Free tier available — one campus, unlimited users, no credit card Start free →

Legal

Data Processing Agreement

Last updated: 25 May 2026 · Version 1.0

This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer and CloudSync Technologies LLC (“CloudSync”, “Processor”) for the use of Probita. It governs the processing of personal data by CloudSync on behalf of the Customer in accordance with the UAE Personal Data Protection Law (PDPL) and applicable data protection legislation.

1. Definitions

  • Controller — the Customer organisation that determines the purposes and means of processing personal data.
  • Processor — CloudSync Technologies LLC, which processes personal data on behalf of the Controller.
  • Personal Data — any information relating to an identified or identifiable natural person processed via Probita.
  • Processing — any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion.

2. Processor obligations

CloudSync agrees to:

  • Process personal data only on documented instructions from the Controller (as described in the Terms of Service and this DPA), unless required by law.
  • Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational measures to protect personal data, as described in our Security page.
  • Assist the Controller with data subject rights requests (access, correction, deletion, portability) within 30 days of notification.
  • Delete or return all personal data at the end of the service relationship, in accordance with our retention policy (30-day grace period after cancellation, then permanent deletion).
  • Provide the Controller with information necessary to demonstrate compliance with this DPA and allow for audits, with reasonable notice.

3. Sub-processors

CloudSync uses the sub-processors listed at it360.sync.school/subprocessors. We will notify the Controller at least 30 days before adding a new sub-processor that processes personal data. The Controller may object to a new sub-processor by emailing privacy@synctechnologies.ae. If the objection cannot be resolved, either party may terminate the agreement with 60 days’ notice.

CloudSync imposes data protection obligations on each sub-processor equivalent to those set out in this DPA.

4. International transfers

Customer data is stored in AWS ap-south-1 (Mumbai, India). By accepting this DPA, the Controller acknowledges that processing will take place in India, which may not have been formally assessed by UAE authorities as providing equivalent data protection to the UAE. CloudSync relies on contractual safeguards (AWS Data Processing Addendum) to ensure adequate protection.

5. Security

CloudSync implements the following technical and organisational measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256-GCM encryption for sensitive secrets at rest
  • Argon2id hashing for passwords
  • PostgreSQL row-level security for tenant isolation
  • Access controls and audit logging for all administrative actions
  • Annual penetration testing (planned; first test Q3 2026)

6. Data breach notification

In the event of a personal data breach, CloudSync will:

  • Notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, where feasible.
  • Provide all information reasonably necessary for the Controller to fulfil its own notification obligations to the relevant supervisory authority and affected data subjects.

7. Audit rights

The Controller may, no more than once per year and with at least 30 days’ written notice, audit or inspect CloudSync’s compliance with this DPA. CloudSync may fulfil this obligation by providing an up-to-date third-party security audit report in lieu of a direct inspection.

8. Data subject rights

The Controller is responsible for responding to data subject rights requests. CloudSync will provide reasonable technical assistance to facilitate such requests (e.g., data export, anonymisation, deletion) within 30 days of written request. Assistance involving significant engineering effort may be charged at our standard professional services rate.

9. Data deletion on termination

Upon termination or expiry of the service agreement, CloudSync will make personal data available for export for 30 days. After this period, all personal data will be permanently deleted from production systems. Audit log entries required by law may be retained for up to 7 years in anonymised or encrypted form.

10. Governing law

This DPA is governed by the laws of the United Arab Emirates. Any disputes are subject to the exclusive jurisdiction of the courts of Dubai, UAE. For enterprise customers, the DIFC courts are the preferred venue.

11. Acceptance

By creating an account and accepting the Terms of Service, the Customer accepts this DPA. For enterprise customers requiring a countersigned DPA document, contact legal@synctechnologies.ae.