D

Legal

Data Processing Agreement

Last updated: 2026-04-21

Draft — pending legal review

This document is a draft prepared on 2026-04-21. It has not yet been reviewed by a licensed legal counsel. Do not rely on it for legal purposes.

Parties

Data Controller: The Customer (agency or broker) identified in the Service Agreement.

Data Processor: in5 Tech DDA Free Zone LLC ("DealPilot"), Knowledge Building, Dubai Silicon Oasis, Dubai, UAE.

Scope & Purpose

This Agreement governs DealPilot's processing of personal data on behalf of the Data Controller for the purpose of delivering DealPilot platform services, including: lead management, deal management, compliance, and content generation.

Processor Obligations

  • Process personal data only on documented instructions from the Controller
  • Ensure authorized personnel are bound by confidentiality
  • Implement appropriate security measures per GDPR Article 32
  • Assist the Controller in fulfilling data subject rights requests
  • Notify the Controller immediately of any government requests for data access

Sub-Processors

The Controller authorizes DealPilot to use the sub-processors listed in the Privacy Policy. DealPilot will notify the Controller 30 days before adding any new sub-processor.

Security

  • AES-256-GCM encryption for PII at rest
  • TLS 1.3 for all data in transit
  • Multi-factor authentication for all administrative access
  • Annual third-party penetration testing
  • Vulnerability management program

Breach Notification

DealPilot will notify the Controller within 72 hours of discovering any personal data breach, in accordance with GDPR and UAE PDPL requirements.

Data Subject Rights

DealPilot will assist the Controller in responding to data subject rights requests (access, rectification, erasure, portability) within 30 days.

Data Transfers

Any transfer of data outside the UAE is subject to appropriate safeguards, including Standard Contractual Clauses with sub-processors in the USA and EU.

Deletion & Return

Upon termination, DealPilot will delete or return all personal data within 30 days, subject to legal retention requirements (e.g., AML records).

Audit Rights

The Controller may conduct one annual audit with 30 days' prior notice. This may be satisfied by SOC 2 or ISO 27001 reports when available.

Liability

Each party's liability under this Agreement is subject to the liability caps set out in the Master Service Agreement.