01Introduction and Parties
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the agreement between Q4 Intelligence Company (“Q4,” “we,” or “us”) and the customer identified in the applicable order form, subscription, or online agreement (“Customer”) governing Customer’s use of Q4’s services (the “Agreement”). This DPA applies to the extent Q4 Processes Customer Personal Data on Customer’s behalf in connection with the Agreement.
Q4 Intelligence Company is a limited liability company registered in Riyadh, Saudi Arabia (Commercial Registration No. 1010976680).
02Definitions
Capitalized terms used but not defined in this DPA have the meaning given to them in the Agreement. In this DPA:
- Personal Data means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Law.
- Processing means any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, retrieval, transmission, or deletion.
- Controller means the entity that determines the purposes and means of Processing Personal Data.
- Processor means the entity that Processes Personal Data on behalf of, and under the instructions of, a Controller.
- Subprocessor means any Processor engaged by Q4 to Process Customer Personal Data on Q4’s behalf.
- Data Subject means the identified or identifiable natural person to whom Personal Data relates.
- Applicable Data Protection Law means the data protection and privacy laws applicable to the Processing of Customer Personal Data under this DPA, which may include the Saudi Personal Data Protection Law and, where applicable to Customer, other data protection laws.
- Security Incident means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
03Scope and Roles
For most Processing under the Agreement, Customer acts as Controller (or, where applicable, as Processor on behalf of a further Controller) of Customer Personal Data, and Q4 acts as Processor, Processing Customer Personal Data on Customer’s behalf and under Customer’s instructions.
Some Processing carried out by Q4 — for example, Processing needed to administer accounts, secure the Service, prevent fraud, or comply with Q4’s own legal obligations — is carried out by Q4 as an independent controller for those limited purposes and is not governed by this DPA.
Each party remains responsible for complying with the obligations that apply to it under Applicable Data Protection Law.
04Customer Instructions
Q4 will Process Customer Personal Data only:
- to provide the Service under the Agreement;
- in accordance with Customer’s documented instructions, including those given through Customer’s configuration and use of the Service; and
- as required by applicable law, in which case Q4 will, where legally permitted, inform Customer of that legal requirement before Processing.
If Q4 believes an instruction infringes Applicable Data Protection Law, Q4 will inform Customer, and is not obligated to comply with that instruction until it is clarified or withdrawn.
05Processing Details
The subject matter, duration, nature and purpose of Processing, the categories of Personal Data that may be involved, and the categories of Data Subjects are set out in Annex 1. Not every category described in Annex 1 is Processed for every Customer — what is actually Processed depends on which parts of the Service Customer uses.
06Confidentiality
Q4 requires personnel authorized to Process Customer Personal Data to be subject to confidentiality obligations, whether contractual or statutory, appropriate to their role and level of access.
07Security Measures
Q4 will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, having regard to the nature of the Processing. A summary of currently implemented measures is set out in Annex 2.
No method of transmission or storage is completely secure, and Q4 does not guarantee that security measures will prevent every possible unauthorized access, use, or disclosure.
08Subprocessors
Customer authorizes Q4 to engage Subprocessors to Process Customer Personal Data in connection with providing the Service. Where Q4 engages a Subprocessor, Q4 will:
- ensure the Subprocessor receives only the Customer Personal Data necessary for it to perform its function;
- remain responsible for that Subprocessor’s Processing obligations to the extent required by Applicable Data Protection Law and the Agreement; and
- maintain a current list of its Subprocessors, summarized in Annex 3.
Customer may contact Q4 at contact@q4.sa for current details of Q4’s Subprocessors.
09Subprocessor Changes
Q4 will notify Customer of material additions or changes to its Subprocessors through commercially reasonable means, such as updating Annex 3 or notifying Customer directly. If Customer has a reasonable data-protection objection to a new Subprocessor, the parties will discuss the concern in good faith.
10International Transfers
Some Subprocessors described in Annex 3 may Process Customer Personal Data outside the Kingdom of Saudi Arabia. Where Q4 transfers Customer Personal Data internationally, it will do so in accordance with Applicable Data Protection Law.
