Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the SaaS Agreement.

  1. 1. Roles:

    • Customer: Data Controller
    • Provider: Data Processor
  2. 2. Scope:

    Provider processes personal data solely for providing the Service.
  3. 3. Processing & Security:

    Provider shall implement reasonable technical and organisational measures, including encryption and access controls. Provider does not guarantee absolute security.
  4. 4. Sub-Processors:

    Provider may engage cloud and infrastructure sub-processors, including hosting providers in the US, UK, or other jurisdictions.
  5. 5. Cross-Border Transfers:

    Customer consents to cross-border processing and storage of data outside Pakistan.
  6. 6. Data Breach:

    Provider shall take reasonable steps to mitigate known data breaches but does not warrant breach-free systems.
  7. 7. Deletion:

    Personal data will be deleted in accordance with the SaaS Agreement’s retention policy.
  8. 8. Termination:

    This DPA terminates automatically upon termination of the SaaS Agreement.