Prepared with reference to GDPR Article 28 & UAE Federal Decree-Law No. 45 of 2021 (PDPL) — Version 2.0
Parties
This Data Processing Agreement ("DPA") supplements the Master Service Agreement, Order Form, or other agreement between the Controller and ZIWO governing the Controller's use of the Services (the "Main Agreement"). This DPA is an agreement between the entity that has entered into the Main Agreement ("Controller", "you", or "your") and ASWAT-ZIWO FZ LLC, a company incorporated under the laws of the United Arab Emirates, with its registered address at Dubai Internet City, Building 17, Office 154, Dubai, UAE (together with its affiliates, "ZIWO", "we", "us", or "our") (together, the "Parties"). This DPA takes effect automatically upon the Controller's acceptance of, or continued use of the Services under, the Main Agreement; a separate signature is only required where the Controller's own process calls for a countersigned copy, using the signature block at the end of this document. Unless otherwise defined in this DPA or in the Main Agreement, all capitalised terms used in this DPA have the meanings given to them in Section 19 (Definitions).
1. Data Processing
1.1 Scope and Roles This DPA applies when personal data is processed by ZIWO on behalf of the controller. In this context, ZIWO acts as a processor to the controller, who may act either as the controller or as a processor of personal data on behalf of its own controllers. 1.2 Controller Controls The Controller can use the configuration tools, exports, and administration features made available within the Services ("Service Controls") to assist it with its obligations under Applicable Data Protection Law, including responding to data subject requests. Taking into account the nature of the processing, the Parties agree it is unlikely that ZIWO would become aware that Personal Data submitted by the Controller is inaccurate or outdated. Nonetheless, if ZIWO becomes aware that personal data is inaccurate or outdated, it will inform the controller without undue delay and provide the Service Controls the Controller can use to correct or erase the data. 1.3 Details of Processing Subject matter: Personal data submitted to, or generated within, ZIWO's cloud contact center and communications platform ("Personal Data") Duration: As between the Parties, determined by the Controller for the term of the Main Agreement, subject to Section 14 (Return or Deletion of Personal Data) Purpose: Provision of the Services initiated by the Controller from time to time under the Main Agreement Nature of processing: Storage, transmission, recording, real-time routing, analytics, and deletion of personal data as described in ZIWO's product documentation and initiated by the controller from time to time Type of Personal Data: Personal data uploaded to, or generated within, the Services under the Controller's ZIWO account, which may include names, phone numbers, email addresses, call recordings, call metadata, and agent activity data Categories of data subjects: The controller's customers, employees, suppliers, agents, and end users 1.4 Compliance with Laws Each party will comply with all laws, rules, and regulations applicable to and binding on it in the performance of this DPA, including the Applicable Data Protection Law.
2. Controller Instructions
The Parties agree that this DPA and the Main Agreement, including instructions the Controller provides through the Services' configuration tools, administration console, and any APIs ZIWO makes available (together, "Documented Instructions"), constitute the Controller's complete instructions regarding ZIWO's processing of Personal Data. ZIWO will process personal data only in accordance with documented instructions. Instructions outside the scope of the Documented Instructions require ZIWO's prior written agreement, including agreement on any additional fees payable by the Controller. If ZIWO declines to follow an instruction that falls outside this scope, the Controller's sole remedy is to terminate this DPA and the Main Agreement in accordance with their terms; such a decline is not, by itself, a breach of this DPA. Taking into account the nature of the processing, the Parties agree it is unlikely that ZIWO can form a view on whether a Documented Instruction infringes the Applicable Data Protection Law. If ZIWO nonetheless forms such a view, it will inform the Controller, and the Controller may withdraw or modify the instruction accordingly.
