Legal

Data Processing Addendum

Processor terms for hosted All Office Subscription Customer Personal Data under UAE PDPL.

Effective 13 August 2026 · Version dpa-en-2026-08-13-draft1

1. Scope and roles

1.1 This DPA forms part of the Terms of Service for the Subscription Service. If this DPA conflicts with the Terms on personal-data processing, this DPA prevails (Terms Clause 20.2).

1.2 Customer determines purposes and means of processing Customer Personal Data in the hosted workspace (controller). Nourvia processes that data only on documented instructions (processor), except where UAE law requires otherwise.

1.3 Nourvia is controller of Site, billing, account and marketing data under the Privacy Policy. Those activities are outside this DPA.

1.4 Customer Personal Data may include: employee identity and HR records; Emirates ID, passport and visa details; payroll and bank details; attendance and leave; customers and suppliers of the Customer; invoices, bills and accounting records; and related logs. Some of this may be PDPL sensitive personal data. Customer warrants it has a PDPL basis to collect it and to instruct Nourvia.

1.5 After handover of a Perpetual Self-Hosted Licence, the Customer is controller of tenant data on Customer-controlled infrastructure. This DPA does not make Nourvia processor of that on-premises data, except personal data the Customer sends Nourvia for support and licence-validation telemetry described in the Privacy Policy.

2. Instructions

Nourvia will process Customer Personal Data only to host, back up, secure, support and update the Subscription Service, and as the Customer instructs through the product and written support requests. Nourvia will inform the Customer if an instruction appears to infringe PDPL, unless the law prohibits that notice.

3. Confidentiality and personnel

Nourvia will ensure persons authorised to process Customer Personal Data are bound by confidentiality and receive appropriate access only.

4. Security

Nourvia will implement technical and organisational measures appropriate to the risk, including: access control; encryption in transit (HTTPS); backups; logging; and environment separation as documented. We do not claim ISO, SOC or similar certifications we do not hold. Customer is responsible for administrator accounts, credentials, authorised users and configurations (Terms Clause 7.8).

5. Subprocessors

Customer authorises Nourvia to use subprocessors described in the Privacy Policy (hosting, backups, email, Cloudflare as applicable to the hosted app, Stripe for billing, and others notified). Nourvia will impose data-protection terms no less protective than this DPA and remains responsible for subprocessors. Nourvia will give thirty (30) days’ notice of a material subprocessor change where practicable; Customer may object on reasonable PDPL grounds and, if unresolved, may cancel the Subscription under Terms Clause 7.5.

6. International transfers

Customer Personal Data may be transferred outside the UAE as described in the Privacy Policy. Nourvia will use a PDPL Art. 22/23 mechanism (typically necessity for a contract, and/or a contract requiring PDPL-level protections). Customer is responsible for any additional basis it needs as controller (including DIFC/ADGM rules, GDPR/UK GDPR, or other local law if the Customer is established or processes data there). This DPA is PDPL-based; a GDPR standard-contractual-clause pack is not included unless a later addendum says so.

7. Assistance

Taking into account the nature of processing, Nourvia will assist the Customer with: data-subject requests; PDPL security and DPIA/regulator questions that relate to Nourvia’s processing; and breach handling. Reasonable professional-services fees may apply to assistance beyond ordinary support.

8. Breach

Nourvia will notify the Customer without undue delay and no later than 72 hours after becoming aware of a personal-data breach affecting Customer Personal Data, with facts then known (nature, categories, likely consequences, measures taken). Customer is responsible for notifying the competent authority (the UAE Data Office where PDPL applies, and any other authority that applies to the Customer) and data subjects unless the law requires Nourvia to notify directly.

9. Return and deletion

On termination or expiry of the Subscription, Nourvia will make Customer Data available for export for thirty (30) days in the export formats then available in the product, then delete or irreversibly anonymise production Customer Personal Data according to the retention schedule, except legal holds and backup expiry cycles.

10. Audits

On reasonable written notice, Nourvia will provide evidence of compliance (security summary, subprocessor list, and — no more than once per 12 months except after a breach — answers to a written questionnaire). On-site audit only if the questionnaire is reasonably insufficient and subject to confidentiality, scheduling and Customer’s cost.

11. Demo tenants

Unless the order says otherwise, demo tenants are evaluation environments with sample data. Customer must not load production identity or payroll data. If Customer does so anyway, Customer remains controller and Nourvia will delete the tenant at expiry as for other demos.

12. Contact

Questions about this DPA: [email protected].