1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the agreement between DIGITRUST TECHNOLOGIES - FZCO ("Processor", "Digitrust") and the business entity using the Service ("Controller", "Customer").
It applies to Personal Data about verification Subjects that Digitrust processes on Customer's documented instructions via the Service. It does not apply to data for which Digitrust is an independent controller (see Privacy Policy).
2. Definitions
Terms in this DPA have the meanings in the UAE PDPL and, where applicable, GDPR. "Personal Data", "Processing", "Controller", "Processor", and "Data Subject" apply accordingly.
Capitalised terms not defined here have the meanings in the Terms of Service.
3. Processing instructions
Digitrust will process Personal Data only on documented instructions from Customer, including configuration of Verification Requests, retention settings within published limits, and use of platform features.
Customer instructs Digitrust to process Subject data to perform identity verification, channel verification (OTP), storage of results, and related support as described in Annex I.
If Digitrust believes an instruction infringes applicable law, we will inform Customer without undue delay.
4. Controller obligations
Customer will: (a) establish and document a lawful basis for processing; (b) provide required privacy notices to Subjects; (c) ensure instructions comply with law; (d) not request unlawful or excessive processing; (e) respond to Data Subject requests to the extent Customer is responsible.
5. Processor obligations
Digitrust will: process only on instructions; ensure personnel confidentiality; implement appropriate technical and organisational measures; assist with Data Subject requests and regulatory enquiries as described below; delete or return data per Section 9.
6. Sub-processors
Customer provides general authorisation for Digitrust to engage sub-processors listed in Annex II. Digitrust will impose data protection obligations on sub-processors substantially similar to this DPA.
We will notify Customer of intended additions or replacements via email or in-app notice with reasonable time to object on reasonable grounds relating to data protection.
7. Data Subject requests
Digitrust will promptly notify Customer if we receive a request from a Data Subject unless prohibited by law. Customer is responsible for responding. Digitrust will provide reasonable assistance at Customer's expense for complex requests.
8. Personal data breach
Digitrust will notify Customer without undue delay and in any event within seventy-two (72) hours after becoming aware of a Personal Data breach affecting Customer Personal Data, with information reasonably available to assist Customer's obligations.
9. DPIAs and consultations
Digitrust will provide reasonable assistance for data protection impact assessments and prior consultations where required, subject to reimbursement of material costs.
10. Deletion and return
On termination or written request, Customer may export data for thirty (30) days. Thereafter Digitrust will delete or anonymise Customer Personal Data within ninety (90) days unless law requires retention.
11. Audits
Digitrust will make available information reasonably necessary to demonstrate compliance and allow audits no more than once per twelve (12) months on thirty (30) days' notice, subject to confidentiality and reimbursement of reasonable costs, unless a supervisory authority requires otherwise.
12. International transfers
Where Personal Data is transferred outside the UAE or EEA/UK, Digitrust will ensure appropriate safeguards as described in Annex III.
13. Liability
Liability arising from this DPA is subject to the limitations and exclusions in the Terms of Service unless mandatory law provides otherwise.
14. Term
This DPA applies for the duration of Customer's use of the Service and survives termination until deletion obligations are fulfilled.
15. Governing law
This DPA is governed by the laws of the United Arab Emirates. Courts of Dubai, UAE have exclusive jurisdiction, subject to mandatory law.