← Back to Sumgate Signal Legal

Data Processing Agreement

1. Parties, scope and incorporation

1.1 This Data Processing Agreement ("DPA") is between SUMGATE TECHNOLOGIES - FZCO, trade licence No. 66961, of IFZA Properties, Premises DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates ("Sumgate", "we", "Processor") and the customer identified in the applicable Order Form or account record ("Customer", "you", "Controller").

1.2 This DPA forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement"). It applies automatically from the date you first use the Service, without further signature. On written request we will execute a counterpart, or a version bearing your entity details, without altering these terms.

1.3 This DPA applies to the extent we process Personal Data on your behalf in providing the Service. It does not apply to processing where we act as controller, which our Privacy Policy describes.

1.4 If there is a conflict, this DPA prevails over the rest of the Agreement in respect of the processing of Personal Data. The Standard Contractual Clauses prevail over this DPA to the extent of any conflict concerning transfers to which they apply.

2. Definitions

2.1 "Data Protection Law" means all laws applicable to the processing under this DPA, including: Regulation (EU) 2016/679 ("GDPR"); the UK GDPR and the Data Protection Act 2018 ("UK Data Protection Law"); the Swiss Federal Act on Data Protection; UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") and its implementing instruments; and applicable United States state privacy laws.

2.2 "Customer Personal Data" means Personal Data contained in Customer Data that we process on your behalf under the Agreement.

2.3 "Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

2.4 "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

2.5 "Sub-processor" means any processor engaged by us to process Customer Personal Data.

2.6 "Controller", "Processor", "Personal Data", "Personal Data Breach", "Data Subject", "processing" and "Supervisory Authority" have the meanings given in the GDPR, and their equivalents under other Data Protection Law.

2.7 Capitalised terms not defined here have the meaning given in the Agreement.

3. Roles and instructions

3.1 The parties agree that, for Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a processor for a third-party controller, you warrant that you have that controller's authority to appoint us as a sub-processor on these terms, and references to your obligations as Controller apply to you as if you were the controller.

3.2 We will process Customer Personal Data only:

  1. to provide, maintain, secure and support the Service in accordance with the Agreement;
  2. in accordance with your documented instructions, of which the Agreement, this DPA, and your configuration of and requests made through the Service form part; and
  3. as required by law applicable to us.

3.3 We will not process Customer Personal Data for our own purposes, and in particular will not sell it, share it for cross-context behavioural advertising, or use it for profiling unrelated to providing the Service.

3.4 If we are required by law to process Customer Personal Data otherwise than on your instruction, we will inform you before processing unless the law prohibits that.

3.5 We will inform you if, in our opinion, an instruction infringes Data Protection Law. We may suspend performance of that instruction until it is amended or confirmed. We are not obliged to give legal advice, and our failure to identify an unlawful instruction does not transfer responsibility for it to us.

3.6 Instructions that go beyond the functionality of the Service, or that require material additional effort, are subject to our written agreement and may be chargeable.

4. Our obligations as processor

4.1 We will:

  1. process Customer Personal Data only as set out in clause 3;
  2. ensure that our personnel who access Customer Personal Data are subject to a duty of confidentiality that survives the end of their engagement, are given access only where needed for their role, and receive appropriate data protection and security training;
  3. implement and maintain the technical and organisational measures in Annex II;
  4. engage Sub-processors only in accordance with clause 5;
  5. assist you as set out in clauses 9, 10 and 11;
  6. notify Personal Data Breaches as set out in clause 7; and
  7. delete or return Customer Personal Data as set out in clause 8.

4.2 We maintain a record of the categories of processing we carry out on your behalf, and will make the relevant parts available to you on reasonable request.

5. Sub-processors

5.1 You give us general written authorisation to engage Sub-processors. The Sub-processors engaged at the effective date are listed in Annex III.

5.2 Before a new Sub-processor begins processing Customer Personal Data, or before we replace one, we will update Annex III and notify you at least 30 days in advance, by email to your account contact or by in-product notice.

5.3 You may object to a new or replacement Sub-processor on reasonable grounds relating to data protection, by written notice within 20 days of our notice, setting out those grounds. We will work with you in good faith to address the objection, which may include offering an alternative configuration. If we cannot do so within 30 days and the Sub-processor is necessary to provide the Service, you may terminate the affected subscription on written notice, and we will refund pre-paid fees covering the unused remainder of the term. That is your exclusive remedy for an unresolved objection.

