Data Processing Addendum (DPA)
Effective 15 May 2026. This Addendum forms part of the master agreement between the parties.
1. Parties & roles
This Data Processing Addendum ("DPA") forms part of the agreement between the Customer (the financial institution, acting as "Controller") and AgileCatalyst ai LTD ("Processor"), operator of the DocChat service (the "Service"). It governs the Processor's processing of personal data on the Controller's behalf under the UAE Personal Data Protection Law (PDPL) and other applicable regional frameworks.
2. Processing details
- Subject matter: Collection, storage, and management of customer documents via the Service.
- Duration: The term of the master services agreement.
- Nature and Purpose: Secure document request, upload, storage, review, and cryptographic audit logging on behalf of the Controller.
- Data types: Contact details (email address, mobile phone number); identity or financial documents uploaded by data subjects; operator account details; and technical/usage metadata.
- Data subjects: The Controller's customers and authorised operators.
3. Processor obligations
The Processor agrees and commits to:
- Process Personal Data only on documented instructions from the Controller, unless required by applicable law.
- Ensure that all personnel authorised to process Personal Data have committed to confidentiality.
- Implement the technical and organisational measures outlined in our Security Overview.
- Assist the Controller in responding to data-subject rights requests under the UAE PDPL.
- Notify the Controller without undue delay (and in any event within 48 hours) upon becoming aware of a security incident affecting Personal Data.
- Delete or return all Personal Data on contract termination per the Controller's instructions.
4. Sub-processors
The Controller authorises the engagement of the following Sub-processors to deliver the Service. The Processor will provide at least 30 days' advance notice of any planned changes to this list, during which the Controller may object on reasonable security grounds.
| Sub-processor | Purpose | Data Categories | Location |
|---|---|---|---|
| Microsoft Azure | Hosting, database, document and audit storage | All customer data (encrypted) | UAE North |
| Resend | Transactional email delivery | Email addresses, delivery metadata (no documents) | US/global |
| SMSGlobal | SMS delivery of links/codes | Phone numbers, message content, delivery status (no documents) | Australia |
| Cloudflare | CDN, WAF, DDoS mitigation, DNS | IP addresses, request metadata | US/global edge |
| PostHog | Product analytics (consent-gated) | Usage events, IP, device information | US Cloud |
| Google Analytics | Web analytics (consent-gated) | Usage events, IP, device information | US/global |
5. International transfers
Where a sub-processor processes data outside the UAE, the Processor applies appropriate safeguards consistent with the cross-border transfer requirements of the UAE PDPL.
6. Security and Audits
We implement the security controls detailed in our Security Overview. Regulated Controller institutions are permitted to conduct reasonable audits to verify compliance, subject to mutual agreement on scope, timing, and confidentiality.