Data Processing Agreement
Plain Language Summary
This Data Processing Agreement ("DPA") is a legal contract between Enigma Labs Technology Limited and our customers that governs how we handle personal data on behalf of our customers when providing our cybersecurity services.
What this means in simple terms:
- You (our customer) are the "Controller" — you decide what personal data is processed and why.
- We (Enigma Labs) are the "Processor" — we process personal data only according to your instructions to deliver our services.
- This agreement is designed to meet the requirements of the DIFC Data Protection Law, DIFC Law No. 5 of 2020 (as amended), the law that applies to Enigma Labs Technology Limited as a company incorporated in the Dubai International Financial Centre.
Key commitments we make:
| Commitment | Details |
|---|---|
| Processing Limitations | We only process personal data to provide our cybersecurity services |
| Security | We implement strong security measures to protect your data |
| Breach Notification | We notify you within 48 hours if there's a security breach |
| Data Subject Rights | We help you respond to data subject requests within 5 business days |
| Data Deletion | We delete your data within 90 days after our agreement ends |
| Sub-processors | We use carefully vetted sub-processors and notify you 30 days before any changes |
This DPA works together with our Terms of Service and Privacy Policy. If there's any conflict between these documents regarding data protection, this DPA takes precedence.
1. Definitions
For the purposes of this Data Processing Agreement, the following terms have the meanings set out below. Capitalized terms not defined herein shall have the meaning given to them in the DP Law or, failing that, in the Principal Agreement.
| Term | Definition |
|---|---|
| "Adequate Jurisdiction" | A jurisdiction determined by the Commissioner to provide an adequate level of protection for Personal Data pursuant to Article 26(2) of the DP Law, as listed in Appendix 3 of the DP Regulations and updated by the Commissioner from time to time on the Data Protection section of difc.ae. |
| "Agreement" | This Data Processing Agreement, including all Annexes attached hereto. |
| "Applicable Data Protection Law" | The DP Law and the DP Regulations, together with any other data protection laws and regulations that apply to a party's Processing of Personal Data under this DPA. |
| "Commissioner" | The Commissioner of Data Protection appointed under the DP Law, the supervisory authority for data protection in the DIFC. |
| "Controller" | The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, as defined in the DP Law. For the purposes of this DPA, the Customer acts as the Controller. |
| "Customer" | The entity that has entered into the Principal Agreement with Enigma Labs Technology Limited to use the Services. |
| "Customer Data" | All Personal Data Processed by Enigma Labs on behalf of the Customer in connection with the provision of the Services. |
| "Data Subject" | The identified or identifiable natural person to whom Personal Data relates. |
| "DIFC" | The Dubai International Financial Centre, a financial free zone in the Emirate of Dubai, United Arab Emirates, with its own civil and commercial law system. |
| "DIFC SCCs" | The standard contractual clauses approved and published by the Commissioner for transfers of Personal Data outside the DIFC to a jurisdiction that is not an Adequate Jurisdiction, pursuant to Article 27(2)(c) of the DP Law and Regulation 5 of the DP Regulations, as updated by the Commissioner from time to time. |
| "DP Law" | The Data Protection Law, DIFC Law No. 5 of 2020, as amended from time to time (including by DIFC Law No. 2 of 2022 and by the DIFC Laws Amendment Law, DIFC Law No. 1 of 2025). |
| "DP Regulations" | The DIFC Data Protection Regulations (Consolidated Version No. 2, in force 1 September 2023), as amended from time to time. |
| "DPA" | This Data Processing Agreement. |
| "DPO" | Data Protection Officer. |
| "Personal Data" | Any information referring to an identified or Identifiable Natural Person, as defined in the DP Law. |
| "Personal Data Breach" | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed. |
| "Principal Agreement" | The Terms of Service or other master agreement between Enigma Labs and the Customer governing the provision of Services. |
| "Processing" | Any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction, as defined in the DP Law. |
| "Processor" | A natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller, as defined in the DP Law. For the purposes of this DPA, Enigma Labs acts as the Processor. |
| "Requesting Authority" | Any public authority with a request over a person or any part of its group for the disclosure and transfer of Personal Data, within the meaning of Article 28 of the DP Law. |
| "Security Incident" | Any actual or suspected unauthorised access to, acquisition of, use of, disclosure of, or destruction of Customer Data, or any other event that compromises the security, confidentiality, or integrity of Customer Data. This includes, but is not limited to, ransomware attacks, unauthorised data access, data exfiltration, malware infections affecting Customer Data, and accidental data exposure. |
| "Services" | The cybersecurity services provided by Enigma Labs to the Customer as described in the Principal Agreement, including but not limited to cybersecurity audits, penetration testing, and incident response. |
| "Sub-processor" | Any Processor engaged by Enigma Labs to Process Customer Data on behalf of the Customer. |
2. Scope and Roles
2.1 Role of the Parties
The parties acknowledge and agree that:
(a) Customer as Controller: The Customer acts as the Controller of Customer Data. The Customer determines the purposes and means of Processing Customer Data and is responsible for ensuring that it has a valid lawful basis for such Processing under Applicable Data Protection Law.
(b) Enigma Labs as Processor: Enigma Labs acts as the Processor of Customer Data. Enigma Labs shall Process Customer Data only on documented instructions from the Customer, including as set forth in this DPA, the Principal Agreement, and as necessary to provide the Services.
(c) Scope of Processing: This DPA applies to all Processing of Customer Data by Enigma Labs in connection with the provision of the Services. Under Article 6(3) of the DP Law, the DP Law applies to Enigma Labs as a Controller or Processor incorporated in the DIFC regardless of whether the Processing takes place in the DIFC or not; this DPA accordingly applies to such Processing regardless of where it occurs.
2.2 Principal Agreement Reference
This DPA is incorporated into and forms an integral part of the Principal Agreement between the parties. In the event of any conflict between the provisions of this DPA and the Principal Agreement regarding the protection of Personal Data, the provisions of this DPA shall prevail.
