Data Processing Agreement
Product: SanadiqCloud
Effective date: 14 August 2026
Status: Pre-production processor terms aligned with actual hosting and features. Publishing this DPA does not mean SanadiqCloud is “GDPR compliant.”
This DPA applies when an organization (“Customer”) uses SanadiqCloud so that Thamar Labs / SanadiqCloud (“Processor”) processes personal data contained in the Customer’s workspace.
Platform account data (login, our billing of the Customer) is described in the Privacy Policy and is processed as controller, not under this DPA.
1. Roles
- Customer is the controller (or processor for its own clients) of workspace content: catalog, inventory, suppliers, sales customers, media, support messages the Customer writes, and similar tenant-scoped records.
- Processor hosts and processes that content to provide SanadiqCloud.
Customer is responsible for the lawfulness of data it uploads (including notices to its own customers and staff).
2. Instructions
Processor will process Customer personal data only to provide the Service, as configured by Customer’s users in the app, as required by law, or as agreed in writing.
3. Categories
Data subjects (examples): Customer’s staff using SanadiqCloud; Customer’s suppliers and sales customers; other people whose data Customer stores (addresses, tax ids, notes).
Personal data (examples): names, emails, phones, addresses, tax identifiers, order/sale records, uploaded files, audit metadata that includes actor identifiers.
Special category data: the product does not provide a dedicated health/biometric module. Customer must not upload special-category data unless it has a lawful basis and accepts that SanadiqCloud is a general business workspace, not a clinical system.
4. Confidentiality
Processor personnel and subprocessors must be under confidentiality obligations. Tenant APIs are designed to scope queries by tenant_id.
5. Security measures (as implemented)
- Authentication (password hashes or Google Sign-In) and session tokens.
- Tenant isolation in application queries.
- TLS expected on production HTTPS endpoints.
- Media objects in S3; delete path removes the object when media-service delete succeeds.
- Audit logging of significant actions (not a full SIEM product).
- Redis for cache and token blacklist — not a second copy of passwords (password hashes are excluded from entity cache policy).
These are engineering controls, not an ISO/SOC certification claim. No SOC 2 / ISO 27001 report is published in this repository.
6. Subprocessors
Customer authorizes the subprocessors in the Privacy Policy table (Stripe, AWS services used for the deployment, Google Sign-In, Firebase/FCM, and in-cluster Redis/RabbitMQ).
Change process: Processor should update the Privacy Policy / this DPA when subprocessors that process Customer personal data are added. A formal objection window is not implemented in the product.
7. International transfers
Production AWS for this product is documented in us-east-1. Stripe and Google may process data outside the Customer’s country. Specific SCC/IDTA modules are not bundled in the app. Customer and Processor must confirm transfer tools before relying on this DPA for EU/UK exports.
8. Assistance with data subject requests
The product has no DSAR export or erasure API for workspace-wide personal data. Processor will reasonably assist via support@sanadiqcloud.com using existing UI/APIs (for example, Customer can edit or delete many records in-app). Timelines are not SLA-backed.
9. Breach notification
There is no automated statutory breach-notification workflow in the codebase. If Processor becomes aware of a personal-data breach affecting Customer data, it will notify Customer without undue delay using available owner/support contacts. Target timelines (e.g. 72 hours) are policy intent, not an implemented timer.
10. DPIAs and audits
Processor will provide reasonably available information about processing (this DPA, architecture docs, subprocessors). On-site audit rights, penetration-test reports, and DPIA templates are not shipped as product features. Any audit right should be agreed in a signed Order Form.
11. Return and deletion
On organization delete, Processor soft-deactivates the tenant and cancels billing. Product, inventory, sales, media, and support handlers do not currently purge tenant rows in real time. Media objects are removed when the media delete use case runs, not automatically on tenant delete.
Customer must export data before requesting deletion if it needs a copy. There is no bulk workspace export API.
A hard-delete / retention schedule is a business and engineering gap (see internal gap report). This DPA does not promise a 30-day wipe.
12. Term
This DPA lasts for as long as Processor processes Customer personal data in the Service, and until deletion/return obligations are actually performed.
13. Contact
support@sanadiqcloud.com.
Still required before live payments: signed DPA counterparties; transfer clauses; breach playbook with clock; purge job; subprocessor notice process; counsel review.