Skip to main content
Document status

Version v1.0, effective 2026-08-31. The official language of the Terms is English; any translation is provided for convenience only.

KOMASHI DATA PROCESSING AGREEMENT

Module D(2) — Data Processing Agreement (DPA)

Version: v1.0 · Effective date: 2026-08-31

This Data Processing Agreement is entered into between the Provider (the "Controller") and BMSHI TECHNOLOGY SERVICES - FZCO ("Komashi", the "Processor") and is incorporated into the Provider Agreement (Module A). It governs Komashi's processing of End User personal data on the Provider's behalf, in accordance with Article 28 GDPR and the UAE PDPL. Capitalized terms not defined here have the meanings in Module 0 or the GDPR.


1. Roles; Scope

In short: For your customers' data on the Platform, you (the Provider) are the controller and Komashi is your processor, acting only on your instructions. This summary is for convenience only and is not legally binding.

1.1. The Controller determines the purposes and means of processing of End User personal data entered into or generated on the Platform in connection with the Provider Services ("Controller Data"). Komashi processes Controller Data solely as Processor on the Controller's behalf.

1.2. The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex 1.

1.3. This DPA does not apply to personal data Komashi processes as a controller (see the Privacy Policy, Section 2.1), nor to payment data. Komashi is not part of the money flow: payments for Provider Services pass directly from End Users, via the Payment Provider, to the Controller; Komashi is not a merchant of record, not a payment service provider, and never holds, receives, controls, or transmits End User funds, card numbers, or payment credentials. Payment processing, and the personal data associated with it, is carried out by the Payment Provider under its own compliance regime.

2. Controller Obligations

2.1. The Controller warrants that: (a) it has a valid legal basis for the processing it instructs; (b) it has provided all legally required information to data subjects; (c) its instructions comply with applicable data protection law; and (d) it will not instruct the processing of special categories of personal data without Komashi's prior written agreement.

2.2. The Controller's instructions are, in the first instance, the Provider Agreement, this DPA, and the Controller's configuration and use of the Platform's features. Additional instructions require written agreement, and Komashi may charge reasonable, cost-based fees for work that goes beyond standard Platform functionality, notified to the Controller in advance. No fee is charged for anything Komashi is required to do under Article 28(3) GDPR, including the assistance in Sections 3.5 and 3.6.

3. Processor Obligations (Art. 28(3) GDPR)

In short: Komashi processes your customers' data only on your instructions, keeps it confidential and secure, helps you meet your own legal duties, and tells you promptly if something goes wrong. Non-binding summary.

Komashi shall:

3.1. Instructions. Process Controller Data only on the Controller's documented instructions (Section 2.2), including with regard to international transfers, unless required to do otherwise by applicable law — in which case Komashi shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest. Komashi shall inform the Controller immediately if, in its opinion, an instruction infringes applicable data protection law.

3.2. Confidentiality. Ensure that persons authorized to process Controller Data are bound by contractual or statutory confidentiality obligations.

3.3. Security. Implement and maintain the technical and organizational measures set out in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to data subjects (Art. 32 GDPR; PDPL security requirements). Komashi may update Annex 2 provided the level of protection is not materially reduced.

3.4. Sub-processors. Not engage a sub-processor without authorization per Section 4.

3.5. Data subject rights. Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts Komashi directly regarding Controller Data, Komashi will direct the data subject to the Controller (Komashi does not itself forward the request) and will not respond substantively except on the Controller's instruction or where legally required.

3.6. Assistance. Assist the Controller in ensuring compliance with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation) and equivalent PDPL obligations, taking into account the nature of the processing and the information available to Komashi. This assistance is provided at no additional charge; Section 2.2 applies only to work that goes beyond what Article 28(3) requires.

3.7. Breach notification. Notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Controller Data, providing (as information becomes available) the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. Komashi's notification is not an acknowledgment of fault or liability. Notification of authorities and data subjects is the Controller's responsibility as controller.

