DATA PROCESSING AGREEMENT
Between:
NEXORA HUB PORTAL – FZCO (“Controller”)
and
The Service Provider (“Processor”)
1. Purpose
This DPA governs personal data processing performed by Processor on behalf of Controller.
2. Definitions
Controller: entity determining purposes and means.
Processor: entity processing on behalf of Controller.
Personal Data: information relating to identified or identifiable individuals.
Processing: collection, storage, use, disclosure and deletion.
3. Subject Matter
Processor processes personal data only for services provided to TicketGol.
Processing may include:
- hosting;
- support;
- CRM;
- payments;
- analytics;
- communications.
4. Instructions
Processor shall process data only upon documented instructions.
5. Confidentiality
Processor shall ensure confidentiality obligations for personnel.
6. Security Measures
Processor shall implement:
- encryption;
- access controls;
- authentication;
- logging;
- backup systems.
7. Subprocessors
Processor shall not appoint subprocessors without authorization.
Processor remains liable.
8. Assistance
Processor shall assist Controller regarding:
- data requests;
- audits;
- breaches;
- compliance obligations.
9. Data Breaches
Processor shall notify Controller without undue delay after becoming aware of a breach.
Notification shall include:
- nature;
- impact;
- categories affected;
- mitigation measures.
10. Audit Rights
Controller may audit Processor compliance.
11. Return and Deletion
Upon termination Processor shall:
- return data; or
- delete data
12. International Transfers
Transfers outside applicable jurisdictions shall require safeguards.
13. Liability
Parties remain responsible under applicable law.
14. Governing Law
This DPA shall be governed by applicable law specified in the main agreement.