2.3 Enigma Labs as Controller
Nothing in this DPA affects Enigma Labs' status as a Controller with respect to its own customer contact information (such as account information, billing details, and business communications), which is Processed in accordance with Enigma Labs' Privacy Policy.
2.4 Foreign Data Protection Regimes
Where the Customer's Processing is also subject to a data protection regime other than the DP Law (for example, because of where the Customer or its Data Subjects are located), the parties may agree additional controller/processor terms — such as standard contractual clauses approved under the relevant foreign regime — as an addendum to this DPA. Absent such an addendum, this DPA is governed by, and drafted to satisfy, the DP Law.
3. Processing Instructions
3.1 Documented Instructions
Enigma Labs shall Process Customer Data only on documented instructions from the Customer, including with regard to transfers of Customer Data to jurisdictions outside the DIFC, unless required to do so by Applicable Data Protection Law or another law applicable to Enigma Labs. In that case, Enigma Labs shall inform the Customer of that legal requirement before Processing, unless the applicable law prohibits such disclosure on important grounds of public interest.
3.2 Deemed Instructions
The Customer's instructions to Enigma Labs for the Processing of Customer Data are deemed to be given through:
(a) This Data Processing Agreement;
(b) The Principal Agreement (Terms of Service);
(c) The Customer's use of the Services and platform features in accordance with the documentation;
(d) Any written instructions provided by the Customer to Enigma Labs through authorized channels.
3.3 Instruction Compliance
Enigma Labs shall promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless Enigma Labs is prohibited from notifying the Customer on important grounds of public interest. Enigma Labs may suspend performance of the affected instruction until the Customer confirms or modifies it.
3.4 Lawfulness of Instructions
The Customer warrants and represents that:
(a) It has established a valid lawful basis for the Processing of Customer Data as required by Applicable Data Protection Law (including, where the DP Law applies to the Customer, the requirements of Articles 9 to 12 of the DP Law);
(b) Its instructions to Enigma Labs for Processing Customer Data comply with Applicable Data Protection Law;
(c) It has provided appropriate information to Data Subjects about the Processing of their Personal Data as required by Applicable Data Protection Law.
3.5 Additional Instructions
If the Customer requires Enigma Labs to Process Customer Data in a manner that falls outside the scope of the deemed instructions set forth in Section 3.2, the Customer shall provide such additional instructions in writing. Enigma Labs shall assess whether it can comply with such additional instructions and shall notify the Customer of any additional costs or technical requirements within a reasonable timeframe.
4. Processor Obligations
Enigma Labs agrees to comply with the obligations applicable to Processors under the DP Law, including Article 24 of the DP Law, and shall:
4.1 Process Only on Documented Instructions
Process Customer Data only on documented instructions from the Customer, including with regard to transfers of Customer Data to jurisdictions outside the DIFC, except where required to do so by Applicable Data Protection Law.
4.2 Ensure Personnel Confidentiality
Take reasonable steps to ensure the reliability of any personnel who have access to Customer Data and ensure that all such personnel:
(a) Are bound by confidentiality obligations with respect to Customer Data;
(b) Have received appropriate training on data protection and security;
(c) Access Customer Data only on a need-to-know basis.
4.3 Implement Appropriate Security Measures
Implement and maintain appropriate technical and organisational measures to protect Customer Data, as required by Article 14(2) of the DP Law, ensuring a level of security appropriate to the risk, as further described in Annex 2 (Technical and Organisational Measures).
4.4 Respect Sub-processor Conditions
Not engage another Processor (Sub-processor) without the prior specific or general written authorisation of the Customer, in accordance with Article 24(3) of the DP Law and Section 6 (Sub-processors).
4.5 Assist with Data Subject Rights
Taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests from Data Subjects exercising their rights under Articles 32 to 40 of the DP Law.
4.6 Assist with Security, Breach Notification, and DPIAs
Taking into account the nature of the Processing and the information available to Enigma Labs:
(a) Assist the Customer in ensuring compliance with the Customer's obligations concerning security of Processing (Article 14(2) of the DP Law), Personal Data Breach notification (Articles 41 and 42 of the DP Law and Regulation 8 of the DP Regulations), and data protection impact assessments (Article 20 of the DP Law);
(b) Provide the Customer with information reasonably necessary to demonstrate compliance with the obligations applicable to Processors under the DP Law and this DPA;
(c) Allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer in accordance with Section 12 (Audit Rights).
4.7 Delete or Return Data After Services End
At the choice of the Customer, delete or return all Customer Data to the Customer after the end of the provision of Services relating to Processing, and delete existing copies unless Applicable Data Protection Law requires storage of the Personal Data, in accordance with Section 13 (Data Retention and Deletion).
4.8 Inform Controller of Non-Compliance
Promptly inform the Customer if, in Enigma Labs' opinion, an instruction infringes Applicable Data Protection Law.
4.9 Maintain Records of Processing
Maintain a record of Processing activities carried out on behalf of the Customer, in accordance with Article 15 of the DP Law and Regulation 2 of the DP Regulations, and make that record available to the Commissioner on request.
5. Security Measures
5.1 General Security Obligation
Enigma Labs shall implement and maintain appropriate technical and organisational security measures to protect Customer Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, theft, alteration, or disclosure, as required by Article 14(2) of the DP Law. These measures shall ensure a level of security appropriate to the harm that might result from such events and the nature of the Customer Data to be protected.
5.2 Technical and Organisational Measures
The specific technical and organisational measures implemented by Enigma Labs are set forth in detail in Annex 2 (Technical and Organisational Measures). These measures include, but are not limited to:
(a) Access controls and authentication mechanisms;
(b) Encryption of data in transit and at rest;
(c) Network security and monitoring;
(d) Application security practices;
(e) Data protection and minimization;
(f) Security event logging and monitoring;
(g) Physical security controls;
(h) Business continuity and disaster recovery measures.
5.3 Regular Testing and Evaluation
Enigma Labs shall regularly test, assess, and evaluate the effectiveness of its technical and organisational measures for ensuring the security of the Processing. This includes:
(a) Regular vulnerability assessments and penetration testing;
(b) Security audits and compliance reviews;
(c) Incident response testing and drills;
(d) Review and updating of security policies and procedures.
