Document content
Data Processing Agreement (DPA)
Introduction
This Data Processing Agreement (the "Agreement") is entered into between the Tajarat Platform (the "Data Controller") and the party providing services that require the processing of personal data on behalf of the Platform (the "Data Processor").
This Agreement forms a supplement to any contract or services agreement entered into between the parties and is intended to regulate personal-data processing in a manner that ensures compliance with the laws applicable in the State of Qatar, in particular Law No. (13) of 2016 on Personal Data Privacy Protection, and any related legislation or regulatory instructions.
Article (1): Definitions
For the purposes of this Agreement, the following terms have the meanings set out below unless the context requires otherwise:
Platform: the Tajarat electronic platform.
Data Controller: the party that determines the purposes and means of processing personal data.
Data Processor: any person or entity that processes personal data on behalf of the Data Controller.
Personal Data: any information relating to an identified or identifiable natural person, directly or indirectly.
Processing: any operation performed on personal data, whether automated or manual, including collection, recording, organisation, storage, modification, use, transfer, disclosure, deletion, or destruction.
Data Breach: any incident resulting in unauthorised access to, loss, disclosure, alteration, or destruction of personal data.
Article (2): Subject Matter of the Agreement
This Agreement governs the processing of personal data carried out by the Data Processor when providing the agreed services to the Platform and sets out each party's responsibilities and obligations in relation to the protection and security of personal data.
Article (3): Scope of Processing
The Data Processor may process personal data only to the extent necessary to perform the agreed services and in accordance with the Platform's written instructions.
The data may not be used for any other purpose unless required by law or with the Platform's prior written approval.
Article (4): Types of Data
Depending on the nature of the service, the data processed may include:
Personal identification data.
Contact data.
Electronic account data.
Order and purchase data.
Shipping and delivery data.
Payment data to the extent permitted by applicable systems and regulations.
Technical records and usage logs.
Any other data necessary to provide the service.
The Data Processor may not collect additional data without a legitimate justification or the Platform's approval.
Article (5): Categories of Data Subjects
The personal data processed may relate to the following categories:
Customers.
Merchants.
Employees.
Service providers.
Website or application visitors.
Any other user of the Platform's services.
Article (6): Obligations of the Data Controller
The Platform will:
Issue clear instructions for processing data.
Ensure that a lawful basis exists for processing personal data.
Provide the Data Processor with the information necessary to perform the services.
Monitor the Data Processor's compliance with this Agreement where appropriate.
Cooperate with the Data Processor in handling requests from data subjects and competent authorities.
Article (7): Obligations of the Data Processor
The Data Processor must:
Process data only in accordance with the Platform's instructions.
Not disclose data to any unauthorised party.
Maintain the confidentiality of the data throughout the term of the Agreement and after its termination.
Implement appropriate technical and organisational measures to protect the data.
Restrict access to data to persons whose work requires it.
Train its employees on data-protection requirements.
Maintain appropriate records of processing activities where applicable.
Article (8): Information Security
The Data Processor must implement appropriate technical and organisational measures to protect personal data against loss, damage, unauthorised access, use, or disclosure, in a manner proportionate to the nature of the data and the level of risk.
Depending on the nature of the service, such measures may include:
Encrypting data in transit and at rest where appropriate.
Managing access permissions in accordance with the principle of least privilege.
Using secure authentication methods for accounts and systems.
Maintaining logs of access and material changes.
Performing periodic backups.
Updating security systems regularly.
Protecting infrastructure against malware and cyberattacks.
The Data Processor is not required to use a specific technical method where it demonstrates an equivalent or higher level of protection.
Article (9): Confidentiality
The Data Processor must keep confidential all data and information obtained in the course of providing the services and may use them only for the purposes specified in this Agreement.
The Data Processor must also ensure that its employees, advisers, and contractors are subject to appropriate confidentiality obligations.
The confidentiality obligation continues after the contractual relationship ends.
Article (10): Sub-processors
The Data Processor may not engage any sub-processor to perform any part of the services except with the Platform's general or specific approval, as provided in the main contract.
In all cases, the Data Processor remains responsible to the Platform for the acts of its sub-processors as if those acts were its own.
Article (11): Data Transfers
Personal data may not be transferred or made available outside the State or to another entity where doing so would violate applicable laws or the Platform's instructions.
Where cross-border data transfer is necessary, the parties must implement appropriate legal and technical safeguards in accordance with applicable legislation.
Article (12): Data Breaches
If the Data Processor becomes aware of a security breach that affects or may affect personal data, it must:
Notify the Platform without undue delay.
Provide the Platform with available information concerning the nature of the incident.
Take necessary measures to contain the incident and limit its effects.
Cooperate with the Platform in investigating and addressing the incident.
Implement corrective measures to prevent recurrence.
The Data Processor may not directly notify data subjects or competent authorities unless required by law or after obtaining the Platform's approval.
Article (13): Data Subject Rights
Within the scope of the services provided, the Data Processor must cooperate with the Platform to enable it to respond to requests from data subjects concerning their rights, including:
Requests for access to data.
Correction of data.
Updating data.
Deletion of data where permitted.
Restriction of processing where applicable.
Article (14): Audit and Compliance
After giving the Data Processor reasonable notice, the Platform may verify compliance with this Agreement by:
Requesting necessary information.
Reviewing relevant certificates or independent reports.
Conducting reasonable audits that do not unreasonably disrupt the Data Processor's business operations.
The Data Processor must cooperate to the extent reasonable and proportionate to the nature of the services.
Article (15): Data Retention
The Data Processor may not retain personal data longer than necessary to perform the services or for any period required by law.
When the purpose of processing ends, the data must be deleted or returned to the Platform in accordance with its instructions, unless retention is required by law.
Article (16): Termination of the Agreement
This Agreement terminates upon termination of the main contract or completion of all data-processing activities, whichever occurs later, unless the parties agree otherwise in writing.
Termination does not release either party from obligations that by their nature survive termination, in particular obligations relating to confidentiality and data protection.
Article (17): Liability
Each party is liable for damage arising from its breach of this Agreement or applicable laws, to the extent of its responsibility for the act or omission that caused the damage, unless the main contract provides otherwise.
Article (18): Notices
All notices relating to this Agreement must be in writing and sent through the electronic means or addresses approved between the parties. A notice takes effect on receipt or on the date on which it is deemed received under the main contract.
Article (19): Amendment of the Agreement
This Agreement may be amended by agreement between the parties or whenever legislative, regulatory, or technical changes require such amendment. Any amendment becomes effective on the date specified in it.
Article (20): Final Provisions
This Agreement forms an integral part of the main contract between the parties and must be read and interpreted together with it.
In the event of a conflict between this Agreement and the main contract concerning data protection, the provisions offering greater protection for personal data will apply, unless the law requires otherwise.
If any provision of this Agreement is held invalid, the validity of the remaining provisions will not be affected.
This Agreement is governed by the laws of the State of Qatar. The Qatari courts or the agreed dispute-resolution body will have jurisdiction over any dispute arising in connection with it, unless the parties agree otherwise.
