Bid.Guide
Data Processing Addendum
← HomeRequest countersignature

1. Definitions

Terms used here have the meanings in the GDPR / Saudi PDPL / UAE PDPL. "Personal Data" means any information relating to an identified or identifiable natural person.

2. Subject matter, duration, nature, purpose

3. Categories of data & data subjects

4. Processor obligations

The Processor shall:

5. Sub-processors

The Controller authorises the engagement of sub-processors listed in the current Sub-processor Register. We give 30 days' prior notice of any addition or replacement; you may object on reasonable grounds. We bind every sub-processor to obligations no less protective than this DPA.

6. International transfers

Personal Data is primarily processed in UAE-North and KSA-Riyadh. Any cross-border transfer of Personal Data subject to GDPR is made under the EU SCCs (2021/914) modules as appropriate, attached as Annex I. Transfers of GCC government-procurement data are made only where lawful in the relevant jurisdiction and subject to a documented Transfer Impact Assessment.

7. Security measures

See Annex II. We maintain ISO 27001 certification; SOC 2 Type II is in progress.

8. Breach notification

We notify the Controller without undue delay and in any event within 24 hours of becoming aware of a Personal Data breach affecting their data, providing: nature, categories, approximate number of records, likely consequences, measures taken or proposed. We assist with onward notification to data subjects and supervisory authorities.

9. Assistance with data-subject rights

We assist the Controller with access, rectification, erasure, restriction, portability, and objection requests via in-app self-service tools and, where needed, dedicated DPO support, normally within 7 days of request.

10. Audits

We make available our current SOC 2 / ISO 27001 reports and audited TOMs on request. Controllers may, on 30 days' notice and at their cost, audit our compliance with this DPA at a frequency not exceeding once per year, scoped to documents and personnel reasonably necessary, subject to confidentiality.

11. Return & deletion

On termination, we return Personal Data on request (export to JSON / CSV / standard formats) and delete remaining copies within 30 days, except where retention is required by law (e.g. KSA 10-year procurement records). Deletion is verified via secure crypto-shredding for any encrypted volumes.

12. Liability

Liability under this DPA is subject to the limitations in the Terms.

Annex I — SCCs / GCC transfer mechanisms

EU SCC modules: 2 (controller → processor) where you transfer EU resident data to us; 3 (processor → sub-processor) for our sub-processor chain. UAE PDPL Article 22 adequacy: we rely on adequacy where the destination jurisdiction has been listed by the UAE Data Office, otherwise on the Standard Contractual Clauses framework issued under UAE PDPL. KSA PDPL Articles 29–32: KSA-resident data is processed in-region; any exception is escalated to the Controller for explicit pre-approval and documented in this Annex.

Annex II — Technical & organisational measures