The short version
- You are the controller, we are the processor. We act only on your documented instructions.
- We never use your data to train models or for any purpose of our own.
- Breach notification to you within 24 hours of becoming aware — on what we know, without waiting to finish the investigation.
- Deletion or return within 30 days of termination, certified in writing on request.
- 30 days' notice before any new sub-processor, with a right to object and terminate.
- Audit rights, annually, plus a security page written to pre-answer your questionnaire.
- All three annexes are here — processing description, security measures, sub-processor list. Nothing is held back for later.
1. What this document is
When Elbi is deployed for your organisation, you are the controller of the personal data your visitors and staff put into it, and Elbetron is your processor. This page is the agreement that governs that relationship.
It is published in full so your legal and procurement teams can read it before there is any conversation about signing. It is incorporated into the main services agreement by reference and executed with it — there is nothing to sign here.
| Controller | Your organisation |
| Processor | Elbetron Technologies, Dammam, Kingdom of Saudi Arabia |
| Governing law | Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia and its Implementing Regulations, supervised by SDAIA |
| Precedence | Where this DPA conflicts with the main agreement on the subject of personal data, this DPA prevails |
This is a template offered in good faith, not legal advice. Have your own counsel review it. We will negotiate reasonable amendments — a processor who refuses to is telling you something.
2. Roles and instructions
- We process personal data only on your documented instructions, which comprise this DPA, the main agreement, and the configuration you set in the product.
- We will tell you if, in our view, an instruction breaches the PDPL or its Regulations. We will not simply carry it out and invoice you.
- We do not process your data for our own purposes. We do not use it to train models, to build products, or to derive anything we sell.
- Where we act as controller in our own right — our own staff accounts, our own security logs — that is covered by our Privacy Policy, not this DPA.
3. Confidentiality
Everyone we authorise to process your data is bound by a written confidentiality obligation that survives the end of their engagement. Access is granted on a least-privilege basis and reviewed. Our own analytics dashboard cannot read message content — that restriction is built into the product, not merely promised.
4. Security measures
We implement and maintain the technical and organisational measures set out in Annex 2 below, consistent with PDPL Article 19. Those measures are published in full and kept current at Security & Compliance, and are verified against the running system rather than asserted.
We will not materially weaken them during the term. If we improve them, the published page changes and you get the benefit without renegotiating.
5. Sub-processors
- You give general authorisation for the sub-processors listed in Annex 3, which is maintained as a live register at Sub-processors.
- We give at least 30 days' written notice before a new sub-processor starts processing.
- You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected service without penalty and without further liability for it.
- Every sub-processor is bound by written terms no less protective than these, and we remain fully liable to you for their performance.
6. Assisting with data subject rights
Elbi is built so that most requests never need to reach us. Access, export and erasure are self-service controls inside the assistant, and they take effect immediately.
- Where a request does reach us, we forward it to you without undue delay and do not respond to it ourselves unless you instruct us to.
- We provide reasonable assistance for you to meet the 30-day response window in the Regulations, taking into account the nature of the processing.
- In practice the 24-hour content ceiling means that by the time most requests arrive, the data in question no longer exists.
7. Personal data breaches
| Notification to you | Without undue delay, and in any case within 24 hours of becoming aware |
| What we send | What happened, categories and approximate volume of data and data subjects affected, likely consequences, and the measures taken or proposed |
| If facts are incomplete | We notify on what we know and update you as we learn more. We do not delay notification to finish the investigation |
| Regulator | You notify SDAIA as controller. We assist and provide what you need |
| Our runbook | A written breach notification runbook exists, naming roles, order of actions and deadlines. Available under NDA |
8. Assistance with assessments
We assist you, at your reasonable request, with data protection impact assessments and with any prior consultation with SDAIA, to the extent the information relates to our processing and is not reasonably available to you. Our own DPIA is available under NDA and usually answers most of it.
9. Return and deletion
- During the term, conversation content is destroyed within 24 hours by the mechanism described in Annex 2 — there is no long-lived store to return.
