Legal

Data Processing Agreement

When Elbi runs for your organisation you are the controller and we are your processor. These are the terms — published in full, annexes included, before you ask for them.

Version 1.0PDPL Art. 8 · processor terms

The short version

  • You are the controller, we are the processor. We act only on your documented instructions.
  • We never use your data to train models or for any purpose of our own.
  • Breach notification to you within 24 hours of becoming aware — on what we know, without waiting to finish the investigation.
  • Deletion or return within 30 days of termination, certified in writing on request.
  • 30 days' notice before any new sub-processor, with a right to object and terminate.
  • Audit rights, annually, plus a security page written to pre-answer your questionnaire.
  • All three annexes are here — processing description, security measures, sub-processor list. Nothing is held back for later.

1. What this document is

When Elbi is deployed for your organisation, you are the controller of the personal data your visitors and staff put into it, and Elbetron is your processor. This page is the agreement that governs that relationship.

It is published in full so your legal and procurement teams can read it before there is any conversation about signing. It is incorporated into the main services agreement by reference and executed with it — there is nothing to sign here.

ControllerYour organisation
ProcessorElbetron Technologies, Dammam, Kingdom of Saudi Arabia
Governing lawPersonal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia and its Implementing Regulations, supervised by SDAIA
PrecedenceWhere this DPA conflicts with the main agreement on the subject of personal data, this DPA prevails

This is a template offered in good faith, not legal advice. Have your own counsel review it. We will negotiate reasonable amendments — a processor who refuses to is telling you something.

2. Roles and instructions

  • We process personal data only on your documented instructions, which comprise this DPA, the main agreement, and the configuration you set in the product.
  • We will tell you if, in our view, an instruction breaches the PDPL or its Regulations. We will not simply carry it out and invoice you.
  • We do not process your data for our own purposes. We do not use it to train models, to build products, or to derive anything we sell.
  • Where we act as controller in our own right — our own staff accounts, our own security logs — that is covered by our Privacy Policy, not this DPA.

3. Confidentiality

Everyone we authorise to process your data is bound by a written confidentiality obligation that survives the end of their engagement. Access is granted on a least-privilege basis and reviewed. Our own analytics dashboard cannot read message content — that restriction is built into the product, not merely promised.

4. Security measures

We implement and maintain the technical and organisational measures set out in Annex 2 below, consistent with PDPL Article 19. Those measures are published in full and kept current at Security & Compliance, and are verified against the running system rather than asserted.

We will not materially weaken them during the term. If we improve them, the published page changes and you get the benefit without renegotiating.

5. Sub-processors

  • You give general authorisation for the sub-processors listed in Annex 3, which is maintained as a live register at Sub-processors.
  • We give at least 30 days' written notice before a new sub-processor starts processing.
  • You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected service without penalty and without further liability for it.
  • Every sub-processor is bound by written terms no less protective than these, and we remain fully liable to you for their performance.

6. Assisting with data subject rights

Elbi is built so that most requests never need to reach us. Access, export and erasure are self-service controls inside the assistant, and they take effect immediately.

  • Where a request does reach us, we forward it to you without undue delay and do not respond to it ourselves unless you instruct us to.
  • We provide reasonable assistance for you to meet the 30-day response window in the Regulations, taking into account the nature of the processing.
  • In practice the 24-hour content ceiling means that by the time most requests arrive, the data in question no longer exists.

7. Personal data breaches

Notification to youWithout undue delay, and in any case within 24 hours of becoming aware
What we sendWhat happened, categories and approximate volume of data and data subjects affected, likely consequences, and the measures taken or proposed
If facts are incompleteWe notify on what we know and update you as we learn more. We do not delay notification to finish the investigation
RegulatorYou notify SDAIA as controller. We assist and provide what you need
Our runbookA written breach notification runbook exists, naming roles, order of actions and deadlines. Available under NDA

8. Assistance with assessments

We assist you, at your reasonable request, with data protection impact assessments and with any prior consultation with SDAIA, to the extent the information relates to our processing and is not reasonably available to you. Our own DPIA is available under NDA and usually answers most of it.

