Skip to content
  • 03Agencies
  • 04Pricing
العربية
Join utajir
utajir/Legal center/Data processing agreement
Version 2026-09-15.2
All documents

06Privacy & data

Data processing agreement

Tajir Global Limited · contact@utajir.com

18 sectionsRelease date: 2026-09-15Archived Arabic and English copy
On this page
  1. Parties, definitions & processing roles
  2. Contract relationship & applicability
  3. Instructions & permitted processing
  4. Customer obligations & authority
  5. Personnel, confidentiality & access
  6. Technical & organizational measures
  7. Subprocessor engagement
  8. Data subject requests
  9. Impact assessments & regulatory cooperation
  10. Personal data breaches & notification
  11. International transfers & overseas access
  12. Data return & deletion
  13. Compliance evidence & audits
  14. Liability & inability to comply
  15. Annex A: processing description
  16. Annex B: security measures schedule
  17. Annex C: subprocessors
  18. Annex D: transfers & regional terms
01

Parties, definitions & processing roles#

1.1Parties and covered data

This DPA is between the Utajir operating company identified in the Terms of Service and the Contracting Customer identified in the Order. Customer Personal Data means personal data we process on its behalf to provide the Services, including data submitted or collected by its authorized users or clients. Processing, processor and controller or data-user terms have the meaning under the relevant data-protection law, without assuming identical roles across laws.

1.2Processor and subprocessor

The customer is controller where it determines purposes, with us as its processor. Where an Agency processes for its client, we are a subprocessor within valid authority and the contract chain. Thrive Connector is the same company's technical name and does not add a party to that chain. Independent relationship-administration data, such as our invoices and legal communications, remains outside processing on behalf and follows the Privacy Policy.

02

Contract relationship & applicability#

2.1Application and duration

This DPA is incorporated into the Service Agreement on acceptance and applies whenever we process personal data on the customer’s behalf to deliver the Service, and afterward as necessary for return, deletion or lawful limited retention. Each party complies with laws applicable to the data, processing and its actual role; mentioning a country does not alone subject every account to its laws.

2.2Precedence and annexes

This DPA prevails over general terms for conflicting data-processing matters, and mandatory terms of an effective transfer instrument prevail within its scope. Annexes A, B, C and D form part of the DPA. Order details, enabled functions and documented instructions specify the customer’s processing scope. Required route details and transfer instruments are completed before a restricted transfer under Annex D; an information link does not execute an unattached instrument.

03

Instructions & permitted processing#

3.1Documented instructions

We process Customer Personal Data only on documented instructions needed for the Service, including account settings and actions by authorized users within their permissions, retaining necessary instruction evidence. The customer remains responsible for valid authority; a limited support request does not authorize opening every account or independent use of data.

3.2Unlawful instructions and other purposes

If we consider an instruction contrary to data-protection law, we promptly inform the customer and suspend the affected processing as necessary until lawfulness is established or instructions changed. Where binding law requires other processing, we verify its applicability and notify the customer beforehand unless legally prohibited. Instructions do not include data sale, pooling unrelated customer databases or general-model training; independent processing needs a valid basis and arrangement and must not override provider or transfer restrictions.

04

Customer obligations & authority#

4.1Lawfulness and authority

The customer provides necessary notices, lawful bases and consents for collecting, sending and processing data for the stated purpose, checks accuracy and relevance and minimizes volume. An Agency instructing for its client ensures it has authority and a contract permitting our engagement and approved subprocessors, without imposing contractual duties on a data subject who is not a party.

4.2Special data and changed use

Customers must not send sensitive categories or data requiring sector-specific arrangements or residency unless service support and scope-specific safeguards are approved in the annex. Notify us before material changes to data categories, purposes or countries so arrangements can be assessed. Customer duties do not excuse duties imposed on us as processor.

05

Personnel, confidentiality & access#

5.1Permissions and confidentiality

Access to Customer Personal Data is limited to people needing it for an authorized function, subject to appropriate contractual, professional or statutory confidentiality. Permissions are granted as needed, reviewed and removed when the need or role ends. This applies to employees and contractors; company affiliation alone does not grant general access.

