QIH DATA PROTECTION FRAMEWORK
Sub-Processor & Data Transfer Policy
This policy explains how Quantum Intelligence Hub Ltd (“QIH”, “we”, “us”) appoints service providers that process personal data, and how QIH manages international transfers across its websites, infrastructure, AI Digital Reception services and related digital operations.
Important: QIH remains responsible for selecting and managing its sub-processors as required by applicable law and contract. Use of a third party does not automatically transfer QIH’s own legal responsibilities. Where QIH acts as a processor for a business customer, the customer remains the controller of its customer and communications data unless the parties agree otherwise in writing.
Section 01
Scope
This policy applies to QIH-controlled services, including qihhub.com and related QIH ecosystem domains, customer portals, hosting and automation environments, educational services, e-commerce operations and AI Digital Reception services. A service-specific agreement, Data Processing Agreement (“DPA”) or order form takes precedence where it provides more specific terms.
Section 02
Roles of the Parties
- QIH is normally a controller for account, billing, sales, website, security and business-administration data processed for its own purposes.
- QIH may act as a processor when it handles customer communication data on behalf of a business customer.
- The business customer is normally the controller for contact lists, call instructions, scripts, recordings, transcripts and other data it submits or causes to be collected through its service.
- A provider appointed by QIH to assist with such processing is a sub-processor to the extent it processes that data on QIH’s behalf.
Section 03
Why We Use Sub-Processors
QIH may engage providers where reasonably necessary to host and secure systems, deliver communications, process payments, operate customer support and CRM functions, provide analytics, maintain backups, deliver educational or e-commerce services, support compliance, or provide AI and automation capabilities.
Section 04
Provider Categories
- cloud, hosting, CDN, DNS, backup and cybersecurity providers;
- telephony, messaging, email and customer-support platforms;
- AI model, speech-to-text, text-to-speech and workflow automation providers;
- payment, banking, invoicing and fraud-prevention providers;
- analytics, logging and service-monitoring providers;
- professional advisers, compliance partners and company-service providers;
- education, certification, fulfilment, supplier and logistics partners.
Named providers may change. QIH will not represent a provider as active unless it is actually used for the relevant service.
Section 05
AI Digital Reception
Depending on configuration, AI Digital Reception may involve telephone and communications providers, speech recognition, text-to-speech, language models, hosting, logging and automation services. These providers may process caller numbers, call metadata, audio, recordings, transcripts, summaries, messages, appointment details and instructions supplied by the customer.
The customer must ensure that its notices, lawful basis, call-recording disclosures, marketing permissions and retention instructions comply with the laws applicable to its callers and campaigns. QIH will process customer data only for documented service purposes, subject to the agreement and DPA.
Section 06
Sub-Processor Due Diligence and Contracts
Before appointing a material provider, QIH seeks proportionate assurance concerning security, privacy, reliability, location and contractual protections. Where required, QIH enters into written data-processing terms requiring confidentiality, appropriate security, assistance with data rights and incidents, deletion or return of data, and equivalent protection when another sub-processor is used.
Section 07
Authorisation and Changes
Where QIH acts as processor, the customer gives general written authorisation for QIH to use sub-processors needed to provide the service. QIH will provide reasonable notice of a material new or replacement sub-processor where required by the DPA, normally through the service, account notice, policy update or email.
A customer with a genuine data-protection objection should contact QIH within the notice period stated in its DPA. The parties will seek a practical solution. If none is reasonably available, the affected service may be terminated in accordance with the agreement. Urgent replacements may be made without advance notice where necessary to address a security, legal or service-continuity risk, with notice provided as soon as reasonably practicable.
Section 08
Data Categories
- identity, business and contact details;
- account, authentication and support records;
- billing, subscription and transaction metadata (full card data is normally handled by the payment provider);
- IP address, device, browser, server, audit and security logs;
- call metadata, audio, recordings, transcripts, summaries and appointment information;
- website, CRM, education, certification, order, delivery and service-usage data;
- documents and instructions supplied for the requested service.
Section 09
International Transfers
Providers may process data in the United Kingdom, European Economic Area and other countries in which they or their infrastructure operate. QIH does not rely on a user’s mere acknowledgement as the legal safeguard for a restricted transfer.
Where required, QIH uses an applicable adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, EU Standard Contractual Clauses, or another lawful transfer mechanism. QIH may also assess transfer risks and implement supplementary contractual, technical or organisational measures where appropriate.
Section 10
Security Measures
Measures are selected according to risk and may include encryption in transit, access controls, least-privilege permissions, multi-factor authentication, logging, monitoring, backups, incident procedures, separation of customer environments and contractual confidentiality. No internet service can guarantee absolute security, but this does not reduce any security duty that applicable law or a written agreement places on QIH.
Section 11
Incidents and Assistance
Material providers are expected to notify QIH of qualifying personal-data incidents without undue delay. Where QIH acts as processor, QIH will notify the affected controller without undue delay after becoming aware of a personal-data breach and will provide available information reasonably needed for the controller’s assessment and regulatory duties. The controller remains responsible for determining whether notification to a regulator or affected individuals is required.
Section 12
Retention, Return and Deletion
QIH instructs providers to retain personal data only for the service, security, backup, dispute, financial or legal period applicable to their function. At the end of processing, data is returned or deleted in accordance with the agreement, subject to backup cycles and lawful retention requirements. Any retained data remains protected and is not used for unrelated purposes.
Section 13
Data Subject Requests
Where QIH acts as processor, it will provide reasonable assistance to the controller with access, correction, deletion, restriction, objection and portability requests, taking account of the nature of processing and available information. Requests concerning a customer-controlled AI Digital Reception deployment should normally be directed first to that business customer.
Section 14
Customer Responsibilities
- submit only data the customer is authorised to process;
- provide legally required privacy and call-recording notices;
- configure retention, access and campaign settings lawfully;
- protect credentials and authorised-user access;
- avoid placing special-category, criminal-offence or other highly sensitive data into a service unless expressly agreed and properly protected;
- notify QIH promptly of suspected misuse, inaccurate instructions or security concerns.
Section 15
Accountability and Audits
QIH maintains proportionate records of material processing and provider relationships. Subject to confidentiality, security and reasonable scope limits, QIH will make available information reasonably necessary to demonstrate compliance with its processor obligations and will support audits where required by an applicable DPA or law.
Section 16
Responsibility and Liability
Each party is responsible for its own acts, omissions, instructions and legal obligations, and for breaches caused by matters within its control. QIH does not exclude responsibility merely because a sub-processor is involved. Contractual liability limits are governed by the applicable service agreement and do not apply where liability cannot lawfully be limited, including fraud or other mandatory statutory liability.
Section 17
Related Documents and Guidance
Section 18
Contact and Updates
Quantum Intelligence Hub Ltd
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Privacy: privacy@qihhub.com
Security: security@qihhub.com
Legal: legal@qihhub.com
QIH may update this policy when providers, services, processing locations or legal requirements change. Material changes will be communicated as described above. Mandatory rights under applicable law are not displaced by this policy.