Data Processing Addendum
This addendum ("DPA") governs our processing of personal data contained in the data you put into ProjectFlow. It applies automatically to every customer — you do not need to ask for it or sign it separately, although we will sign a copy on request if your procurement process needs one.
1. Scope and precedence
This DPA forms part of the Terms of Service between SMR Future Technologies, a business established in India ("Processor", "we"), and the customer identified in the account ("Controller", "you").
Where this DPA conflicts with the Terms of Service or any order form on a matter of personal data protection, this DPA prevails.
It applies for as long as we process Customer Personal Data on your behalf.
2. Definitions
- Applicable Data Protection Law — the Saudi Personal Data Protection Law and its implementing regulations, and any other data protection law applicable to the processing.
- Customer Personal Data — personal data within Customer Data, as defined in the Terms of Service, that we process on your behalf.
- Controller, Processor, Data Subject, Processing, Personal Data Breach — as defined in Applicable Data Protection Law.
- Sub-processor — a third party engaged by us to process Customer Personal Data.
3. Roles of the parties
For Customer Personal Data, you are the Controller and we are the Processor. You decide what personal data goes into the Service and why; we act only on your instructions.
For Account Data — the information we hold about you as our customer — we are an independent Controller, and our Privacy Notice governs that, not this DPA.
We will not sell Customer Personal Data, use it for our own purposes, use it for advertising, or use it to train machine-learning models.
4. Your obligations
You warrant and undertake that:
- you have a lawful basis for the personal data you put into the Service, and where consent is that basis, you have obtained it;
- you have given the required privacy information to the individuals concerned — your subcontractors' staff, your own employees, signatories on your contracts;
- your instructions to us will not put us in breach of Applicable Data Protection Law;
- you will not deliberately configure the Service to process Sensitive Data as a primary function, and you will tell us in advance if you intend to process it at scale so that we can agree additional measures.
Being realistic about Sensitive Data. Saudi construction subcontract and mobilisation packs routinely carry Iqama and national ID copies, passport copies and medical fitness certificates. Some of that is Sensitive Data under the PDPL, and it will end up in uploaded documents whatever any contract says. So we do not pretend a blanket prohibition solves it: you remain the Controller of that data, and we apply the measures in Annex II to all Customer Personal Data including any Sensitive Data incidentally present.
You are responsible for configuring roles and permissions appropriately, and for removing access when someone leaves. We provide the controls; the decisions are yours.
5. Our obligations
We will:
- process Customer Personal Data only on your documented instructions, which comprise this DPA, the Terms of Service, and your use of the Service's features;
- process it only to provide, secure and support the Service, and to comply with the law;
- tell you if, in our opinion, an instruction breaches Applicable Data Protection Law — and we may decline to act on it until it is resolved;
- where we are required by law to process beyond your instructions, inform you before doing so unless the law prohibits it;
- implement and maintain the technical and organisational measures in Annex II.
6. Confidentiality of personnel
We limit access to Customer Personal Data to personnel who need it to provide or support the Service. Those individuals are bound by written confidentiality obligations that survive the end of their engagement, and their access is granted on a least-privilege basis and removed when no longer required.
7. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The measures in place are set out in Annex II.
We may update those measures as the Service evolves, provided we do not materially reduce the overall level of security.
8. Sub-processors
You give us general authorisation to engage sub-processors, subject to this clause.
- The current list is published at /legal/subprocessors/ and forms part of this DPA.
- Before adding or replacing a sub-processor, we will give you at least 30 days' notice by email to your workspace administrators and by updating that page.
- You may object on reasonable data-protection grounds within those 30 days. We will not transfer your Customer Personal Data to an objected sub-processor while your objection is unresolved. If that is not technically possible we will tell you, and you may terminate immediately with a pro-rata refund of prepaid fees.
- We will work with you in good faith to find an alternative. If there is not one, you may terminate the affected subscription without penalty and receive a pro-rata refund for the unused period. Be aware that where the objection concerns our core infrastructure provider, the only remedy available is termination of the whole subscription — we are not going to imply otherwise.
