Data Processing Agreement

Marginal AI · Last updated 28 September 2026

Parties, scope and definitions

This Data Processing Agreement (“DPA”) forms part of the agreement between the business customer identified in the Order or other applicable business contract (“Customer”) and the Quantimental Technologies Ltd legal entity identified as its contracting provider (“Provider”). It applies to personal data Provider processes on Customer’s behalf to provide the contracted Marginal AI services.

“Applicable Data Protection Law” means the data protection and privacy laws applicable to the relevant processing, including, where applicable, the EU General Data Protection Regulation, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection and applicable US state privacy laws, in each case as amended and to the extent in force.

“Customer Data” means information submitted by or on behalf of Customer through the contracted services, including prompts, research questions, files, configuration information and API requests, and outputs to the extent they contain or reveal that information. It does not transfer ownership of Provider’s independently obtained source data or technology.

“Customer Personal Data” means personal data in Customer Data that Provider processes on Customer’s behalf. Other data-protection terms have their meanings under Applicable Data Protection Law. References to this DPA include its agreed schedules.

Roles and processing particulars

Customer is controller and Provider is processor for Customer Personal Data. If Customer acts as processor for another controller, Provider is its subprocessor and Customer confirms that the appointment and instructions are authorised.

The Processing Schedule identifies the processing subject matter, duration, nature, purpose, categories of individuals and personal data, and Customer’s rights and obligations. The parties will agree an extension of the scope before carrying out additional processing outside that schedule.

A party is an independent controller only for processing whose purposes and essential means it independently determines. Such processing must be separately identified and supported by the required lawful basis and transparency information. The use of the same brand, a common shareholder or a contracting-company designation does not determine these roles by itself.

Instructions and Customer obligations

Provider will process Customer Personal Data only on Customer’s documented instructions, including instructions concerning international transfers. The agreement, completed schedules, Customer’s authorised use of the contracted services and authorised support instructions form those instructions within the agreed scope.

If Provider is legally required to process without Customer’s instructions, it will do so only to the extent permitted by Applicable Data Protection Law and will inform Customer beforehand unless the law prohibits that information. This provision does not expand an exception permitted by a mandatory transfer instrument.

Provider will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Provider may suspend the affected processing while the parties resolve the issue and will not knowingly carry out an unlawful instruction.

Customer is responsible for lawful instructions, an appropriate lawful basis, required notices and authorisations, and ensuring that submitted data falls within the agreed scope. These responsibilities do not relieve Provider of its own obligations.

Confidentiality, security and use restrictions

Provider will limit access to Customer Personal Data to authorised persons who need it for the permitted processing and are bound by appropriate confidentiality obligations.

Provider will maintain technical and organisational measures appropriate to the nature and risks of the processing, including the measures specified in the Security Schedule and those required by Applicable Data Protection Law. Changes to measures will not materially reduce the overall protection provided or breach an express contractual commitment.

Provider will not sell Customer Personal Data, disclose it for a third party’s independent model training, or use it for purposes outside Customer’s documented instructions except as expressly permitted by this DPA and Applicable Data Protection Law.

General language about improving the Service does not authorise Provider to use Customer Personal Data or Customer’s confidential information to train models or improve services for other customers for Provider’s own purposes. Any separately agreed additional processing must specify its purpose, the parties’ roles and its lawful basis, and must not be inconsistent with applicable processor or service-provider restrictions.

Processing necessary to deliver the requested service, provide authorised support and protect that service remains permitted within Customer’s instructions. Genuinely anonymous statistics may be used only where their creation and use are lawful and do not disclose Customer’s confidential information. Removing direct identifiers or hashing information does not, by itself, make it anonymous.

Subprocessors

Customer gives general written authorisation for the subprocessors identified in the Subprocessor Schedule supplied with the agreement. Provider will inform Customer in advance of a proposed addition or replacement, with sufficient time to give a meaningful opportunity to object on reasonable data-protection grounds before the affected processing begins.

The parties will work in good faith to resolve a reasonable objection. If no reasonable solution is available, Customer may terminate the affected services before the new processing begins and receive a refund of prepaid subscription fees attributable to the unused affected services. Unaffected services remain governed by the agreement.

Provider will bind each subprocessor to the data-protection obligations required for its processing, including protections no less protective than the applicable obligations imposed on Provider by this DPA. Provider remains responsible to Customer for performance of those obligations by its subprocessors.

An affiliate is not exempt from these requirements merely because it shares a name or ownership with Provider. A supplier chosen by Customer for Customer’s independent agent is not automatically Provider’s subprocessor; the relevant processing role depends on the actual arrangement.