5.4 Personnel Security
Enigma Labs shall ensure that all personnel with access to Customer Data:
(a) Undergo background checks where permitted by law and appropriate for their role;
(b) Receive regular security awareness and data protection training;
(c) Are bound by confidentiality obligations (contractual or statutory).
5.5 Security Documentation
Enigma Labs shall maintain documentation of its security measures and make such documentation available to the Customer upon request, subject to the confidentiality obligations set forth in the Principal Agreement.
5.6 Security Certifications
Enigma Labs is pursuing the following security certifications to demonstrate its commitment to information security:
| Certification | Status | Target Timeline |
|---|---|---|
| ISO 27001 (Information Security Management) | In Progress | 2026 |
| ISO 27017 (Cloud Security Controls) | In Progress | 2026 |
| ISO 27018 (Cloud Privacy) | In Progress | 2026 |
Upon achieving certifications, certificates and relevant audit reports will be made available to Customers under appropriate confidentiality obligations.
6. Sub-processors
6.1 General Authorization
The Customer provides general written authorisation, for the purposes of Article 24(3) of the DP Law, for Enigma Labs to engage Sub-processors to Process Customer Data on the Customer's behalf. The current list of approved Sub-processors is set forth in Annex 3 (Approved Sub-processors).
6.2 Sub-processor Requirements
Enigma Labs shall ensure that any Sub-processor:
(a) Is bound by a written contract that imposes on the Sub-processor data protection obligations substantially equivalent to those imposed on Enigma Labs under this DPA;
(b) Processes Customer Data only to the extent necessary to perform the services subcontracted to it;
(c) Implements appropriate technical and organisational security measures;
(d) Complies with Applicable Data Protection Law.
6.3 Sub-processor Monitoring
Enigma Labs conducts periodic security assessments of Sub-processors to ensure ongoing compliance with security and data protection requirements. This includes:
(a) Review of Sub-processor security certifications and audit reports;
(b) Assessment of Sub-processor security practices and controls;
(c) Monitoring of Sub-processor compliance with contractual obligations.
6.4 Sub-processor Changes
(a) Advance Notice: Enigma Labs shall provide the Customer with at least thirty (30) days' advance written notice before engaging any new Sub-processor to Process Customer Data.
(b) Notification Method: Such notice shall be provided via email to the Customer's designated contact and by updating the Sub-processor list, the current version of which is available upon request to hello@enigmalab.io.
(c) Objection Right: The Customer may object to the engagement of a new Sub-processor by providing written notice to Enigma Labs within fourteen (14) days of receiving notice of the proposed engagement.
(d) Resolution Process: If the Customer objects to a new Sub-processor, the parties shall discuss the objection in good faith. If the parties cannot reach a mutually acceptable resolution within fourteen (14) days of Enigma Labs receiving the objection, the Customer may terminate the affected Services by providing thirty (30) days' written notice to Enigma Labs.
6.5 Liability for Sub-processors
Enigma Labs shall remain fully liable to the Customer for the performance of any Sub-processor's obligations under this DPA. Any act or omission of a Sub-processor shall be deemed an act or omission of Enigma Labs for the purposes of this DPA.
6.6 Current Sub-processors
The Sub-processors currently engaged by Enigma Labs and authorized by the Customer are listed in Annex 3 (Approved Sub-processors).
7. Data Subject Rights
7.1 Assistance with Data Subject Requests
Taking into account the nature of the Processing, Enigma Labs shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests from Data Subjects exercising their rights under Articles 32 to 40 of the DP Law, including:
(a) The right to withdraw consent (Article 32 of the DP Law);
(b) The rights of access, rectification, and erasure (Article 33 of the DP Law);
(c) The right to object to Processing;
(d) The right to restriction of Processing;
(e) The right to data portability;
(f) Rights relating to automated individual decision-making, including the right to human intervention where Personal Data is Processed through autonomous or semi-autonomous systems (Regulation 10 of the DP Regulations);
(g) The right not to be discriminated against for exercising any of these rights.
7.2 Notification of Direct Requests
If Enigma Labs receives a request directly from a Data Subject relating to Customer Data, Enigma Labs shall:
(a) Not respond to such request without the Customer's prior written authorization;
(b) Promptly (within 48 hours) forward the request to the Customer;
(c) Provide the Customer with reasonable cooperation and assistance in responding to the request.
7.3 Technical Measures
Enigma Labs shall implement appropriate technical measures to enable the Customer to respond to Data Subject requests, including:
(a) Providing functionality to export, modify, or delete Customer Data as applicable;
(b) Maintaining accurate records of Processing activities;
(c) Ensuring data is stored in a structured, commonly used, and machine-readable format where appropriate.
7.4 Response Timeline and Costs
(a) Response Timeline: Enigma Labs shall respond to Customer requests for assistance with Data Subject rights within five (5) business days of receiving the request. The parties acknowledge that the DP Law requires the Customer, as Controller, to respond to Data Subjects within one month of a verified request, and Enigma Labs shall provide its assistance so as to reasonably enable the Customer to meet that deadline.
(b) Costs: Enigma Labs shall provide reasonable assistance to the Customer in responding to Data Subject requests at no additional cost, provided that such requests do not exceed a reasonable frequency or volume (generally, up to 10 requests per month).
(c) Excess Requests: If the volume or complexity of requests requires disproportionate effort, the parties may agree on appropriate cost-sharing arrangements.
8. Security Incidents
8.1 Definition of Security Incident
A "Security Incident" means any actual or reasonably suspected:
(a) Unauthorised access to, acquisition of, use of, disclosure of, or destruction of Customer Data;
(b) Event that compromises the security, confidentiality, or integrity of Customer Data;
(c) Personal Data Breach as defined under the DP Law.