5.2Support and training

Support and maintenance access is limited to a defined task and appropriate authority, with administrative access and sensitive actions recorded according to risk. Customer data is not copied into a test environment or external support tool merely for convenience; a necessary purpose, safeguards and appropriate contract are required. People with access are bound by confidentiality and role-appropriate instructions and training, and permissions are reviewed on role change or departure.

06

Technical & organizational measures#

6.1Appropriate protection

We undertake to establish and maintain Annex B measures proportionate to the processing nature, scope, purposes, likelihood and severity of harm, considering technology and implementation costs. This includes confidentiality, integrity, availability and restoration of access where needed. Necessary safeguards precede the relevant customer-data processing; labeling a function beta does not authorize bypassing a necessary measure.

6.2Evolving measures

Protection methods may evolve while maintaining the agreed overall level without material reduction during service delivery. Material changes are documented and additional safeguards for higher-risk data reviewed. If a necessary measure cannot be met, we inform the customer and adopt preventive action or an acceptable alternative under the inability-to-comply provisions rather than continue unlawful processing.

07

Subprocessor engagement#

7.1Authorization and change notice

The customer authorizes subprocessors whose legal names and scope appear in approved Annex C. Under general authorization for changes, we give advance notice of additions or replacements, functions, countries and safeguards within the annex's agreed period, allowing reasoned data-protection objections before processing begins. Merely publishing a name is insufficient where direct notice is contractually required.

7.2Contracts, objections and responsibility

A written subprocessor contract provides substantively equivalent relevant processing protections and limits access to necessary purposes and data. We remain responsible to the customer for its data-protection performance under law and contract. We assess objections and seek remediation or an alternative; absent a lawful resolution, affected processing stops or the affected Service ends with settlement of unused prepaid fees under the Terms of Service. Objections do not entitle access to other customers' data or require unlawful processing to continue.

08

Data subject requests#

8.1Receiving and routing requests

If we receive a request concerning data processed for the customer, we inform it without undue delay and direct the requester to the appropriate party where suitable. We do not directly disclose or delete data without documented instructions unless legally required, in which case we inform the customer as permitted. Agency chains must route the matter to the actual controller.

8.2Assisting rights fulfilment

Taking account of processing nature and necessary capabilities, we assist with search, access, correction, deletion, restriction and export to fulfil valid requests within legal deadlines. Any reasonable lawful additional cost for exceptional assistance outside ordinary service is agreed beforehand; an unagreed fee or commercial dispute must not obstruct an urgent legal duty. Verification protects others' data and remains limited to what is needed.

09

Impact assessments & regulatory cooperation#

9.1Impact assessments

We provide available necessary information about our processing, measures and providers to assist required data-protection impact assessments, taking account of processing nature. The controller determines the assessment's purposes and final decision; receipt of our information does not automatically approve high-risk activity or guarantee the assessment outcome.

9.2Authorities and consultation

We cooperate with prior consultation and regulatory enquiries or investigations concerning our processing where law requires, coordinating with the customer as permitted. Relevant evidence is supplied securely with protection for others' data and legitimate secrets, without using confidentiality to obstruct mandatory disclosure to a competent authority.

10

Personal data breaches & notification#

10.1Personal data breach and initial notice

A personal data breach is a security event causing accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Personal Data. Not every service fault is a breach. On awareness of a breach affecting data within our processing, we notify the approved customer contact without undue delay and within any shorter legally required or effective agreed deadline; notification does not await a completed investigation.

10.2Information, follow-up and responsibilities

Notice includes known breach nature, categories and approximate numbers where possible, likely effects, measures taken or proposed and a contact point. Information is supplemented as it becomes available, necessary evidence preserved and harm and causes addressed. Each party determines authority and individual notification duties by role, with our cooperation. The GDPR controller-to-authority deadline is not a universal processor or worldwide deadline. Notice neither automatically admits liability nor removes it.

11

International transfers & overseas access#

11.1International transfer and access

We do not transfer Customer Personal Data to a country or allow international access outside authorized documented routes and required legal safeguards. Assessment includes storage, backups, support and onward processors. A legally restricted transfer does not begin until the appropriate transfer instrument is entered into and the required party, country and security details are completed in Annex D or an associated signed addendum. Accepting this page alone does not execute unattached standard contractual clauses.

