← Back to legal

Data Processing Agreement

The contractual framework governing how Root Digit processes personal data on behalf of customers, designed to support compliance with GDPR, UK GDPR, UAE PDPL, CCPA and equivalent regimes.

Effective date: January 1, 2026 · Version 3.1

This Data Processing Agreement ("DPA") forms part of the agreement between Root Digit ("Processor") and the customer ("Controller") for the provision of services that involve the processing of Personal Data. This DPA applies to the extent Root Digit processes Personal Data on behalf of the Controller in connection with the services provided.

1. Definitions

Capitalised terms used but not defined in this DPA have the meanings given to them in Applicable Data Protection Law. For the purposes of this DPA:

  • "Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of Personal Data under the agreement, including, where applicable, the EU GDPR, the UK GDPR, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the California Consumer Privacy Act, and any implementing national legislation.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Sub-processor" have the meanings given to them in the EU GDPR.
  • "Services" means the products, professional services, or managed services provided by Root Digit to the Controller under the agreement.
  • "Standard Contractual Clauses" means, as applicable, the standard contractual clauses approved by the European Commission, the UK International Data Transfer Addendum, and any equivalent transfer mechanisms recognised under Applicable Data Protection Law.

2. Subject matter and duration

The subject matter of the Processing is the provision of the Services. The duration of Processing is the term of the agreement and any post-termination period required for the return or deletion of Personal Data. The nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Annex I.

3. Processor obligations

Root Digit shall:

  • process Personal Data only on documented instructions from the Controller, including with regard to international transfers;
  • ensure that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations;
  • implement and maintain the technical and organisational measures described in Annex II;
  • only engage Sub-processors in accordance with Section 5 below;
  • assist the Controller, taking into account the nature of the Processing, in fulfilling its obligations to respond to Data Subject requests;
  • assist the Controller in ensuring compliance with security, breach notification, data protection impact assessment, and prior consultation obligations;
  • at the Controller's choice, delete or return all Personal Data after the end of the Services, unless storage is required by law;
  • make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections.

4. Security of processing

Root Digit operates an information security management system aligned to ISO/IEC 27001 and implements the controls described in Annex II. These include, at minimum:

  • encryption of Personal Data in transit using TLS 1.2 or higher and encryption at rest using AES-256 or equivalent;
  • role-based access control with least-privilege defaults, multi-factor authentication, and continuous access reviews;
  • network segmentation, vulnerability management, and continuous monitoring of production environments;
  • secure development lifecycle including threat modelling, peer review, dependency scanning, and pre-deployment security testing;
  • tested incident response procedures, business continuity plans, and disaster recovery runbooks;
  • regular employee training on data protection, security, and acceptable use.

5. Sub-processors

The Controller authorises Root Digit to engage Sub-processors for the provision of the Services. The current list of Sub-processors is available on request. Root Digit will provide reasonable advance notice of any intended changes to the list, giving the Controller an opportunity to object on reasonable grounds related to data protection. Where the Controller objects, the parties will work in good faith to resolve the objection; failing resolution, the Controller may terminate the affected Service.

Root Digit imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains liable to the Controller for the performance of each Sub-processor's obligations.

6. International transfers

Where Personal Data originating in a regulated jurisdiction is transferred to a country that has not received an adequacy decision, the parties will rely on the applicable Standard Contractual Clauses or another recognised transfer mechanism. Root Digit will, where required, perform and document a transfer impact assessment and implement supplementary measures appropriate to the destination jurisdiction.

7. Personal Data breaches

Root Digit will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data breach affecting the Controller's Personal Data. The notification will include the information required to allow the Controller to meet its own notification obligations under Applicable Data Protection Law, to the extent such information is available.

8. Data subject rights

Root Digit will, taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subject rights. The Controller is responsible for responding to such requests directly.

9. Audits

The Controller has the right to audit Root Digit's compliance with this DPA, subject to reasonable advance notice, confidentiality obligations, and limitations on operational disruption. Root Digit's then-current independent third-party audit reports (such as ISO/IEC 27001 certification, SOC 2 Type II, or equivalent) will satisfy audit obligations to the maximum extent permitted by Applicable Data Protection Law.

10. Return and deletion

Upon termination or expiration of the agreement, Root Digit will, at the Controller's choice, return or delete all Personal Data within thirty (30) days, unless retention is required by Applicable Law, in which case Root Digit will continue to protect the Personal Data in accordance with this DPA until deletion is permitted.

11. Liability and conflicts

The liability of each party under this DPA is governed by the limitations of liability set out in the agreement. To the extent of any conflict between this DPA and the agreement, this DPA prevails to the extent it concerns the Processing of Personal Data.

Annex I — Description of processing

  • Categories of Data Subjects: as instructed by the Controller, typically the Controller's employees, customers, end users, and authorised third parties.
  • Categories of Personal Data: as instructed by the Controller, typically identification data, contact data, employment data, technical and usage data, and other categories specified in the relevant order form or statement of work.
  • Special category data: processed only where expressly instructed and contractually permitted.
  • Nature of processing: as required to provide the Services, including hosting, storage, computation, support, monitoring, analysis, and related operations.
  • Purpose of processing: the provision of the Services to the Controller.
  • Duration: the term of the agreement, plus any required retention period.

Annex II — Technical and organisational measures

Root Digit maintains a comprehensive set of technical and organisational measures, summarised below. The current detailed measures are available on request and are reviewed at least annually.

  • Information security governance with executive sponsorship and dedicated security team.
  • Encryption in transit and at rest, key management aligned to industry standards.
  • Identity and access management with least privilege, multi-factor authentication, and joiner-mover-leaver controls.
  • Network and host hardening, vulnerability management, patch management, and continuous monitoring.
  • Secure software engineering lifecycle including code review, dependency scanning, and security testing.
  • Operational resilience including backup, disaster recovery, business continuity, and tested incident response.
  • Personnel security including background screening (where lawful), confidentiality obligations, and ongoing training.
  • Vendor risk management with documented due diligence and contractual safeguards.

Contact

Questions about this DPA, or requests to execute it, should be sent to [email protected]. Our registered offices are at the Dubai International Financial Centre, Dubai, United Arab Emirates and 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States.

Cookie Policy

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. You can also choose "Necessary Only" to limit cookies to essential website functions only. Learn more