Privacy & DataLast updated: October 2026

Data Processing & Data Protection Addendum (DPA)

Architectural and legal framework governing Data Controller and Data Processor responsibilities, multi-tenant isolation, and cross-border data safeguards.

Key Compliance Highlights
  • Defines the ISP Operator as the Data Controller of its subscriber records and QC NetCore as the Data Processor.
  • Enforces strict database-level multi-tenant isolation via PostgreSQL Row-Level Security (RLS) keyed by `organization_id`.
  • Aligns with the Kenya Data Protection Act, 2019 and international data protection standards.

Section 1Data Controller & Data Processor Roles

In the context of multi-tenant ISP operations on QC NetCore, data protection roles are structured as follows:

  • ISP Tenant as Data Controller: Each onboarded ISP Operator determines the purposes and means of collecting its end-subscribers' personal data (names, phone numbers, installation addresses, and broadband plans). The ISP Operator is the Data Controller for its subscriber base.
  • QC NetCore as Data Processor: QC NetCore processes subscriber personal data, session logs, and billing records strictly on behalf of and in accordance with the documented configuration instructions of the respective ISP Operator.
  • QC NetCore as Data Controller (Operator Accounts): With respect to the account registration and billing details of the ISP Operators themselves, QC NetCore acts as an independent Data Controller.

Section 2Technical Multi-Tenant Isolation (Row-Level Security)

Every operational table in the QC NetCore PostgreSQL schema (`subscribers`, `service_plans`, `invoices`, `payments`, `routers`, `vouchers`, `active_sessions`, and `network_alerts`) is partitioned by an `organization_id` foreign key and protected by PostgreSQL Row-Level Security (RLS) policies.

This architecture ensures that an authenticated operator belonging to Tenant A is cryptographically and logically prevented from querying, modifying, or exporting subscriber or financial records belonging to Tenant B.

Section 3Cloud Infrastructure & Cross-Border Processing Safeguards

To provide high-availability cloud hosting and database resilience, tenant data is stored in secure cloud data centers operated by our core infrastructure providers (Supabase / AWS cloud infrastructure and Vercel edge network). All data transmissions between operator browsers, captive portals, and our cloud endpoints are encrypted in transit via HTTPS/TLS.

Section 4Data Breach Notification & Return/Deletion of Tenant Data

In the event of a confirmed unauthorized disclosure of tenant personal data within QC NetCore's cloud infrastructure, QC NetCore will notify affected ISP Operators without undue delay, providing relevant technical forensic details to assist the ISP Operator in fulfilling any statutory notification duties under the Kenya Data Protection Act, 2019 or local regulations.

Upon termination of a tenant agreement, the ISP Operator may export its subscriber and invoice records in standard structured formats, after which tenant data is scheduled for secure deletion in accordance with our retention schedule.

Questions About This Policy or Compliance Verification?

Reach our legal, privacy, billing, and security engineering desk directly via email or WhatsApp.