11.2Government demands and safeguard failure

We review government demands for authority, validity and scope, challenging or seeking to narrow them on reasonable grounds to the extent required by applicable safeguards, and notify the customer unless prohibited. Only legally required data is disclosed. If necessary transfer protection cannot continue, we inform the customer and adopt valid supplementary measures or suspend the route and return or delete data under the applicable mechanism; changing a privacy notice alone does not cure the failure.

12

Data return & deletion#

12.1Return or deletion choice

At processing end, we return or delete Customer Personal Data at the customer’s choice under documented instructions. The 30-day retrieval window and request and delivery methods in Terms section 12 apply. Active copies are deleted within 30 days after that window or a valid deletion request, unless instructions or law require sooner. We coordinate instructions with subprocessors and respect others’ rights without using them to withhold data that can lawfully be returned. This window does not replace data-subject response deadlines.

12.2Isolated copies and execution evidence

Backups expire within 90 days of active-copy deletion and remain isolated and protected from ordinary use, with deletion instructions reapplied after restoration. Each legal hold has an identified reason, scope and reviewed duration, limited to what law requires. On request, we provide appropriate deletion confirmation and explain any remaining exception. Invoice retention does not justify retaining unrelated customer content.

13

Compliance evidence & audits#

13.1Information demonstrating compliance

We make reasonably necessary information available to demonstrate compliance with this DPA, including control descriptions and evidence that actually exists. A suitable questionnaire or report may be the starting point if it addresses the issue; we do not promise nonexistent assurance reports, and a general report does not close additional audit rights required by law or a specific event.

13.2Inspections and reasonable conditions

We allow and contribute to audits, including inspection by the customer or its authorized independent auditor, within the processing scope and reasonable notice, security and confidentiality arrangements. Service disruption and access to others' data are avoided, and repeated requests coordinated without defeating necessary rights. Ordinary limits must not obstruct competent-authority audits, breach investigation or serious noncompliance concerns. Lawful additional costs are agreed in advance and findings followed by appropriate remediation.

14

Liability & inability to comply#

14.1Inability to meet obligations

A party informs the other without undue delay if it cannot meet a material data-protection obligation, identifying the affected route and possible remedy. That route may be suspended as necessary and terminated if no lawful solution is available, with data protected and returned or deleted and unused prepayments settled where due. Commercial disagreement does not require unlawful transfer or use to continue.

14.2Liability and individual rights

Party liability is read with the Terms of Service and any approved special cap, without limiting liability, compensation or data-subject rights that law or transfer clauses do not permit restricting. We remain responsible for subprocessor performance as required by law and contract. A data subject does not need the Contracting Customer's permission to exercise direct statutory or transfer-clause rights.

15

Annex A: processing description#

15.1Annex A — subject, nature and purposes

Subject: data for accounts covered by the Order to provide enabled administration, communication, content, commerce and integration tools for personal or business use. Nature: receipt, organization, storage, retrieval, display, authorized transfer, updating and deletion according to the function. Purposes: carrying out customer instructions for those functions and related support and protection. Duration: the service term and necessary retrieval and deletion under section 12. Frequency is ongoing or on demand for the specified function, without authorizing every possible processing activity.

15.2People, categories and specification

The processor is Tajir Global Limited at Bayfield Building, 99 Hennessy Rd, Wan Chai, Hong Kong, contact contact@utajir.com; the customer, contact person and any Agency authority are identified in the subscription record or Order. Depending on selected functions, individuals include users, contacts, clients, buyers, learners, members and recipients. Administration covers identity, contact details and permissions; commerce covers order and delivery data; learning and communities cover content, enrollment and progress; communications cover messages, attachments and recipients; integrations cover account identifiers, permissions and necessary records. Sensitive or sector-regulated categories are excluded by default and require written agreement on support and safeguards. Enabled functions and customer instructions record categories actually used; this description does not expand them.

