Intelligent Enterprise Engineering Doha · Riyadh · Amman
Legal

Data Processing Agreement

Last updated: August 2026

The standard terms governing Binnovy’s processing of personal data on behalf of enterprise customers, aligned first to Qatar’s PDPPL and supplemented for GDPR/UK GDPR where applicable.

01Status and incorporation

This Data Processing Agreement ("DPA") forms part of the commercial agreement between BINNOVY BUSINESS INNOVATION TECHNOLOGY QFZ LLC ("Binnovy") and the customer identified in the relevant order form or agreement ("Customer") where Binnovy processes personal data on Customer’s behalf. If there is a conflict concerning personal-data processing, this DPA prevails over the general Terms of Service, while a specifically negotiated data-protection schedule prevails over this standard DPA to the extent stated in that schedule.

02Definitions and roles

"Personal Data", "Processing", "Controller" and "Processor" have the meanings given by the Qatar PDPPL and, where applicable, the GDPR/UK GDPR or other governing privacy law. For Customer Personal Data processed under this DPA, Customer acts as Controller (or Processor for its own controller) and Binnovy acts as Processor (or sub-processor, as applicable), except where Binnovy independently determines the purpose and means of a separate processing activity and therefore acts as Controller for that activity.

03Customer instructions and lawfulness

Binnovy will process Customer Personal Data only on Customer’s documented instructions, including those contained in the commercial agreement, configuration and authorized support requests, unless processing is required by applicable law. Where legally permitted, Binnovy will inform Customer before processing required by law. Customer is responsible for the lawfulness, fairness, transparency, accuracy and scope of the data and instructions it provides, including notices, consents and other legal bases required from data subjects.

04Processing details

The subject matter, nature, purpose, duration, categories of data subjects and categories of personal data are described in Annex I and may be further specified in the order form or service documentation. Binnovy will not materially expand processing beyond those instructions without Customer authorization or another valid legal basis.

05Confidentiality and personnel

Binnovy will limit access to Customer Personal Data to personnel and authorized contractors who need access for the service and are bound by confidentiality obligations. Binnovy will maintain appropriate privacy, security and role-based training for personnel with access to personal data.

06Security measures

Binnovy will implement and maintain appropriate administrative, technical and physical safeguards proportionate to the sensitivity of Customer Personal Data and the risks of processing, taking into account applicable Qatar requirements and, where relevant, Article 32 GDPR principles. Baseline measures are summarized in Annex II. Customer-specific security commitments, certifications or control parameters apply only if stated in the applicable security schedule, order form or current verified trust documentation.

07Personal-data breaches

Binnovy will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available to Binnovy about the nature of the incident, affected data and systems, likely consequences, containment and remediation, and a contact point for coordination. Information may be provided in phases as the investigation develops. Binnovy will reasonably assist Customer with legally required notifications, taking into account the nature of processing and information available to Binnovy.

08Data-subject requests

Taking into account the nature of processing, Binnovy will provide reasonable technical and organizational assistance enabling Customer to respond to requests to exercise data-protection rights. If Binnovy receives a request concerning Customer Personal Data directly from a data subject, Binnovy will redirect the requester to Customer or notify Customer unless law requires Binnovy to respond independently.

09Compliance assistance

Binnovy will provide reasonable assistance, taking into account the nature of processing and information available to it, with privacy impact assessments, consultations with competent authorities, security inquiries and other controller obligations that apply to the service. Additional professional services outside the standard service scope may be subject to agreed fees.

10Sub-processors

Customer grants Binnovy general authorization to engage approved sub-processors for the service, subject to this section and any stricter authorization model in the commercial agreement. Binnovy will impose written data-protection obligations on each sub-processor that are no less protective in substance for the relevant processing than Binnovy’s obligations under this DPA. Binnovy remains responsible for the performance of its sub-processor obligations to the extent required by applicable law and contract.

Binnovy will maintain a current Sub-processors page identifying approved sub-processors that may process Customer Personal Data, their service purpose and relevant processing location. Binnovy will provide advance notice of a material new or replacement sub-processor where the agreement or applicable law requires notice, allowing Customer a reasonable opportunity to raise a documented data-protection objection.

