GDPR compliance

Qevatrix QualityOS logoQevatrix QualityOSqualityos.qevatrix.com

GDPR compliance

QualityOS processes personal data as your processor under the EU GDPR and UK GDPR. This register documents each article, how the platform meets it and what remains your responsibility as controller.

Lawfulness, fairness and transparency

Art. 5(1)(a)

Processing principles

Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.

Every processing purpose in the platform is documented in the records of processing below, and Qevatrix acts only on documented instructions from the customer as controller.

Your responsibility: Publish your own privacy notice covering the clinical, quality and regulatory processing you run in Qevatrix.

Purpose limitation

Art. 5(1)(b)

Processing principles

Data must be collected for specified, explicit and legitimate purposes only.

Records are bound to a workspace and a product module; cross-product transfers (for example ClinicalOS to EvidenceOS) are explicit, audited events carrying coded data for a stated purpose.

Data minimisation

Art. 5(1)(c)

Processing principles

Data must be adequate, relevant and limited to what is necessary.

Direct identifiers are detected and removed on import by default, subjects are handled by code, and exports carry only the fields required for the stated purpose.

Accuracy

Art. 5(1)(d)

Processing principles

Data must be accurate and, where necessary, kept up to date.

Records are versioned with controlled state transitions; corrections create a new revision rather than overwriting history, and the audit trail names the person who made the change.

Storage limitation

Art. 5(1)(e)

Processing principles

Data must be kept in identifiable form no longer than necessary for the purposes of processing.

Retention schedules and legal holds are configured per record class in the retention module; expired records are flagged for disposition with an approval step.

Your responsibility: Set retention periods that reflect your regulatory obligations (for example device lifetime plus the statutory record period).

Integrity and confidentiality

Art. 5(1)(f)

Processing principles

Data must be processed with appropriate security, including protection against unauthorised access.

Row-level security scopes every row to one workspace, transport is TLS 1.2+, data at rest is encrypted, and privileged operations run through audited server functions.

Accountability

Art. 5(2)

Processing principles

The controller must be able to demonstrate compliance with the principles.

Append-only audit trails, e-signature records, security scan history and validation packs provide documentary evidence on demand.

Lawful basis for account and quality data

Art. 6(1)(b)/(c)/(f)

Lawful bases

Processing needs a lawful basis: contract, legal obligation, legitimate interests, consent or a public interest task.

Account, billing and audit data are processed to perform the subscription contract (Art. 6(1)(b)) and to meet Qevatrix's own legal obligations (Art. 6(1)(c)). Security logging relies on legitimate interests (Art. 6(1)(f)).

Your responsibility: Record the lawful basis for your own use of the platform in your ROPA.

Special category health data

Art. 9(2)(i)/(j)

Lawful bases

Health data may only be processed under an Article 9 condition, such as public health, scientific research or explicit consent.

Clinical data is de-identified at import wherever the study design allows. Where identifiable data is necessary, the customer as controller relies on explicit consent (Art. 9(2)(a)), scientific research (Art. 9(2)(j)) or the medical devices public-health condition (Art. 9(2)(i)).

Your responsibility: Hold and evidence the Article 9 condition — usually participant consent and ethics approval — before uploading identifiable clinical data.

Consent records

Art. 7

Lawful bases

Where consent is the basis, it must be freely given, specific, informed and demonstrable, and withdrawable.

Consent versions, dates and withdrawal events are recorded against the subject record in ClinicalOS and carried on transfers to StudyOS and EvidenceOS.

Your responsibility: Upload the approved consent form version used at each site.

Right of access

Art. 15

Data subject rights

Data subjects may obtain confirmation of processing and a copy of their personal data.

A subject search across the workspace returns every record referencing a subject code, exportable as a structured pack with the processing purposes and recipients.

Your responsibility: Verify the requester's identity before releasing any pack.

Right to rectification

Art. 16

Data subject rights

Inaccurate personal data must be corrected without undue delay.

Corrections are made as a new record revision; the previous value stays in the audit trail so regulated traceability is preserved.