Examples of Security Incidents include, but are not limited to:
- Ransomware attacks affecting systems containing Customer Data
- Unauthorised access to Customer Data by internal or external actors
- Data exfiltration or theft of Customer Data
- Malware infections affecting systems processing Customer Data
- Accidental exposure or disclosure of Customer Data
- Loss or theft of devices containing Customer Data
8.2 Security Incident Notification
(a) Timeline: Enigma Labs shall notify the Customer without undue delay and in any case within forty-eight (48) hours after becoming aware of a Security Incident affecting Customer Data.
(b) Notification Method: Notification shall be provided via email to the Customer's designated security contact. If no security contact has been designated, notification shall be sent to the Account Administrator.
(c) Content of Notification: The notification shall include, to the extent available:
(i) A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
(ii) The likely consequences of the Security Incident;
(iii) The measures taken or proposed to be taken by Enigma Labs to address the Security Incident, including measures to mitigate its possible adverse effects;
(iv) Contact details for more information, including hello@enigmalab.io.
(d) Ongoing Updates: Enigma Labs shall provide updates to the Customer as new information becomes available that is relevant to the Security Incident, at least every 24 hours during active incident response and as appropriate thereafter.
8.3 Regulatory Notifications
The parties acknowledge that, in respect of Customer Data for which the Customer is the Controller, it is the Customer's responsibility to assess and, where required, make any notification of a Personal Data Breach to the Commissioner under Article 41 of the DP Law and Regulation 8.1 of the DP Regulations, and to communicate with affected Data Subjects under Article 42 of the DP Law and Regulation 8.2, or to make any equivalent notifications required under other Applicable Data Protection Law. Where Enigma Labs acts as Controller of any affected Personal Data, Enigma Labs shall make the corresponding notifications itself.
8.4 Notification Limitations
Enigma Labs' obligation to report or respond to a Security Incident under this Section is not and will not be construed as an acknowledgment by Enigma Labs of any fault or liability with respect to the Security Incident.
8.5 Cooperation and Remediation
Enigma Labs shall:
(a) Cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of each Security Incident;
(b) Implement appropriate measures to prevent recurrence of similar Security Incidents;
(c) Provide the Customer with information reasonably requested to enable the Customer to comply with its notification obligations to the Commissioner and to Data Subjects under Articles 41 and 42 of the DP Law and Regulation 8 of the DP Regulations, or under other Applicable Data Protection Law.
8.6 Documentation and Records
Enigma Labs shall maintain records of all Security Incidents affecting Customer Data, including:
(a) Facts relating to the Security Incident;
(b) Effects of the Security Incident;
(c) Remedial action taken.
Such records shall be made available to the Customer upon request and to the Commissioner upon request.
9. Data Protection Impact Assessments
9.1 Assistance with DPIAs
Taking into account the nature of the Processing and information available to Enigma Labs, Enigma Labs shall assist the Customer with any data protection impact assessment ("DPIA") that the Customer is required to conduct under Article 20 of the DP Law prior to undertaking High Risk Processing Activities (or under any equivalent provision of other Applicable Data Protection Law), including by providing:
(a) Information about the Services and how Customer Data is Processed;
(b) Information about the technical and organisational security measures implemented;
(c) Information about Sub-processors and their Processing activities;
(d) Any other information reasonably necessary for the Customer to conduct its DPIA.
9.2 Prior Consultation
If a DPIA indicates that the Processing would result in a high risk to Data Subjects in the absence of mitigating measures, and the Customer is required or elects to consult the Commissioner before proceeding, Enigma Labs shall provide reasonable assistance to the Customer for such consultation.
9.3 Autonomous and Semi-Autonomous Systems
Where the Services involve the Processing of Customer Data through autonomous or semi-autonomous systems within the meaning of Regulation 10 of the DP Regulations, Enigma Labs shall provide the Customer with the information reasonably necessary for the Customer to meet its own obligations under Regulation 10 (including notice, transparency, and human-intervention requirements).
9.4 Information Provision
Enigma Labs shall respond to reasonable requests for information in connection with DPIAs within a reasonable timeframe, not to exceed fifteen (15) business days from receipt of the request.
10. International Data Transfers
10.1 Hosting Commitment
Enigma Labs hosts Customer Data on Scaleway cloud infrastructure located in Paris, France, and Amsterdam, Netherlands. France and the Netherlands are each an Adequate Jurisdiction under Article 26(2) of the DP Law and Appendix 3 of the DP Regulations, so Customer Data may be transferred to and stored in those locations without any additional transfer mechanism. Unless otherwise agreed in writing, all Customer Data shall be stored and processed in Adequate Jurisdictions.
10.2 Transfers to Non-Adequate Jurisdictions
Where Enigma Labs transfers Customer Data to a jurisdiction that is not an Adequate Jurisdiction, such transfer shall be made only in compliance with Article 27 of the DP Law and pursuant to one of the following transfer mechanisms:
(a) The DIFC SCCs (Article 27(2)(c) of the DP Law and Regulation 5 of the DP Regulations);
(b) Another appropriate safeguard recognised under Article 27(2) of the DP Law (such as binding corporate rules or an approved code of conduct or certification mechanism);
(c) A specific derogation under Article 27 of the DP Law, applied only where genuinely applicable and not as a routine substitute for a safeguard.
10.3 DIFC Standard Contractual Clauses
Where the DIFC SCCs are used, Enigma Labs shall enter into the DIFC SCCs with the relevant recipient (including any Sub-processor located in a non-Adequate Jurisdiction), as further described in Annex 4 (Standard Contractual Clauses).
10.4 Transfer Assessments
Before transferring Customer Data to a non-Adequate Jurisdiction, Enigma Labs shall carry out a reasonable assessment of the circumstances of the transfer and the laws and practices of the destination jurisdiction. A summary of such assessments shall be made available to the Customer upon request, subject to confidentiality obligations.
10.5 Supplementary Measures
Where required by Applicable Data Protection Law or the outcome of a transfer assessment, Enigma Labs shall implement appropriate supplementary measures (such as encryption or pseudonymisation) to protect Customer Data transferred to a non-Adequate Jurisdiction.
10.6 Onward Transfers
Enigma Labs shall ensure that any onward transfer of Customer Data by a Sub-processor is subject to protections substantially equivalent to those set out in this Section 10.