11Data Subject Requests
Where Q4 acts as Processor, Q4 will provide Customer with reasonable assistance to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law — including access, correction, deletion, restriction, and portability — to the extent those rights apply and Q4 is able to assist. These requests are currently handled administratively; Customer or a Data Subject may contact Q4 at contact@q4.sa.
12Security Incidents
Q4 will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data, to the extent required by Applicable Data Protection Law. That notice will include available information about the nature of the incident, the Customer Personal Data affected, its likely consequences, and the remediation steps Q4 has taken or plans to take.
13Deletion and Return
On termination of the Agreement or on Customer’s request, Q4 will delete or return Customer Personal Data as required by the Agreement and Applicable Data Protection Law, subject to any legal retention obligations and the lifecycle of Q4’s backup systems.
14Audits and Information
Q4 will make available information reasonably necessary to demonstrate its compliance with this DPA. Where Applicable Data Protection Law requires an audit beyond the information Q4 makes available, the parties will agree on the scope, timing, and confidentiality terms of that audit in good faith.
15Liability
Each party’s liability arising out of or in connection with this DPA, including liability of Q4 and its Subprocessors, is subject to the limitation and exclusion of liability provisions in the Agreement, except where Applicable Data Protection Law does not permit such a limitation to apply.
16Term
This DPA remains in effect for as long as Q4 Processes Customer Personal Data on Customer’s behalf under the Agreement.
17Governing Relationship
This DPA forms part of the Agreement. If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls to the extent of that conflict.
A1Annex 1 — Details of Processing
Subject matter. Provision of Q4’s financial research and AI-powered software services.
Duration. For the term of the Agreement, plus any period during which Q4 retains Customer Personal Data as permitted by Section 13.
Nature and purpose of Processing. Collection, storage, retrieval, analysis, transmission, deletion, and AI-assisted Processing, where applicable, in order to provide, secure, and support the Service.
Categories of Personal Data. Depending on how Customer uses the Service, Processing may include:
- account and profile information;
- business contact information;
- prompts and chat inputs submitted to Q4’s AI features;
- documents uploaded to the Service;
- usage and activity metadata;
- data from third-party integrations Customer connects; and
- meeting, audio, or transcript data, where Customer uses a feature that involves it.
Data Subjects. Customer’s users; Customer’s employees or contractors; and, where applicable, individuals whose information appears in content Customer provides to or through the Service.
A2Annex 2 — Technical and Organizational Measures
Q4 currently implements the following measures. This summary describes measures in place as of the date of this DPA and may evolve as the Service does.
- Encryption in transit (TLS/HTTPS) for data sent to and from the Service.
- Restricted administrative access, limited to a specific, approved list of accounts.
- Authentication and access controls for accounts and administrative tools.
- Internal AI usage telemetry designed not to store prompts, model outputs, or document content — only operational metadata such as which model handled a request, token counts, and cost.
- Logging for operational and security purposes, where applicable.
A3Annex 3 — Subprocessors
Core infrastructure. Every use of the Service runs on these:
- Vercel — hosting, serverless functions, and file storage.
- PostgreSQL database hosting — Q4’s primary database (provider to be confirmed).
Feature-dependent providers. Engaged only where the corresponding feature is enabled or used:
- OpenAI, Anthropic, xAI, Moonshot AI, Mistral AI — AI model providers for AI Chat and related features.
- Jina AI — retrieval/embedding support for AI Chat.
- Reducto — document parsing and extraction for filings and uploaded documents.
- AssemblyAI — transcription of earnings call audio.
- Google — Calendar API, only if Customer connects a Google Calendar to the Earnings Calendar feature.
- Recall.ai, Cisco Webex — only where the Meeting Capture feature is used.
- Moyasar, StreamPay — payment processing, only for paid subscriptions.
Not every provider listed above is engaged for every Customer — only those tied to features Customer actually uses. Contact contact@q4.sa for the current list.
A4Annex 4 — Region-Specific Terms
This Annex reserves space for region-specific data protection terms that may apply to certain customers. These terms are not currently operative and do not form part of this DPA unless and until expressly incorporated by a signed written agreement between the parties.
- Saudi Personal Data Protection Law (PDPL) specific terms — reserved.
- EU/UK GDPR and Standard Contractual Clauses (SCC) terms, where applicable — reserved.
