Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms of Service (the “Agreement”) between ABUSE TECH - FZCO, a free zone company registered with the International Free Zone Authority (IFZA), Dubai Digital Park, Dubai, United Arab Emirates (“Nxor”, “we”, “processor”), and the customer subscribing to the Service (“Customer”, “you”, “controller”). It applies where, in your use of the Service, you submit personal data relating to your personnel, clients, or other individuals (“Customer Personal Data”) and we process that data on your behalf. Where this DPA conflicts with the Agreement on data-protection matters, this DPA prevails.
1. Roles and Scope
For Customer Personal Data, you act as the controller (or as a processor acting for your own customers) and Nxor acts as the processor. Nxor processes Customer Personal Data only to provide the Service under the Agreement and on your documented instructions, including as set out in this DPA. This DPA applies in addition to the Privacy Policy, which governs personal data for which Nxor is itself the controller (such as account and billing data).
2. Definitions
“Data protection laws” means the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations (“PDPL”), as supervised by the UAE Data Office, and, where applicable, the EU and UK General Data Protection Regulation (“GDPR”). “Processing”, “controller”, “processor”, “data subject”, and “personal data” have the meanings given in the data protection laws. “Sub-processor” means any third party engaged by Nxor to process Customer Personal Data, including AI Providers and infrastructure providers.
3. Customer Instructions
Nxor will process Customer Personal Data only on your documented instructions, including transferring it to the AI Providers necessary to generate Output, unless required to act otherwise by a law to which Nxor is subject; in that case Nxor will inform you of that legal requirement before processing, unless the law prohibits it. You are responsible for ensuring that your instructions and your use of the Service comply with the data protection laws, and that you have a lawful basis for the Customer Personal Data you submit.
4. Nature and Purpose of Processing
Subject matter: provision of the AI aggregation Service. Duration: the term of the Agreement, plus any limited retention described below. Nature and purpose: receiving Inputs, routing them to AI Providers, returning Output, and operating, securing, and supporting the Service. Types of personal data: any personal data contained in Inputs and Outputs, which is determined and controlled by you. Categories of data subjects: any individuals whose data you choose to include in Inputs (for example your employees, clients, or contacts).
You acknowledge that you control what you submit and agree not to submit special categories of personal data, government-identifier data, or other highly sensitive data unless you have ensured an appropriate lawful basis and safeguards; the Service is not designed as a repository for such data.
5. Confidentiality
Nxor ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and process the data only as necessary to provide the Service.
6. Security
Nxor implements technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls, network protection, logging, and monitoring. You are responsible for the security of your own systems and credentials and for the decisions you make about what data to submit.
7. No Training; No Sale
Nxor does not sell Customer Personal Data and does not use the content of your Inputs or Outputs to train Nxor's own models. Nxor contracts with AI Providers on terms intended to limit their use of submitted content to delivering the Service. Each AI Provider processes data under its own terms; you acknowledge that Nxor does not control the AI Providers' models.
8. Sub-processors
You provide general authorisation for Nxor to engage sub-processors, including AI Providers, hosting and storage providers, and Paddle (as Merchant of Record for payment data). Nxor imposes data-protection obligations on its sub-processors substantially similar to those in this DPA and remains responsible for their performance of those obligations. Nxor will make available a current list of sub-processors on request and will give reasonable notice of intended changes, allowing you to object on reasonable data-protection grounds.
9. International Transfers
Customer Personal Data may be processed outside the UAE, including in jurisdictions where AI Providers and infrastructure providers operate. Where data is transferred internationally, Nxor applies the safeguards required by the PDPL and, for GDPR-covered transfers, an approved transfer mechanism such as Standard Contractual Clauses or transfer to an adequate jurisdiction.
10. Assistance to the Controller
Taking into account the nature of the processing, Nxor will provide reasonable assistance to help you respond to data-subject requests and to meet your obligations regarding security, breach notification, and, where applicable, data-protection impact assessments and prior consultation with a supervisory authority.
11. Data Subject Requests
If Nxor receives a request from a data subject relating to Customer Personal Data, Nxor will, where lawful, direct the data subject to you and will not respond directly except on your instruction or as required by law.
12. Personal Data Breach
Nxor will notify you without undue delay, and where feasible within 72 hours of becoming aware, of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to help you meet your notification obligations under the data protection laws.
13. Deletion and Return
On termination of the Agreement, Nxor will delete or, on request, return Customer Personal Data within a reasonable period, except to the extent retention is required by law or for the limited operational and security purposes described in the Privacy Policy. Inputs and Outputs are retained only for a limited period to operate and secure the Service and are then deleted or anonymised, subject to law.
14. Audits
Nxor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice, confidentiality, frequency limits, and Nxor's security and operational requirements. Nxor may satisfy audit requests by providing third-party certifications or reports where available.
15. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
16. Term and Governing Law
This DPA takes effect on your acceptance of the Agreement and continues for as long as Nxor processes Customer Personal Data. It is governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai, consistent with the governing-law and dispute-resolution provisions of the Agreement.
17. Contact
ABUSE TECH - FZCO — IFZA, Dubai Digital Park, Dubai, United Arab Emirates. Data protection enquiries: [email protected] · Legal: [email protected]