleted where technically available, subject to legal obligations, security records and an agreed backup process. Some project deletion paths archive records rather than immediately erasing every related record.
Account, project, enquiry, billing, audit and backup retention varies by category and legal need. Any customer-specific return, erasure or backup-deletion schedule must be stated in the written agreement.
Information and review
Quantara will make available reasonable information about the implemented controls and relevant providers so a customer can assess the service. Any audit process, cost allocation and confidentiality controls must be set in the written agreement.
Particulars requiring completion
- Registered processor entity, address and authorized signatory.
- Active production hosting, database, object-storage and email providers and their regions.
- Cross-border locations and contractual or other transfer safeguards.
- Retention, return, erasure and backup-deletion schedule by data category.
- Contractual incident-notification process and customer escalation contacts.
Customer-specific contracting details, service regions, transfer safeguards, retention requirements and commercial terms are confirmed in the applicable order form, quotation or written agreement before a paid enterprise commitment.
Contact and privacy requests
Use the verified channels below for privacy rights, security reports, legal questions and support. Do not send passwords, authentication tokens or confidential project documents by email or WhatsApp.
- Email: solution@vistabylara.com
- Telephone: +971 50 799 4292
- WhatsApp: +971 50 799 4292