Data Processing Agreement (DPA)
Version: 1.0
Effective Date: June 16, 2026
1. Introduction and Incorporation
This Data Processing Agreement («DPA») forms an integral part of the Master Services Agreement, Statement of Work, or any other written agreement (the «Agreement») between Unistack Software Services - FZCO («Processor», «we», «us», or «our») and the customer («Controller», «you», or «your»).
By entering into the Agreement, the Parties agree to the terms of this DPA. In the event of any conflict between this DPA and the Agreement regarding the processing of Personal Data, the terms of this DPA shall prevail.
2. Definitions
Capitalized terms used but not defined in this DPA shall have the meanings given to them in the Agreement or Applicable Data Protection Laws:
- «Applicable Data Protection Law» means all applicable laws relating to the processing of Personal Data, including but not limited to the UAE Federal Decree-Law No. 45 of 2021 (UAE PDPL), the EU General Data Protection Regulation (GDPR), and the UK GDPR.
- «Personal Data», «Processing», «Data Subject», and «Personal Data Breach» have the meanings given in Applicable Data Protection Law.
- «Standard Contractual Clauses» (SCCs) means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as adopted by the European Commission.
3. Scope and Nature of Processing
Processor shall process Personal Data only on documented instructions from the Controller (including this DPA and the Agreement). The details of the processing are as follows:
- Subject matter: Provision of software development, IT, AI/ML, and related services.
- Duration: For the duration of the Agreement, plus any period required for secure data deletion or as mandated by law.
- Nature and purpose: Development, testing, deployment, hosting, and maintenance of software solutions.
- Categories of Data Subjects: Employees, contractors, or end-users of the Controller.
- Categories of Personal Data: Names, contact details, professional information, and technical identifiers (e.g., IP addresses). Processor shall not process Special Categories of Personal Data (e.g., health, biometric data) unless explicitly authorized in writing.
4. Processor Obligations
- Confidentiality: Processor ensures that all personnel authorized to process Personal Data are bound by a strict duty of confidentiality.
- Security: Processor implements and maintains appropriate Technical and Organizational Measures (TOMs) to protect Personal Data, as detailed in our Trust & Security Policy.
- Assistance: Processor shall reasonably assist the Controller in fulfilling its obligations to respond to Data Subject rights requests, conduct Data Protection Impact Assessments (DPIAs), and ensure compliance with security breach notification obligations.
5. Sub-processors
- General Authorization: Controller grants Processor a general written authorization to engage Sub-processors.
- Transparency: Processor maintains an up-to-date list of all authorized Sub-processors. The current list is publicly available at: https://getunistack.com/legal/sub-processors.
- Objection Right: Processor will notify the Controller of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance. The Controller may object to such changes on reasonable data protection grounds.
- Liability: Processor shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA. Processor remains fully liable to the Controller for the acts and omissions of its Sub-processors.
6. International Data Transfers
If Processor transfers Personal Data originating from the European Economic Area (EEA), UK, or Switzerland to a third country (including the UAE) not recognized as providing an adequate level of protection, such transfer shall be governed by the EU Standard Contractual Clauses (SCCs) and/or the UK International Data Transfer Addendum (IDTA), which are incorporated herein by reference. Processor warrants compliance with UAE PDPL requirements for cross-border data transfers.
7. Personal Data Breach Notification
Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours of becoming aware of a Personal Data Breach. The notification will include the nature of the breach, categories of data/subjects affected, likely consequences, and measures taken to mitigate the breach. Processor will fully cooperate with the Controller in investigating and remedying the breach.
8. Audit Rights
Upon at least thirty (30) days' prior written notice, and no more than once per calendar year, the Controller (or an independent auditor bound by confidentiality) may audit Processor's compliance with this DPA. To minimize business disruption, Processor may satisfy this requirement by providing the Controller with a recent, relevant third-party audit report (e.g., SOC 2, ISO 27001) or by completing the Controller's standard security questionnaire.
9. Data Retention and Deletion
Upon termination or expiration of the Agreement, or upon the Controller's written request, Processor shall, at the Controller's choice, securely delete or return all Personal Data to the Controller, and delete existing copies, unless Applicable Data Protection Law requires the storage of such data.
10. Governing Law
This DPA shall be governed by and construed in accordance with the laws specified in the Agreement, subject to the mandatory provisions of Applicable Data Protection Law.
11. Contact Information
For any questions or requests regarding this DPA or data protection practices, please contact us at:
Email: compliance@getunistack.com
Address: Unistack Software Services - FZCO, IFZA Business Park, DDP, PO Box 342001, Dubai, UAE.