3. Confidentiality of Personal Data
ZIWO will not access, use, or disclose Personal Data to any third party except as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body. If a governmental body sends ZIWO a demand for personal data, ZIWO will attempt to redirect the governmental body to request the data directly from the controller and may provide the controller's basic contact details as part of that effort. Where ZIWO is compelled to disclose personal data, it will give the controller reasonable notice of the demand to allow the controller to seek a protective order or other appropriate remedy, unless legally prohibited from doing so.
4. Confidentiality Obligations of ZIWO Personnel
ZIWO restricts its personnel from processing personal data without authorization, as described in Annex 1 (Security Standards). ZIWO imposes appropriate contractual and, where applicable, statutory obligations on its personnel, including obligations of confidentiality, data protection, and data security, which survive termination of employment or engagement.
5. Security of Data Processing
5.1 ZIWO Measures ZIWO has implemented and will maintain the technical and organizational measures described in Annex 1 (Security Standards). ZIWO may update, replace, or improve any specific tool, control, or sub-processor referenced in Annex 1 at its discretion, provided the change does not materially reduce the overall level of security; such updates do not require the Controller's consent or amendment of this DPA. 5.2 Controller Measures The Controller may elect to implement additional technical and organizational measures to protect Personal Data, including pseudonymization and encryption, measures to ensure the confidentiality, integrity, availability, and resilience of any processing systems it operates, and measures to back up and archive its own data. Such measures, and their adequacy for the Controller's purposes, are the Controller's sole responsibility.
6. Sub-processing
6.1 Authorized Sub-processors The Controller provides general authorization to ZIWO's use of sub-processors to carry out processing activities on Personal Data on ZIWO's behalf ("Sub-Processors"), in accordance with this Section. The current list of sub-processors is maintained at ZIWO's compliance portal, trust.ziwo.io. At least fourteen (14) days before engaging a new sub-processor, ZIWO will update the published list. To object to a new Sub-Processor on reasonable, documented data-protection grounds, the Controller may: (i) terminate the Main Agreement in accordance with its terms; (ii) cease using the specific Service for which ZIWO has engaged that Sub-Processor; or (iii) request migration of the relevant Personal Data to a region where ZIWO has not engaged that Sub-Processor, where such migration is technically feasible. 6.2 Sub-processor Obligations Where ZIWO authorizes a Sub-Processor under Section 6.1: (i) ZIWO will restrict the Sub-Processor's access to Personal Data to what is necessary to provide or maintain the Services; (ii) ZIWO will enter into a written agreement imposing on the Sub-Processor, to the extent it performs the same processing activities as ZIWO under this DPA, the same contractual obligations ZIWO has under this DPA; and (iii) ZIWO remains responsible for its own compliance with this DPA and for any Sub-Processor act or omission that causes ZIWO to breach its obligations under this DPA, subject always to the limitations in Section 16 (Liability).
7. ZIWO Assistance with Data Subject Requests
Taking into account the nature of the processing, the Service Controls are the technical and organizational measures by which ZIWO assists the Controller in responding to data subject requests under the Applicable Data Protection Law. If a data subject sends a request directly to ZIWO, ZIWO will promptly forward it to the Controller once ZIWO has identified that the request relates to personal data for which the Controller is responsible. The Controller authorizes ZIWO, on its own behalf and on behalf of any controllers the Controller represents, to respond to that data subject solely to confirm the request has been forwarded. The Parties agree this represents the full scope of assistance ZIWO is required to provide under this Section 7.
8. Optional Security Features
ZIWO makes available a range of service controls that the controller can elect to use. The Controller is responsible for: (a) implementing the measures described in Section 5.2, as it considers appropriate; (b) properly configuring the Services; (c) using the Service Controls to restore availability and access to Personal Data in a timely manner following a physical or technical incident, including through backups and routine archiving; and (d) taking any further steps it considers adequate to maintain appropriate security, protection, and deletion of Personal Data.
