Data Processing Agreement

Last updated: 27 August 2026

بِسْمِ اللهِ الرَّحْمٰنِ الرَّحِيْمِ

In the name of God, the Most Gracious, the Most Merciful

1. Introduction

This Data Processing Agreement ("DPA") forms part of, and is governed by, the Terms and Conditions("Agreement") between Mamluk LLC-FZ ("Processor", "we", "us") and the customer ("Controller", "you") for use of the Bahriya cloud platform ("Platform").

It applies where you process personal data through the Platform and are subject to the UAE Federal Decree-Law No. 45/2021 on the Protection of Personal Data ("UAE Data Protection Law"), Regulation (EU) 2016/679 ("GDPR"), or equivalent legislation. Capitalised terms not defined here have the meaning given in the Agreement. In the event of a conflict between this DPA and the Agreement, this DPA prevails in respect of the processing of personal data.

For clarity, and without displacing the definitions in the Agreement:

  • "Customer Data" has the meaning given in clause 2 of the Agreement — namely any data, content, code, container images, secrets, configuration, or materials uploaded, stored, or processed by you through the Platform. This DPA governs only the personal data contained within Customer Data.
  • References to the Controller are references to the Customer under the Agreement, and references to the Processor are references to the Company.

2. Roles of the Parties

You determine the purposes and means of processing personal data contained in Customer Data. We process that personal data only on your behalf, as a processor.

Where we determine the purposes and means of processing ourselves — including account administration, authentication, billing, platform security, and abuse prevention — we act as an independent controller. That processing is governed by our Privacy Policy and not by this DPA.

3. Details of Processing

  • Subject matter: provision of the Platform under the Agreement.
  • Duration: the term of the Agreement, plus the retention period in clause 9.
  • Nature and purpose: hosting, storage, transmission, and compute execution of Customer Data as directed by you through the Platform, its APIs, and its command-line tooling.
  • Types of personal data: determined solely by you. We have no visibility into, or control over, the categories of personal data you choose to deploy.
  • Categories of data subjects: determined solely by you.

3.1 Special Categories of Personal Data

You must not process special categories of personal data through the Platform — including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, data concerning health or sex life, or data relating to criminal convictions and offences — without our prior written agreement. The Platform is general-purpose infrastructure and is not, by default, configured or contracted for the heightened obligations that such data attracts.

4. Processing Instructions

We process personal data only on your documented instructions, including in respect of transfers, unless required to do otherwise by law to which we are subject. Where the law requires it, we will inform you before processing, unless that law prohibits us from doing so.

The Agreement, this DPA, and your configuration and use of the Platform together constitute your complete documented instructions. We will inform you if, in our opinion, an instruction infringes applicable data protection law.

5. Confidentiality

Personnel authorised to process personal data are bound by obligations of confidentiality, are subject to role-based access controls, and access Customer Data only where necessary to operate the Platform, to comply with law, or to respond to a support request you have authorised.

6. Security

We implement appropriate technical and organisational measures, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects. Current measures are set out in Annex II.

You are responsible for configuring your own workloads securely, including your choice of container images, network policies, authentication, and the handling of secrets within your applications.

7. Sub-Processors

You grant us general written authorisation to engage the sub-processors listed in Annex III. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

We will give you at least 14 days' notice before adding or replacing a sub-processor, by email to the Organisation owner or through the Platform. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected service without penalty, and without prejudice to fees already accrued.

8. Personal Data Breach

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known at the time:

  • The nature of the breach, including the categories and approximate number of data subjects and records concerned.
  • The likely consequences of the breach.
  • The measures taken or proposed to address it and to mitigate its effects.

Where the full information is not available at once, we will provide it in phases as it becomes available. We will provide reasonable assistance to help you meet your own notification obligations to a supervisory authority or to data subjects.

9. Deletion and Return

On termination of the Agreement you may export Customer Data through the Platform for a period of 30 days, in accordance with clause 12.4 of the Agreement. After that period we delete Customer Data, save where retention is required by law.

Copies of Customer Data held in operational backups are removed on the ordinary backup rotation cycle. For managed datastore backups this is a rolling window of seven daily snapshots, so backup copies are purged within seven days of deletion.

10. Data Subject Rights

You have direct access to Customer Data through the Platform, its console, and its APIs, and are expected to respond to data subject requests yourself. Taking into account the nature of the processing, we will provide reasonable assistance where you cannot fulfil a request through the Platform's own functionality.

If we receive a request directly from a data subject in respect of Customer Data, we will not respond to it substantively, and will forward it to you without undue delay.

11. Audit and Information

We will make available to you the information necessary to demonstrate compliance with this DPA. Where available, we will satisfy audit requests by providing certifications or a completed security questionnaire.

Where that is not sufficient, you may audit no more than once in any twelve-month period, on at least 30 days' written notice, at your own cost, subject to confidentiality obligations, and provided the audit does not disrupt our operations or compromise the security or confidentiality of other customers' data. We may charge a reasonable fee for assistance that goes materially beyond providing the information described above.

12. International Transfers

Customer Data is processed in the regions you select. The countries in which we operate infrastructure are published at bahriya.cloud/locations.

Where personal data is transferred outside the UAE or the European Economic Area, we ensure appropriate safeguards are in place, including the European Commission's Standard Contractual Clauses where required. Where the Standard Contractual Clauses apply, they are incorporated into this DPA by reference and prevail over any conflicting term.

13. Liability

Liability under this DPA is subject to the limitations and exclusions in clauses 8 and 9 of the Agreement. Nothing in this DPA limits any liability which cannot lawfully be limited, including a data subject's rights to compensation under applicable data protection law.

Annex I — Processing Details

The subject matter, duration, nature, and purpose of processing, together with the types of personal data and categories of data subjects, are as set out in clause 3. Because you control what you deploy, you are responsible for maintaining your own record of the specific categories processed through the Platform.

Annex II — Technical and Organisational Measures

  • Encryption of secrets at rest. Secrets, vault items, and registry credentials are encrypted using AES-256 before they are written to disk, and are never returned in plaintext through the API.
  • Encryption in transit. TLS is used for traffic to the Platform, to the API, and between platform components.
  • Access control. Role-based access control with per-Organisation roles and least-privilege defaults; authentication is delegated to a dedicated identity provider.
  • Network isolation. Workloads are isolated per project, with customer-definable network policies governing permitted traffic.
  • Activity logging. Infrastructure actions, API calls, and login events are logged and retained for security and operational purposes.
  • Segregation. Customer workloads are logically separated from one another and from platform control-plane services.
  • Patching. Platform images and dependencies are updated on a regular cycle, and out of cycle where a vulnerability warrants it.
  • Personnel. Access to production systems is limited to authorised personnel bound by confidentiality obligations.

Annex III — Sub-Processors

Infrastructure providers

These providers supply data centre, compute, storage, and network capacity. They receive no account, profile, or billing data, hold no relationship with individual Bahriya customers, and do not access Customer Data. They are sub-processors because Customer Data is stored on their infrastructure.

  • Hetzner — data centre and infrastructure capacity.
  • Melbicom — data centre and infrastructure capacity.
  • Aruba Cloud — data centre and infrastructure capacity.
  • UpCloud — data centre and infrastructure capacity.

Functional providers

These providers are sent identifiable personal data in order to perform a specific function.

  • Brevo (Sendinblue) and Mailtrap — transactional and broadcast email delivery (name, email address). Both are in active use and a given message may be routed through either.
  • Stripe — payment processing (billing and payment details).

Contact

For questions about this DPA, or to request a signed counterpart, contact us at hello@bahriya.cloud.