This Customer Data Processing Agreement (the DPA) is entered into between Opeare FZE, a free zone establishment incorporated in the United Arab Emirates under trade licence number 4430085.01 with registered office at SPC Free Zone, Sharjah, United Arab Emirates (OpeAre), and the customer who has registered for an Account on the Service (the Customer). OpeAre and the Customer are each a Party and together the Parties.
This DPA forms part of the Terms of Service available at opeare.com/terms (the Terms) and is incorporated into the Terms by reference. By accepting the Terms, the Customer accepts this DPA. No separate signature is required.
This DPA governs the Processing of Personal Data by OpeAre on behalf of the Customer in the course of OpeAre providing the Service. It is intended to comply with the United Arab Emirates Personal Data Protection Law, Federal Decree-Law No. 45 of 2021 (the PDPL), and in particular the obligations of Processors under Article 8 of the PDPL.
1. Definitions
1.1 Capitalised terms not defined in this DPA have the meanings given in the Terms. In this DPA:
(a) Customer Personal Data means Personal Data that the Customer or a User uploads, inputs, generates, or otherwise causes to be Processed through the Service (including within uploaded documents, populated templates, and AI-Feature inputs and outputs), in respect of which the Customer is the Controller and OpeAre is the Processor;
(b) Controller, Processor, Data Subject, Personal Data, and Processing have the meanings given in the PDPL;
(c) Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data;
(d) Subprocessor means any third party engaged by OpeAre to Process Customer Personal Data, including AI service providers;
(e) UAE Data Office means the federal data protection regulator established under Federal Decree-Law No. 44 of 2021.
2. Roles of the Parties and scope
2.1 The Customer is the Controller of Customer Personal Data. OpeAre is the Processor of Customer Personal Data, acting on the documented instructions of the Customer as set out in this DPA and the Terms.
2.2 The subject matter, nature and purpose, duration, types of Personal Data, and categories of Data Subjects to which the Processing relates are set out in Schedule 1.
2.3 This DPA applies only to Customer Personal Data Processed by OpeAre in its capacity as Processor. It does not apply to Personal Data of the Customer’s own Users or Account holders where OpeAre acts as Controller; that Processing is governed by the OpeAre Privacy Policy available at opeare.com/privacy.
3. Processing on documented instructions
3.1 OpeAre shall Process Customer Personal Data only on the documented instructions of the Customer, including with regard to transfers of Customer Personal Data outside the United Arab Emirates, unless required to do otherwise by Applicable Law.
3.2 The Customer’s documented instructions are set out in this DPA, the Terms, and (where applicable) Customer-specific configurations of the Service. The Customer may issue additional written instructions consistent with this DPA.
3.3 If OpeAre considers that an instruction infringes the PDPL or any other Applicable Law, OpeAre shall notify the Customer in writing without undue delay.
4. Confidentiality of OpeAre personnel
4.1 OpeAre shall ensure that any person authorised by OpeAre to Process Customer Personal Data is subject to a duty of confidentiality (whether by statutory obligation or contractual undertaking) and has received appropriate training on data protection requirements.
5. Security of Processing
5.1 OpeAre shall implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are described in Schedule 2.
5.2 In assessing the appropriate level of security, OpeAre takes account of the state of the art, the costs of implementation, the nature, scope, context, and purposes of the Processing, and the risks of varying likelihood and severity to the rights and freedoms of Data Subjects.
6. Subprocessors
6.1 The Customer grants OpeAre general authorisation to engage Subprocessors, including AI service providers, to support the provision of the Service, subject to this Section 6.
6.2 The Subprocessors currently engaged by OpeAre are listed in Schedule 3. OpeAre will inform the Customer of any intended addition or replacement of Subprocessors at least thirty (30) days before the change takes effect, giving the Customer the opportunity to object on reasonable data protection grounds.
6.3 OpeAre shall impose, by written contract, data protection obligations on each Subprocessor that are no less protective than the obligations imposed on OpeAre under this DPA. OpeAre remains responsible to the Customer for the acts and omissions of its Subprocessors.
6.4 In respect of AI service providers, OpeAre shall ensure by contract that Customer Personal Data is not used by the AI service provider to train third-party AI models without the Customer’s instruction, and that appropriate confidentiality and data protection obligations apply.
7. Assistance with Data Subject rights
7.1 OpeAre shall assist the Customer, by appropriate technical and organisational measures and insofar as reasonably possible, in responding to requests from Data Subjects seeking to exercise their rights under the PDPL.
7.2 If OpeAre receives a request directly from a Data Subject relating to Customer Personal Data, OpeAre shall forward the request to the Customer without undue delay and shall not respond directly except on the Customer’s instructions or as required by Applicable Law.
8. Personal Data Breach notification
8.1 OpeAre shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notification shall include, to the extent then known to OpeAre:
(a) a description of the nature of the Personal Data Breach;
(b) the categories and approximate number of Data Subjects affected and Personal Data records concerned;
(c) the likely consequences of the Personal Data Breach;
(d) the measures taken or proposed by OpeAre to address the Personal Data Breach and mitigate its effects;
(e) a point of contact for further information.