9. Security Incident Notification
9.1 Security Incident ZIWO will notify the Controller of a security incident without undue delay after becoming aware of it and will take appropriate measures to address the security incident, including measures to mitigate its adverse effects. 9.2 ZIWO Assistance To enable the Controller to notify a security incident to supervisory authorities or data subjects where required, ZIWO will include in its notification such information about the security incident as it is able to disclose, taking into account the nature of the processing, the information available to ZIWO, and any applicable confidentiality restrictions. The Parties agree that the Controller, not ZIWO, is best placed to determine the likely consequences of a security incident for its own data subjects. 9.3 Unsuccessful Security Incidents An unsuccessful security incident is not subject to this Section 9. An unsuccessful security incident is one that results in no unauthorized access to personal data or to ZIWO's equipment or facilities storing personal data and may include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial-of-service attempts, or packet sniffing that does not result in access beyond headers. 9.4 No Admission ZIWO's obligation to report or respond to a security incident under this Section 9 is not, and will not be construed as, an acknowledgement of fault or liability by ZIWO with respect to that security incident. 9.5 Communication Notifications under this Section 9 will be delivered to the Controller's designated administrator contact by any means ZIWO selects, including email. It is the controller's sole responsibility to ensure its designated contacts maintain accurate, current details. 9.6 Notification Obligations Where ZIWO notifies the Controller of a security incident, or the Controller otherwise becomes aware of any accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data, the Controller is responsible for determining whether any notification or other obligation arises under the applicable data protection law and for taking the necessary action to comply. This does not limit ZIWO's obligations under Sections 9.1 and 9.2.
10. ZIWO Certifications and Audits
10.1 Certifications Upon the Controller's written request, and provided the Parties have an applicable non-disclosure agreement in place, ZIWO will make available its current ISO 27001 certificate (or documentation evidencing an alternative standard substantially equivalent to ISO 27001). 10.2 ZIWO Audits ZIWO uses external auditors to verify the adequacy of its security measures. This audit: (a) is performed at least annually; (b) is performed according to ISO 27001 or a substantially equivalent standard; (c) is performed by independent third-party security professionals selected and paid for by ZIWO; and (d) results in an audit report ("Report") that constitutes ZIWO's Confidential Information. 10.3 Audit Reports At the Controller's written request, and provided the Parties have an applicable non-disclosure agreement in place, ZIWO will provide the Controller with a copy of the Report so the Controller can reasonably verify ZIWO's compliance with its obligations under this DPA. 10.4 DPIA Assistance Taking into account the nature of the processing and the information available to it, ZIWO will assist the Controller with data protection impact assessments and prior consultations by providing the information made available under this Section 10.
11. Controller Audits
The Controller's audit and inspection rights under the Applicable Data Protection Law, including any rights under the Standard Contractual Clauses, are satisfied by instructing ZIWO to carry out the audit described in Section 10. If the Controller wishes to change this instruction, it may request a change by written notice as provided for in the Main Agreement. If ZIWO declines to follow an audit instruction requested by the Controller, the Controller's sole remedy is to terminate the Main Agreement in accordance with its terms. Nothing in this Section 11 entitles the Controller to conduct an on-site audit, to access ZIWO's other customers' data, or to access ZIWO's proprietary systems or source code.
12. International Transfers of Personal Data
12.1 Regions ZIWO processes personal data from ZIWO's available hosting regions (currently the UAE, KSA, the United States, Europe, India, Egypt, Morocco, and Pakistan) (each a "region") and will assign the region(s) applicable to the controller's account, taking into account operational, legal, and business considerations. Once the region(s) have been assigned, ZIWO will not transfer personal data outside the assigned region(s) except as necessary to provide the Services or to comply with the law or a valid and binding order of a governmental body. A request by the Controller to restrict processing to a specific region, or to a region not already covered by ZIWO's standard footprint, including an EU-only configuration, is subject to ZIWO's assessment of the Controller's legitimate business reason for the request, a written change order, and any additional fees. 12.2 Standard Contractual Clauses Subject to Section 12.3, the Standard Contractual Clauses apply only to Personal Data subject to the GDPR that is transferred, directly or by onward transfer, to a Third Country. Where the controller acts as a controller, the controller-to-processor clauses apply. Where the Controller acts as a processor on behalf of its own controllers, the Processor-to-Processor Clauses apply, and, taking into account that ZIWO has no direct relationship with those controllers, the Controller will fulfill ZIWO's obligations to its own controllers under the Processor-to-Processor Clauses. 12.3 Alternative Transfer Mechanism The Standard Contractual Clauses will not apply to a transfer if ZIWO has adopted Binding Corporate Rules or an alternative recognized compliance standard for that transfer.