- We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
9. Cross-border transfers
Customer Personal Data is currently processed in the AWS US East (N. Virginia) region, in the United States, and transactional email is sent from the same region. This is a transfer outside the Kingdom of Saudi Arabia, and you should treat it as a material fact when assessing whether the hosted Service is appropriate for your data.
A transfer of this kind requires a recognised basis under Applicable Data Protection Law — an adequacy determination covering the destination, or an approved safeguard such as the standard contractual clauses issued by SDAIA — plus a documented transfer risk assessment.
That mechanism is not yet in place. We have not executed SDAIA standard contractual clauses with our hosting provider and we have not completed a transfer risk assessment. We will not describe this as done before it is, and you should factor that into your own assessment as Controller.
You instruct us to transfer Customer Personal Data outside the Kingdom as described in Annex I. As Controller, you remain responsible for satisfying yourself that the transfer meets the conditions applicable to you, and we will provide the information you reasonably need to do so.
If your obligations require Customer Personal Data to remain within the Kingdom, the hosted Service in its current configuration is not suitable, and a self-hosted deployment on your own infrastructure is the correct route. Raise this with us before you subscribe.
9A. Government and law enforcement access
Hosting in the United States means our provider is subject to United States legal process. This clause says what we do about that.
If we receive a legally binding request from a public authority for Customer Personal Data, we will:
- notify you before disclosing, and where we are legally prohibited from notifying you, use reasonable efforts to obtain a waiver of that prohibition and tell you as soon as we lawfully can;
- review the request's legality and challenge it where there are reasonable grounds to consider it unlawful or overbroad, including seeking measures to suspend its effect;
- disclose only the minimum data responsive to the request;
- keep a record of each request and make that record available to you.
As at the effective date of this DPA we have received no such request. We will keep that statement accurate.
10. Assisting you
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures with:
- Data subject requests. The Service's own export and deletion tools let you satisfy most requests yourself, without contacting us. If you receive a request you cannot fulfil through the product, we will help. If a data subject contacts us directly about your Customer Personal Data, we will not respond substantively — we will refer them to you and tell you promptly.
- Security, breach notification and impact assessments, and any prior consultation with a supervisory authority, so far as the information is available to us.
Assistance is provided at no additional charge for reasonable volumes. If requests become excessive or repetitive we may charge our reasonable costs, having told you first.
11. Personal data breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event in time to allow you to meet your own notification deadlines — which, under the current Saudi rules, means notifying the competent authority within 72 hours of becoming aware.
Our notification will include, to the extent known and as it becomes known:
- the nature of the breach, including the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address it and mitigate its effects;
- a contact point for more information.
We will not delay an initial notification in order to complete our investigation. Notifying you is not an admission of fault by either party.
12. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you appoint.
In practice, we expect to satisfy this by answering a security questionnaire and providing documentation. An on-site or systems audit may be requested no more than once in any twelve months (or after a Personal Data Breach), on at least 30 days' notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or the security of other customers. You bear your own costs; we bear ours unless the audit reveals a material breach by us.
We hold no third-party certification. We cannot offer an ISO 27001 certificate or a SOC 2 report in place of an audit, because we do not have one. We say so here rather than let it surface during your due diligence.
13. Return and deletion
You may export Customer Data yourself at any time during the subscription, in open formats, without asking us.
On termination, and at your choice, we will return or delete Customer Personal Data. Deletion is initiated as a 30-day recoverable suspension (60 days where a subscription has lapsed through non-payment), during which you may still request an export or a restore, after which the workspace site is torn down.
Three things survive that, and we would rather you knew now than found out at audit:
- The torn-down site is archived rather than erased; reclaiming that storage is a separate operator step.
- Billing and tax records are retained for the statutory period, attached to an anonymised account record.
- A reduced operational audit record is retained. It is pseudonymised, not anonymised — the actor reference is cleared but the action, target reference and timestamp remain.
