OTOLINK DATA PROCESSING AGREEMENT (DPA) V1.0
Effective Date: 1st April 2023
This Data Processing Agreement ("DPA") forms part of the Master Services Agreement, Terms & Conditions, Quote, Statement of Work ("Principal Agreement") entered into between OTOLINK LLC ("Processor") and the Customer ("Controller").
Where there is any conflict between this DPA and the Principal Agreement, this DPA shall prevail only with respect to the processing of Personal Data.
1. Definitions
1.1 APPLICABLE DATA PROTECTION LAWS
Means all applicable privacy and data protection legislation, including but not limited to:
• Kingdom of Saudi Arabia Personal Data Protection Law (PDPL)
• UAE Federal Personal Data Protection Law
• GDPR (where applicable)
• Any implementing regulations or successor legislation.
1.2 Controller: The party determining the purposes and means of processing Personal Data.
1.3 Processor: OTOLINK LLC.
1.4 Personal Data: Any information relating to an identified or identifiable natural person.
1.5 Data Subject: The individual to whom Personal Data relates.
1.6 Processing: Any operation performed on Personal Data including collection, storage, organisation, retrieval, transmission, use, disclosure, deletion or destruction.
1.7 Sub-Processor: Any third party engaged by Processor to process Personal Data.
2. Purpose
The Processor shall process Personal Data solely for the purpose of providing the Services described in the Principal Agreement.
3. Scope of Processing
Processor shall:
• process Personal Data only on documented instructions from Controller;
• process only data necessary to provide the Services;
• comply with Applicable Data Protection Laws.
4. Nature of Processing
Processing may include:
• Hosting
• Storage
• Synchronisation
• Retrieval
• Display
• Backup
• Technical support
• System maintenance
• Disaster recovery
• Security monitoring
• Analytics using anonymized or aggregated data only.
5. Controller Responsibilities
The Controller shall:
5.1 Determine the lawful basis for processing Personal Data.
5.2 Provide all required privacy notices.
5.3 Obtain all required consents where applicable.
5.4 Ensure all Personal Data supplied to Processor is lawfully collected.
5.5 Remain solely responsible for determining the purposes and legal basis of processing.
5.6 Ensure that all content uploaded into the Services, including but not limited to text, images, logos, trademarks, videos, fonts, customer information, and other intellectual property, is lawfully owned or appropriately licensed. The Processor shall not be responsible for verifying ownership, licensing, or legal rights relating to Customer Content.
6. Processor Responsibilities
Processor shall:
6.1 Process Personal Data only under documented instructions.
6.2 Ensure employees are bound by confidentiality obligations.
6.3 Implement appropriate technical and organisational security measures.
6.4 Provide reasonable assistance to Controller in complying with Applicable Data Protection Laws.
6.5 Notify Controller without undue delay after becoming aware of a confirmed Personal Data Breach.
6.6 Maintain appropriate records relating to processing activities where required by applicable law.
7. Security Measures
Processor shall implement reasonable technical and organisational safeguards including, where appropriate:
• Encryption in transit
• Encryption at rest
• Authentication controls
• Access control
• Role-based permissions
• Firewalls
• Malware protection
• Vulnerability management
• Disaster recovery procedures
• Secure backups
• Security monitoring
Processor may update its security measures from time to time provided the overall level of protection is not materially reduced.
8. OTOLINK SaaS Platform
Controller acknowledges that OTOLINK provides a multi-tenant Software-as-a-Service platform.
Accordingly:
• application components may be shared;
• infrastructure may be shared;
• software libraries may be shared;
• reusable code modules may be shared;
• computing resources may be shared.
Processor shall ensure logical separation between Customer environments at all times.
The existence of shared software components shall not constitute disclosure of Customer Data.
9. White-Label Platform
Controller acknowledges that OTOLINK operates a white-label platform supporting multiple independent customers.
Shared code libraries, reusable software components, standard templates, application frameworks and technical assets may exist across customer environments without exposing Customer Data.
10. Sub-Processors
Processor may engage Sub-Processors.
Processor shall:
• maintain a current Sub-Processor list;
• impose contractual confidentiality obligations;
• remain responsible for Sub-Processor performance.
Controller may reasonably object to newly appointed Sub-Processors.
11. International Data Transfers
Where Personal Data is transferred outside its originating jurisdiction, Processor shall implement appropriate safeguards required under Applicable Data Protection Laws.
12. Data Subject Rights
Processor shall provide reasonable assistance to Controller in responding to requests relating to:
• access;
• correction;
• deletion;
• restriction;
• portability;
• objection;
where legally applicable.
13. Personal Data Breaches
Upon becoming aware of a confirmed Personal Data Breach affecting Controller Data, Processor shall:
• notify Controller without undue delay;
• provide available information;
• cooperate in mitigation activities.
Notification shall not constitute an admission of liability.
14. Audit Rights
Controller may request reasonable evidence demonstrating compliance.
Where an audit is reasonably required:
• no more than once annually;
• minimum thirty (30) days' notice;
• during business hours;
• without disrupting Processor operations;
• Controller shall bear audit costs unless material non-compliance is identified.
15. Data Retention
Upon termination of the Services, Controller may request:
• return of Personal Data; or
• deletion of Personal Data.
Archived backups maintained as part of Processor's standard disaster recovery processes may continue to exist until overwritten in accordance with Processor's normal retention schedules.
16. Confidentiality
Each Party shall protect Confidential Information using at least the same degree of care applied to its own confidential information.
These obligations survive termination.
17. Intellectual Property
Nothing in this DPA transfers ownership of:
• software;
• source code;
• APIs;
• documentation;
• application frameworks;
• reusable software modules;
• platform components;
• databases;
• artificial intelligence models;
• configurations.
All Intellectual Property Rights remain the exclusive property of OTOLINK.
18. Use of Anonymized Data
Processor may use anonymized, aggregated and statistical information generated through operation of the Services for:
• product improvement;
• platform optimisation;
• security monitoring;
• benchmarking;
• artificial intelligence training;
• reporting;
• service analytics.
No Customer or individual shall be identifiable from such data.
19. Limitation of Liability
Except where prohibited by law:
The liability of each Party shall be governed by the liability provisions contained in the Principal Agreement.
Neither Party shall be liable for:
• indirect damages;
• consequential damages;
• loss of profits;
• loss of goodwill;
• business interruption.
Nothing limits liability arising from:
• fraud;
• wilful misconduct;
• liabilities which cannot legally be excluded.
20. Compliance
Each Party shall comply with Applicable Data Protection Laws.
Nothing in this DPA transfers the Controller's statutory obligations as Data Controller to Processor.
Processor does not provide legal advice regarding compliance with Applicable Data Protection Laws.
21. Governing Law
This DPA shall be governed by the governing law specified in the Principal Agreement.
22. Order of Precedence
In the event of inconsistency:
1. Principal Agreement
2. Statement of Work
3. This Data Processing Agreement
Appendix A – Description of Processing
|
Item |
Description |
|
Controller |
Customer |
|
Processor |
OTOLINK LLC |
|
Purpose |
Provision of SaaS automotive solutions |
|
Categories of Data Subjects |
Customers, prospects, employees, suppliers, authorised users |
|
Categories of Personal Data |
Contact details, vehicle information, booking data, customer interaction data, service history, user credentials, transaction data |
|
Processing Activities |
Hosting, storage, retrieval, display, support, synchronisation, backup, analytics |
|
Retention |
In accordance with the Principal Agreement and applicable law |
|
Sub-Processors |
Cloud hosting, SMS gateway providers, email providers, telephony providers, payment gateways, analytics providers, support providers |