DATA PROCESSING ADDENDUM (DPA)
Data Processing Addendum (DPA)
Details about how Muhasib processes Customer Data and the security measures in place.
1. Introduction
This Data Processing Addendum ("DPA") forms an integral part of the Terms and Conditions between Muhasib and the Customer (the "Agreement"). This DPA sets forth the terms and conditions under which Muhasib (as a Processor) will process Personal Data on behalf of Customer (as Controller) in connection with the provision of the Muhasib Service.
2. Roles and Responsibilities
2.1 Controller and Processor: Customer is the Controller of Customer Data and determines the purposes and means of Processing. Muhasib is the Processor and will process Customer Data only on Customer's documented instructions, as set forth in the Agreement and this DPA.
2.2 Processing Instructions: Muhasib shall process Customer Data only for the purpose of providing the Service and as otherwise instructed by Customer in writing, unless required by applicable law to process the Personal Data.
3. Details of Processing
- Nature and Purpose: Provision, maintenance, and support of the Muhasib Service, including hosting, backups, updates, and assistance.
- Types of Personal Data: Contact information, financial and transactional data, personnel records, customer and supplier data, and any other data uploaded by Customer during normal use of the Service.
- Categories of Data Subjects: Customers' employees, contractors, agents, customers, suppliers, and other third parties whose data is uploaded to the Service.
4. Subprocessors
Customer hereby authorizes Muhasib to engage subprocessors to provide elements of the Service. Muhasib will:
- Maintain a list of subprocessors and make it available upon request.
- Enter into written agreements with subprocessors imposing obligations substantially similar to those contained in this DPA.
5. Security Measures
Muhasib shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to:
- Access controls and role-based permissions;
- Encryption in transit (TLS) and at rest where applicable;
- Regular vulnerability scanning and security testing;
- Backup, disaster recovery, and business continuity procedures;
- Logging, monitoring, and incident detection systems.
6. Breach Notification
Muhasib will notify Customer without undue delay upon becoming aware of a Personal Data breach affecting Customer Data, provide reasonable details regarding the breach, and cooperate with Customer to investigate and remediate the breach.
7. Audit Rights
Customer may reasonably request and receive information necessary to demonstrate Muhasib's compliance with the obligations set forth in this DPA. Where necessary, Muhasib will permit audits or inspections by Customer or an independent auditor appointed by Customer, subject to confidentiality and reasonable notice.
8. International Transfers
Where Muhasib or its subprocessors transfer Personal Data outside the UAE, Muhasib will ensure appropriate safeguards are in place (such as standard contractual clauses or other lawful transfer mechanisms) and will inform Customer of such transfers.
9. Data Retention and Deletion
Upon termination or expiration of the Agreement, Muhasib will: (a) return Customer Data to Customer in a commonly used machine-readable format if requested; and (b) delete or irreversibly anonymize Customer Data from its systems after a reasonable period unless retention is required by applicable law.
10. Confidentiality
Muhasib shall ensure that any personnel authorized to process Customer Data are under appropriate confidentiality obligations.
11. Liability
Each Party's liability with respect to Personal Data shall be determined in accordance with the Agreement, subject to applicable law.
12. Contact
For DPA-related inquiries: dpo@zellarc.ae