Legal document
Data Processing Agreement
Tareeq Technologies Ltd ·
Effective: 1 May 2025 ·
Version 1.0 ·
Incorporates UK GDPR SCCs and Saudi PDPL obligations
For enterprise customers: This standard DPA is incorporated by reference into your subscription agreement. If your organisation requires a countersigned DPA, contact
[email protected] and we will provide an executable version within 5 business days.
1 Parties and definitions
This Data Processing Agreement ("DPA") is entered into between:
Data Controller ("Customer")
Your organisation
The entity that has accepted Tareeq's Terms of Service and is responsible for the personal data processed through the Tareeq platform.
Data Processor ("Tareeq")
Tareeq Technologies Ltd
Registered in England and Wales. Processes personal data on behalf of the Customer to deliver the DNS filtering service.
In this DPA:
- "Service" means the Tareeq DNS filtering platform including the dashboard, resolver, and agent software.
- "Personal Data" has the meaning given in the UK GDPR / EU GDPR (Article 4(1)).
- "Processing" has the meaning given in UK GDPR Article 4(2).
- "DNS Query Data" means domain names queried, timestamps, verdicts, and masked client IP addresses generated through use of the Service.
- "Sub-processor" means any third party engaged by Tareeq to process Personal Data in connection with the Service.
2 Subject matter and nature of processing
| Field | Detail |
| Subject matter | DNS query filtering, threat detection, and network security analytics |
| Duration | For the term of the Customer's subscription, plus any legally required retention period |
| Nature | Collection, storage, analysis, automated decision-making (blocking/allowing), deletion |
| Purpose | Providing DNS filtering, security threat detection, and dashboard analytics to the Customer |
| Data subjects | Employees, contractors, and network users of the Customer whose devices use the Tareeq resolver |
| Personal data types | DNS query logs (domain, verdict, timestamp, masked IP), account email addresses, session identifiers |
3 Tareeq's obligations as processor
Tareeq shall, with respect to any Personal Data processed on the Customer's behalf:
3.1 — Instructions
Process Personal Data only on documented instructions from the Customer, including those set out in this DPA, unless required to do so by applicable law. Tareeq shall inform the Customer if, in its opinion, an instruction infringes applicable data protection legislation.
3.2 — Confidentiality
Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 — Security
Implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include: TLS 1.2+ encryption in transit, encryption at rest, access controls, and regular security reviews. See Section 8 of our
Privacy Policy for full details.
3.4 — Sub-processors
Not engage any sub-processor without prior specific or general written authorisation of the Customer. Tareeq's current sub-processors are listed at
privacy.html §5. Tareeq shall give the Customer at least
14 days' written notice of any intended addition or replacement of sub-processors, during which the Customer may reasonably object.
3.5 — Data subject rights
Assist the Customer in fulfilling its obligations to respond to data subject requests (access, rectification, erasure, portability, restriction, objection) within
5 business days of receiving a written request from the Customer.
3.6 — Security assistance
Assist the Customer in ensuring compliance with security obligations, impact assessments, and prior consultation requirements, taking into account the nature of processing and information available to Tareeq.
3.7 — Deletion on termination
At the Customer's choice, delete or return all Personal Data to the Customer after the end of the provision of services, and delete existing copies unless applicable law requires their storage. Data export is available via the dashboard (JSON/CSV) or by request to
[email protected].
3.8 — Audit
Make available to the Customer all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Given Tareeq's small scale, such audits shall be conducted with reasonable notice (minimum 30 days), at the Customer's expense, and no more than once per year unless a security incident has occurred.
4 Customer's obligations as controller
The Customer represents and warrants that:
- It has a valid legal basis to process Personal Data through the Service (e.g. legitimate interests for corporate network monitoring, with appropriate staff notice).
- It has provided any required notices to data subjects (employees, network users) about DNS monitoring, in accordance with applicable law.
- It will not use the Service to process Special Category Data (health, biometric, religious or political data) unless expressly agreed in writing.
- It will ensure that any instructions given to Tareeq comply with applicable data protection law.
5 International transfers
Tareeq's standard infrastructure is located in Singapore (Railway, asia-southeast1). Where this constitutes a transfer of Personal Data from the UK or EEA to a third country, Tareeq relies on:
- International Data Transfer Agreements (IDTAs) approved by the ICO for UK transfers; and
- Standard Contractual Clauses (Module 2: Controller to Processor) approved by the European Commission for EEA transfers.
These clauses are incorporated by reference into this DPA and available on request.
GCC/KSA data residency: Enterprise customers requiring Personal Data to remain in the GCC region may request a dedicated deployment on AWS Bahrain (me-south-1). Contact [email protected] to discuss. Additional fees may apply.
6 Security incidents and breach notification
In the event of a Personal Data breach, Tareeq shall:
- Notify the Customer without undue delay and within 48 hours of becoming aware of the breach (to allow the Customer to meet its 72-hour regulatory obligation).
- Provide, as available: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach.
- Cooperate with the Customer and take reasonable steps to mitigate the effects and remediate the breach.
Breach notifications should be sent to the Customer's account email. Customers may report suspected incidents to [email protected].
7 Term and termination
This DPA enters into force on the date the Customer accepts Tareeq's Terms of Service and remains in effect for the duration of the subscription. On termination:
- Tareeq will make Customer data available for export for 30 days following termination.
- After 30 days, all Personal Data will be deleted from Tareeq's systems, except where retention is required by law.
- Billing records are retained for 7 years as required by UK tax law.
8 Liability and governing law
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Tareeq Terms of Service. This DPA shall be governed by and construed in accordance with the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
For customers in KSA, this DPA additionally incorporates the obligations of the Saudi Personal Data Protection Law (PDPL) and its implementing regulations as amended from time to time.
Request a countersigned DPA
This standard DPA is incorporated into your subscription agreement at the point of account creation. If your procurement or legal team requires a physically or digitally countersigned version, contact us:
[email protected] — please include your organisation name and company registration number. We will respond within 5 business days.
Processor
Tareeq Technologies Ltd
Controller
Your Organisation
Accepted at account creation by checking "I agree to the Privacy Policy and DPA" during sign-up.