Policies

Data Processing Agreement

Last Updated - 31st December 2025

Purpose and Scope

This Data Processing Agreement applies to situations where Web Collective FZE processes personal data on behalf of our clients in connection with the services we provide. In these scenarios, our clients typically act as Data Controllers—determining what personal data is collected and how it's used—while we act as Data Processors, handling the data according to our clients' instructions and applicable data protection laws.

This DPA is particularly relevant for clients who engage us for services that involve processing personal data belonging to their customers, users, or employees. It's designed to ensure compliance with data protection regulations including the EU General Data Protection Regulation (GDPR), UAE data protection laws, and other applicable frameworks.

Definitions

To ensure clarity throughout this agreement, we define key terms as follows:

Personal Data efers to any information relating to an identified or identifiable natural person. This could include names, email addresses, phone numbers, IP addresses, or any other data that can directly or indirectly identify an individual.

Processing means any operation or set of operations performed on personal data, whether automated or not. This includes collecting, recording, organizing, storing, adapting, retrieving, consulting, using, disclosing, combining, restricting, erasing, or destroying personal data.

Data Controller is the entity that determines the purposes and means of processing personal data. In most of our client relationships, our clients are the Data Controllers with respect to their customers' or users' personal data.

Data Processor is the entity that processes personal data on behalf of and according to the instructions of the Data Controller. Web Collective acts as a Data Processor when we handle personal data belonging to our clients' customers or users.

Sub-processor refers to any third-party processor engaged by us to process personal data on behalf of the Data Controller.

Data Subject is the individual person whose personal data is being processed.

Roles and Responsibilities

Understanding the division of responsibilities between Web Collective and our clients is essential for effective data protection.

Web Collective's Obligations as Data Processor

When we process personal data on your behalf, we commit to processing it only according to your documented instructions. We will not use your data for any purpose other than those you've explicitly authorized. If we believe your instructions violate data protection laws, we'll inform you immediately.

We ensure that everyone on our team who has access to personal data is bound by confidentiality obligations. This includes both contractual confidentiality requirements and professional duties of discretion. Our team members receive training on data protection principles and understand the importance of handling personal data responsibly.

We implement appropriate technical and organizational security measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures are detailed in the Security Measures section below.

We'll assist you in responding to data subject requests—such as access requests, deletion requests, or requests for data portability—to the extent feasible given the nature of the processing we perform for you. We understand that you have legal obligations to respond to these requests within specific timeframes, and we'll prioritize providing the information or assistance you need.

If we become aware of a personal data breach affecting data we process on your behalf, we'll notify you without undue delay, typically within 72 hours of becoming aware of the breach. Our notification will include details about the nature of the breach, the categories and approximate number of data subjects affected, and the measures we've taken or propose to take to address the breach.

Upon termination of our services, we'll either delete or return all personal data to you, according to your instructions. We'll provide certification that we've completed this process. If we're legally required to retain certain data, we'll inform you and continue to protect that data according to this agreement.

We'll make available all information necessary to demonstrate our compliance with data processing obligations and allow for audits and inspections upon reasonable notice and during normal business hours. We understand that you may need to verify our compliance with this agreement and applicable laws.

Your Obligations as Data Controller

As the Data Controller, you're responsible for ensuring you have a lawful basis for processing personal data and for complying with all applicable data protection laws. You'll provide clear, documented instructions to us regarding how to process personal data on your behalf.

You're responsible for obtaining necessary consents from data subjects and providing them with appropriate privacy notices. You'll also handle data subject requests, though we'll assist you as needed and as our processing activities permit.

You warrant that you've obtained all necessary rights and permissions to provide personal data to us for processing and that such processing doesn't violate any applicable laws or third-party rights.

Security Measures

Security is fundamental to everything we do at Web Collective. We implement comprehensive security measures to protect personal data from unauthorized access, alteration, disclosure, or destruction.

Our website and applications are built with security in mind from the ground up. We use HTTPS encryption for all data transmitted between users' browsers and our servers, ensuring that data in transit cannot be intercepted. Our hosting provider, Vercel, maintains robust physical and network security controls, including firewalls, intrusion detection systems, and 24/7 monitoring.

We implement strict access controls that ensure only authorized personnel can access personal data, and then only to the extent necessary for their specific roles. Access is granted based on the principle of least privilege—people have access only to the data and systems they genuinely need.

We use Sentry for continuous security monitoring, error tracking, and incident detection. This allows us to identify and respond to security issues quickly. Our code repositories on GitHub are protected with multi-factor authentication and strict access controls.

All of our service providers, including Resend for email delivery, are selected in part because of their strong security practices and compliance with industry standards. We require our service providers to maintain security measures that are consistent with our own commitments.

We conduct regular security assessments to identify potential vulnerabilities and ensure our security measures remain effective against evolving threats. Our team stays informed about current security best practices and emerging risks in the rapidly changing digital landscape.

We maintain incident response procedures that enable us to respond quickly and effectively to security incidents. These procedures include steps for containment, investigation, notification, and remediation.

While we implement robust security measures, we acknowledge that no system can guarantee absolute security. We're committed to maintaining a security posture that appropriately reflects the sensitivity of the data we process and the current threat landscape.

Sub-processors

To deliver our services effectively, we may engage third-party sub-processors to assist with specific functions. We carefully select our sub-processors based on their technical capabilities, security practices, and compliance with data protection requirements.

