Legal centre

All the agreements and policies governing your use of the Wthaiq platform, in one organised place.

All documents are governed by the laws of the Arab Republic of Egypt · Effective date: 1 June 2026

Data processing agreement (DPA)

Print / PDF
Note: This English text is provided for convenience only. The Arabic version is the authoritative and binding text; in the event of any discrepancy or conflict of interpretation, the Arabic text prevails.
Issue date: 1 June 2026Date of entry into force and effect: 1 June 2026Last updated: 1 June 2026

Last updated: 1 June 2026

Effective date: 1 June 2026

Chapter One: General Provisions

1. Introduction

This Data Processing Agreement (the "Agreement" or the "DPA") forms an integral part of the Terms and Conditions of Use, the User Agreement and any services agreement concluded between Wthaiq (the "Processor") and the Customer (the "Controller") where Wthaiq processes personal data on behalf of the Customer.

The purpose of this Agreement is to regulate the processing of personal data in accordance with the applicable laws and regulations, including, where applicable, the General Data Protection Regulation (GDPR), the Saudi Personal Data Protection Law (PDPL), the Emirati legislation relating to data protection, and any other applicable laws.

2. Scope of Application

This Agreement applies where Wthaiq processes personal data on behalf of the Customer in the course of providing the services, whether the processing is carried out directly or through approved sub-processors.

3. Definitions

For the purposes of this Agreement, the following terms shall have the meanings set out against each of them:

  • Controller: the person or entity that determines the purposes and means of the processing of personal data.
  • Processor: Wthaiq, when it processes personal data on behalf of the Controller.

Processing: any operation carried out on personal data, whether by automated or non-automated means, such as collection, recording, organisation, storage, use, transfer or erasure.

Personal data: any information relating to an identified or identifiable natural person, in accordance with the applicable law.

Sub-Processor: any third party engaged by Wthaiq to process personal data on behalf of the Customer.

Personal data breach: any incident leading to the destruction, loss, alteration or disclosure of personal data, or to unauthorised access to it.

4. Priority of the Agreement

If a conflict exists between this Agreement and any other document governing the processing of data, priority shall be given to this Agreement in relation to the processing of personal data, unless the law requires otherwise.


Chapter Two: The Subject Matter of the Processing

5. Subject Matter of the Processing

Wthaiq processes personal data on behalf of the Customer for the purpose of providing the digital services requested by the Customer, including the creation of documents, their management, electronic signature, the retention of records, and any other services provided by the system.

6. Duration of the Processing

The processing of the data continues throughout the period during which the services are provided, or throughout any additional period required by the laws, the contractual obligations or the data retention policies.

7. Nature of the Processing

The processing may include, depending on the service used:

  • Collecting the data.
  • Organising it.
  • Storing it.
  • Displaying it.
  • Amending it.
  • Transmitting it.
  • Signing it electronically.
  • Archiving it.
  • Erasing it.
  • Any other operations necessary for the provision of the services.

8. Categories of Data

The personal data processed may include, depending on the nature of the Customer's use:

  • Identity data.
  • Contact data.
  • Account data.
  • Document data.
  • Electronic signature data.
  • Usage data.
  • IP addresses.
  • Activity logs.
  • Any other data which the Customer chooses to enter into the Platform.

Chapter Three: The Customer's Instructions

9. Processing in Accordance with the Instructions

Wthaiq processes personal data solely on the basis of the documented instructions issued by the Customer, unless the law requires otherwise of it.

In that case, Wthaiq shall, if the law so permits, inform the Customer before carrying out the processing.

10. Responsibility for the Instructions

The Customer acknowledges that it is responsible for:

  • The lawfulness of the data it provides.
  • The existence of a legal basis for processing the data.
  • The correctness of the instructions issued to Wthaiq.
  • Compliance with the applicable laws.

Wthaiq bears no responsibility for any unlawful instructions, or instructions contrary to the law, issued by the Customer.

11. Instructions Contrary to the Law

If Wthaiq reasonably considers that one of the Customer's instructions may contravene an applicable law, it may notify the Customer and request clarifications, or suspend the implementation of those instructions until the issue is resolved, without this constituting a breach of its contractual obligations.

