Qonvera
PrivacyTermsDPA
Home/Legal/Data Processing Agreement
Qonvera legal

Data Processing Agreement

The Qonvera Data Processing Agreement governing how Aether Solutions processes personal data on behalf of customers.

Effective dateJuly 22, 2026Last updatedJuly 22, 2026
On this page
1. DEFINITIONS2. SCOPE AND ROLE OF THE PARTIES3. CUSTOMER INSTRUCTIONS4. CONFIDENTIALITY5. SECURITY6. SUB-PROCESSORS7. INTERNATIONAL DATA TRANSFERS8. DATA SUBJECT RIGHTS9. PERSONAL DATA BREACH10. DATA PROTECTION IMPACT ASSESSMENTS & AUDITS11. RETURN OR DELETION OF DATA12. LIABILITY13. MISCELLANEOUS

This Data Processing Agreement (“DPA”) is entered into by and between:

Aether Solutions - F.Z.E, a free zone establishment incorporated under the laws of the United Arab Emirates, with its principal place of business at Ajman free zone building c1, Ajman, United Arab Emirates (“Processor”, “Aether Solutions”); and the Customer entity that has entered into the Terms of Service for the Qonvera platform (“Controller”, “Customer”).

Effective Date: July 22, 2026

This DPA is incorporated into and forms part of the Terms of Service or other written or electronic agreement between Customer and Aether Solutions governing Customer’s use of the Qonvera platform (the “Agreement”). This DPA becomes legally binding on both parties when Customer electronically accepts the Agreement, enters into an Order Form that incorporates the Agreement, or otherwise uses the Qonvera platform after being presented with the Agreement. No separate signature is required.

1. DEFINITIONS

“Applicable Data Protection Law” means all data protection and privacy laws and regulations applicable to the processing of Personal Data under the Agreement, including (where applicable) the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and any other applicable data protection laws.

“Personal Data” means any information relating to an identified or identifiable natural person processed by Aether Solutions on behalf of Customer under the Agreement.

“Processing”, “Controller”, “Processor”, “Data Subject”, “Sub-processor”, and “Supervisory Authority” have the meanings given in the GDPR.

“Customer Data” means all data, including Personal Data, submitted to or processed through the Qonvera platform by Customer or its Users.

2. SCOPE AND ROLE OF THE PARTIES

2.1 Roles. For the purposes of Applicable Data Protection Law, Customer is the Controller and Aether Solutions is the Processor with respect to Personal Data processed under the Agreement.

2.2 Subject Matter. The subject matter of processing is the provision of the Qonvera platform and related services as described in the Agreement.

2.3 Duration. The duration of processing is the term of the Agreement and any post-termination period as specified in the Agreement or this DPA.

2.4 Nature and Purpose. The nature and purpose of processing is to provide the Qonvera platform, including CRM, messaging, analytics, AI features, integrations, and related support.

2.5 Types of Personal Data and Data Subjects.

  • Types of Personal Data: Names, contact details, company information, conversation history, attachments, internal notes, sales data, pipeline information, tags, tasks, activity logs, user account data, and any other data submitted by Customer or its Users.
  • Categories of Data Subjects: Customer’s employees, agents, contractors, representatives, and Customer’s own customers, leads, or contacts.

3. CUSTOMER INSTRUCTIONS

3.1 Documented Instructions. Aether Solutions shall process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law. Customer instructs Aether Solutions to process Personal Data as necessary to provide the Qonvera platform and related services, as further described in the Agreement and this DPA.

3.2 Additional Instructions. Additional instructions outside the scope of the Agreement require prior written agreement and may be subject to additional fees.

4. CONFIDENTIALITY

Aether Solutions shall ensure that persons authorized to process Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

5. SECURITY

5.1 Security Measures. Aether Solutions shall implement appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, as described in the Agreement and Privacy Policy.

5.2 Customer Responsibilities. Customer is responsible for using the Qonvera platform in accordance with the Agreement and for implementing appropriate security measures for its own systems and credentials.

6. SUB-PROCESSORS

6.1 Authorization. Customer authorizes Aether Solutions to engage Sub-processors to process Personal Data as necessary to provide the Qonvera platform.

6.2 Sub-processor Obligations. Aether Solutions shall ensure that Sub-processors are bound by data protection obligations no less protective than those in this DPA.

6.3 List of Sub-processors. A current list of Sub-processors is available upon request. Aether Solutions will notify Customer of any intended changes to Sub-processors, giving Customer the opportunity to object on reasonable grounds.

6.4 Liability. Aether Solutions remains liable for the acts and omissions of its Sub-processors.

7. INTERNATIONAL DATA TRANSFERS

7.1 Transfers. Aether Solutions may transfer Personal Data outside the country of origin as necessary to provide the Qonvera platform, subject to implementing appropriate safeguards as required by Applicable Data Protection Law.

7.2 Mechanisms. Where required, Aether Solutions will use Standard Contractual Clauses or other lawful transfer mechanisms for transfers of Personal Data from the EEA, UK, or Switzerland to countries not recognized as providing an adequate level of protection.

8. DATA SUBJECT RIGHTS

8.1 Assistance. Taking into account the nature of the processing, Aether Solutions shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer’s obligations to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law.

8.2 Notification. If Aether Solutions receives a request directly from a Data Subject relating to Personal Data processed on behalf of Customer, Aether Solutions will promptly notify Customer and will not respond to the request except on Customer’s documented instructions or as required by law.

9. PERSONAL DATA BREACH

9.1 Notification. Aether Solutions shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of Customer.

9.2 Cooperation. Aether Solutions will provide reasonable assistance to Customer to investigate, mitigate, and remediate the breach, and to fulfill Customer’s obligations to notify Supervisory Authorities or Data Subjects as required by law.

10. DATA PROTECTION IMPACT ASSESSMENTS & AUDITS

10.1 Assistance. Aether Solutions shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, to the extent required by Applicable Data Protection Law and relating to the processing of Personal Data by Aether Solutions.

10.2 Audits. Upon reasonable written notice, Aether Solutions shall make available to Customer all information necessary to demonstrate compliance with this DPA and, where required by law, allow for and contribute to audits conducted by Customer or an independent auditor mandated by Customer (subject to confidentiality and security obligations, and not more than once per year unless required by law or following a material breach).

11. RETURN OR DELETION OF DATA

11.1 Deletion. Upon termination or expiration of the Agreement, Aether Solutions shall, at Customer’s choice, delete or return all Personal Data processed on behalf of Customer, unless retention is required by applicable law.

11.2 Retention Period. Unless otherwise instructed, Aether Solutions will delete Personal Data within ninety (90) days after termination, subject to any legal retention obligations.

12. LIABILITY

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

13. MISCELLANEOUS

13.1 Governing Law. This DPA shall be governed by and construed in accordance with the laws specified in the Agreement.

13.2 Order of Precedence. In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the subject matter herein.

13.3 Amendments. No modification of this DPA shall be effective unless in writing and signed or accepted electronically by both parties.

ELECTRONIC ACCEPTANCE. This DPA is effective and binding through the electronic acceptance and incorporation mechanisms described above as of the Effective Date.

Aether Solutions - F.Z.E Ajman free zone building c1 Ajman, United Arab Emirates Email: legal@aethersolutions.tech Website: https://qonvera.com

Qonvera

Conversation intelligence for every sales team.

HomeLegal contactPrivacyTermsDPA
© 2026 Qonvera