9. Return and deletion

  • During the term, conversation content is destroyed within 24 hours by the mechanism described in Annex 2 — there is no long-lived store to return.
  • At the end of the term, at your choice, we delete or return all remaining personal data processed on your behalf, and delete existing copies, within 30 days.
  • Encrypted backups are overwritten on their normal cycle — 7 days local, 30 days off-site — after which no copy remains.
  • We certify deletion in writing on request.
  • The only exception is data we are required by Saudi law to retain, which we will identify to you.

10. Audits and information

  • We make available the information reasonably necessary to demonstrate compliance with this DPA — including our RoPA, DPIA, breach runbook and the published security page.
  • We allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, and subject to confidentiality.
  • We will answer a security questionnaire. Security & Compliance is written to pre-answer most of one, including the parts where the answer is no.

11. Transfers outside the Kingdom

Conversation content does not leave Saudi Arabia. Processing, storage and destruction all happen in-Kingdom, and the encrypted backup replica is in a Saudi region by deliberate choice.

Two limited transfers are disclosed in the sub-processor register: routing in transit via a global edge network, and staff sign-in emails through a relay hosted abroad. Both are covered by written agreements and handled under PDPL Article 29. We will not add a new cross-border transfer without notice under clause 5.

12. Liability and term

Liability under this DPA is governed by the limitations in the main services agreement, except where the PDPL does not permit limitation. This DPA takes effect when the main agreement does, and continues for as long as we process personal data on your behalf.

Annex 1 — Description of processing

Subject matterProvision of the Elbi AI assistant and its associated administration and analytics
DurationThe term of the main agreement, plus the deletion window in clause 9
Nature and purposeAnswering end-user queries from content you approve; transcribing voice; extracting text from files the end user attaches; routing to your human agents; producing anonymised service-quality metrics
Types of personal dataMessage content; voice audio (transient); content of files the end user attaches (transient); a pseudonymous conversation identifier; IP address and user-agent; consent records; your staff account details
Special categoriesNot intentionally processed. The assistant is instructed never to request them and identifiers are redacted at capture. Residual risk is documented in our DPIA
Categories of data subjectYour website visitors and customers; your staff who use the dashboard or agent portal
FrequencyContinuous, for the term

Annex 2 — Technical and organisational measures

Summarised here; published in full and kept current at Security & Compliance.

AreaMeasure
Encryption in transitTLS 1.3
Encryption at restauthenticated encryption applied in the application before storage, key held outside the database
DiskFull-disk encryption
MinimisationStructured identifiers redacted before storage and before the model sees the text
RetentionMessage content destroyed within 24 hours, enforced hourly by a backstop that runs even when the normal path fails. Voice audio and uploaded files never stored
Access controlIndividual accounts, role-based permissions, two-factor authentication, session expiry, audit logging, least privilege
NetworkHost firewall, intrusion banning, reverse-proxy route allowlist, rate limiting, malware scanning on uploads
ResilienceNightly encrypted backup, round-trip verified, replicated to a second Saudi region; 7 days local / 30 days off-site
Data locationAll processing and storage inside the Kingdom of Saudi Arabia; no external AI provider in the path
TestingRepeatable behavioural, grounding, retrieval and capacity test suites run against the live system

Annex 3 — Approved sub-processors

Maintained as a live register at Sub-processors. As at the date of this version:

Sub-processorPurposeLocation
Edge network providerIngress, TLS termination, protection against attackGlobal edge
Transactional mail relayTransactional email for staff sign-inUnited States
In-Kingdom cloud providerEncrypted off-site backup storage (ciphertext only)Riyadh, Saudi Arabia
Website analytics providerVisit counts for the a-i.sa website only — never customer or conversation dataUnited States

No AI, speech or OCR provider appears in this annex, and none is intended to.

Contact

Emailglobal.business@elbetron.com
PostElbetron Technologies, Dammam, Kingdom of Saudi Arabia
RelatedSub-processors · Security & Compliance · Privacy Policy

Version 1.0. Published for review. Not legal advice — have your counsel read it before you rely on it.