Data Processing Addendum (DPA)

Effective 15 May 2026. This Addendum forms part of the master agreement between the parties.

1. Parties & roles

This Data Processing Addendum ("DPA") forms part of the agreement between the Customer (the financial institution, acting as "Controller") and AgileCatalyst ai LTD ("Processor"), operator of the DocChat service (the "Service"). It governs the Processor's processing of personal data on the Controller's behalf under the UAE Personal Data Protection Law (PDPL) and other applicable regional frameworks.

2. Processing details

  • Subject matter: Collection, storage, and management of customer documents via the Service.
  • Duration: The term of the master services agreement.
  • Nature and Purpose: Secure document request, upload, storage, review, and cryptographic audit logging on behalf of the Controller.
  • Data types: Contact details (email address, mobile phone number); identity or financial documents uploaded by data subjects; operator account details; and technical/usage metadata.
  • Data subjects: The Controller's customers and authorised operators.

3. Processor obligations

The Processor agrees and commits to:

  • Process Personal Data only on documented instructions from the Controller, unless required by applicable law.
  • Ensure that all personnel authorised to process Personal Data have committed to confidentiality.
  • Implement the technical and organisational measures outlined in our Security Overview.
  • Assist the Controller in responding to data-subject rights requests under the UAE PDPL.
  • Notify the Controller without undue delay (and in any event within 48 hours) upon becoming aware of a security incident affecting Personal Data.
  • Delete or return all Personal Data on contract termination per the Controller's instructions.

4. Sub-processors

The Controller authorises the engagement of the following Sub-processors to deliver the Service. The Processor will provide at least 30 days' advance notice of any planned changes to this list, during which the Controller may object on reasonable security grounds.

Sub-processorPurposeData CategoriesLocation
Microsoft AzureHosting, database, document and audit storageAll customer data (encrypted)UAE North
ResendTransactional email deliveryEmail addresses, delivery metadata (no documents)US/global
SMSGlobalSMS delivery of links/codesPhone numbers, message content, delivery status (no documents)Australia
CloudflareCDN, WAF, DDoS mitigation, DNSIP addresses, request metadataUS/global edge
PostHogProduct analytics (consent-gated)Usage events, IP, device informationUS Cloud
Google AnalyticsWeb analytics (consent-gated)Usage events, IP, device informationUS/global

5. International transfers

Where a sub-processor processes data outside the UAE, the Processor applies appropriate safeguards consistent with the cross-border transfer requirements of the UAE PDPL.

6. Security and Audits

We implement the security controls detailed in our Security Overview. Regulated Controller institutions are permitted to conduct reasonable audits to verify compliance, subject to mutual agreement on scope, timing, and confidentiality.

Ready to modernize your compliance?

Join the forward-thinking UAE financial institutions using DocChat to collect documents securely.