Legal document

Data Processing Agreement

Tareeq Technologies Ltd  ·  Effective: 1 May 2025  ·  Version 1.0  ·  Incorporates UK GDPR SCCs and Saudi PDPL obligations

For enterprise customers: This standard DPA is incorporated by reference into your subscription agreement. If your organisation requires a countersigned DPA, contact [email protected] and we will provide an executable version within 5 business days.

1 Parties and definitions

This Data Processing Agreement ("DPA") is entered into between:

Data Controller ("Customer")
Your organisation
The entity that has accepted Tareeq's Terms of Service and is responsible for the personal data processed through the Tareeq platform.
Data Processor ("Tareeq")
Tareeq Technologies Ltd
Registered in England and Wales. Processes personal data on behalf of the Customer to deliver the DNS filtering service.

In this DPA:

2 Subject matter and nature of processing

FieldDetail
Subject matterDNS query filtering, threat detection, and network security analytics
DurationFor the term of the Customer's subscription, plus any legally required retention period
NatureCollection, storage, analysis, automated decision-making (blocking/allowing), deletion
PurposeProviding DNS filtering, security threat detection, and dashboard analytics to the Customer
Data subjectsEmployees, contractors, and network users of the Customer whose devices use the Tareeq resolver
Personal data typesDNS query logs (domain, verdict, timestamp, masked IP), account email addresses, session identifiers

3 Tareeq's obligations as processor

Tareeq shall, with respect to any Personal Data processed on the Customer's behalf:

3.1 — Instructions
Process Personal Data only on documented instructions from the Customer, including those set out in this DPA, unless required to do so by applicable law. Tareeq shall inform the Customer if, in its opinion, an instruction infringes applicable data protection legislation.
3.2 — Confidentiality
Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 — Security
Implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include: TLS 1.2+ encryption in transit, encryption at rest, access controls, and regular security reviews. See Section 8 of our Privacy Policy for full details.
3.4 — Sub-processors
Not engage any sub-processor without prior specific or general written authorisation of the Customer. Tareeq's current sub-processors are listed at privacy.html §5. Tareeq shall give the Customer at least 14 days' written notice of any intended addition or replacement of sub-processors, during which the Customer may reasonably object.
3.5 — Data subject rights
Assist the Customer in fulfilling its obligations to respond to data subject requests (access, rectification, erasure, portability, restriction, objection) within 5 business days of receiving a written request from the Customer.
3.6 — Security assistance
Assist the Customer in ensuring compliance with security obligations, impact assessments, and prior consultation requirements, taking into account the nature of processing and information available to Tareeq.
3.7 — Deletion on termination
At the Customer's choice, delete or return all Personal Data to the Customer after the end of the provision of services, and delete existing copies unless applicable law requires their storage. Data export is available via the dashboard (JSON/CSV) or by request to [email protected].
3.8 — Audit
Make available to the Customer all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Given Tareeq's small scale, such audits shall be conducted with reasonable notice (minimum 30 days), at the Customer's expense, and no more than once per year unless a security incident has occurred.

4 Customer's obligations as controller

The Customer represents and warrants that:

5 International transfers

Tareeq's standard infrastructure is located in Singapore (Railway, asia-southeast1). Where this constitutes a transfer of Personal Data from the UK or EEA to a third country, Tareeq relies on:

These clauses are incorporated by reference into this DPA and available on request.

GCC/KSA data residency: Enterprise customers requiring Personal Data to remain in the GCC region may request a dedicated deployment on AWS Bahrain (me-south-1). Contact [email protected] to discuss. Additional fees may apply.

6 Security incidents and breach notification

In the event of a Personal Data breach, Tareeq shall:

Breach notifications should be sent to the Customer's account email. Customers may report suspected incidents to [email protected].

7 Term and termination

This DPA enters into force on the date the Customer accepts Tareeq's Terms of Service and remains in effect for the duration of the subscription. On termination:

8 Liability and governing law

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Tareeq Terms of Service. This DPA shall be governed by and construed in accordance with the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

For customers in KSA, this DPA additionally incorporates the obligations of the Saudi Personal Data Protection Law (PDPL) and its implementing regulations as amended from time to time.

Request a countersigned DPA

This standard DPA is incorporated into your subscription agreement at the point of account creation. If your procurement or legal team requires a physically or digitally countersigned version, contact us:

[email protected] — please include your organisation name and company registration number. We will respond within 5 business days.

Processor
Tareeq Technologies Ltd
Registered in England and Wales
Email: [email protected]
Controller
Your Organisation
Accepted at account creation by checking "I agree to the Privacy Policy and DPA" during sign-up.