Our current sub-processors include Resend for email delivery and subscriber management, Vercel for website hosting and content delivery, GitHub for code repository management, Google (including Google Analytics, Google Ads, Google Tag Manager) for analytics and advertising services, Microsoft (Clarity) and Hotjar for behavioral analytics and session recording, and Sentry for security monitoring and error tracking.

We require all sub-processors to enter into written agreements that impose data protection obligations consistent with this DPA. Before engaging a new sub-processor or changing an existing one, we'll notify you and provide you with an opportunity to object to the change. If you have reasonable grounds to object—for example, if the new sub-processor doesn't meet adequate security or privacy standards—we'll work with you to find an alternative solution or allow you to terminate the affected services without penalty.

International Data Transfers

The digital services we provide and the cloud infrastructure that powers them operate globally, which means personal data may be transferred to and processed in countries outside the UAE and outside the European Economic Area.

When personal data is transferred internationally, we ensure appropriate safeguards are in place to protect it. For transfers from the EEA, we rely on mechanisms recognized under GDPR, such as Standard Contractual Clauses approved by the European Commission, adequacy decisions recognizing that certain countries provide adequate data protection, or other legally valid transfer mechanisms.

Many of our service providers operate globally and have implemented their own data protection frameworks. For example, Google has certified compliance with various international data protection frameworks, and our hosting provider Vercel implements appropriate technical and organizational measures regardless of where data is processed.

We ensure that any entity receiving personal data outside of its original jurisdiction provides a level of protection that's consistent with applicable data protection laws and this agreement.

Data Subject Rights

Data subjects—the individuals whose personal data is processed—have important rights under data protection laws. While you, as the Data Controller, are primarily responsible for facilitating these rights, we'll provide reasonable assistance in helping you fulfill data subject requests.

Data subjects have the right to access their personal data, understand how it's being processed, and receive a copy of their data. They can request correction of inaccurate data and deletion of data when it's no longer necessary for the purposes for which it was collected or when they withdraw consent.

They can also request restriction of processing in certain circumstances, such as while the accuracy of data is being verified or while their objection to processing is being considered. Data subjects have the right to receive their data in a portable format and to object to certain types of processing, particularly processing based on legitimate interests.

When you receive a data subject request related to personal data we process on your behalf, notify us promptly so we can assist in fulfilling the request. We'll provide the information or take the actions necessary to enable you to respond within legally required timeframes, typically within 30 days.

Data Breach Notification

Despite our best security efforts, data breaches can occur. If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data we process on your behalf, we'll notify you without undue delay.

Our notification will include a description of the nature of the breach, including where possible the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned. We'll describe the likely consequences of the breach and the measures taken or proposed to address it, including measures to mitigate possible adverse effects.

We'll provide sufficient information to enable you to meet your own notification obligations to supervisory authorities and data subjects. We understand that you may need to notify relevant authorities within 72 hours of becoming aware of a breach, and we'll prioritize getting you the information you need to meet this deadline.

We'll cooperate with you in investigating the breach and preventing future incidents. This may include providing access to relevant records, assisting in communications with affected data subjects, and implementing additional security measures.

Audits and Compliance

Demonstrating compliance with data protection obligations is important for building and maintaining trust. We'll make available to you all information necessary to demonstrate compliance with the obligations in this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you.

We request reasonable advance notice of any audit—typically at least 30 days—and ask that audits be conducted during normal business hours to minimize disruption to our operations. We may require that auditors execute confidentiality agreements before accessing our systems or facilities, as they may encounter confidential information about our business operations or other clients.

If you choose to conduct an audit, we'll cooperate fully and provide access to relevant personnel, systems, and documentation. We'll respond promptly to any findings or recommendations arising from the audit.

In lieu of an audit, you may accept certifications, attestation reports, or other documentation from independent auditors that demonstrate our compliance with relevant standards, such as SOC 2 reports or ISO certifications.

Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was processed or as required by applicable law. Upon termination or expiration of our services, we'll delete or return all personal data to you according to your instructions, except where we're legally required to retain certain information.

Deletion means that data is permanently removed from our systems in a manner that prevents its reconstruction or recovery. Where complete deletion is technically infeasible, we'll implement measures to make the data inaccessible and unusable for any purpose.

We'll provide certification of deletion upon request, confirming that we've completed the deletion process in accordance with your instructions and this agreement.

If we're legally required to retain certain personal data—for example, for tax or accounting purposes—we'll inform you of this requirement and continue to protect the retained data according to this agreement until the retention period expires.

Liability

Each party's liability under this DPA is subject to the limitations and exclusions in our main services agreement. However, nothing in this DPA limits or excludes either party's liability for fraud, gross negligence, or intentional misconduct.

Web Collective is liable only for damages caused by our failure to comply with data protection obligations specifically directed at processors under applicable data protection law or where we've acted outside or contrary to your lawful instructions. We're not liable for damages resulting from your failure as Data Controller to comply with data protection obligations or from your provision of unlawful instructions.

Both parties acknowledge that data protection is a shared responsibility requiring cooperation and good faith from both sides.

Contact for Data Protection Matters

For questions or concerns about data processing, security, or compliance under this DPA, please contact our data protection officer at privacy@webcollective.co.