13. Termination of the DPA
This DPA continues in force until the termination of the Main Agreement (the "Termination Date").
14. Return or Deletion of Personal Data
At any time up to the Termination Date, and for ninety (90) days following the Termination Date, ZIWO will return or delete Personal Data when the Controller uses the Service Controls to request such return or deletion. No later than the end of this 90-day period, the Controller must close all ZIWO accounts containing Personal Data; if it does not, ZIWO may proceed to delete the remaining Personal Data without further notice. Notwithstanding the foregoing, ZIWO may retain personal data to the extent required by applicable law, provided such data is processed for no other purpose. Any personal data retained beyond the periods set out in this Section 14 is handled in accordance with ZIWO's internal Data Retention Policy, as updated from time to time.
15. Duties to Inform
Where personal data becomes subject to confiscation during bankruptcy or insolvency proceedings, or similar third-party measures, while being processed by ZIWO, ZIWO will inform the controller without undue delay and will notify the relevant parties of such proceedings (for example, creditors or a bankruptcy trustee) that any affected personal data is the controller's property and responsibility and remains at the controller's sole disposition.
16. Liability
Each Party's total aggregate liability to the other under this DPA, whether in contract, tort, or otherwise, is limited to one hundred United States dollars (US$100) for any and all claims of any kind, consistent with the limitation of liability set out in the Main Agreement's Terms and Conditions. Neither party is liable to the other for any indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenue, goodwill, or data, even if advised of the possibility of such damages. Nothing in this Section 16 limits either party's liability for fraud, willful misconduct, or breach of Section 3 or Section 4 (Confidentiality), or any liability that cannot be excluded under applicable law. The Controller will indemnify and hold ZIWO harmless against any claim, loss, fine, or regulatory action arising from: (a) the Controller's Personal Data or the means by which it was obtained; (b) a documented instruction that is later found to be unlawful; or (c) the controller's failure to maintain a valid legal basis for processing, as warranted in Section 1.4.
17. Governing Law and Jurisdiction
This DPA is governed by and construed in accordance with the laws of the United Arab Emirates. Any dispute arising under or in connection with this DPA is subject to the exclusive jurisdiction of the courts of Dubai, UAE, without prejudice to either Party's right to seek interim injunctive relief in any competent jurisdiction.
18. Entire Agreement; Conflict
This DPA incorporates the Standard Contractual Clauses by reference where Section 12 applies. Except as amended by this DPA, the Main Agreement remains in full force and effect. If there is a conflict between the Main Agreement and this DPA on data protection matters, this DPA controls; for all other matters, the Main Agreement controls. This DPA may only be amended by a written instrument signed by authorized representatives of both parties. If any provision of this DPA is found invalid or unenforceable, the remaining provisions continue in full force and effect.