- At the end of the term, at your choice, we delete or return all remaining personal data processed on your behalf, and delete existing copies, within 30 days.
- Encrypted backups are overwritten on their normal cycle — 7 days local, 30 days off-site — after which no copy remains.
- We certify deletion in writing on request.
- The only exception is data we are required by Saudi law to retain, which we will identify to you.
10. Audits and information
- We make available the information reasonably necessary to demonstrate compliance with this DPA — including our RoPA, DPIA, breach runbook and the published security page.
- We allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, and subject to confidentiality.
- We will answer a security questionnaire. Security & Compliance is written to pre-answer most of one, including the parts where the answer is no.
11. Transfers outside the Kingdom
Conversation content does not leave Saudi Arabia. Processing, storage and destruction all happen in-Kingdom, and the encrypted backup replica is in a Saudi region by deliberate choice.
Two limited transfers are disclosed in the sub-processor register: routing in transit via a global edge network, and staff sign-in emails through a relay hosted abroad. Both are covered by written agreements and handled under PDPL Article 29. We will not add a new cross-border transfer without notice under clause 5.
12. Liability and term
Liability under this DPA is governed by the limitations in the main services agreement, except where the PDPL does not permit limitation. This DPA takes effect when the main agreement does, and continues for as long as we process personal data on your behalf.
Annex 1 — Description of processing
| Subject matter | Provision of the Elbi AI assistant and its associated administration and analytics |
| Duration | The term of the main agreement, plus the deletion window in clause 9 |
| Nature and purpose | Answering end-user queries from content you approve; transcribing voice; extracting text from files the end user attaches; routing to your human agents; producing anonymised service-quality metrics |
| Types of personal data | Message content; voice audio (transient); content of files the end user attaches (transient); a pseudonymous conversation identifier; IP address and user-agent; consent records; your staff account details |
| Special categories | Not intentionally processed. The assistant is instructed never to request them and identifiers are redacted at capture. Residual risk is documented in our DPIA |
| Categories of data subject | Your website visitors and customers; your staff who use the dashboard or agent portal |
| Frequency | Continuous, for the term |
Annex 2 — Technical and organisational measures
Summarised here; published in full and kept current at Security & Compliance.
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.3 |
| Encryption at rest | authenticated encryption applied in the application before storage, key held outside the database |
| Disk | Full-disk encryption |
| Minimisation | Structured identifiers redacted before storage and before the model sees the text |
| Retention | Message content destroyed within 24 hours, enforced hourly by a backstop that runs even when the normal path fails. Voice audio and uploaded files never stored |
| Access control | Individual accounts, role-based permissions, two-factor authentication, session expiry, audit logging, least privilege |
| Network | Host firewall, intrusion banning, reverse-proxy route allowlist, rate limiting, malware scanning on uploads |
| Resilience | Nightly encrypted backup, round-trip verified, replicated to a second Saudi region; 7 days local / 30 days off-site |
| Data location | All processing and storage inside the Kingdom of Saudi Arabia; no external AI provider in the path |
| Testing | Repeatable behavioural, grounding, retrieval and capacity test suites run against the live system |
Annex 3 — Approved sub-processors
Maintained as a live register at Sub-processors. As at the date of this version:
| Sub-processor | Purpose | Location |
|---|---|---|
| Edge network provider | Ingress, TLS termination, protection against attack | Global edge |
| Transactional mail relay | Transactional email for staff sign-in | United States |
| In-Kingdom cloud provider | Encrypted off-site backup storage (ciphertext only) | Riyadh, Saudi Arabia |
| Website analytics provider | Visit counts for the a-i.sa website only — never customer or conversation data | United States |
No AI, speech or OCR provider appears in this annex, and none is intended to.
Contact
| global.business@elbetron.com | |
| Post | Elbetron Technologies, Dammam, Kingdom of Saudi Arabia |
| Related | Sub-processors · Security & Compliance · Privacy Policy |
Version 1.0. Published for review. Not legal advice — have your counsel read it before you rely on it.