This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Controller", "you") submits for verification email addresses relating to data subjects in the Kingdom of Saudi Arabia. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with the Saudi Personal Data Protection Law issued by Royal Decree No. M/19 ("PDPL"), as amended, and the rules and guidance of the National Data Management Office within the Saudi Data and AI Authority (SDAIA), when acting as a data processor on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the PDPL, "Controller" means you and "Processor" means BounceZero.
We process personal data on EU infrastructure (OVH, France). BounceZero does not maintain an establishment in the Kingdom of Saudi Arabia; this Addendum governs our processing of personal data of Saudi data subjects on your behalf.
2. Governing Law and Regulator
The processing described in this Addendum is governed, so far as the data subjects are in the Kingdom of Saudi Arabia, by the PDPL (fully in force since 14 September 2024), its implementing regulations, and the rules and decisions of SDAIA and its National Data Management Office. Sanctions for non-compliance include administrative fines and other measures imposed by the competent authority.
3. Role and Scope
For the email verification services described in the Master DPA, you act as the Controller and we act as the Processor. The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise. Where the PDPL applies to our processing directly, we comply with the obligations it imposes on processors as well as on controllers, including maintaining records of processing.
4. Data Subject Rights
We will assist you in responding to requests from data subjects exercising their rights under the PDPL, including the right to:
- Be informed of the processing of their personal data, including its purpose and the recipients.
- Access their personal data held by you or by us on your behalf.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of personal data when the processing is no longer necessary or lawful.
- Object to processing, including for direct marketing, and to portability on your instruction.
If a data subject contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions. You are responsible for the legal basis of the processing, including consent or another lawful basis available under the PDPL.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without undue delay and in any event within 72 hours of becoming aware of it, consistent with the Master DPA and the notification window applicable under the PDPL for breaches that may cause harm. You, as the Controller, are responsible for notifying the National Data Management Office and affected data subjects as required. We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of Saudi data subjects is processed on EU infrastructure. The PDPL permits the transfer of personal data outside the Kingdom where the transfer does not affect national security or the Kingdom's higher interests and the recipient jurisdiction maintains an adequate level of protection; consent of the data subject is also required where the Law so provides (Art. 29). To the extent any transfer relies on contractual safeguards, we rely on the Standard Contractual Clauses set out in the Master DPA. A copy is available on request at [email protected].
7. Additional Obligations
- Processor contract: the PDPL requires the Controller and Processor to be bound by a written contract covering the processing. This Addendum and the Master DPA constitute that record.
- Consent support: we retain the evidence of lawful processing instructions you rely on as your legal basis, so that you can demonstrate consent or another lawful basis for the processing.
- Security: we maintain the technical and organisational measures set out in Section 5 of the Master DPA, consistent with the security obligations under the PDPL.
- Records: we maintain processing records that allow you to demonstrate compliance with your obligations as Controller.
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.