This Data Processing Agreement (“DPA”) forms part of the SaaS
Agreement.
-
1. Roles:
- Customer: Data Controller
- Provider: Data Processor
-
2. Scope:
Provider processes personal data solely for providing the Service.
-
3. Processing & Security:
Provider shall implement reasonable technical and organisational measures, including
encryption and access controls. Provider does not guarantee absolute security.
-
4. Sub-Processors:
Provider may engage cloud and infrastructure sub-processors, including hosting providers
in the US, UK, or other jurisdictions.
-
5. Cross-Border Transfers:
Customer consents to cross-border processing and storage of data outside Pakistan.
-
6. Data Breach:
Provider shall take reasonable steps to mitigate known data breaches but does not
warrant breach-free systems.
-
7. Deletion:
Personal data will be deleted in accordance with the SaaS Agreement’s retention policy.
-
8. Termination:
This DPA terminates automatically upon termination of the SaaS Agreement.