Data Processing Agreement

Between the Customer as controller and the Company as processor, under the Saudi Personal Data Protection Law (Royal Decree M/19 of 9/2/1443H, as amended) and its implementing regulations, and, for customers in the EU/EEA or the UK, the GDPR or UK GDPR.

  1. Purpose. Data is processed only to issue validity certificates and to operate and support the Service — never to train models or for any other purpose without the Customer's written consent.
  2. Data. Document text the Customer sends, its cryptographic fingerprints, account data (organisation name, email) and usage logs. The Customer avoids sending sensitive personal data unless necessary.
  3. Instructions. The Company processes data only on the Customer's documented instructions: this agreement and the Customer's API calls.
  4. Security. Per-customer encryption of stored text (AES-256-GCM); master key kept outside the database; TLS in transit; API keys stored only as fingerprints; tenant isolation; audit log; detection of any unauthorised change to storage; encrypted daily backups.
  5. Confidentiality. Access is limited to staff bound by confidentiality, on a need-to-know basis.
  6. Location. The Service is hosted, and data is stored encrypted, in DigitalOcean's data centre in Frankfurt, Germany (European Union), and is operated by the Company's team from the Kingdom of Saudi Arabia. This transfer follows the Saudi Personal Data Protection Law and its Regulation on Personal Data Transfer outside the Kingdom, with the safeguards in clause 7. The Company gives 30 days' notice of any change of hosting location.
  7. International transfers. All Customer Data stays stored in the EU; the Company's access to it from Saudi Arabia for operations and support is an international transfer. For Customers in the EU/EEA, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated by reference, with the Kingdom of Saudi Arabia as the third country; for UK Customers, the ICO's International Data Transfer Addendum applies. These clauses prevail on transfer matters.
  8. Sub-processors. Listed in the annex. The Company gives 30 days' notice of any change and the Customer may object.
  9. Incidents. The Company notifies the Customer without undue delay and within 24 hours of becoming aware of a breach affecting its data, with the information the Customer needs to meet its own notification duties.
  10. Data subject rights. The Company assists with access, correction and erasure requests; erasure is also available directly through the API (DELETE /v1/account).
  11. Retention and deletion. Data is kept for the subscription and deleted within 30 days of its end or of the Customer's request, including backups on rotation, except records the law requires (such as billing).
  12. Audit. The Company provides evidence of compliance on request; the Customer can independently verify its ledger through the signed root and public key.

Annex — Sub-processors

Party Purpose Location
DigitalOcean, LLC Hosting the Service, storing encrypted data and backups Frankfurt, Germany (EU)
Cloudflare, Inc. Hosting the product page and DNS; no document data passes through it International
Moyasar Payments for GCC customers; card data never reaches the Company Kingdom of Saudi Arabia
Paddle Merchant of Record and payments outside the GCC United Kingdom / international

Effective from publication on the website. Last updated: 2026-10-01.