11. Disclosure Requests from Public Authorities
11.1 Handling of Requests
If Enigma Labs receives a request from a Requesting Authority for the disclosure or transfer of Customer Data, Enigma Labs shall, in accordance with Article 28 of the DP Law:
(a) Exercise reasonable caution and diligence to determine the validity and proportionality of the request, including ensuring that any disclosure is made solely for the purpose of meeting the objectives identified in the request;
(b) Assess the impact of the proposed disclosure in light of the potential risks to the rights of affected Data Subjects and, where appropriate, implement measures to minimise such risks, including by redacting or minimising the Customer Data disclosed or applying appropriate technical measures to safeguard the transfer;
(c) Where reasonably practicable, obtain appropriate written and binding assurances from the Requesting Authority that it will respect the rights of affected Data Subjects and comply with the general data protection principles of the DP Law.
11.2 Notice to the Customer
Where possible under applicable law, Enigma Labs shall provide the Customer with reasonable notice before disclosing Customer Data to a Requesting Authority, so that the Customer may seek to challenge or limit the request. Enigma Labs may consult the Commissioner in relation to any such request.
11.3 Records
Enigma Labs shall maintain a record of requests received from Requesting Authorities concerning Customer Data and the responses given, and shall make that record available to the Customer upon reasonable request, except where prohibited by applicable law.
12. Audit Rights
12.1 Documentation and Compliance Evidence
Enigma Labs shall make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations applicable to Processors under Article 24 of the DP Law and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
12.2 Primary Audit Method: Third-Party Reports
As the primary means of demonstrating compliance, Enigma Labs shall provide the Customer with:
(a) Copies of ISO 27001, ISO 27017, and ISO 27018 certificates (once obtained);
(b) Copies of SOC 2 Type II reports (once obtained);
(c) Responses to reasonable security questionnaires (up to 100 questions annually);
(d) Evidence of compliance upon reasonable request.
Enigma Labs is currently pursuing ISO 27001, ISO 27017, and ISO 27018 certifications, with expected completion in 2026.
12.3 On-Site Audits
On-site audits of Enigma Labs' facilities and operations shall be permitted only if:
(a) The information provided under Section 12.2 is insufficient to demonstrate compliance with this DPA;
(b) Following a confirmed Security Incident affecting Customer Data;
(c) Required by Applicable Data Protection Law or a regulatory authority.
12.4 On-Site Audit Conditions
Any on-site audit shall be subject to the following conditions:
(a) Advance Notice: The Customer shall provide at least thirty (30) days' advance written notice of the proposed audit;
(b) Timing: The audit shall be conducted during Enigma Labs' normal business hours;
(c) Confidentiality: The Customer and its auditors shall be bound by confidentiality obligations with respect to any proprietary or confidential information of Enigma Labs accessed during the audit;
(d) Cost Allocation: The Customer shall bear all costs associated with the audit, unless the audit reveals material non-compliance by Enigma Labs with its obligations under this DPA, in which case Enigma Labs shall bear its own costs;
(e) Scope: The scope of the audit shall be limited to those Processing activities relevant to Customer Data;
(f) Frequency: Except for audits triggered by a Security Incident or required by law, the Customer may conduct no more than one (1) on-site audit per calendar year.
12.5 Commissioner Inspections
Nothing in this Section limits the Commissioner's powers to conduct investigations and inspections under Article 46(3)(b) of the DP Law. Enigma Labs shall respond to any notice of inspection from the Commissioner's office in accordance with Regulation 4.2 of the DP Regulations, and shall inform the Customer of any Commissioner inspection that materially concerns the Processing of Customer Data, unless prohibited from doing so.
12.6 Audit Reports
Enigma Labs shall provide the Customer with a written report of any audit conducted by Enigma Labs or a third party that is relevant to the Processing of Customer Data, subject to confidentiality obligations.
12.7 Cooperation
Enigma Labs shall cooperate reasonably with the Customer and its auditors during any audit, including by:
(a) Providing access to relevant personnel;
(b) Providing access to relevant documentation and records;
(c) Answering questions and providing explanations.
13. Data Retention and Deletion
13.1 Duration of Processing
Enigma Labs shall Process Customer Data only for the duration of the Principal Agreement, unless otherwise instructed by the Customer or required by Applicable Data Protection Law.
13.2 Data Export Period
Upon termination or expiry of the Principal Agreement, or upon the Customer's written request, the Customer shall have thirty (30) days to export or retrieve Customer Data from the Services.
13.3 Data Deletion
(a) Timeline: Following the expiration of the export period under Section 13.2, Enigma Labs shall delete all Customer Data within ninety (90) days, unless:
(i) The Customer requests earlier deletion;
(ii) Applicable Data Protection Law requires retention of the Personal Data;
(iii) The data has been anonymized or aggregated such that it no longer constitutes Personal Data.
(b) Method: Deletion shall be performed using industry-standard secure deletion methods that render the data irretrievable.
(c) Exceptions: Enigma Labs may retain Customer Data beyond the deletion period to the extent required by Applicable Data Protection Law, including for:
(i) Compliance with legal obligations;
(ii) Establishment, exercise, or defense of legal claims;
(iii) Anonymized analytics and statistical purposes.
13.4 Deletion Confirmation
Upon the Customer's written request, Enigma Labs shall provide written confirmation that Customer Data has been deleted in accordance with this Section, provided that such request is made within sixty (60) days of the deletion date.
13.5 Return of Data
At the Customer's written request prior to termination, Enigma Labs shall return Customer Data to the Customer in a structured, commonly used, and machine-readable format, instead of or in addition to deletion.
14. Liability
14.1 Liability Cap
Subject to Section 14.2, each party's aggregate liability arising out of or relating to this DPA, whether in contract, tort, or under any other theory of liability, shall be limited to the same extent as set forth in the Principal Agreement. For clarity, the liability cap under the Principal Agreement is twelve (12) months of Fees paid by the Customer to Enigma Labs under the Principal Agreement in the twelve (12) months preceding the event giving rise to liability.
