Data Processing Agreement (DPA)
Last updated: 2026-07-07
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer organization subscribing to the Service (the “Customer”) and RasedPro Technologies (“RasedPro”, “we”, “us”) governing the processing of Personal Data through the RasedPro web application, mobile app, and related services (the “Service”). It reflects the parties' obligations under the Saudi Personal Data Protection Law (“PDPL”) and the implementing regulations issued by the Saudi Data & AI Authority (“SDAIA”).
1. Definitions
Terms such as Personal Data, Processing, Controller, Processor, Data Subject, and Personal Data Breach have the meanings given to them in the PDPL and its implementing regulations. Customer Personal Data means Personal Data submitted to the Service by or on behalf of the Customer, or generated by the Service on the Customer's behalf. Sub-processor means a third party engaged by RasedPro to process Customer Personal Data.
2. Roles of the parties
For Customer Personal Data, the Customer is the data Controller: it determines the purposes and means of processing, is responsible for the lawfulness of the data it submits, and for obtaining any consents or providing any notices the PDPL requires of Controllers. RasedPro Technologies is the data Processor and processes Customer Personal Data only on the Customer's behalf and under this DPA.
3. Subject matter, duration, nature, and purpose
The subject matter of processing is the provision of the Service: multi-tenant HR, payroll, attendance, leave, approvals, e-signature, and reporting workflows. Processing continues for the duration of the Customer's subscription and any wind-down period described in Section 12. The nature of processing includes collection, storage, structuring, retrieval, use, disclosure to authorized users within the Customer's tenant, and deletion. The purpose is limited to delivering, securing, supporting, and maintaining the Service as configured by the Customer.
4. Categories of data subjects and personal data
Data subjects: the Customer's employees, contractors, and other users the Customer invites to its tenant.
Categories of Personal Data:
- Identity and contact data: name (English and Arabic), email, phone number, emergency contact, date of birth.
- National ID or Iqama number and expiry date, and nationality.
- Employment data: employee number, job title, department, manager, hire date, contract details, employment status.
- Payroll and financial data: salary and salary components, allowances, deductions, bank account and IBAN.
- Attendance data: clock-in/clock-out timestamps and, where the Customer enables it and the data subject consents, approximate GPS location at clock-in/clock-out.
- Leave and HR records: leave requests, approvals, balances, performance reviews.
- Electronic signatures and signed documents.
- Operational data: audit logs (actor, action, timestamp, IP address, user agent) and device push tokens for mobile notifications.
5. Processor obligations
RasedPro Technologies shall:
- process Customer Personal Data only on documented instructions from the Customer (including the Customer's configuration and use of the Service), unless required otherwise by Saudi law — in which case we will inform the Customer of that legal requirement before processing, unless the law prohibits such disclosure;
- promptly inform the Customer if, in our opinion, an instruction infringes the PDPL or SDAIA regulations;
- ensure that all personnel authorized to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality;
- not use Customer Personal Data for our own purposes, and not sell or disclose it to third parties except as permitted under this DPA;
- maintain records of processing activities as required by the PDPL.
6. Security measures
We implement and maintain technical and organizational measures appropriate to the risk, including:
- encryption in transit (TLS 1.2+) for all connections to the Service;
- encryption at rest for sensitive PII fields (including national ID/Iqama numbers, bank account, and IBAN);
- bcrypt password hashing — passwords are never stored in plain text;
- role-based access control (RBAC) and strict per-tenant data isolation;
- comprehensive audit logging of privileged and data-affecting actions;
- least-privilege access for production systems, limited to personnel with a documented business need;
- encrypted database backups.
7. Sub-processors
The Customer grants RasedPro Technologies a general authorization to engage the following Sub-processors, each bound by written terms imposing data-protection obligations no less protective than this DPA:
- Resend — transactional email delivery.
- Expo — mobile push notification delivery.
- Cloud hosting / infrastructure provider — compute, storage, and database hosting for the Service.
- Moyasar — payment processing for subscription billing.
- Sentry — application error monitoring.
We will notify the Customer of any intended addition or replacement of a Sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds before the change takes effect. RasedPro Technologies remains liable for its Sub-processors' performance of their data-protection obligations.
8. International transfers
Any transfer of Customer Personal Data outside the Kingdom of Saudi Arabia is carried out in accordance with PDPL Article 29 and the transfer regulations issued by SDAIA. Where a Sub-processor processes data outside the Kingdom, we ensure appropriate safeguards are in place, transfer only the minimum data necessary for the relevant function, and do not transfer data in a manner that would prejudice national interests or the rights of data subjects under the PDPL.
9. Assistance with data subject rights
Taking into account the nature of the processing, we assist the Customer through appropriate technical and organizational measures (including in-product self-service tools) in fulfilling its obligation to respond to Data Subject requests under the PDPL — including access, correction, deletion, and withdrawal of consent. If a Data Subject contacts us directly regarding Customer Personal Data, we will refer the request to the Customer without undue delay.
10. Personal data breach notification
We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it — sufficient to enable the Customer to meet its own notification obligations to SDAIA and affected Data Subjects under the PDPL.
11. Audit rights
On reasonable advance written notice, and no more than once per year unless required by a supervisory authority or following a Personal Data Breach, we will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including responses to security questionnaires and provision of relevant documentation. Audits must not unreasonably disrupt the Service and are subject to confidentiality obligations.
12. Return or deletion of data
Upon termination or expiry of the Customer's subscription, and at the Customer's written election, we will return Customer Personal Data in a commonly used format or delete it, within thirty (30) days, and delete existing copies — except to the extent Saudi law requires continued retention (including retention of employment records under Saudi labor law), in which case we will continue to protect the retained data under this DPA and process it only for that legal purpose.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying agreement between the Customer and RasedPro Technologies. Nothing in this DPA limits either party's liability where such limitation is not permitted under the PDPL or other applicable Saudi law.
14. Governing law and jurisdiction
This DPA is governed by the laws of the Kingdom of Saudi Arabia, including the PDPL and its implementing regulations. The competent courts and judicial committees of the Kingdom of Saudi Arabia have exclusive jurisdiction over any dispute arising out of or in connection with this DPA.
15. Contact
Questions about this DPA or our processing practices: privacy@rasedpro.com