12. Limits of Wthaiq's Role

Wthaiq, in its capacity as data processor, does not determine the purposes or means of the processing of the Customer's data except within the limits imposed by the nature of the service, the law or the documented instructions issued by the Customer.

Chapter Four: Wthaiq's Obligations as Data Processor

13. Confidentiality Obligation

Wthaiq undertakes to ensure that the persons authorised to process personal data:

  • Are subject to an appropriate obligation of confidentiality.
  • Or are legally bound to preserve the confidentiality of the data.
  • Obtain only the permissions necessary to perform their duties.
  • Comply with the information security policies in force.

14. Security Measures

Wthaiq undertakes to implement reasonable and appropriate technical and organisational measures, proportionate to the nature of the data and the risks associated with its processing, with the aim of protecting personal data from:

  • Unauthorised access.
  • Loss.
  • Destruction.
  • Unlawful alteration.
  • Unauthorised disclosure.
  • Any unlawful processing.

These measures may include, depending on the nature of the service:

  • Encryption where appropriate.
  • Control of access permissions.
  • Logging and monitoring.
  • Backups.
  • Business continuity plans.
  • Cybersecurity measures.

15. Restriction of Access

Access to personal data is confined to the persons who need it in order to perform their functions or to provide the services, and to the minimum permissions necessary.

16. Use of the Data

Wthaiq does not use personal data for any purpose falling outside:

  • Carrying out the Customer's instructions.
  • Providing the agreed services.
  • Complying with the applicable laws.
  • Protecting the security of the Platform or defending legal rights, to the extent permitted by law.

Chapter Five: Sub-Processors

17. Engagement of Sub-Processors

Wthaiq may engage sub-processors to provide certain services, such as:

  • Cloud hosting.
  • Email services.
  • Backup services.
  • Monitoring and security services.
  • Payment processing services.
  • Technical support services.
  • Google Drive (Google LLC) — for retaining an archival copy of the content of the documents generated on the Platform.
  • Didit — for identity verification upon request, including the processing of images of official documents and face-matching data (biometric data).
  • Any other technical services necessary for the operation of the Platform.

In particular: (a) Wthaiq uses the Google Drive service (Google LLC) to retain an archival copy of the content of the documents which the Customer creates on the Platform, within a limited access scope (drive.file) inside the Google Drive account of the Platform's operator. (b) Wthaiq uses the Didit service for identity verification, and this takes place only where the sender or the signatory requests the activation of an identity confirmation step on a particular document or signature; this includes the processing of an image of the official document (identity card/passport) and face-matching data (biometric data) for the purpose of verifying the identity of the signatory exclusively. The result of this verification is retained linked to the signature record and the document concerned, and is subject to the same retention period applied to the audit log and to signed contracts.

18. Responsibility for Sub-Processors

When engaging a sub-processor, Wthaiq undertakes to conclude appropriate contractual arrangements imposing on that processor data protection obligations which are, in substance, no less than the obligations set out in this Agreement, and that to the extent required by law.

19. Change of Sub-Processors

Wthaiq may add, replace or remove any sub-processor where operational, technical, security or commercial necessity so requires.

Where appropriate, customers shall be notified, or an updated list of sub-processors shall be published, in accordance with what the applicable laws or agreements provide.

20. Responsibility for External Services

Wthaiq bears no responsibility for the independent acts or failures of external service providers outside the scope of its reasonable control, without prejudice to any responsibility imposed on it by law in its capacity as data processor.


Chapter Six: Rights of Data Subjects

21. Assistance with Data Subject Requests

Wthaiq shall provide, to the extent permitted by the nature of the service and in a manner consistent with the law, reasonable assistance to the Customer in responding to data subjects' requests relating to their rights, such as:

  • The right of access.
  • The right to rectification.
  • The right to erasure.
  • The right to restriction of processing.
  • The right to data portability.
  • The right to object, where applicable.

22. Direct Requests

If Wthaiq receives a direct request from a data subject relating to data processed by the Customer in its capacity as controller, it may:

  • Refer the requester to the Customer.
  • Notify the Customer of the request, where that is legally permissible.
  • Refrain from responding to the request directly unless the law requires it to do so.

