Data Processing Agreement
This Data Processing Agreement (DPA) is concluded between the Customer (Controller) and NO BORING SHOPS L.L.C-FZ (Processor) and forms an integral part of the Terms of Service. It is written to the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021); where the Controller is established in the European Union, it is additionally concluded pursuant to Article 28 GDPR and the Processor's obligations are read to the higher standard.
1. Scope and instructions
This DPA governs the processing of personal data by NO BORING SHOPS L.L.C-FZ (Processor) on behalf of the Customer (Controller) in connection with the TeamIntel services.
The Processor shall process personal data only on documented instructions from the Controller, including transfers to third countries, unless required to do so by applicable law.
2. Obligations of the processor
The Processor shall:
- Process personal data only on documented instructions from the Controller
- Ensure persons authorized to process data have committed to confidentiality
- Implement appropriate technical and organizational security measures
- Respect conditions for engaging sub-processors
- Assist the Controller with data subject rights requests
- Assist with the Controller’s own obligations (security, breach notification, impact assessments)
- Delete or return all personal data upon termination
- Make available information necessary to demonstrate compliance
3. Sub-processors
The Processor shall not engage another processor without prior specific or general written authorization of the Controller. A current list of sub-processors is maintained and made available to the Controller. The Controller shall be notified of any intended changes to sub-processors with at least 30 days notice.
4. Data security
The Processor implements the following technical and organizational measures:
- AES-256 encryption of data at rest
- TLS 1.3 encryption of data in transit
- Role-based access control and principle of least privilege
- Multi-factor authentication for all administrative access
- Regular security audits and penetration testing
- EU-resident infrastructure
- Automated backup and disaster recovery procedures
- Network segmentation and intrusion detection systems
5. Personal data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. Notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
6. Data subject rights
The Processor shall assist the Controller in responding to data subject requests, including access, rectification, erasure, restriction, portability and objection. The Processor shall promptly forward any data subject request it receives directly to the Controller.
7. Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA. The Controller may conduct audits, including inspections, with reasonable notice. The Processor shall contribute to and cooperate with such audits. Where the Processor holds a current third-party audit report, it may be offered to satisfy an audit request; the Processor holds no such certification at present and makes no representation that one exists.
8. Termination
Upon termination of data processing services, the Processor shall, at the choice of the Controller, delete or return all personal data and delete existing copies unless applicable law requires storage. Data shall be available for export for 90 days following termination.
9. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA shall limit either party's liability for breaches of data protection obligations to the extent such limitation is not permitted by applicable law.