11International transfers and residency

Binnovy will process Customer Personal Data in the locations permitted by the service configuration, order form and Customer’s documented residency requirements. A claim of in-country, sovereign or air-gapped processing applies only where the relevant deployment has been specifically configured and agreed. Cross-border transfers will use safeguards required by applicable law. Where a transfer of EEA personal data requires the European Commission Standard Contractual Clauses, or a UK transfer requires an approved UK mechanism, the parties will incorporate the appropriate module or addendum by reference or execution as required.

12Government and law-enforcement requests

If Binnovy receives a legally binding demand for Customer Personal Data from a public authority, Binnovy will, where legally permitted, notify Customer and assess the request for legal validity and scope. Binnovy will disclose only data it is legally required to disclose and will not voluntarily provide Customer Personal Data to a public authority beyond lawful authority and the terms of the agreement.

13Audit and evidence

Binnovy will make available information reasonably necessary to demonstrate compliance with this DPA. Where appropriate, this may include current independent audit reports, certifications, control summaries, security documentation or responses to a reasonable assessment. If that information is insufficient for a legal obligation, Customer may request an audit subject to reasonable scope, confidentiality, security, frequency and non-disruption conditions. Audits must not expose other customers’ data, privileged information or security-sensitive details beyond what is necessary.

14Return and deletion

Upon termination or expiry of the service, and subject to Customer’s written choice where technically supported, Binnovy will return or delete Customer Personal Data in accordance with the service’s documented export/deletion process, except to the extent retention is required by law or maintained temporarily in protected backup cycles. Retained data remains subject to this DPA until deleted or anonymized.

15Liability and precedence

Liability arising under this DPA is subject to the liability framework in the applicable commercial agreement, except to the extent mandatory data-protection law requires otherwise. Nothing in this DPA limits a data subject’s rights or a regulator’s powers where they cannot lawfully be limited by contract.

16Governing law

Unless the commercial agreement validly provides otherwise, this DPA is governed by the same law and dispute forum as the commercial agreement. Where no signed commercial agreement specifies them, the governing-law and dispute provisions in the Terms of Service apply, subject to mandatory privacy-law jurisdiction and regulatory authority.

17Annex I — Details of processing

  • Controller / Customer — the customer identified in the applicable order form or commercial agreement.
  • Processor — BINNOVY BUSINESS INNOVATION TECHNOLOGY QFZ LLC, Registration No. FZA 1075, Building 1, Street 504, Zone 49, Qatar Free Zones, Doha, State of Qatar.
  • Subject matter — provision, hosting, support, security, administration and operation of the contracted Binnovy service.
  • Duration — the term of the service plus limited post-termination periods required for export, backup cycling, legal retention or dispute preservation.
  • Nature and purpose — hosting, storage, transmission, computation, authentication, administration, monitoring, support, governance, logging and other service functions configured by Customer.
  • Data subjects — Customer personnel, authorized users, end users, contacts and other persons whose personal data Customer chooses to process through the service.
  • Personal-data categories — determined by Customer’s use case and configuration; may include business-contact, account, authentication, usage, content, transaction, support and technical data.
  • Special-category / special-nature data — not assumed. Customer must identify such data before processing where the service, law or security model requires additional authorization or controls.

18Annex II — Baseline technical and organizational measures

  • Identity and access management based on least privilege and role-appropriate authentication.
  • Encryption for personal data in transit and, where supported by the relevant storage/service layer, at rest using current industry-standard cryptography.
  • Segregation of customer environments, data and privileges appropriate to the deployment architecture.
  • Secure configuration, change control, vulnerability management and patching procedures.
  • Centralized logging, security monitoring and audit records appropriate to the service and risk.
  • Backup, recovery, resilience and business-continuity measures proportionate to service commitments.
  • Incident detection, containment, investigation, remediation and breach-notification processes.
  • Confidentiality commitments and security/privacy training for authorized personnel.
  • Supplier due diligence and contractual controls for approved sub-processors.
  • Privacy-by-design and data-minimization considerations when new processing functionality is designed or materially changed.
  • Customer-configurable residency, sovereignty or isolated-deployment controls where included in the contracted service.

19Annex III — Sub-processors

The binding operational list of approved sub-processors is maintained on /sub-processors and forms part of this DPA by reference where the commercial agreement adopts general authorization. Customer-specific sub-processors or locations may also be listed in the order form or a deployment schedule. The public list must be populated from Binnovy’s verified production vendor inventory before binding publication; vendor names, purposes or locations must not be guessed or published before verification.

Need a signed DPA?

Request the executable DPA through the contact page.