14.2 Exclusions from Liability Cap
The liability cap in Section 14.1 shall not apply to:
(a) Either party's gross negligence or willful misconduct;
(b) Breaches of confidentiality obligations;
(c) Indemnification obligations;
(d) Liability that cannot be limited or excluded under Applicable Data Protection Law;
(e) Death or personal injury caused by negligence;
(f) Fraud or fraudulent misrepresentation.
14.3 Statutory Allocation of Liability
The parties acknowledge the principles of liability set out in Articles 64 and 64A of the DP Law, under which:
(a) A Controller involved in Processing that infringes the DP Law is liable for the damage caused by the Processing;
(b) A Processor is liable for damage caused by Processing only where it has not complied with obligations of the DP Law specifically directed to Processors, or where it has acted outside or contrary to the lawful instructions of the Controller;
(c) Where more than one Controller or Processor is responsible for damage caused by the same Processing, each responsible person may be held jointly and severally liable to the Data Subject for the entire damage; as between the parties, each party shall be entitled to recover from the other that part of any compensation paid which corresponds to the other party's share of responsibility for the damage.
14.4 Regulatory Fines
Administrative fines imposed by the Commissioner under Article 62 of the DP Law (or by another regulator under other Applicable Data Protection Law) are the sole responsibility of the party on which they are imposed, and neither party shall be required to indemnify the other for such fines. Each party shall nevertheless remain responsible for the consequences of its own violations of Applicable Data Protection Law, including where such violations result from the Customer's unlawful instructions or from Enigma Labs' failure to comply with its obligations as a Processor.
14.5 Indemnification for Data Subject Claims
(a) The Customer shall indemnify and defend Enigma Labs against any claims, damages, and expenses (including reasonable legal fees) brought by Data Subjects or third parties arising from:
(i) The Customer's instructions to Enigma Labs;
(ii) The Customer's failure to comply with its obligations under Applicable Data Protection Law.
(b) Enigma Labs shall indemnify and defend the Customer against any claims, damages, and expenses (including reasonable legal fees) brought by Data Subjects or third parties arising from Enigma Labs' breach of its obligations under this DPA.
15. Term and Termination
15.1 Effective Date
This DPA shall become effective on the earlier of:
(a) The date the Principal Agreement is executed by both parties;
(b) The date the Customer first uses the Services.
15.2 Duration
This DPA shall remain in effect for the duration of the Principal Agreement and shall automatically terminate upon termination or expiry of the Principal Agreement, except for provisions that by their nature should survive termination.
15.3 Surviving Provisions
The following provisions shall survive termination of this DPA:
(a) Section 13 (Data Retention and Deletion);
(b) Section 14 (Liability);
(c) Section 16 (General Provisions);
(d) Any other provisions that by their nature should survive termination.
15.4 Effect on Principal Agreement
Termination of this DPA shall not affect the Principal Agreement, which shall continue in full force and effect according to its terms. However, if the Customer terminates this DPA due to Enigma Labs' material breach that cannot be cured, the Customer may also terminate the Principal Agreement for cause.
16. General Provisions
16.1 Entire Agreement
This DPA, together with the Principal Agreement, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, negotiations, and discussions, whether oral or written, relating to such subject matter.
16.2 Amendments
No amendment, modification, or waiver of any provision of this DPA shall be effective unless in writing and signed by authorized representatives of both parties. Enigma Labs may update this DPA from time to time to reflect changes in Applicable Data Protection Law or the Services. The Customer shall be notified of material changes at least thirty (30) days before they take effect.
16.3 Severability
If any provision of this DPA is held by a court of competent jurisdiction to be invalid, illegal, or unenforceable, such provision shall be deemed modified to the minimum extent necessary to make it valid, legal, and enforceable, or if such modification is not possible, such provision shall be deemed severed from this DPA, and the remaining provisions shall continue in full force and effect.
16.4 No Third-Party Beneficiaries
This DPA is for the benefit of the parties hereto and their respective successors and permitted assigns. Nothing in this DPA shall be construed to create any rights or obligations in any third party, except as expressly provided herein. For the avoidance of doubt, nothing in this DPA limits or excludes any right that a Data Subject has directly under the DP Law, including the private right of action under Article 64A of the DP Law.
16.5 Order of Precedence
In the event of any conflict or inconsistency between the provisions of this DPA and:
(a) The Principal Agreement: The provisions of this DPA shall prevail with respect to data protection matters;
(b) The DIFC SCCs (where applicable to a transfer): The provisions of the DIFC SCCs shall prevail in respect of the transfers they govern.
16.6 Governing Law
This DPA, and any dispute, claim, or non-contractual obligation arising out of or in connection with it, shall be governed by and construed in accordance with the laws applicable in the Dubai International Financial Centre, including the DP Law.
16.7 Dispute Resolution
Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute-resolution provisions of the Principal Agreement, under which the parties submit to the exclusive jurisdiction of the DIFC Courts — namely the DIFC Court of First Instance, with appeal to the DIFC Court of Appeal — subject to the informal-resolution, small-claims, and injunctive-relief provisions of the Principal Agreement. The language of proceedings shall be English.
16.8 Waiver
No waiver of any provision of this DPA shall be effective unless in writing and signed by the waiving party. No failure or delay by either party in exercising any right, power, or remedy under this DPA shall operate as a waiver thereof, nor shall any single or partial exercise of any such right, power, or remedy preclude any other or further exercise thereof.
16.9 Assignment
Enigma Labs may assign this DPA to any affiliate or in connection with a merger, acquisition, corporate reorganisation, or sale of all or substantially all of its assets. The Customer may not assign this DPA without the prior written consent of Enigma Labs, except to an affiliate or in connection with a merger, acquisition, or sale of all or substantially all of its assets.
16.10 Notices
All notices under this DPA shall be in writing and delivered to the addresses set forth in Section 17 (Contact Information) or to such other address as either party may designate by written notice. Notices shall be deemed given:
(a) When delivered personally;
(b) Three (3) business days after being sent by registered mail;
(c) One (1) business day after being sent by email with confirmation of receipt.
