All legal documents

Data Processing Agreement (DPA)

Between [COMPANY_LEGAL_NAME] ("Processor", "MyAdvisior") and the Customer ("Controller").

Effective date: [EFFECTIVE_DATE]

Draft for legal review. This DPA is written to align with Saudi PDPL and GDPR Art. 28. It must be finalized by qualified counsel and, where GDPR applies, accompanied by Standard Contractual Clauses for restricted transfers. See legal/README.md.

This DPA forms part of the Terms of Service and applies where MyAdvisior processes Personal Data on the Customer's behalf in connection with the Platform.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Sub-processor" have the meanings given under applicable data-protection law (PDPL; and the GDPR/UK GDPR where applicable). "Customer Personal Data" means Personal Data within Customer Content processed by MyAdvisior as Processor.

2. Roles and scope

2.1 The Customer is the Controller (or processor acting for a third-party controller) and MyAdvisior is the Processor of Customer Personal Data.

2.2 Subject matter & duration: the provision of the Platform for the term of the Customer's subscription. Nature & purpose: hosting, storage, retrieval, AI analysis, and related processing to deliver the Platform. Types of data: as determined by the Customer (may include names, contacts, matter/case details, and document contents). Data subjects: as determined by the Customer (e.g. the Customer's staff, clients, counterparties).

3. Processor obligations

MyAdvisior will:

  1. Process only on documented instructions from the Customer (including via the Platform's features and configuration), unless required by law (in which case it will inform the Customer where lawful).
  2. Ensure persons authorized to process are bound by confidentiality.
  3. Implement appropriate technical and organizational security measures (Section 6 / Annex B).
  4. Respect the conditions for engaging Sub-processors (Section 4).
  5. Assist the Customer, taking into account the nature of processing, with: responding to Data Subject requests; security; breach notification; data-protection impact assessments; and prior consultation.
  6. At the Customer's choice, delete or return Customer Personal Data at the end of the service and delete existing copies, except where retention is legally required (Section 7).
  7. Make available information necessary to demonstrate compliance and allow for audits as set out in Section 8.
  8. Notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, with the information reasonably available.

4. Sub-processors

4.1 The Customer provides general authorization for MyAdvisior to engage Sub-processors to provide the Platform. A current list is maintained at [SUBPROCESSOR_LIST_URL] (e.g. cloud hosting, object storage, email, payment processing, error tracking, and AI provider).

4.2 MyAdvisior will impose data-protection obligations on Sub-processors substantially similar to those in this DPA and remains responsible for their performance.

4.3 MyAdvisior will give the Customer notice of intended changes to Sub-processors and a reasonable opportunity to object on reasonable data-protection grounds.

5. Data Subject rights & assistance

MyAdvisior will, to the extent legally permitted, promptly notify the Customer of Data Subject requests it receives relating to Customer Personal Data and will not respond directly except on the Customer's instruction. The Platform provides Customer-administrator tools to access, export, correct, and delete Customer Content to help the Customer meet its obligations.

6. Security measures

MyAdvisior maintains measures designed to ensure a level of security appropriate to the risk, including those summarized in Annex B. MyAdvisior does not claim any specific certification unless and until independently audited.

7. Retention, return, and deletion

On termination or expiry, and on Customer request, MyAdvisior will delete or return Customer Personal Data within a commercially reasonable period, subject to legal-retention obligations and the expiry of routine backups on a rolling schedule.

8. Audit

MyAdvisior will make available information reasonably necessary to demonstrate compliance with this DPA. Where required by applicable law, and subject to reasonable confidentiality and security conditions, the Customer may conduct (or appoint an auditor to conduct) an audit no more than once per year, or following a breach, on reasonable prior notice.

9. International transfers

Where MyAdvisior transfers Customer Personal Data across borders, it will use a lawful transfer mechanism under applicable law. For restricted transfers subject to GDPR/UK GDPR, the applicable Standard Contractual Clauses (and UK Addendum) are incorporated by reference and prevail over conflicting DPA terms to the extent required. (Attach/execute as required; confirm with counsel.)

10. Liability & precedence

Liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict on data-protection matters, this DPA prevails over the Terms.


Annex A — Processing details

  • Categories of data subjects, data, special categories, processing operations, and duration: as configured by the Customer through its use of the Platform (Section 2.2).

Annex B — Technical & organizational measures (summary)

  • Tenant isolation via database row-level security (a restricted, non-superuser runtime role to which RLS policies actually apply); cross-tenant access is prevented at the data layer.
  • Encryption in transit; private object storage for uploaded files (no public URLs).
  • Authentication: password hashing, optional MFA with encrypted secrets, short-lived access tokens with refresh-token rotation.
  • Access control: role-based permissions; platform-operator functions restricted to dedicated roles.
  • Abuse controls: rate-limiting and per-tenant usage quotas.
  • Auditability: an append-only audit log of significant actions.
  • Operations: environment-variable/secret validation at boot, monitoring/metrics, alerting, regular backups, and a disaster-recovery restore drill.

Annex C — Sub-processors

  • Maintained at [SUBPROCESSOR_LIST_URL].