MeandRoboQIYADA
Legal

Data Processing Addendum

Version 1.0 · Print or save as PDF
Draft for legal review — this document has not yet been finalised.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer and MeandRobo Artificial Intelligence Solutions W.L.L. ("MeandRobo"). It applies whenever MeandRobo processes personal data contained in Customer Data on the Customer's behalf. It takes effect automatically when the Customer accepts the Terms; no signature is needed. A countersigned copy is available on request at info@meandrobo.com.qa.

1. Definitions and roles

1.1 Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the Applicable Data Protection Law. "Applicable Data Protection Law" means all data protection laws that apply to the processing, which may include Qatar Law No. 13 of 2016 on the Protection of Personal Data Privacy, the Saudi Personal Data Protection Law, UAE Federal Decree-Law No. 45 of 2021, the data protection laws of Bahrain, Oman, Kuwait and Egypt, Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, and applicable US laws.

1.2 The Customer is the controller (or, where it acts for another controller, a processor) of personal data in Customer Data ("Customer Personal Data"). MeandRobo is the processor (or sub-processor). Details of the processing are set out in Annex 1.

2. Processing on instructions

2.1 MeandRobo processes Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case it informs the Customer before processing unless the law prohibits this. The Terms, this DPA and the Customer's use and configuration of the Service are the Customer's complete instructions.

2.2 MeandRobo will inform the Customer immediately if, in its opinion, an instruction infringes Applicable Data Protection Law.

2.3 MeandRobo will not sell Customer Personal Data, use it for advertising, or use it to train, retrain or improve any artificial-intelligence model, and will ensure that its sub-processors are bound by equivalent restrictions.

3. Confidentiality

MeandRobo ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality and accesses it only as needed to provide the Service, give support the Customer asks for, maintain security, or comply with the law.

4. Security

MeandRobo implements and maintains the technical and organisational measures described in Annex 2, appropriate to the risk. It may update them provided the overall level of security is not reduced.

5. Sub-processors

5.1 The Customer gives general authorisation for MeandRobo to engage the sub-processors listed on the Sub-processors page (Annex 3).

5.2 MeandRobo will give at least 30 days' notice of any new or replacement sub-processor by updating that page and notifying the Workspace owner by email or in the app. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused period.

5.3 MeandRobo imposes on each sub-processor, by written contract, data-protection obligations that are no less protective than this DPA, and remains responsible to the Customer for its sub-processors' performance.

5.4 Services the Customer chooses to connect (such as Microsoft 365, a mailbox provider or a calendar provider) and PayPal are not MeandRobo's sub-processors; they act under their own terms with the Customer.

6. Assistance

6.1 Data-subject requests. Taking into account the nature of the processing, MeandRobo provides tools in the Service (viewing, correcting, exporting and deleting data) and reasonable assistance to help the Customer respond to requests from data subjects. If MeandRobo receives a request directly, it will forward it to the Customer within 5 business days and will not respond itself except to confirm that the request has been passed on, unless the Customer instructs otherwise or the law requires.

6.2 Other assistance. MeandRobo will give reasonable assistance to the Customer with security, breach notification, data protection impact assessments and consultations with supervisory authorities, taking into account the information available to it.

7. Personal data breaches

7.1 MeandRobo will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it.

7.2 The notice will describe, as far as then known: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Information not yet available will be provided as it becomes available.

7.3 MeandRobo will take reasonable steps to contain, investigate and remedy the breach, and will cooperate with the Customer's own notifications to authorities and individuals. Notifying the Customer is not an admission of fault.

8. Deletion and return

8.1 During the Service the Customer can export Customer Personal Data at any time.

8.2 When a Workspace is closed, MeandRobo keeps the data available for export for 30 days and then deletes it, unless the law requires storage. Backup copies are overwritten within a further 60 days. MeandRobo will confirm deletion in writing on request.

9. Audits and information

9.1 MeandRobo will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including written answers to security questionnaires and its records of processing.

9.2 Where that information is not sufficient, or where a supervisory authority requires it, the Customer may carry out an audit (itself or through an independent auditor bound by confidentiality) no more than once a year, on at least 30 days' notice, during business hours, in a way that does not disrupt the Service or compromise other customers' data. Each party bears its own costs, unless the audit reveals a material breach by MeandRobo.

10. International transfers

10.1 MeandRobo may process Customer Personal Data in Qatar, in the countries where its sub-processors operate (listed in Annex 3), and in other countries with appropriate safeguards.

