This DPA forms part of the agreement between Yousef Abdullah (a sole trader trading as Attestly) (“Attestly”, the “Processor”) and the customer identified in the applicable order or account (“Customer”, the “Controller”) for the use of Attestly (the “Service”). It governs the Processor’s processing of Personal Data on behalf of the Controller.
“Personal Data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given under Applicable Data Protection Law. “Applicable Data Protection Law” means all privacy and data protection laws applicable to the processing, including, as relevant, the EU/UK General Data Protection Regulation (GDPR), the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”), the DIFC Data Protection Law (DIFC Law No. 5 of 2020), and the ADGM Data Protection Regulations 2021.
The Controller determines the purposes and means of processing; the Processor processes Personal Data only on the Controller’s documented instructions, including as set out in this DPA and the Service configuration. The subject matter, duration, nature, and purpose of processing, and the categories of data and data subjects, are described in Annex A.
The Controller authorises the Processor to engage the subprocessors listed in the Privacy Policy (§3 and §3a), which describes each subprocessor’s purpose, the data shared, and its processing location. The Processor imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. The Processor will give the Controller advance notice of any intended addition or replacement of a subprocessor and a reasonable opportunity to object.
Application and database hosting occur in the Processor’s primary region, the United States, with EU (Frankfurt) hosting available for eligible plans and on request. AI processing (drafting and semantic matching) is performed by subprocessors located in the United States. Where Personal Data is transferred across borders, the Processor relies on appropriate safeguards recognised under Applicable Data Protection Law, including the EU Standard Contractual Clauses and equivalent mechanisms for UAE PDPL, DIFC, and ADGM transfers, as set out in Annex C.
The Processor maintains the measures in Annex B, including encryption in transit and at rest, hashed credentials, per-tenant access scoping, rate limiting, and audit logging. The Processor reviews these measures periodically and may update them provided the level of protection is not reduced.
The Processor will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller’s data, with the information reasonably available to support the Controller’s own notification obligations (including the GDPR 72-hour framework and PDPL breach-notification requirements, where applicable).
Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise data-subject rights under Applicable Data Protection Law.
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and security controls. The Processor may satisfy audit requests by providing its current third-party attestations (e.g., SOC 2 / ISO 27001) under NDA.
On termination of the Service, the Processor will, at the Controller’s choice, delete or return the Personal Data and delete existing copies, except to the extent retention is required by law. Production data is deleted within the period stated in the Privacy Policy; backups age out on their normal rotation.
This DPA remains in effect for the duration of the processing under the agreement. Liability is subject to the limitations in the underlying agreement. This DPA is governed by England and Wales, without prejudice to any mandatory provisions of Applicable Data Protection Law.
| Subject matter | Drafting and management of security-questionnaire answers from Controller-provided content. |
|---|---|
| Duration | For the term of the agreement, plus the retention window in the Privacy Policy. |
| Nature & purpose | Storage, retrieval, semantic matching, and AI-assisted drafting to deliver the Service. |
| Categories of data | Account data (name, work email); Controller content that may contain Personal Data (e.g., names/roles in policies or questionnaires). Controller should avoid uploading special-category data. |
| Data subjects | Controller’s personnel and any individuals referenced in Controller content. |