17. Contact Information
17.1 DPA Inquiries
For questions or inquiries regarding this Data Processing Agreement, please contact:
Email: hello@enigmalab.io
Postal Address: Enigma Labs Technology Limited Attn: Legal Department IH-00-01-01-OF-01, Level 1, Innovation One, Dubai International Financial Centre Dubai, United Arab Emirates
17.2 Data Protection Officer
Enigma Labs has voluntarily appointed a Data Protection Officer who can be contacted for matters related to data protection:
Email: hello@enigmalab.io
Postal Address: Enigma Labs Technology Limited Attn: Data Protection Officer IH-00-01-01-OF-01, Level 1, Innovation One, Dubai International Financial Centre Dubai, United Arab Emirates
17.3 Supervisory Authority
The supervisory authority for Enigma Labs' Processing of Personal Data under the DP Law is:
Commissioner of Data Protection
| Field | Details |
|---|---|
| Address | Level 14, The Gate, PO Box 74777, DIFC, Dubai, United Arab Emirates |
| commissioner@dp.difc.ae | |
| Website | https://www.difc.ae (Data Protection section) |
17.4 Customer Designated Contact
The Customer shall designate a primary contact for DPA-related matters, including Security Incident notifications and Sub-processor change notifications. The Customer shall provide Enigma Labs with the name and email address of this contact and promptly notify Enigma Labs of any changes.
17.5 Alternative Contacts
For urgent matters, the following contacts are available:
| Purpose | Contact |
|---|---|
| Security Incidents | hello@enigmalab.io |
| General Support | hello@enigmalab.io |
| Privacy Inquiries | hello@enigmalab.io |
18. Execution
18.1 Binding Agreement
This DPA is entered into and becomes legally binding upon the earlier of:
(a) The Customer's electronic acceptance of this DPA through the Services;
(b) The Customer's execution of a Principal Agreement (Terms of Service or other master agreement) that incorporates this DPA by reference;
(c) The Customer's first use of the Services after this DPA is made available.
18.2 No Physical Signature Required
No physical signature is required for this DPA to be legally binding. Electronic acceptance, including clicking "I Accept" or similar acknowledgment, or using the Services after this DPA is made available, constitutes valid acceptance under the laws applicable in the DIFC, including the DIFC Electronic Transactions Law.
18.3 Counterparts
If the parties choose to execute this DPA in counterparts (for example, in connection with an Order Form or enterprise agreement), each counterpart shall be deemed an original, and all counterparts together shall constitute one and the same agreement.
18.4 Authority
Each party represents and warrants that:
(a) It has the legal power and authority to enter into this DPA;
(b) The person accepting this DPA on behalf of the party is authorized to do so;
(c) This DPA constitutes a legal, valid, and binding obligation.
Annex 1: Description of Processing
This Annex 1 describes the Processing of Customer Data carried out by Enigma Labs on behalf of the Customer, documenting the particulars required for Controller–Processor arrangements under Article 24 of the DP Law.
A1.1 Subject Matter
The subject matter of the Processing is the provision of Enigma Labs' cybersecurity services to the Customer, including cybersecurity audits, penetration testing, incident response, and related services.
A1.2 Duration
The duration of the Processing is the term of the Principal Agreement (Terms of Service), including any renewal periods, plus the data retention period specified in Section 13 of this DPA.
A1.3 Nature and Purpose of Processing
| Element | Details |
|---|---|
| Nature of Processing | Collection, storage, analysis, alerting, reporting, and deletion of security-related data. |
| Purpose of Processing | To provide the cybersecurity services described in the Principal Agreement, including: cybersecurity audits, penetration testing, incident response, and related security assessment and remediation services. |
A1.4 Types of Personal Data
The following types of Personal Data may be Processed in connection with the Services:
| Category | Examples |
|---|---|
| Employee Identifiers | Names, usernames, employee IDs, email addresses, job titles, department information |
| Network Identifiers | IP addresses, device IDs, MAC addresses, hostnames, network session identifiers |
| Authentication Data | Login timestamps, logout timestamps, session information, authentication tokens, multi-factor authentication status |
| Security Event Data | Access logs, threat alerts, anomaly detection data, security incident records, audit trails |
| Identity and Access Management Data | User roles, permissions, group memberships, access rights, privilege levels |
A1.5 Categories of Data Subjects
The Personal Data Processed relates to the following categories of Data Subjects:
| Category | Description |
|---|---|
| Customer's Employees | Employees of the Customer who use systems or networks monitored by the Services |
| Customer's Contractors and Consultants | Third-party contractors, consultants, and temporary workers with access to Customer systems |
| Customer's End-Users | End-users of Customer's products or services, if applicable |
| Network Users | Any individuals whose data transits Customer's monitored network |
A1.6 Controller's Obligations
The Customer (Controller) shall:
(a) Ensure that it has a valid lawful basis for the Processing of Customer Data under Applicable Data Protection Law;
(b) Provide appropriate information to Data Subjects about the Processing of their Personal Data;
(c) Ensure that its instructions to Enigma Labs comply with Applicable Data Protection Law;
(d) Obtain any necessary consents or authorizations for the Processing of Customer Data;
(e) Comply with all other obligations applicable to Controllers under Applicable Data Protection Law.
A1.7 Processor's Obligations
Enigma Labs (Processor) shall:
(a) Process Customer Data only on documented instructions from the Customer;
(b) Implement appropriate technical and organisational security measures;
(c) Ensure the confidentiality of personnel with access to Customer Data;
(d) Engage Sub-processors only in accordance with Section 6 of this DPA;
(e) Assist the Customer in responding to Data Subject requests;
(f) Assist the Customer with security obligations, breach notification, and DPIAs;
(g) Delete or return Customer Data at the end of the provision of Services;
(h) Provide information to demonstrate compliance with the obligations applicable to Processors under Article 24 of the DP Law;
(i) Allow for and contribute to audits and inspections.
Annex 2: Technical and Organisational Measures
This Annex 2 describes the technical and organisational security measures implemented by Enigma Labs to protect Customer Data, as required by Article 14(2) of the DP Law.
