Draft — pending legal review, not yet in effect
This document is a working draft published for review. It has not been approved by legal counsel, does not bind either party, and will change before it takes effect. Bracketed items such as [PLACEHOLDER] and [CONFIRM] are still to be completed.
Data Processing Agreement
Draft version — effective date: [PLACEHOLDER: effective date]
This Data Processing Agreement ("DPA") forms part of the Terms of Service for Agencies between the subscribing Agency (the "Controller") and [PLACEHOLDER: legal entity name] (the "Processor"). It applies whenever the Processor processes personal data on the Controller's behalf in providing the Service. It is designed to meet the requirements of the Egyptian Personal Data Protection Law No. 151 of 2020 and its Executive Regulations (the "PDPL") and follows the structure of Article 28 of the EU General Data Protection Regulation (the "GDPR") where the GDPR applies to the Controller.
1. Roles of the parties
The Agency is the controller of personal data contained in Agency Data — for example its staff users, its advertiser clients and their contact persons, leads, and the people named in bookings, proposals, invoices and notes. SkylineDOOH is the processor of that data and processes it only to provide the Service.
SkylineDOOH is an independent controller only for the limited data it needs to run its own business with the Agency: account-owner contact details, billing records, and security and service logs.
2. Scope and details of processing
Subject matter and duration: hosting and operating the Service for the term of the subscription plus the export and deletion periods in the Terms.
Nature and purpose: storage, organisation, retrieval, display, transmission (for example sending emails the Controller triggers), backup and deletion, solely to provide the Service.
- Data subjects: the Controller's staff users; its advertiser clients and their representatives; leads and enquirers; other individuals the Controller records.
- Categories of data: names, business email addresses and phone/WhatsApp numbers, company names and job roles, account credentials (passwords are stored only as salted hashes; two-factor secrets encrypted), booking, proposal, invoice and payment records, notes and uploaded files, and technical data such as IP addresses and session identifiers.
- Special categories: the Service is not designed for sensitive personal data within the meaning of the PDPL (such as health, biometric, financial-account or criminal data). The Controller must not upload such data unless agreed in writing.
3. Processing on documented instructions
The Processor processes personal data only on the Controller's documented instructions, which consist of the Terms, this DPA and the Controller's use and configuration of the Service. If the Processor believes an instruction breaches the PDPL or other applicable data-protection law, it will inform the Controller promptly. If the law requires processing other than on instructions, the Processor will inform the Controller first unless the law prohibits it.
4. Confidentiality
The Processor ensures that every person it authorises to process personal data is bound by an appropriate duty of confidentiality and has access only to the extent necessary.
5. Security measures
The Processor implements appropriate technical and organisational measures, which currently include:
- logical isolation of each Organization's data, enforced in the application's data-access layer for every query;
- encryption in transit (TLS) for all connections to the Service;
- salted password hashing, encrypted storage of two-factor secrets and emailed sign-in codes, and optional or Controller-mandated two-factor authentication for staff;
- role-based permissions configurable by the Controller, and an audit log of key changes to records;
- restricted administrative access to production systems, regular backups and error monitoring;
- [CONFIRM] encryption at rest for database volumes and object storage, and backup frequency and retention.
6. Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors listed on the Sub-processors page. The Processor will give at least [PLACEHOLDER: 30] days' notice of any new or replacement sub-processor by email or in the Service. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected Service and receive a pro-rata refund of prepaid fees.
The Processor imposes data-protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible to the Controller for their performance.
7. Assistance with data-subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under the PDPL (including access, correction, erasure, restriction and objection) and, where applicable, the GDPR. If the Processor receives such a request directly, it will forward it to the Controller without undue delay and will not respond itself except on the Controller's instruction.
8. Personal data breaches
The Processor will notify the Controller without undue delay, and in any event within [PLACEHOLDER: 48] hours, after becoming aware of a personal data breach affecting Agency Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
The Processor will provide the information and cooperation the Controller reasonably needs to meet its own obligations, including notifying the Personal Data Protection Center within the period the PDPL requires (currently 72 hours) and informing affected data subjects where required.
9. Data protection impact assessments and consultation
The Processor provides reasonable assistance with data protection impact assessments and with any consultation with the Personal Data Protection Center or another competent supervisory authority, to the extent they relate to the Processor's processing.
10. Return and deletion
At the end of the Service, the Processor makes Agency Data available for export and then deletes it in accordance with the timelines in section 9 of the Terms, unless the law requires continued storage. On request the Processor will confirm deletion in writing.
11. Audits and information
The Processor makes available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, including written answers to security questionnaires no more than once a year. Where that information is insufficient, or where a regulator requires it, the Controller may conduct an audit on at least [PLACEHOLDER: 30] days' notice, during business hours, at its own cost, by an auditor bound by confidentiality, and without access to other customers' data.
12. International transfers
Some sub-processors process data outside Egypt, as shown on the Sub-processors page (for example the hosting region in the European Union and email and analytics providers in the United States). The Processor will transfer personal data across borders only where the PDPL permits it, including by obtaining any licence or permit from the Personal Data Protection Center that the PDPL requires [CONFIRM], and, where the GDPR applies, under an adequacy decision or Standard Contractual Clauses.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where applicable data-protection law does not permit such a limitation. In the event of conflict between this DPA and the Terms regarding personal data, this DPA prevails.
Data protection contact for the Processor: [PLACEHOLDER: data protection officer name and email].