Anything retained remains subject to the confidentiality and security obligations of this DPA for as long as we hold it. If your own retention policy cannot accommodate the archive step, raise it with us before you subscribe.
Backups are rolling and are overwritten in the ordinary course; deletion runs against live systems immediately and works through backups as they cycle.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Applicable Data Protection Law does not permit that.
15. Term
This DPA takes effect when you begin using the Service and continues until we have deleted or returned all Customer Personal Data in accordance with clause 13. Clauses that by their nature should survive, do.
Annex I — Details of processing
| Subject matter | Provision of the ProjectFlow hosted commercial-control service. |
|---|---|
| Duration | The term of the subscription, plus the deletion period in clause 13. |
| Nature and purpose | Hosting, storage, retrieval, structuring, computation, transmission, backup and deletion of Customer Data, so as to provide the Service, support it, and keep it secure. |
| Frequency | Continuous, for the duration of the subscription. |
| Categories of data subject | Your employees and contractors who use the Service; individuals named in your commercial documents — subcontractor and supplier contacts, site personnel, contract signatories, approvers, tender respondents and vendor representatives. |
| Categories of personal data | Names; business contact details (email, telephone); job title and role; employer or company; user account identifiers and authentication metadata; actions recorded in the audit log with timestamps; and any personal data you choose to include in project documents, correspondence, tenders or uploaded files. |
| Special-category data | Not intended, but may be incidentally present in uploaded documents — identity documents and medical fitness certificates are common in construction mobilisation packs. See clause 4. |
| Retention | Customer Data: the subscription term plus the deletion window in clause 13. Billing and tax records: the statutory period. Audit records: as stated in the Privacy Notice. |
| Controller | The customer identified in the account. |
| Processor | SMR Future Technologies, established in India. Registered address and registration details on request. |
| Sub-processors | As published at /legal/subprocessors/. |
| Processing location | United States — AWS US East (N. Virginia), where the platform runs. India — where our own personnel are located and from where they administer and support the Service. Both are transfers outside the Kingdom; see clause 9. |
Annex II — Security measures
These are the measures actually in place. We have deliberately not listed controls we do not operate.
| Encryption in transit | TLS on every public endpoint. Plain HTTP answers only with a redirect to HTTPS; HSTS is set at the edge. |
|---|---|
| Encryption at rest | Server-side encryption on stored data and backups. |
| Access control | Role-based permissions enforced server-side, never in the browser. Where a caller may not read a figure, the interface shows it as unavailable rather than as a zero. |
| Authentication | Passwords stored as salted hashes with a minimum strength policy. Optional two-factor authentication with recovery codes. Session and recovery tokens stored hashed. |
| Tenant isolation | Each customer is provisioned as a separate tenant with its own data store. |
| Rate limiting | Applied to authentication and one-time-password endpoints, keyed on the true client address, to bound credential and OTP brute-forcing. |
| Administrative access | Least privilege, no shared accounts, no inbound remote-shell port. Sensitive tenant operations such as purge require a second approver. |
| Logging and traceability | Operational audit log recording action, actor, target and timestamp, retained independently of the record it describes. |
| Secrets management | Credentials held in a managed parameter store, never in source control. Automated secret scanning in the development pipeline. |
| Backups and resilience | Automated snapshots on a defined retention schedule, encrypted at rest. |
| Secure development | Peer review before merge, automated type checking, linting and test suites, and dependency management as part of the build. |
| Deletion | 30-day recoverable suspension (60 days on the non-payment path), then teardown of the tenant site, anonymisation of the account record, and retention of tax records as required by law. See clause 13 — the archive step means teardown is not immediate erasure. |
Contact
Data protection matters, and anything arising under this DPA — assistance with a data subject request, a breach notification, a sub-processor objection, an audit request or a signed counterpart — go to info@smrfuturetechnologies.com.
Please give us an equivalent contact on your side. If you have not, notices under this DPA go to your workspace administrators.
Related documents: Terms of Service · Privacy Notice · Sub-processors