5.4 We will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and, where the Sub-processor is outside the EEA or the UK, an appropriate transfer mechanism.

5.5 We remain responsible to you for a Sub-processor's performance of its data protection obligations, to the same extent as if we performed them ourselves, subject to clause 15.

5.6 We may engage a new Sub-processor with immediate effect, notifying you as soon as practicable, where the change is necessary to address a serious security risk or to comply with a legal requirement. Your objection right under 5.3 still applies after the event.

5.7 Providers of Connected Services that you choose to connect — such as your CRM, mail, calling and meeting platforms — are not our Sub-processors. They are your own controllers or processors, and we access them on your authorisation.

6. Security

6.1 Having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing as well as the risks to Data Subjects, we will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Those measures are described in Annex II.

6.2 We may update those measures, provided we do not materially reduce the overall level of protection during a subscription term. Annex II will be kept current.

6.3 You are responsible for assessing whether the measures in Annex II are appropriate for the Customer Personal Data you choose to submit, and for the risk it presents. You must not submit Personal Data whose sensitivity exceeds what those measures are designed to protect. In particular, and as required by the Agreement, you must not submit special category Personal Data, government identifiers, payment card data, health data, biometric data, or Personal Data of children.

7. Personal data breach

7.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.2 The notification will describe, to the extent then known: the nature of the breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in phases without undue delay.

7.3 We will take reasonable steps to contain and remediate the breach, and will cooperate with you and provide the information you reasonably need to meet your own notification obligations to Supervisory Authorities and Data Subjects.

7.4 You are responsible for notifying Supervisory Authorities and Data Subjects where the law requires it. We will not notify them on your behalf, or make any public statement identifying you, without your prior written consent, unless we are legally required to.

7.5 Our notification under this clause is not an acknowledgement of fault or liability.

7.6 Unsuccessful attempts that do not compromise the security of Customer Personal Data — such as blocked login attempts, port scans, failed authentication, or denial-of-service attempts that are absorbed — are not Personal Data Breaches and are not individually notifiable.

8. Deletion and return

8.1 On expiry or termination of the Agreement, we will delete Customer Personal Data in accordance with the retention periods in section 9 of the Privacy Policy, and in any event within 30 days after the end of the 30-day post-termination access window, unless you ask for earlier deletion or for return.

8.2 You may at any time, during or after the term, request in writing that we delete Customer Personal Data. We will do so within 30 days of the request and confirm in writing.

8.3 On written request made before deletion, we will make Customer Personal Data available for export in a structured, commonly used, machine-readable format. Requests received after deletion cannot be met.

8.4 We may retain Customer Personal Data to the extent, and for as long as, required by law applicable to us, and will continue to protect it under this DPA for as long as we hold it. Copies present in routine backups are overwritten in the ordinary backup cycle, within 35 days.

9. Data subject requests

9.1 Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligations to respond to Data Subject requests to exercise their rights.

9.2 The Service provides functionality that lets you locate, export, correct and delete Customer Personal Data. You should use that functionality in the first instance.

9.3 If we receive a request from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will, without undue delay, tell the Data Subject to contact you, and inform you of the request where we can identify your account, unless the law prohibits it.

9.4 Where you ask us for assistance that the Service's functionality does not provide, we will give reasonable assistance. We may charge for assistance that requires more than de minimis effort, at our then-current rates, having told you in advance.

10. Assessments and prior consultation

10.1 We will provide reasonable assistance with data protection impact assessments and prior consultation with Supervisory Authorities, where those relate to our processing and you cannot reasonably obtain the information elsewhere.

10.2 We will make available our current security documentation, sub-processor list, transfer impact assessment, and completed responses to a standard security questionnaire. Those documents are our Confidential Information and satisfy this clause in the first instance.

10.3 You remain responsible for carrying out your own assessment. Given that the Service analyses employee and third-party communications and produces profiling output, a data protection impact assessment is likely to be required of you before deployment. We do not carry it out for you and it is not our responsibility.

11. Audits and information rights

11.1 We will make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, by you or an auditor you mandate.

11.2 That obligation is satisfied in the first instance by our providing the documentation described in clause 10.2, and by responding to reasonable written questions.