16

Annex B: security measures schedule#

16.1Annex B — measures schedule

Annex B — Baseline measures: individually assigned, need-based permissions and revocation when a role ends; protection of passwords, tokens and keys from display and public logs; appropriate encryption of customer-data transmission over public networks; controlled access to databases, files, backups and keys; enforcement of account boundaries for reading, modification, export and background operations; and support access confined to authorized purposes with confidentiality and suitable records. Development and testing are separated from customer processing, with real data excluded absent necessity and safeguards. This annex claims no end-to-end encryption, certification or specific technology outside an agreed scope.

16.2Recovery, development and oversight

Measures also include security-impact review of changes; risk-based vulnerability assessment and remediation; suitable event records excluding secrets and excessive content; backup management and restore testing appropriate to covered data; export and deletion under section 12; incident response and notices under section 10; appropriate staff training; and provider assessment and contractual access limits. We give authorized customers suitable evidence through section 13’s audit process, identifying relevant service boundaries and exceptions. This annex specifies no guaranteed uptime percentage or recovery time; those require a separate SLA.

17

Annex C: subprocessors#

17.1Annex C — linked register

Annex C comprises the Subprocessor Register in the accepted release and the processing schedule associated with the Order. Acceptance authorizes providers identified in that schedule for their specified functions after legal entity, data and individual categories, storage and access countries, safeguards and start date are supplied. A provider’s business address is not a guaranteed data-storage location, and a provider whose route details are incomplete is not authorized. These details precede the relevant function; later additions and replacements follow the notice and objection procedure below.

17.2Change and objection arrangements

We send direct notice to the account’s designated contact email at least 30 days before adding or replacing a subprocessor. You may object on reasonable data-protection grounds within 30 days of receiving notice. The provider does not process your data before that period ends and your objection is addressed under section 7. If continuing the Service would breach law or expose data to unacceptable risk, we discuss a lawful alternative or stop the affected part with proper settlement; urgency is not consent to an undisclosed provider. No separate mailing-list subscription is required to receive notice.

18

Annex D: transfers & regional terms#

18.1Annex D — European Union

Annex D — For European transfers requiring standard contractual clauses, we provide the official Decision 2021/914 text with parties, transfer description, measures, competent authority, law, courts and required selections before transfer begins. The module depends on roles and the Decision’s scope, potentially controller-to-processor or processor-to-processor in an Agency chain. A general reference to this page does not replace the applicable instrument, and the clauses are not modified contrary to their protection. Required assessment, supplementary measures and safeguards extend to onward transfers.

18.2United Kingdom and Switzerland

A UK restricted transfer does not begin without an effective mechanism, such as the IDTA or UK Addendum to EU clauses where appropriate, with required tables and selections completed. Swiss data follows a mechanism, safeguards and adaptations consistent with Swiss law. We provide the instrument for the customer’s route; selecting Hong Kong courts does not replace choices required by that instrument.

18.3Service-provider restrictions and other markets

Where California service-provider or contractor requirements apply to processing on the customer’s behalf, we limit it to the specified permitted business purposes in this annex. We do not sell or share the data in the statutory sense, retain, use or disclose it outside the relationship, or combine it with other-source data except as law permits. We provide the required protection, notify the customer if unable to comply, and allow reasonable steps to verify, stop and remedy unauthorized use, including after that notice. Other-market requirements are attached to the relevant route before processing that requires them operates; website language alone establishes neither legal coverage nor compliance.

End of document
Previous documentCookies & similar technologiesNext documentSubprocessors

On this page

  1. 01Parties, definitions & processing roles
  2. 02Contract relationship & applicability
  3. 03Instructions & permitted processing
  4. 04Customer obligations & authority
  5. 05Personnel, confidentiality & access
  6. 06Technical & organizational measures
  7. 07Subprocessor engagement
  8. 08Data subject requests
  9. 09Impact assessments & regulatory cooperation
  10. 10Personal data breaches & notification
  11. 11International transfers & overseas access
  12. 12Data return & deletion
  13. 13Compliance evidence & audits
  14. 14Liability & inability to comply
  15. 15Annex A: processing description
  16. 16Annex B: security measures schedule
  17. 17Annex C: subprocessors
  18. 18Annex D: transfers & regional terms
Questions or corrections:
contact@utajir.com

Tajir Global Limited · contact@utajir.com

Back to top