3.8. Deletion or return. At the Controller's choice, delete or return all Controller Data after the end of the provision of the Services, and delete existing copies, unless applicable law requires storage. In the absence of an election, Controller Data is soft-deleted and then permanently deleted in accordance with the retention periods in Section 9.2 of the Privacy Policy (Module D(1)), which govern. Deletion is scheduled and automatic; deletion from backups occurs on the backup rotation cycle stated there (Privacy Policy Section 9.2(c)), which is not searched or edited record-by-record.

    (a) Records retained under a statutory duty. Privacy Policy Section 9.2a is an exception to this Section 3.8 and prevails over a deletion or return election. In particular, invoices the Controller issued through the Platform are the Controller's own accounting records and are retained for the statutory record-keeping period applicable to the Controller (Privacy Policy Section 9.2a(b)); Komashi holds them in a restricted state, uses them for no other purpose, and deletes them at the end of that period. The Controller may instruct Komashi in writing to apply a longer period required by its national law, and may at any time obtain a copy or an export of those records.

3.9. Audits. Make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or its mandated auditor.

    (a) How an audit request is met. Komashi does not currently hold a SOC 2 report or ISO/IEC 27001 certification. Komashi may first satisfy an audit request by providing, within thirty (30) days of the request: the current version of Annex 2 (Technical and Organisational Measures) together with a written statement, signed by an authorised representative, confirming that those measures are in place; the current sub-processor list (Annex 3); a description of the hosting and infrastructure arrangements, including the certifications held by Komashi's own hosting and infrastructure providers; the results of the most recent penetration test or security assessment, where one has been carried out; and written answers to the Controller's reasonable, specific security questions. Where that information does not reasonably enable the Controller to verify compliance, the Controller may proceed to an inspection under paragraph (b), and Komashi shall not refuse it on the ground that paragraph (a) has been complied with.

    (b) Inspections. On-site or remote inspections require 30 days' notice, occur at most once per year (absent a personal data breach or a requirement of a competent supervisory authority), must not unreasonably disrupt operations, are subject to confidentiality, and are at the Controller's cost.

    (c) If Komashi later obtains a certification. If Komashi obtains a SOC 2 report, ISO/IEC 27001 certification, or an equivalent independent audit report, it will make the report or certificate available to the Controller on request under confidentiality, and may satisfy audit requests through it under paragraph (a). Obtaining such a certification does not remove the Controller's right to an inspection under paragraph (b).

4. Sub-processors

In short: You give general approval for our vetted sub-processors (hosting, email, etc.). We list them publicly, tell you before adding one, and you can object. Non-binding summary.

4.1. The Controller grants a general written authorization for Komashi to engage the sub-processors listed at https://komashi.com/legal/subprocessors (Annex 3).

4.2. Komashi shall inform the Controller of intended additions or replacements at least 14 days in advance (via the list page, email, or the Platform), giving the Controller the opportunity to object on reasonable data-protection grounds. If an objection cannot be resolved within thirty (30) days, the Controller may terminate the affected Services without penalty and without any early-termination charge, with a proportionate refund of any Fees prepaid for the unexpired period.

4.3. Komashi shall impose on each sub-processor, by written contract, data protection obligations materially equivalent to those in this DPA, and remains fully liable to the Controller for the sub-processor's performance.

5. International Transfers

In short: Controller Data is stored and processed in the EU/EEA, with no access from the UAE. Some application-level sub-processors are in or owned from the United States; those transfers run on the EU Standard Contractual Clauses, backed by a documented transfer impact assessment. Non-binding summary.

5.1. Komashi and its sub-processors may process Controller Data in the locations listed in Annex 3. Komashi shall not transfer Controller Data to a country lacking adequate protection without a valid transfer mechanism.

5.2. Where Controller Data is processed. For Controller Data subject to the GDPR, Komashi: (a) stores and processes such data within the EU/EEA, save for the transfers identified in Section 5.2a; (b) keeps all backups within the EU/EEA; and (c) provides access to such data from within the EU/EEA, maintaining no technical means of access from the United Arab Emirates. Komashi's registration as a UAE company does not, by itself, constitute a transfer of Controller Data, and no Controller Data is transferred to or accessible from the UAE.