8.3 OpeAre shall cooperate with the Customer in responding to and managing the Personal Data Breach, including in any required notifications to the UAE Data Office and affected Data Subjects under the PDPL.
9. Assistance with Customer compliance
9.1 OpeAre shall provide reasonable assistance to the Customer in ensuring compliance with the Customer’s own obligations under the PDPL, including in relation to:
(a) security of Processing;
(b) notification and communication of Personal Data Breaches;
(c) data protection impact assessments, where applicable;
(d) prior consultation with the UAE Data Office, where applicable.
10. Return or deletion at end of Processing
10.1 On termination of the Customer’s Subscription or other use of the Service, or on written request of the Customer, OpeAre shall at the Customer’s choice either return all Customer Personal Data to the Customer in a structured commonly used format, or securely delete it.
10.2 OpeAre may retain Customer Personal Data only to the extent and for the period required by Applicable Law (including UAE tax law), in which case OpeAre shall continue to apply the protections of this DPA for the duration of such retention.
11. Information rights
11.1 OpeAre shall make available to the Customer, on reasonable written request, information necessary to demonstrate compliance with this DPA, including:
(a) a description of the technical and organisational measures implemented;
(b) the current list of Subprocessors and their roles;
(c) any independent audit reports or certifications applicable to the Service.
12. Cross-border transfers
12.1 Customer Personal Data may be Processed in jurisdictions outside the United Arab Emirates by OpeAre or by Subprocessors, only:
(a) to jurisdictions recognised as providing an adequate level of data protection under the PDPL or by the UAE Data Office; or
(b) subject to appropriate contractual safeguards under Article 22 of the PDPL imposing on the recipient obligations equivalent to those required under the PDPL.
12.2 Details of the jurisdictions involved are set out in Schedule 3.
13. Liability
13.1 The limitations and exclusions of liability set out in the Terms apply to OpeAre’s liability under this DPA.
14. Term and termination
14.1 This DPA takes effect on the Effective Date and continues for as long as OpeAre Processes Customer Personal Data on behalf of the Customer.
14.2 This DPA terminates automatically on completion of OpeAre’s obligations under Section 10.
15. General
15.1 In the event of conflict between the Terms and this DPA, this DPA prevails to the extent of the conflict in relation to the Processing of Customer Personal Data.
15.2 This DPA is governed by the laws of the United Arab Emirates. The dispute resolution provisions of the Terms apply to any dispute under this DPA.
15.3 OpeAre may update this DPA from time to time. Material changes will be notified to the Customer by email or through the Service at least thirty (30) days before they take effect.
Schedule 1 - Details of the Processing
Subject matter:
Provision of the OpeAre legal operations platform to the Customer, including storage, transmission, and Processing of Customer-uploaded documents, populated templates, AI-Feature inputs and outputs, and other Customer Content.
Nature and purpose of Processing:
Storage, organisation, retrieval, consultation, transmission, analysis (including AI-assisted analysis on Customer instruction), and (on Customer instruction or in accordance with retention rules) deletion of Customer Personal Data, in order to enable the Customer to produce, review, manage, and store legal documents and to operate the Service.
Duration of Processing:
The duration of the Customer’s Subscription or other use of the Service, and any post-termination period during which OpeAre is required to retain data under Applicable Law or by Customer instruction.
Categories of Personal Data:
Personal Data input, uploaded, or generated through the Service, which may include: full names, contact details, job titles, employment terms, salary information, passport numbers, Emirates ID numbers, financial details, corporate records, and other information contained in documents Processed through the Service.
Categories of Data Subjects:
Employees, officers, directors, contractors, counterparties, and other natural persons whose Personal Data the Customer inputs into or uploads to the Service in connection with the Customer’s business operations.
Schedule 2 - Technical and organisational measures
OpeAre implements the following technical and organisational security measures:
(a) encryption of Customer Personal Data in transit (TLS) and at rest;
(b) role-based access controls with least-privilege principles for OpeAre personnel;
(c) multi-factor authentication for administrative access;
(d) logging and monitoring of access to Customer Personal Data;
(e) environmental separation of production, staging, and development systems;
(f) security review of Subprocessors and contractual data protection obligations;
(g) documented incident response and breach notification procedures;
(h) contractual obligations on AI service providers preventing use of Customer Personal Data for third-party AI model training without Customer instruction;
(i) periodic review and update of these measures.
Schedule 3 - Subprocessors
The Subprocessors engaged by OpeAre as at the Effective Date are:
- Stripe - Payment processing and Subscription billing. Primary processing location: Ireland (European Union).
- Vercel - Hosting of the Service and platform infrastructure. Primary processing location: United Kingdom (London, eu-west-2). Edge locations global.
- Supabase - Database hosting and authentication. Primary processing location: United Kingdom (London, eu-west-2).
- Resend - Transactional email delivery (Account confirmations, password resets, Service notifications). Primary processing location: United States.
- AI service providers - Provision of AI Features including document review, summarisation, extraction, and drafting assistance. Contractual restrictions apply preventing use of Customer Personal Data for third-party AI model training without Customer instruction. Primary processing location: United States and/or European Union.
An up-to-date list of Subprocessors, including current AI service providers, is available on request to contact@opeare.com.