23. Cooperation

The two parties shall cooperate, each within the limits of its role and responsibilities, in order to carry out the obligations relating to data subjects' rights and to comply with the applicable laws.

24. Limits of the Assistance

Wthaiq provides assistance to the extent that is technically possible and commercially reasonable, and is not obliged to take measures that go beyond the nature of the agreed services or that the law imposes on the controller alone.

Chapter Seven: Personal Data Breaches

25. Notification of a Data Breach

If Wthaiq becomes aware of the occurrence of a personal data breach affecting the data which it processes on behalf of the Customer, it shall exert reasonable efforts to notify the Customer without undue delay, to the extent permitted by law.

This notification shall not be deemed an admission of liability, of fault or of contractual breach.

26. Content of the Notification

Where possible, the notification shall include information such as:

  • The nature of the incident.
  • The categories of data affected.
  • The measures which Wthaiq has taken or intends to take.
  • The available information that assists the Customer in fulfilling its legal obligations.
  • The information may be completed in stages if not all the details are available at the time of the notification.

27. Cooperation in Handling the Incident

Wthaiq shall cooperate, to the extent reasonable and proportionate to the nature of the service, with the Customer in investigating the data breach and limiting its effects, without prejudice to confidentiality obligations or to the rights of other parties.


Chapter Eight: International Data Transfers

28. International Transfer

Wthaiq or its service providers may process or store personal data in different countries where this is necessary for the provision of the services.

Any transfer of data shall be carried out in accordance with the applicable laws, and using the appropriate legal safeguards where required.

29. Safeguards

Where the law requires the provision of specific safeguards for cross-border data transfers, Wthaiq may rely on the means permitted by law, including by way of example:

  • Standard Contractual Clauses (SCCs).
  • Adequacy decisions, where available.
  • Any other approved legal mechanisms.

30. Processing Locations

Wthaiq may change the locations of data processing or hosting where operational, security or commercial necessity so requires, provided that compliance with the applicable legal requirements continues.


Chapter Nine: Termination of the Services

31. Return or Erasure of the Data

Upon termination of the services, and based on the Customer's instructions or in accordance with what the service allows, Wthaiq shall, to the extent permitted by law, do the following:

  • Return the data to the Customer, if the service supports that.
  • Erase the data.
  • Or continue to retain it if the law requires or permits that.
  • This is also subject to the Data Retention Policy and the Data Deletion Policy.

32. Legal Retention

If the retention of certain data is required under a law, a judicial order or a regulatory obligation, Wthaiq may retain it throughout the period necessary for that purpose, while continuing to apply the appropriate security measures.


Chapter Ten: Audit and Compliance

33. Information Relating to Compliance

Wthaiq may provide the Customer with the reasonable information which demonstrates its compliance with its obligations under this Agreement, to the extent that this does not result in a breach of the confidentiality of information, the security of its services or the rights of other customers.

34. Audits

If the law or the agreement concluded with the Customer grants a right of audit, any audit shall be carried out:

  • After reasonable prior notice.
  • During normal business hours.
  • In a manner that does not disrupt the operation of Wthaiq's services.
  • In compliance with the confidentiality of information.
  • And in a manner consistent with the security procedures in force.

Wthaiq may confine itself to providing independent audit reports or compliance certificates where these reasonably achieve the required purpose.


Chapter Eleven: General Provisions

35. Amendment of the Agreement

Wthaiq may amend this Agreement where that is necessary in order to comply with the laws, to improve the services or to keep pace with regulatory requirements.

The amendments enter into force from the date of their publication or from the date specified in them, as permitted by law.

36. Final Acknowledgement

The Customer acknowledges that it has read the Data Processing Agreement, has understood the roles and responsibilities prescribed for each of the controller and the processor, and agrees to be bound by its provisions when using Wthaiq's services which involve the processing of personal data on its behalf.


Governing Law and Jurisdiction

This document is governed by and shall be construed in accordance with the laws of the Arab Republic of Egypt, and the competent Egyptian courts shall have jurisdiction to determine any dispute arising out of or relating to it, and any arbitration — if agreed upon by the two parties — shall be conducted within the Arab Republic of Egypt and in accordance with its laws, without prejudice to any mandatory rights conferred on the User under the applicable laws of his country of residence.