11.3 If that documentation does not reasonably satisfy your obligations, you may request an on-site or remote audit, subject to the following, which the parties agree are reasonable:

  1. not more than once in any 12-month period, except where a Supervisory Authority requires more, or following a confirmed Personal Data Breach affecting your Customer Personal Data;
  2. on at least 30 days' written notice, at a mutually agreed time during business hours, and conducted so as to minimise disruption;
  3. limited in scope to systems, records and premises relevant to the processing of your Customer Personal Data;
  4. the auditor must not be a competitor of ours, and must sign a confidentiality undertaking acceptable to us before access;
  5. no access to any other customer's data, to our source code or model configuration, or to information whose disclosure would breach a duty of confidentiality owed to a third party; and
  6. at your cost, including our reasonable costs of supporting the audit.

11.4 Audits of a Sub-processor are conducted through us. We will exercise our audit rights against the Sub-processor and share the results, rather than granting direct access.

11.5 Audit findings are the Confidential Information of both parties and may be disclosed only to your professional advisers or, where required, to a Supervisory Authority.

12. International transfers

12.1 You acknowledge that we are established in the United Arab Emirates and that our Sub-processors are located as stated in Annex III, so that providing the Service involves transfers of Customer Personal Data outside the EEA, the United Kingdom and Switzerland.

12.2 Where Customer Personal Data is subject to the GDPR and is transferred to us, the SCCs, Module Two (Controller to Processor), are incorporated into this DPA and completed as set out in Annex IV. Where you act as processor for a third-party controller, Module Three (Processor to Processor) applies instead.

12.3 Where Customer Personal Data is subject to UK Data Protection Law, the UK Addendum is incorporated and completed as set out in Annex IV.

12.4 Where Customer Personal Data is subject to Swiss law, the SCCs apply with the modifications recognised by the Swiss Federal Data Protection and Information Commissioner, including that references to the GDPR are read as references to the Swiss Act and that "Supervisory Authority" includes the Commissioner.

12.5 For onward transfers to Sub-processors, we rely on the SCCs, Module Three, or another valid transfer mechanism.

12.6 Where the PDPL applies, we rely on contractual clauses providing appropriate safeguards, as that law permits for transfers to jurisdictions without an adequacy determination.

12.7 If a transfer mechanism is invalidated or amended, the parties will cooperate in good faith to implement a replacement without undue delay. If no lawful mechanism is available, we may suspend the affected processing, and either party may terminate the affected subscription with a pro-rata refund of pre-paid fees.

12.8 Authority access requests. If we receive a legally binding request from a public authority for Customer Personal Data, we will, unless legally prohibited: notify you without undue delay; provide the information we lawfully can about the request; challenge the request where there are reasonable grounds to consider it unlawful under the law of the requesting authority or under applicable conflicting obligations; and disclose only the minimum required. We will keep a record of such requests and make it available to you on request.

13. Your obligations as controller

13.1 You warrant and undertake that:

  1. you have a lawful basis for all processing you instruct, and have given all required notices to Data Subjects — including Data Subjects who are not your personnel;
  2. where the law requires consent — including consent to the recording, interception or transcription of calls and meetings, and any consent required for monitoring of workers — you have obtained it, can evidence it, and will tell us without undue delay if it is withdrawn in a way that affects our processing;
  3. you have completed any consultation with employee representatives, works councils or trade unions that applies;
  4. your instructions comply with Data Protection Law and do not require us to breach it;
  5. you have carried out any required data protection impact assessment; and
  6. you will not submit the categories of data excluded by clause 6.3.

13.2 You are responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which you acquired it.

13.3 You will not, by act or omission, cause us to be in breach of Data Protection Law.

13.4 Your indemnity in section 19.2 of the Agreement applies to breaches of this clause.

14. AI processing commitments

14.1 To provide the Service, we transmit Customer Personal Data to the large language model providers listed in Annex III for inference.

14.2 We warrant that, in respect of Customer Personal Data:

  1. it is not used to train, fine-tune or improve any generalised, foundational or frontier AI or machine learning model, by us or by any Sub-processor;
  2. each AI Sub-processor is engaged under terms that prohibit such use and that require it not to retain the data beyond what is necessary to return a response and to meet its own legal obligations;
  3. it is not stored in conjunction with any such model; and
  4. it is not used by an AI Sub-processor for that provider's own purposes.

