Data processing agreement.
This Data Processing Agreement ("DPA") forms part of the MIQAS Terms of Service and applies automatically to every customer, without signature, from the moment a workspace is created. It governs how Ensign Establishment for Advertising ("Ensign") processes personal data on your behalf under the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL).
1. Roles
For the personal data of your end customers that you connect to MIQAS (orders, website and app events, delivery-app exports), you are the Controller and Ensign is the Processor: we process that data only on your documented instructions, which are given through your use of the product (connecting a source, enabling a forwarding integration, requesting a report). For your own account data (name, email, billing), Ensign is the Controller as described in the Privacy Policy.
2. Scope of processing
Subject matter: operating the MIQAS analytics and attribution service. Duration: the life of your subscription plus the 30-day recovery window. Nature and purpose: ingestion, storage, aggregation, attribution, reporting, and, at your instruction, forwarding of hashed conversion identifiers to the ad platforms you connect. Data subjects: your end customers. Data categories: order and transaction data, website and app event data, and the contact identifiers your connected systems provide.
3. Your responsibilities as Controller
You warrant that you have a lawful basis under PDPL for the end-customer data you connect to MIQAS, that your own privacy notice covers this processing, and that you will not send sensitive data (health, credit, biometric, or similar) into the platform.
4. Confidentiality and security
We apply the measures described in our PDPL notice: encryption in transit (TLS 1.2+) and at rest (AES-256), database-level workspace isolation (Row Level Security), role-based access, hashed credentials, webhook signature verification, and audited administrative access. Everyone with access to customer data is bound by confidentiality obligations.
5. Sub-processors
You authorize the sub-processors listed in the Privacy Policy (database and authentication hosting, application hosting, transactional email, AI processing under a zero-data-retention configuration, and payment processing). We will update the Privacy Policy before adding a sub-processor; continuing to use the Service after the update constitutes acceptance, and you may terminate under the Terms if you object.
6. Cross-border transfers
Transfers outside the Kingdom occur only as described in the PDPL notice, under the appropriate-safeguards route of PDPL Article 29 (SDAIA Standard Contractual Clauses and processor data processing agreements kept on file).
7. Assistance with data subject rights
If your end customer exercises a PDPL right against you, we assist: workspace data is exportable self-serve, and targeted corrections or deletions can be requested at contact@ensignksa.com; we act within 15 business days of a verified request.
8. Breach notification
If a personal-data breach affects data we process for you, we notify you without undue delay after becoming aware, with enough detail for you to meet your own PDPL notification duties, and we notify SDAIA within 72 hours where the law requires it of us.
9. Deletion and return
On termination, workspace data is retained for 30 days for recovery and then permanently deleted, except where KSA law requires longer retention. You can export a full copy at any time before deletion from Settings → Privacy & your data.
10. Audit
Once per 12 months, on reasonable written notice, you may request a written description of our security measures and sub-processor arrangements sufficient to demonstrate compliance with this DPA.
11. Precedence and contact
If this DPA conflicts with the Terms, this DPA prevails for data protection matters. Questions: contact@ensignksa.com.