Attestly

Data Processing Agreement

Last updated: 17 August 2026 · Effective: 17 August 2026

⚠ Template — not legal advice. This Data Processing Agreement (DPA) template was generated for Attestly and is not a substitute for review by a qualified attorney or privacy specialist. Fill in every [bracketed] field, confirm it matches your live processing and subprocessors, and have counsel adapt the jurisdiction annexes (GDPR, UAE PDPL, DIFC, ADGM) to your actual entity and data flows before signing.

This DPA forms part of the agreement between Yousef Abdullah (a sole trader trading as Attestly) (“Attestly”, the “Processor”) and the customer identified in the applicable order or account (“Customer”, the “Controller”) for the use of Attestly (the “Service”). It governs the Processor’s processing of Personal Data on behalf of the Controller.

1. Definitions

“Personal Data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given under Applicable Data Protection Law. “Applicable Data Protection Law” means all privacy and data protection laws applicable to the processing, including, as relevant, the EU/UK General Data Protection Regulation (GDPR), the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”), the DIFC Data Protection Law (DIFC Law No. 5 of 2020), and the ADGM Data Protection Regulations 2021.

2. Roles and scope of processing

The Controller determines the purposes and means of processing; the Processor processes Personal Data only on the Controller’s documented instructions, including as set out in this DPA and the Service configuration. The subject matter, duration, nature, and purpose of processing, and the categories of data and data subjects, are described in Annex A.

3. Processor obligations

4. Subprocessors

The Controller authorises the Processor to engage the subprocessors listed in the Privacy Policy (§3 and §3a), which describes each subprocessor’s purpose, the data shared, and its processing location. The Processor imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. The Processor will give the Controller advance notice of any intended addition or replacement of a subprocessor and a reasonable opportunity to object.

5. International transfers and data location

Application and database hosting occur in the Processor’s primary region, the United States, with EU (Frankfurt) hosting available for eligible plans and on request. AI processing (drafting and semantic matching) is performed by subprocessors located in the United States. Where Personal Data is transferred across borders, the Processor relies on appropriate safeguards recognised under Applicable Data Protection Law, including the EU Standard Contractual Clauses and equivalent mechanisms for UAE PDPL, DIFC, and ADGM transfers, as set out in Annex C.

6. Security

The Processor maintains the measures in Annex B, including encryption in transit and at rest, hashed credentials, per-tenant access scoping, rate limiting, and audit logging. The Processor reviews these measures periodically and may update them provided the level of protection is not reduced.

7. Personal data breaches

The Processor will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller’s data, with the information reasonably available to support the Controller’s own notification obligations (including the GDPR 72-hour framework and PDPL breach-notification requirements, where applicable).

8. Data-subject rights

Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise data-subject rights under Applicable Data Protection Law.

9. Audits

The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and security controls. The Processor may satisfy audit requests by providing its current third-party attestations (e.g., SOC 2 / ISO 27001) under NDA.

10. Return and deletion

On termination of the Service, the Processor will, at the Controller’s choice, delete or return the Personal Data and delete existing copies, except to the extent retention is required by law. Production data is deleted within the period stated in the Privacy Policy; backups age out on their normal rotation.

11. Term, liability, and governing law

This DPA remains in effect for the duration of the processing under the agreement. Liability is subject to the limitations in the underlying agreement. This DPA is governed by England and Wales, without prejudice to any mandatory provisions of Applicable Data Protection Law.


Annex A — Details of processing

Subject matterDrafting and management of security-questionnaire answers from Controller-provided content.
DurationFor the term of the agreement, plus the retention window in the Privacy Policy.
Nature & purposeStorage, retrieval, semantic matching, and AI-assisted drafting to deliver the Service.
Categories of dataAccount data (name, work email); Controller content that may contain Personal Data (e.g., names/roles in policies or questionnaires). Controller should avoid uploading special-category data.
Data subjectsController’s personnel and any individuals referenced in Controller content.

Annex B — Technical and organisational measures

Annex C — Transfer mechanisms


← Privacy Policy  ·  Terms of Service  ·  Home