14.3 We will send to an AI Sub-processor only the data reasonably necessary to produce the analysis you requested.

14.4 Where Customer Personal Data is obtained through a platform provider that restricts its use in AI systems, we observe those restrictions. Our commitments in respect of Google user data are set out in section 6 of the Privacy Policy and form part of this DPA.

14.5 Output produced by the Service is Customer Personal Data where it relates to an identified or identifiable individual, and is subject to this DPA. We draw your attention to clause 10.3 and to section 8.5 of the Agreement.

15. Liability

15.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions and to the aggregate cap in section 20 of the Agreement, and the parties agree that a claim under this DPA and a claim under the Agreement in respect of the same facts count together towards a single cap.

15.2 Clause 15.1 does not limit either party's liability to a Data Subject or to a Supervisory Authority, or the operation of the SCCs where they apply.

15.3 Where the SCCs apply and a provision of this DPA would reduce a Data Subject's rights under them, the SCCs prevail to that extent.

16. Term, changes and general

16.1 This DPA takes effect when the Agreement does and continues until we have deleted or returned all Customer Personal Data under clause 8. Clauses that by their nature should survive do so.

16.2 We may amend this DPA where necessary to reflect a change in Data Protection Law, a decision of a Supervisory Authority or court, a change of transfer mechanism, or a change in the Service, provided the amendment does not materially reduce the protection given to Customer Personal Data. Section 22 of the Agreement governs notice.

16.3 Annex III may be updated in accordance with clause 5.2 without further formality.

16.4 This DPA is governed by the law stated in section 25 of the Agreement, except that where the SCCs apply, the SCCs are governed by the law they specify in Annex IV, and disputes under them are resolved as they provide.

16.5 If a provision of this DPA is invalid or unenforceable, the remainder continues in force.

Annex I — Description of processing

A. List of parties

Data exporter / Controller: the Customer identified in the Order Form or account record. Contact details, and the name of its data protection contact, are those held in its account. Activities relevant to the transfer: use of the Service to analyse its sales deals. Role: Controller (or, where clause 3.1 applies, processor).

Data importer / Processor: SUMGATE TECHNOLOGIES - FZCO, IFZA Properties, Premises DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates. Contact: hello@sumgate.io. Activities relevant to the transfer: provision of the Sumgate Signal deal intelligence service. Role: Processor.

B. Description of the transfer

C. Competent supervisory authority

Where the SCCs apply, the competent Supervisory Authority is that of the EEA Member State in which the data exporter is established or, where the data exporter is not established in the EEA, the authority of the Member State in which the data exporter's representative under Article 27 GDPR is established, or in which the Data Subjects whose Personal Data is transferred are located. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the Federal Data Protection and Information Commissioner.

Annex II — Technical and organisational measures

These are the measures in force at the effective date. They are contractual commitments, and clause 6.2 governs changes.

1. Encryption

2. Access to Connected Services

3. Access control

4. Pseudonymisation and minimisation

5. Logging and monitoring

6. Resilience and availability

7. Secure development and vulnerability management

8. Personnel

9. Incident response

10. Sub-processor governance

11. Certifications

We do not currently hold ISO/IEC 27001 certification or a completed SOC 2 Type II report. We will update this Annex if that changes. Nothing in our marketing material should be read as a representation that either has been obtained.

Annex III — Sub-processors

Current as at the effective date. Clause 5.2 governs changes.

Providers of Connected Services chosen by the Customer are not Sub-processors — see clause 5.7.

Annex IV — Transfer mechanisms

1. EU Standard Contractual Clauses

Where clause 12.2 applies, the SCCs are incorporated into this DPA and completed as follows:

By entering into the Agreement, the parties are deemed to have signed the SCCs at the Annexes.

2. UK International Data Transfer Addendum

Where clause 12.3 applies, the UK Addendum (version B1.0) is incorporated, completed as follows:

3. Switzerland

Where clause 12.4 applies, the SCCs apply with these modifications: references to the GDPR are read as references to the Swiss Federal Act on Data Protection; the competent authority is the Federal Data Protection and Information Commissioner; the term "Member State" does not exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence; and, to the extent the transfer concerns data of legal entities protected under Swiss law, the SCCs apply to that data as well.

4. Availability

A completed copy of the applicable transfer mechanism, and our transfer impact assessment, are available from hello@sumgate.io.