Draft — pending legal review
This document is a draft prepared on 2026-04-21. It has not yet been reviewed by a licensed legal counsel. Do not rely on it for legal purposes.
Parties
Data Controller: The Customer (agency or broker) identified in the Service Agreement.
Data Processor: in5 Tech DDA Free Zone LLC ("DealPilot"), Knowledge Building, Dubai Silicon Oasis, Dubai, UAE.
Scope & Purpose
This Agreement governs DealPilot's processing of personal data on behalf of the Data Controller for the purpose of delivering DealPilot platform services, including: lead management, deal management, compliance, and content generation.
Processor Obligations
- Process personal data only on documented instructions from the Controller
- Ensure authorized personnel are bound by confidentiality
- Implement appropriate security measures per GDPR Article 32
- Assist the Controller in fulfilling data subject rights requests
- Notify the Controller immediately of any government requests for data access
Sub-Processors
The Controller authorizes DealPilot to use the sub-processors listed in the Privacy Policy. DealPilot will notify the Controller 30 days before adding any new sub-processor.
Security
- AES-256-GCM encryption for PII at rest
- TLS 1.3 for all data in transit
- Multi-factor authentication for all administrative access
- Annual third-party penetration testing
- Vulnerability management program
Breach Notification
DealPilot will notify the Controller within 72 hours of discovering any personal data breach, in accordance with GDPR and UAE PDPL requirements.
Data Subject Rights
DealPilot will assist the Controller in responding to data subject rights requests (access, rectification, erasure, portability) within 30 days.
Data Transfers
Any transfer of data outside the UAE is subject to appropriate safeguards, including Standard Contractual Clauses with sub-processors in the USA and EU.
Deletion & Return
Upon termination, DealPilot will delete or return all personal data within 30 days, subject to legal retention requirements (e.g., AML records).
Audit Rights
The Controller may conduct one annual audit with 30 days' prior notice. This may be satisfied by SOC 2 or ISO 27001 reports when available.
Liability
Each party's liability under this Agreement is subject to the liability caps set out in the Master Service Agreement.