workspace_premiumCertifada
ProductHow it worksPricingFAQ
Sign inGet started arrow_forward
description Legal & Regulatory v2.0

Data Processing Agreement (DPA)

Standard Data Processing Terms for enterprise customers processing personal data under GDPR Article 28 and UAE PDPL.

event Effective Date: 2026-01-01gavel UAE / ADGM / DIFC & Global Standards
Legal AgreementsshieldPrivacy PolicygavelTerms of ServicecookieCookie PolicydescriptionData Processing AgreementreportAcceptable Use Policy
Trust & SecuritylockSecurity OverviewverifiedTrust Centerverified_userCompliance & GovernancehubSubprocessors Listbug_reportResponsible DisclosureaccessibilityAccessibility Statement
Enterprise ProcurementspeedService Level Agreementreceipt_longRefund & Billing PolicyapiAPI Terms of Usecontact_supportContact & Support
toc On This Page:
1. Scope & Definitions2. Processor Obligations3. Standard Contractual Clauses (SCCs)4. Authorized Subprocessors5. Security Audits & Compliance Documentation

# 1. Scope & Definitions

This DPA applies to all processing of personal data conducted by Certifada ('Processor') on behalf of Customer ('Controller') in connection with credential issuance services.

# 2. Processor Obligations

Processor agrees to process personal data strictly in accordance with Controller documented instructions, implement AES-256 technical and organizational security measures, and ensure personnel confidentiality commitments.

# 3. Standard Contractual Clauses (SCCs)

Where personal data is transferred outside the EEA or UAE to countries without an adequacy decision, the EU Standard Contractual Clauses (Module 2 Controller-to-Processor) are hereby incorporated by reference.

# 4. Authorized Subprocessors

Controller grants general authorization to Processor to engage infrastructure subprocessors listed on our Subprocessors Page. Processor will provide 14 days notice prior to adding new subprocessors.

# 5. Security Audits & Compliance Documentation

Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with GDPR Article 28 and UAE PDPL requirements, including ISO/SOC audit summaries upon request.

verified_user

Have questions about our legal policies or need custom enterprise terms?

Our legal and security team is available to assist enterprise procurement teams with custom DPA execution, data residency compliance, or SLA addendums.

mail Contact Legal Teamdescription Request Custom DPA
workspace_premiumCertifada

The certificate lifecycle platform. Design, issue, deliver and verify digital credentials your recipients can trust — at any scale.

gavel UAE PDPL & EU GDPRverified_user ISO & SOC2 Ready

Product

ProductHow it worksPricingRecipient Wallet

Trust & Security

Security OverviewTrust CenterCompliance & StandardsSubprocessorsResponsible Disclosure

Legal & Privacy

Privacy PolicyTerms of ServiceCookie PolicyData Processing (DPA)Acceptable Use PolicyCookie settings

Enterprise & SLA

Enterprise SLAAPI Terms of UseAccessibility StatementRefund & Billing PolicyContact & Legal Support
© 2026 Certifada — All rights reserved.•UAE & Global Enterprise Infrastructure
Powered by CuspForge Technologies L.L.C
cookie
We use analytics cookies

Certifada needs a few essentials to work. We'd also like to measure how the site is used so we can improve it. Analytics only runs if you say yes. Read our cookie policy