Certifada
ProductHow it worksPricingBlogHelpFAQ
Sign inGet startedarrow_forward
Productarrow_outwardHow it worksarrow_outwardPricingarrow_outwardBlogarrow_outwardHelparrow_outwardFAQarrow_outward
Sign inGet started arrow_forward
description Legal & Regulatory v2.1

Data Processing Agreement (DPA)

Standard Data Processing Terms for enterprise customers processing personal data under GDPR Article 28 and UAE PDPL.

event Last updated: 2026-09-13gavel Sharjah Media City, Sharjah, United Arab Emirates
Legal AgreementsshieldPrivacy PolicygavelTerms of ServicecookieCookie PolicydescriptionData Processing AgreementreportAcceptable Use Policy
Trust & SecuritylockSecurity OverviewverifiedTrust Centerverified_userCompliance & GovernancehubSubprocessors Listbug_reportResponsible DisclosureaccessibilityAccessibility Statement
Enterprise ProcurementspeedService Level Agreementreceipt_longRefund & Billing PolicyapiAPI Terms of Usecontact_supportContact & Support
toc On This Page:
1. Scope & Definitions2. Processor Obligations3. Standard Contractual Clauses (SCCs)4. Authorized Subprocessors5. Security Audits & Compliance Documentation

# 1. Scope & Definitions

These processing terms apply where Certifada processes recipient and workspace data for the customer. The customer determines the purpose, recipients, fields, and publication settings. Processing covers storage, issuance, delivery, verification, support, and deletion for the service duration and applicable retention period. Data may include names, contact details, credential content, and activity records relating to recipients and authorized users. A signed DPA and its completed schedules take precedence for their subject matter.

# 2. Processor Obligations

We process customer data on documented instructions, subject to law, and require confidentiality and appropriate security. We assist with rights requests, breaches, and legally required assessments. We notify customers of a personal-data breach without undue delay after awareness. At the end of processing, we return or delete data as instructed unless law requires retention. Instructions that appear unlawful will be raised with the customer.

# 3. Standard Contractual Clauses (SCCs)

Where required, the parties must document the applicable transfer mechanism, parties, processing details, and safeguards before a restricted transfer. A reference to EU Standard Contractual Clauses alone does not complete their annexes or resolve UAE or other local transfer requirements. Contact hello@cuspforge.com to arrange the appropriate documentation.

# 4. Authorized Subprocessors

The provider list identifies services used for customer processing and optional integrations. For subprocessors we engage on the customer’s behalf, we require appropriate data protection terms and remain responsible for their obligations under the applicable DPA. We provide at least 14 days’ advance notice of intended additions or replacements and an opportunity to raise reasonable data-protection objections. Customer-selected integrations are governed by the customer’s provider arrangements.

# 5. Security Audits & Compliance Documentation

We provide information reasonably needed to demonstrate applicable processor obligations and cooperate with proportionate audits under the DPA, with safeguards for confidentiality, security, and other customers. An audit report or certification is represented as available only when specifically confirmed. Contact hello@cuspforge.com for due-diligence requests.

verified_user

Questions about these policies?

Contact us about privacy, security, billing, or an enterprise agreement.

mail Contact usdescription Data processing terms
Certifada

The certificate lifecycle platform. Design, issue, deliver and verify digital credentials your recipients can trust — at any scale.

gavel Privacy & data protectionverified_user Security information

Product

ProductHow it worksPricingVerify a CredentialRecipient WalletAboutComparisonsBlog

Help

Getting startedDocumentationContact us

Trust & Security

Security OverviewTrust CenterCompliance & StandardsSubprocessorsResponsible Disclosure

Legal & Privacy

Privacy PolicyTerms of ServiceCookie PolicyData Processing (DPA)Acceptable Use PolicyCookie preferences

Enterprise & SLA

Enterprise SLAAPI Terms of UseAccessibility StatementRefund & Billing PolicyContact & Legal Support
© 2026 Certifada — All rights reserved.•Sharjah Media City, Sharjah, United Arab Emirates
Powered by CuspForge Technologies L.L.C