This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Controller", "you") submits for verification email addresses relating to data subjects in the United Arab Emirates. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") and the guidance of the UAE Data Office when acting as a data processor on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the PDPL, "Controller" means you and "Processor" means BounceZero (PDPL Art. 1).
We process personal data on EU infrastructure (OVH, France). BounceZero does not maintain an establishment in the UAE; this Addendum governs our processing of personal data of UAE data subjects on your behalf.
2. Governing Law and Regulator
The processing described in this Addendum is governed, so far as the data subjects are in the UAE, by the PDPL (in force since 2 January 2022), its Executive Regulations, and the guidance of the UAE Data Office. The PDPL is a consent-based framework and, with limited exceptions, personal data may be processed only with the data subject's consent or on another basis expressly available under the Law. Non-compliance may result in administrative fines and other measures imposed by the UAE Data Office.
3. Role and Scope
For the email verification services described in the Master DPA, you act as the Controller and we act as the Processor. The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise. Where the PDPL applies to our processing directly, we comply with the obligations it imposes on processors as well as on controllers.
4. Data Subject Rights
We will assist you in responding to requests from data subjects exercising their rights under the PDPL, including the right to:
- Access the personal data processed and information about the processing.
- Correct inaccurate or incomplete personal data.
- Request deletion or destruction of personal data.
- Object to the processing in the circumstances set out in the Law.
- Portability of personal data, on your instruction.
If a data subject contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions. You are responsible for the legal basis of the processing, including consent or another lawful basis available under the PDPL.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without undue delay and in any event within 72 hours of becoming aware of it, consistent with the Master DPA and the notification window applicable under the PDPL and its Executive Regulations. You, as the Controller, are responsible for notifying the UAE Data Office and affected data subjects as required, including in cases of serious harm. We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of UAE data subjects is processed on EU infrastructure. The PDPL does not require personal data to be kept within the UAE, and transfers to a recipient in another country are permitted where the conditions in the Law and its Executive Regulations are met, including the data subject's consent and the existence of appropriate safeguards. To the extent any transfer relies on contractual safeguards, we rely on the Standard Contractual Clauses set out in the Master DPA. A copy is available on request at [email protected].
7. Additional Obligations
- Consent support: we retain the evidence of lawful processing instructions you rely on as your legal basis, so that you can demonstrate consent or another lawful basis for the processing.
- Security: we maintain the technical and organisational measures set out in Section 5 of the Master DPA, consistent with the security obligations under the PDPL.
- Data minimisation: only the email addresses and derived metadata necessary for validation are processed.
- Records: we maintain processing records that allow you to demonstrate compliance with your obligations as Controller.
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.