19. Definitions
Applicable Data Protection Law: All laws and regulations applicable to and binding on a party's processing of personal data, including, as applicable, the GDPR and the PDPL. Documented Instructions: The Controller's instructions regarding ZIWO's processing of Personal Data, as described in Section 2. GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation). PDPL: UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Personal Data: Any information relating to an identified or identifiable natural person, as defined under GDPR Article 4(1), that is processed by ZIWO on the Controller's behalf under the Main Agreement. Processing/Process: Any operation performed on personal data, including collection, storage, transmission, recording, analysis, or deletion. Controller: The entity that determines the purposes and means of processing personal data. Processor: The entity that processes personal data on behalf of the controller. Sub-Processor: Any third party engaged by ZIWO to carry out processing activities on personal data on ZIWO's behalf. Region: A hosting location within ZIWO's infrastructure, as described in Section 12.1. Security Incident: A breach of ZIWO's security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data, excluding an unsuccessful security incident as described in Section 9.3. Service Controls: The controls, including security features and functionalities, that the Services provide, as described in ZIWO's product documentation. Standard Contractual Clauses (SCCs): The Controller-to-Processor Clauses or the Processor-to-Processor Clauses, as approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as applicable under Section 12.2. TOMs: The technical and organizational measures described in Annex 1. Third Country: A country outside the European Economic Area not recognized by the European Commission as providing an adequate level of data protection.
Annex 1 — Security Standards
ZIWO will maintain an information security program designed to (a) enable the Controller to secure Personal Data against accidental or unlawful loss, access, or disclosure; (b) identify reasonably foreseeable risks to the security and availability of ZIWO's infrastructure; and (c) minimize physical and logical security risks through regular risk assessment and testing. ZIWO designates personnel to coordinate and be accountable for this program. 1. Logical Security - Access Controls: ZIWO restricts access to its infrastructure to authorized personnel only, as necessary to provide the Services, using firewalls, zero-trust network access, and authentication controls that segregate each customer's data from other customers' data. - Restricted User Access: Access is provisioned on a least-privilege basis according to job function; administrator-level access requires review and approval; access privileges are reviewed at least quarterly and revoked in a timely manner upon change of role or departure; multi-factor authentication is required for remote and administrative access. - Vulnerability Assessments: ZIWO performs regular vulnerability assessments and penetration testing of its infrastructure and tracks identified issues to resolution. - Application Security: New services and significant new features undergo a security review before public launch. - Change Management: Changes to production infrastructure are logged, authorized, tested, and documented before deployment; unauthorized changes are detected and tracked to resolution. - Data Integrity: Controls are maintained to protect data integrity during transmission, storage, and processing; encryption in transit (TLS 1.2+) and at rest (AES-256) is applied by default. - Business Continuity and Disaster Recovery: ZIWO maintains a risk management program covering identification of, response to, and recovery from events that could impair the Services, with defined recovery time and recovery point objectives. - Incident Management: ZIWO maintains documented incident response plans covering detection, containment, investigation, and remediation, with defined escalation paths. - Storage Media Decommissioning: Storage media is sanitised, degaussed, or destroyed in accordance with industry-standard practice before disposal. 2. Physical Security - Access Controls: Physical access to hosting facilities is restricted to authorised personnel with a legitimate business need, monitored, logged, and periodically reviewed. - Availability: Hosting infrastructure is geographically redundant, designed to tolerate hardware failure, and includes automated failover. 3. Personnel - Security Training: ZIWO maintains security awareness training for personnel, reviewed and updated at least annually. - Background Checks: Where permitted by law, ZIWO requires background checks appropriate to the employee's role and level of access. - Endpoint Management: Company-managed devices are enrolled in unified endpoint management with enforced security baselines. 4. Continued Evaluation ZIWO conducts periodic reviews of this information security program and will update it as necessary to respond to new security risks and to adopt new technologies.
Annex 2 — Standard Contractual Clauses (SCCs)
Where personal data is transferred from the European Economic Area to a third country, including the UAE, in circumstances covered by Section 12.2, such transfer is governed by the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as adopted by the European Commission in Decision 2021/914 of 4 June 2021. Module applicable: Module Two (Controller to Processor); Module Three (Processor to Processor), where Section 12.2 applies. The SCCs are incorporated by reference into this DPA. In the event of a conflict between the SCCs and this DPA, the SCCs prevail with respect to international transfers of personal data. The full text of the EU SCCs is available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914