Legal

Data Processing Addendum

This addendum forms part of the Terms of Use and governs our processing of personal data on your behalf. It applies automatically — you do not need to request or sign a separate copy, though we will countersign one if your procurement process requires it.

Version 3.0Effective 1 August 2026Updated 1 August 2026
In short
  • You are the controller; we are the processor acting only on your instructions.
  • Your application data stays in the regions you select.
  • Sub-processors are listed below and you get 30 days notice before we add one.
  • We notify you of a personal data breach within 48 hours of confirming it.

1. Roles and scope

You determine the purpose and means of processing personal data contained in your content; we process it only to provide the services, to comply with your instructions, and to meet legal obligations. Where we process account and billing data about your staff, we do so as a controller under the Privacy Policy.

2. Details of processing

ItemDetail
Subject matterHosting, building, storing, and transmitting your application and its data
DurationFor the term of your account, plus the deletion windows in section 7
NatureStorage, computation, transmission, backup, logging, and support access on request
Data subjectsWhoever your application serves — determined by you, not by us
Data typesWhatever your application stores. We do not require or inspect categories.

3. Our obligations

  • Process only on your documented instructions, and tell you if an instruction appears unlawful.
  • Keep processing confidential and bind staff to confidentiality that survives their employment.
  • Apply the technical and organisational measures described in Security.
  • Assist you with data subject requests, impact assessments, and regulator enquiries.
  • Make available the information needed to demonstrate compliance, and permit audit on reasonable notice.

4. Sub-processors

You authorise the sub-processors below. Each is bound by terms no less protective than this addendum, and we remain liable for their performance. We give 30 days notice before adding one; if you object on reasonable data-protection grounds, you may terminate the affected service without penalty.

Sub-processorPurposeLocation
Infrastructure providersCompute, storage, and network capacity in the regions you selectPer region
Payment processorCard processing and invoicingEU, US
Email providerTransactional and account emailEU
Model providersAI features you trigger, under zero-retention termsUS, EU
Support platformTickets and correspondenceEU

5. International transfers

Application data remains in the regions you choose. Where personal data leaves the EEA, UK, or UAE, we rely on Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with supplementary measures including encryption in transit and at rest and a policy of challenging unlawful access requests.

6. Breach notification

We notify you without undue delay and in any event within 48 hours of confirming a personal data breach affecting your content, with the nature of the breach, the categories and approximate volume of records, the likely consequences, and the measures taken. You remain responsible for notifying regulators and data subjects where required.

7. Return and deletion

  • You can export your data at any time through the API, CLI, or dashboard.
  • Deleting a resource purges it, including from backup media, within 30 days.
  • On account closure, content is retained for 14 days for export, then deleted within a further 30 days.
  • We keep only what law requires — billing records for 7 years, with no application content.

8. Data subject requests

If we receive a request relating to your data, we redirect it to you rather than answering it. Where you need our help to locate or delete records, we assist at no charge for reasonable volumes.

9. Liability and precedence

The liability cap in the Terms of Use applies to this addendum. Where this addendum conflicts with the Terms of Use on the processing of personal data, this addendum prevails.

Contact

Darwa Technologies FZ-LLC, Dubai Internet City, Dubai, United Arab Emirates. Written notice may be sent to legal@darwa.com. Security reports go to security@darwa.com. Privacy requests go to privacy@darwa.com.