Data Processing Agreement
Our Article 28-style processing terms, in force automatically when you process personal data on Sahabti.
Data Processing Agreement
Effective: 21 August 2026
This Data Processing Agreement ("DPA") applies whenever you use Sahabti to process personal data for which you are the controller — for example, the users of an application you host on an instance. It forms part of the Terms of Service and takes effect when you accept them. No signature is needed; a countersigned copy is available on request from [email protected].
In this DPA you are the Controller and Sahabti is the Processor. Terms such as "personal data", "processing", "data subject" and "supervisory authority" carry the meaning given in Jordan's Personal Data Protection Law No. 24 of 2023 and, where it applies to you, the GDPR.
1. Subject matter and duration
We process personal data on your behalf only to provide the Service described in the Terms, for as long as your account exists, plus the deletion window in Deletion and return below.
2. Roles and instructions
We process personal data only on your documented instructions. Using the Service — creating instances, running workloads, configuring backups — is your instruction. We will also process where the law requires it; if that happens we will tell you first, unless the law forbids us from telling you.
We are the controller, not your processor, for the account data described in the Privacy Policy — the identity and billing relationship between you and us. This DPA does not cover that.
If we believe an instruction breaches the Personal Data Protection Law or the GDPR, we will say so.
3. Nature of the processing
Storage, hosting, transmission, backup, and the compute you run. We do not read, analyse, index or mine the contents of your instances, and we do not use them to train models.
4. Categories of data and data subjects
You decide these. Typically: your own end users, employees or customers, and whatever personal data your application stores — commonly identifiers, contact details, authentication data and usage records. Do not place special-category data on the Service without telling us first, so we can confirm the platform meets the additional controls you need.
5. Confidentiality
Everyone we authorise to process personal data is bound by confidentiality obligations that survive the end of their engagement, and is granted only the access their role requires.
6. Security measures
We maintain the technical and organisational measures described on the Security page, which include at minimum:
- TLS 1.2 or higher for all public traffic, with HTTP redirected to HTTPS and HSTS enforced.
- Per-tenant network isolation, so one tenant's instances cannot reach another's private network.
- Staff access over a private path, limited to the people who operate the platform, with an audit trail of actions taken from the operator console.
- Credentials stored as hashes; API tokens shown once and never recoverable from us.
- Rate limiting on authentication endpoints, and quota and bandwidth limits per plan.
- Customer-initiated backups and snapshots, deleted with the resource they belong to.
We may change these measures, but not in a way that materially reduces the level of protection.
7. Subprocessors
You give general authorisation for the subprocessors listed in the Privacy Policy. We will publish notice at least 30 days before adding a new one. If you object on reasonable data-protection grounds within those 30 days, we will work with you on an alternative; if there is none, you may terminate the affected part of the Service without penalty.
Each subprocessor is bound by written terms no less protective than this DPA, and we remain liable to you for their performance.
8. Data subject requests
If a data subject contacts us directly about data you control, we will not respond substantively — we will refer them to you and let you know. Where you cannot resolve a request through the Service yourself, we will give you reasonable assistance without undue delay.
9. Deletion and return
You can export or delete data yourself at any time through the Service. On termination, we remove personal data processed on your behalf from live systems within 30 days, and copies held in backups go as those backups are rotated or overwritten, except where the law requires us to keep it.
10. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you. The notice will describe what we know at the time: the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken. We will assist you in meeting your own notification duties.
11. Audits and assistance
On request, and no more than once a year (or after a breach affecting you), we will provide the information reasonably needed to demonstrate compliance with this DPA, and answer a security questionnaire. Where that is not enough for your regulator, we will agree a scope for an audit at your cost, conducted with reasonable notice and without disrupting other tenants.
We will assist you with data protection impact assessments and prior consultations, taking into account the information available to us.
12. International transfers
See International transfers in the Privacy Policy. Where a transfer of personal data outside your jurisdiction is required, we rely on Standard Contractual Clauses or an equivalent approved mechanism, which are incorporated into this DPA by reference for those transfers.
13. Precedence
Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.
14. Contact
Data protection questions: [email protected]. Contractual questions: [email protected].