Data Processing Agreement
This agreement applies when Qrenox processes personal data for the merchant in connection with the service. It supplements the terms of service and is read with them to protect data and carry out the merchant’s instructions.
1. Roles
The merchant determines the purposes and means of processing its customer data and is responsible for collection and the customer relationship. Qrenox acts as processor under the merchant’s documented instructions, with a limited ability to process data independently for platform security and fraud prevention within the limits of law.
2. Subject and duration
Processing covers receiving and confirming orders, communications, delivery operations, operational views and support. It continues while the service is used and then follows the export and deletion rules in this agreement and the privacy policy.
3. Data and data subjects
Data may include name, phone number, address, city, order details, delivery status, message content and technical information needed to operate the service. Data subjects are the merchant’s customers and people interacting with an order or message. The merchant will not submit unnecessary or sensitive data without an appropriate legal basis and instructions.
4. Instructions and responsibilities
Qrenox processes data under this agreement, the merchant’s settings and documented instructions. If an instruction appears unlawful or creates a serious risk to data or the platform, Qrenox may temporarily suspend it, notify the merchant and request clarification.
5. Confidentiality
Qrenox personnel and authorized persons are bound by confidentiality and may use the data only to provide and protect the service, following need-to-know access.
6. Security measures
Passwords are stored as PBKDF2-HMAC-SHA256 and cannot be recovered from the database. Store and messaging credentials are encrypted, and the system refuses to save them when no encryption key is configured. A session token is kept only as a hash. Every database query uses bound parameters; every inbound Meta webhook is verified by signature; every route checks record ownership before returning anything. Transport is HTTPS with a one-year HSTS policy. Backups are encrypted to a public key whose private half is never on the server, and the backup script refuses to keep a file that is not a real encrypted archive.
What is not claimed. Customer details — name, phone, address and message text — are stored without field-level encryption; what is encrypted is connection credentials and backups. There is no general-purpose audit log; what is recorded is erasures, message history and order events. Measures are reviewed in light of risks and service development, and the security page sets each one against the code that implements it.
7. Subprocessors
Qrenox may use specialized subprocessors for hosting, infrastructure, messaging, delivery and language models. It imposes obligations appropriate to the processing and remains responsible for their selection and relationship within this agreement.
Qrenox will notify the merchant of a new subprocessor through the dashboard or email at least 14 days in advance where practicable. For a reasonable data-protection objection, the parties will cooperate in good faith. If unresolved, the merchant may terminate the affected service or subscription under the terms, without requiring Qrenox to redesign its infrastructure for one merchant.
8. International transfers
Processing may occur outside Morocco because of provider locations. Qrenox applies appropriate contractual, organizational and technical safeguards and shares only data necessary for the stated purpose.
9. Assistance
Qrenox assists the merchant through available platform functions with access, correction, export, deletion and data-subject requests. The merchant will provide the required information without undue delay.
10. Data incidents
When Qrenox confirms a security incident affecting the merchant’s data, it will notify the merchant without undue delay and aims to provide an initial notice within 72 hours of confirmation, with reasonable updates. The merchant, as the party responsible for its customer relationship, handles required notices to people or authorities unless law or the parties require otherwise.
11. Audit
Qrenox provides reasonable information demonstrating compliance, such as a description of measures, questionnaire or available report. On-site audits are not routine and require justification, advance notice and coordination protecting platform confidentiality, security and reasonable costs.
12. Return and deletion
At the end of the relationship, the merchant may request an export within 30 days. Qrenox deletes operational data within 30 days of a deletion request. There is no automatic deletion when a subscription simply lapses — data is kept until deletion is asked for, and we would rather say so than state a sweep that does not run.
Encrypted backups are not edited selectively: the copies on the server are overwritten on their own 14-day cycle, and an offsite copy, where one is configured, is not pruned automatically today. Data already written to a backup can therefore outlive an operational deletion. Independently of any of this, the merchant can erase one customer's personal data at any time from the dashboard, with immediate effect.
13. Liability
Each party is responsible for its obligations under law and this agreement. Any liability cap is governed by the terms of service and applies only to the extent permitted by applicable law.
14. Precedence and contact
If there is a conflict about data processing, this agreement controls over the terms of service only for its subject matter. Contact: contact@qrenox.com.