Right to erasure

Art. 17

Data subject rights

Data must be erased on request, unless processing is necessary for a legal obligation, public health, or archiving in the public interest.

Erasure is executed as irreversible pseudonymisation of the identifying fields; regulated quality and vigilance records are retained under the Art. 17(3)(b)/(c) exemptions and the retention register records why.

Your responsibility: Decide and document whether the medical device retention exemption applies before actioning an erasure request.

Right to restriction

Art. 18

Data subject rights

Processing must be restricted while accuracy or a legitimate-interest objection is verified.

A legal hold flag freezes the record from further processing and export while keeping it readable to authorised reviewers.

Right to data portability

Art. 20

Data subject rights

Data provided by the subject must be portable in a structured, commonly used, machine-readable format.

Subject packs and register exports are produced as CSV and XLSX alongside indexed PDF.

Right to object

Art. 21

Data subject rights

Subjects may object to processing based on legitimate interests or for direct marketing.

Marketing subscriptions carry a one-click unsubscribe and are stored separately from clinical and quality records; objections are logged with the outcome.

One-month response clock

Art. 12(3)

Data subject rights

Requests must be answered without undue delay and within one month, extendable by two further months for complex requests.

Rights requests recorded in the console start a one-month clock with upcoming and overdue notifications to the request owner, mirroring the CAPA and vigilance clocks.

Documented instructions only

Art. 28(3)(a)

Processor obligations

The processor may process personal data only on documented instructions from the controller.

The Data Processing Agreement forms part of the subscription terms and defines the instruction set; Qevatrix support staff access customer data only on a logged, time-boxed request.

Confidentiality of personnel

Art. 28(3)(b)

Processor obligations

Persons authorised to process the data must be under a duty of confidentiality.

All Qevatrix personnel are bound by written confidentiality obligations that survive termination.

Subprocessors

Art. 28(2)/(4)

Processor obligations

Subprocessors require general or specific written authorisation and must be bound by equivalent obligations.

The subprocessor register lists hosting, email and AI providers with their role, location and transfer mechanism. Customers are notified before a new subprocessor is added and may object.

Assistance with rights, DPIAs and breaches

Art. 28(3)(e)/(f)

Processor obligations

The processor must assist the controller with data subject requests, impact assessments and breach notification.

Subject packs, the records of processing and the security register are self-service. Qevatrix supplies a DPIA input pack and supports breach assessment within 24 hours of becoming aware.

Deletion or return at end of service

Art. 28(3)(g)

Processor obligations

Data must be deleted or returned at the controller's choice when the service ends.

On termination the workspace is exported in full on request and irreversibly deleted after a 30-day grace period, backups rolling off within a further 30 days.

Records of processing activities

Art. 30(2)

Processor obligations

Processors must keep a record of all categories of processing carried out for each controller.

The ROPA register below is maintained per product and is exportable for supervisory authority requests.

Your responsibility: Maintain your controller-side ROPA under Art. 30(1).

Pseudonymisation and encryption

Art. 32(1)(a)

Security of processing

Appropriate technical measures including pseudonymisation and encryption of personal data.

Subjects are handled by code, identifiers are stripped at import, data at rest is encrypted and all traffic uses TLS 1.2+.

Confidentiality, integrity, availability and resilience

Art. 32(1)(b)

Security of processing

Ongoing confidentiality, integrity, availability and resilience of processing systems.

Row-level security on every table, append-only audit trails with SHA-256 integrity hashes on exports, managed Postgres with point-in-time recovery and daily backups.

Regular testing and evaluation

Art. 32(1)(d)

Security of processing

A process for regularly testing, assessing and evaluating the effectiveness of the measures.

Automated security scans run on a nightly schedule with findings triaged in an append-only register; software validation (IQ/OQ/PQ) is re-executed on material change.

Access control and authentication

Art. 32(4)

Security of processing

Persons acting under the processor's authority must not process data except on instruction.