Personal data breaches

Provider will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. It will provide the information then available about the breach, the affected data and individuals, likely consequences, steps taken or proposed, and a contact for further information. Information may be provided in stages without undue further delay.

Provider will take appropriate steps to contain, investigate and remedy the breach and reasonably assist Customer with required notifications. Notification will not be delayed solely because an investigation is incomplete. Each party remains responsible for notifications required of it by law.

Assistance and individuals’ requests

Taking account of the nature of processing and the information available to it, Provider will assist Customer with obligations concerning individuals’ rights, security, breach notifications, data protection impact assessments and consultation with supervisory authorities.

Provider will promptly pass to Customer requests it receives concerning Customer Personal Data and will not respond substantively except on Customer’s instructions or as legally required. Requests concerning Provider’s separate controller processing remain Provider’s responsibility.

Any lawful charge for exceptional assistance must be reasonable and agreed in advance and must not prevent compliance with mandatory obligations. Provider will not charge Customer for work necessary to remedy Provider’s own breach of this DPA.

Compliance information and audits

Provider will make available the information necessary to demonstrate compliance with its applicable processor obligations and will allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer.

The parties may use relevant documents, existing assurance reports and remote assessments first where appropriate. Reasonable arrangements for notice, confidentiality, security, protection of unrelated customers and minimising disruption may apply. They must not prevent a legally required audit or inspection, a competent authority’s access, or an assessment justified by a material concern about compliance.

Return, deletion and retention

At the end of the relevant processing services, Provider will, at Customer’s choice, return or delete Customer Personal Data and delete remaining copies, unless retention is required by law and permitted by Applicable Data Protection Law.

The Processing Schedule specifies the return-request arrangements, applicable format, completion periods, backup treatment and any legally permitted retention exception. The arrangements will preserve any minimum retrieval period or other rights required by applicable law or transfer safeguards. Customer may give its return or deletion instruction before service termination.

Any data lawfully retained will remain protected, be used only for the permitted retention purpose, and be deleted when that reason ends. Provider will confirm completion of the agreed deletion on request. Routine service termination or a general account-deletion clause does not override these rights.

International transfers

Provider will make or permit a restricted international transfer of Customer Personal Data only where a valid mechanism and any required supplementary protections are in place under Applicable Data Protection Law.

The International Transfer Schedule identifies the relevant parties, roles, processing and access countries, and applicable transfer mechanism. Where contractual safeguards are needed, the applicable approved clauses and completed particulars identified in that schedule form part of the agreement before the transfer begins. General acceptance of the Service is not a substitute for a required transfer instrument.

Provider will fulfil the transfer obligations for which it is responsible and reasonably assist Customer with its relevant obligations. It will notify Customer if it can no longer comply with the applicable safeguards and suspend a transfer that cannot lawfully continue. The termination, return, deletion and third-party rights required by a mandatory transfer instrument remain available.

Additional US processor and California terms

Where applicable US state privacy law requires a controller-processor agreement, Provider will comply with Customer’s lawful instructions, protect confidentiality, assist with applicable consumer requests and assessments, supply required compliance information, and permit the oversight required by that law.

Where the California Consumer Privacy Act, as amended, applies to processing under this DPA, Customer discloses Customer Personal Data only for the limited and specific business purposes described in the Processing Schedule. Provider will not sell or share that information within the statutory meanings; retain, use or disclose it outside those purposes or the direct business relationship except as expressly permitted by law; or combine it with personal information from other sources except as expressly permitted by law.

Provider will provide the level of privacy protection required by applicable law, notify Customer if it determines it can no longer meet its obligations, and permit reasonable and appropriate steps to verify compliance and stop and remedy unauthorised use. Provider will assist with applicable rights requests, audits and assessments and impose the required obligations on relevant subcontractors. Provider understands and will comply with these restrictions.

Precedence and survival

This DPA and its schedules prevail over conflicting provisions concerning Customer Personal Data. Mandatory transfer clauses prevail to the extent they require. General liability caps, forum clauses and exclusions of third-party rights do not restrict rights or obligations that applicable law or mandatory transfer clauses do not permit the parties to restrict.

The applicable contract otherwise governs liability. This DPA does not create an additional indemnity for regulatory fines. Its protections continue while Provider retains Customer Personal Data.

Schedules

The Processing, Security, Subprocessor and International Transfer Schedules form part of this DPA. They are supplied with the Order, which identifies the schedule version that applies (current version: 2026-09-28). Customers may request the current version at support@marginal-ai.com before placing an Order.

Copyright © 2026: Quantimental Technologies Ltd.
Terms and Conditions Privacy Policy Cookie Preferences