10.2 EEA, Switzerland and UK. To the extent the Customer transfers personal data subject to the GDPR to MeandRobo in a country without an adequacy decision, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (Module 2, controller to processor; or Module 3, processor to processor, where the Customer is a processor) are incorporated into this DPA by reference, completed as follows: Clause 7 (docking) applies; Clause 9 option 2 (general authorisation, 30 days' notice); Clause 11 optional language does not apply; Clause 13 and Annex I.C: the supervisory authority is that of the Member State in which the Customer is established or, if the Customer is not established in the EEA, the Member State in which its representative under Article 27 GDPR is established (or, failing that, the Irish Data Protection Commission); Clauses 17 and 18: the law and courts of Ireland; Annexes I–III: Annexes 1–3 of this DPA. For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated: Table 1 is completed with the parties' details in the Terms; Table 2 selects the Modules above; Table 3 is completed by Annexes 1–3 of this DPA; Table 4: neither party may end the Addendum under its Section 19; for Swiss transfers, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss FDPIC. If a new set of clauses is adopted for importers already subject to the GDPR, the parties will use it.

10.3 Saudi Arabia and other jurisdictions. Where the law of another jurisdiction requires a specific transfer mechanism (for example, the standard contractual clauses issued by the Saudi Data & AI Authority), the parties agree to rely on that mechanism, which MeandRobo will provide on request, and to cooperate on any transfer risk assessment required.

10.4 Government requests. If MeandRobo receives a request from a public authority for Customer Personal Data, it will (unless legally prohibited) notify the Customer promptly, assess the lawfulness of the request, challenge it where there are reasonable grounds, and disclose only the minimum required.

11. Customer obligations

The Customer is responsible for: having a lawful basis for the processing and giving the notices the law requires to its data subjects (including employees, correspondents and business-card contacts); obtaining any permit required by law (for example, for "special nature" personal data under Qatar Law No. 13 of 2016); not uploading special categories of data unless necessary and lawful; configuring users and permissions appropriately; and the lawfulness of its instructions.

12. Artificial intelligence

12.1 AI Features process Customer Personal Data only to produce Output for the Customer. MeandRobo uses AI model providers only under terms that prohibit training on Customer Data; the current provider (Google, Gemini API paid service) retains prompts and responses for up to 55 days solely for abuse monitoring, and, for market-intelligence requests grounded with Google Search, stores the prompt and output for 30 days to produce search results and to debug and test its systems.

12.2 For the purposes of the EU Artificial Intelligence Act, MeandRobo is the provider of the AI system made available through the Service and the Customer is a deployer. MeandRobo designs the Service so that users are informed when they interact with an AI assistant. The Customer is responsible for any disclosure required when it publishes or distributes AI-generated content, and for not using the Service for high-risk purposes (such as decisions about individuals' credit, hiring, firing, insurance or access to essential services).

13. Liability and term

13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where the Applicable Data Protection Law provides otherwise.

13.2 This DPA lasts as long as MeandRobo processes Customer Personal Data.

13.3 If there is a conflict between this DPA and the Terms, this DPA prevails on the processing of personal data. If there is a conflict between this DPA and incorporated Standard Contractual Clauses, the Standard Contractual Clauses prevail.

Annex 1 — Details of processing

Annex 2 — Technical and organisational security measures

  1. Encryption: TLS for all data in transit; AES-256-GCM encryption of two-factor secrets, mailbox credentials, access tokens and backups; passwords stored as salted one-way hashes.
  2. Access control: two-factor authentication; session expiry after inactivity; role-, company- and module-level permissions within each workspace; administrator-controlled use of signatures and stamps.
  3. Separation: each customer workspace is held in a separate database schema; requests are routed to the correct workspace by the server, not the browser.
  4. Logging: audit log of sign-ins, data changes and administrative actions; server logs for security monitoring.
  5. Resilience: automated daily encrypted backups that are regularly restore-tested, and retention of daily and weekly backups for up to about eight weeks. After any restore, deletions and workspace closures made since the backup are re-applied.
  6. Staff access: least-privilege administrative access; confidentiality obligations; access to Customer Data only for support, security or legal reasons.
  7. Application security: input validation, rate limiting on public forms and sign-in, protection against common web attacks, dependency updates, and review of changes before deployment.
  8. Incident response: a documented process to detect, contain, assess, notify and remediate incidents within the time limits in section 7.
  9. AI safeguards: only paid AI services that do not train on Customer Data; human confirmation before any email is sent; no automated decisions with legal effect on individuals.
  10. Data minimisation and deletion: retention limits as set out in the Privacy Policy; deletion of credentials when an integration is disconnected; workspace deletion after the retrieval period.

Annex 3 — Sub-processors

The current list is published at /subprocessors.