5.2a. Transfers to third countries; Standard Contractual Clauses. Certain sub-processors identified in Annex 3 are established outside the EU/EEA, and specified categories of Controller Data are therefore transferred to a third country within the meaning of Chapter V GDPR. Annex 3 identifies, for each such sub-processor, the categories of Controller Data concerned, the country of establishment, and the transfer mechanism relied on.

    (a) Mechanism. Each such transfer is made under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), incorporated into this DPA by reference and completed as follows: Module Two (controller-to-processor) between the Controller and Komashi and Module Three (processor-to-processor) for onward sub-processing; Clause 7 (docking) applies; the Clause 11 optional independent-redress mechanism does not apply; Clause 17 (governing law) = Ireland; Clause 18 (forum) = the courts of Ireland; SCC Annexes I–III are completed from Annexes 1–3 of this DPA. Where a sub-processor has itself adopted the same Standard Contractual Clauses, or is certified under an adequacy decision applicable to it, Komashi may rely on that mechanism instead, and Annex 3 states which applies. In case of conflict, the SCCs prevail over this DPA.

    (b) Transfer impact assessment. Komashi has carried out and documented a transfer impact assessment for the transfers identified in Annex 3, covering the law of the destination country, the categories of data concerned, and the supplementary measures applied. The assessment is reviewed at least annually and on any change to the sub-processor list, and a copy is made available to the Controller on request under Section 3.9.

    (c) Supplementary measures. For each transfer, Komashi applies the measures recorded in the transfer impact assessment, which include as a minimum: transmission encrypted in transit; data minimisation, so that only the categories stated in Annex 3 leave the EU/EEA; contractual commitments that the sub-processor will not use Controller Data for its own purposes, including model training; and a commitment by the sub-processor to notify Komashi of any binding request from a public authority to the extent it is legally permitted to do so.

    (d) New third-country sub-processors. Komashi shall not engage a new sub-processor outside the EU/EEA without first completing the assessment in paragraph (b) and following the notice-and-objection process in Section 4.2.

    (e) UK GDPR. For Controller Data subject to the UK GDPR, the same Standard Contractual Clauses apply as amended by the UK International Data Transfer Addendum (version B.1.0 or successor).

5.3. For Controller Data subject to the PDPL, cross-border transfers comply with Articles 22–23 PDPL and applicable Executive Regulations.

6. Liability; Order of Precedence

6.1. Liability under this DPA is subject to the limitations in Section 10 of Module 0, except where such limitation is prohibited by applicable data protection law or the SCCs. That limitation operates between the parties only. It does not affect, and cannot restrict, a data subject's right to compensation under Article 82 GDPR against either party.

6.2. In case of conflict: (1) the SCCs, (2) this DPA, (3) the Provider Agreement.

7. Term

7.1. This DPA applies for as long as Komashi processes Controller Data and survives termination of the Provider Agreement until all Controller Data is deleted or returned under Section 3.8.


Annexes 1–3

Annex 1 (Description of Processing) and Annex 2 (Technical and Organizational Measures, Art. 32 GDPR) form part of this DPA and are set out in "Module D(2) — Annexes 1–2" (module-d2-annexes.md). Annex 3 (Authorized Sub-processors) forms part of this DPA and is set out in a further separate document, "Module D(2) — Annex 3 (Authorized Sub-processors)" (module-d2-annex-3-subprocessors.md), also published at https://komashi.com/legal/subprocessors. Each has its own version and effective date. Annex 2 may be updated by Komashi under Section 3.3 (provided the level of protection is not materially reduced); Annex 3 is maintained under the general authorization in Section 4.1, with the notice-and-objection process in Section 4.2. Where the SCCs apply under Section 5.2a, SCC Annexes I–III are completed from Annexes 1–3 (I←Annex 1, II←Annex 2, III←Annex 3). In case of conflict between any summary elsewhere and these Annexes, the Annexes govern.