Role-based access (owner, admin, member), per-site scoping in EvidenceOS, MFA and SSO options, idle logoff on consoles handling health data, and re-authentication for signatures.

Your responsibility: Remove leavers on their last working day and review workspace roles at least annually.

Transfers outside the EEA

Art. 44–46

International transfers

Transfers to third countries need an adequacy decision or appropriate safeguards such as Standard Contractual Clauses.

EU and UK customer data is hosted in EU regions by default. Where a subprocessor processes outside the EEA, the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum apply, backed by a transfer impact assessment.

Your responsibility: Choose the EU hosting region at onboarding if your data must remain in the EEA.

EU and UK representatives

Art. 27

International transfers

Controllers or processors outside the Union must designate a representative in the Union where Article 3(2) applies.

Qevatrix designates an EU representative and a UK representative; contact details are supplied in the DPA and on request.

Notification to the controller without undue delay

Art. 33(2)

Personal data breaches

The processor must notify the controller without undue delay after becoming aware of a breach.

Qevatrix notifies the affected workspace owners within 24 hours of becoming aware, with the categories of data, approximate numbers, likely consequences and mitigation taken.

72-hour supervisory authority clock

Art. 33(1)

Personal data breaches

The controller must notify the competent supervisory authority within 72 hours unless the breach is unlikely to result in a risk.

Breach records in the console start a 72-hour clock with a documented risk assessment and notification decision, mirroring the HIPAA four-factor assessment for dual-regulated customers.

Your responsibility: Make and record the notification decision — it belongs to you as controller.

Communication to data subjects

Art. 34

Personal data breaches

High-risk breaches must be communicated to the affected data subjects without undue delay.

The breach record captures the subject-communication decision, the wording used and the date sent, so the file is complete for the supervisory authority.

Data subject request clocks — Art. 12(3)

Each request must be answered without undue delay and within one month, extendable by two further months where the request is complex.

Access (Art. 15)30 daysRectification (Art. 16)30 daysErasure (Art. 17)30 daysRestriction (Art. 18)30 daysPortability (Art. 20)30 daysObjection (Art. 21)30 days

Records of processing — Art. 30(2)

ActivityApplicationsData subjectsData categoriesRetention
Workspace accounts and access controlAll applicationsCustomer employees and contractorsName, work email, role, authentication events, IP addressLife of the subscription plus 6 years of audit trail
Quality and regulatory recordsQualityOS, RegulatoryOS, DeviceOSEmployees, suppliers, complainantsAuthor and approver identity, e-signature meaning, complaint contact detailsDevice lifetime plus the statutory retention period set by the customer
Clinical data intake and de-identificationClinicalOSStudy participants and patientsHealth data (special category), subject code, outcome scores, dates generalised on importPer protocol, minimum 10 years for EU MDR clinical evidence
Sponsor oversight and monitoringStudyOSStudy participants, site staffCoded subject records, site personnel names and roles, monitoring findingsPer protocol and trial master file requirements
Registry and evidence analysisEvidenceOSPatients in post-market registriesCoded, de-identified clinical outcomes and implant dataPer registry charter
Sales enquiries and newsletterPublic websiteProspective customersName, work email, company, message content24 months after last interaction, or until unsubscribe
Billing and subscription managementAll applicationsCustomer billing contactsBilling name, address, VAT identifier, invoice history (card data never touches Qevatrix)10 years (statutory accounting retention)

Subprocessors — Art. 28(2)

Managed cloud hosting and database

Application hosting, database, object storage and backups

EU (default) — region selected at onboarding

Within the EEA; SCCs where support is provided from outside the EEA

Payment processing

Subscription billing and invoicing

EU / United States

EU Standard Contractual Clauses and UK Addendum

Transactional email

Account, subscription and notification email delivery

EU / United States

EU Standard Contractual Clauses and UK Addendum

AI model providers (Qevatrix Intelligence)

Drafting and cross-referencing text submitted by the user

EU / United States

EU Standard Contractual Clauses; zero-retention processing and no training on customer data