A2.1 Organisational Measures
| Measure | Implementation |
|---|---|
| Information Security Policies | Enigma Labs maintains comprehensive information security policies aligned with ISO 27001 standards, covering areas such as access control, asset management, cryptography, physical security, operations security, communications security, and incident management. |
| Security Roles and Responsibilities | Clear security roles and responsibilities are defined, including a designated Information Security Officer responsible for overseeing the information security program. |
| Employee Background Checks | Background checks are conducted on employees with access to Customer Data, where permitted by applicable law and appropriate for their role. |
| Security Awareness Training | All employees with access to Customer Data receive regular security awareness and data protection training, including training on phishing, password security, and incident reporting. |
| Confidentiality Agreements | All employees and contractors with access to Customer Data are bound by confidentiality obligations, either contractual or statutory. |
| Incident Response Procedures | Documented incident response procedures are in place to detect, respond to, and recover from Security Incidents. Regular testing and drills are conducted. |
| Business Continuity Planning | Business continuity and disaster recovery plans are maintained and regularly tested to ensure the availability of the Services and protection of Customer Data. |
| Vendor Risk Management | A vendor risk management program is in place to assess and monitor the security practices of Sub-processors and other third-party service providers. |
| Regular Security Assessments | Regular security assessments, including vulnerability scans and penetration tests, are conducted to identify and address security weaknesses. |
A2.2 Technical Measures
Access Control
| Control | Implementation |
|---|---|
| Role-Based Access Control (RBAC) | Access to Customer Data is granted based on job roles and responsibilities, following the principle of least privilege. |
| Principle of Least Privilege | Users are granted only the minimum access rights necessary to perform their job functions. |
| Multi-Factor Authentication (MFA) | MFA is required for all administrative access to systems containing Customer Data. |
| Unique User IDs | Each user has a unique identifier for accessing systems and applications. |
| Access Reviews | Regular access reviews are conducted to ensure that access rights remain appropriate and to remove access for terminated employees or changed roles. |
| Privileged Access Management | Enhanced controls are in place for privileged accounts, including additional monitoring and approval workflows. |
Encryption
| Control | Implementation |
|---|---|
| Data in Transit | All data transmitted between the Customer and Enigma Labs' systems is encrypted using TLS 1.2 or higher. |
| Data at Rest | Customer Data stored by Enigma Labs is encrypted using AES-256 or equivalent encryption. |
| Key Management | Encryption keys are securely managed using industry-standard practices, including key rotation and secure storage. |
| Certificate Management | SSL/TLS certificates are properly managed, monitored for expiration, and renewed as needed. |
Network Security
| Control | Implementation |
|---|---|
| Firewalls | Network firewalls are deployed to control and monitor network traffic. |
| Intrusion Detection/Prevention | Intrusion detection and prevention systems (IDS/IPS) are in place to identify and block malicious activity. |
| Network Segmentation | Networks are segmented to isolate critical systems and limit the potential impact of security incidents. |
| DDoS Protection | DDoS protection measures are in place to maintain service availability. |
| VPN for Administrative Access | VPN is required for remote administrative access to production systems. |
Application Security
| Control | Implementation |
|---|---|
| Secure SDLC | Security is integrated throughout the software development lifecycle, including security requirements, design reviews, and security testing. |
| Code Reviews | Code reviews are conducted to identify and remediate security vulnerabilities. |
| Vulnerability Scanning | Regular vulnerability scanning is performed on applications and infrastructure. |
| Penetration Testing | Penetration testing is conducted periodically by qualified security professionals. |
| Web Application Firewall (WAF) | WAF is deployed to protect web applications from common attacks. |
| Input Validation | Input validation is implemented to prevent injection attacks and other input-based vulnerabilities. |
Data Protection
| Control | Implementation |
|---|---|
| Data Classification | Data classification policies are in place to identify and protect sensitive data appropriately. |
| Data Minimization | Only data necessary for the provision of Services is collected and retained. |
| Pseudonymization | Pseudonymization techniques are used where appropriate to reduce privacy risks. |
| Secure Deletion | Secure deletion methods are used when data is no longer needed, ensuring data is irretrievable. |
Monitoring and Logging
| Control | Implementation |
|---|---|
| Security Event Logging | Security events are logged, including access to Customer Data, administrative actions, and system changes. |
| Log Integrity Protection | Log integrity is protected to prevent tampering or unauthorized modification. |
| Anomaly Detection | Anomaly detection systems are in place to identify suspicious activity. |
| 24/7 Monitoring | Security monitoring is conducted 24/7 to detect and respond to security incidents. |
Physical Security
| Control | Implementation |
|---|---|
| Data Center Access Controls | Physical access to data centers (via Scaleway) is strictly controlled, with multi-factor authentication, security personnel, and surveillance systems. |
| Environmental Controls | Environmental controls are in place to protect equipment from fire, flood, and other hazards. |
| Equipment Security | Equipment containing Customer Data is physically secured and disposed of securely when no longer needed. |
Availability
| Control | Implementation |
|---|---|
| Redundant Infrastructure | Redundant infrastructure is deployed to ensure service availability. |
| Automated Backups | Automated backups are performed regularly to enable data recovery. |
| Disaster Recovery | Disaster recovery procedures are in place and regularly tested. |
| Failover Capabilities | Failover capabilities are implemented to minimize service disruption. |
Annex 3: Approved Sub-processors
This Annex 3 lists the Sub-processors currently engaged by Enigma Labs to Process Customer Data on behalf of the Customer. The Customer provides general authorisation for the use of these Sub-processors.
A3.1 List of Approved Sub-processors
| Sub-processor | Legal Entity | Address | Processing Activities | Data Location |
|---|---|---|---|---|
| Scaleway | Scaleway SAS | 8 rue de la Ville l'Evêque, 75008 Paris, France | Cloud infrastructure, data hosting, compute, storage | France and Netherlands (Adequate Jurisdictions) |
| Microsoft | Microsoft Ireland Operations Limited | One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland | Business email, productivity tools (internal communications) | Ireland / EU (Adequate Jurisdictions) |
| Intercom | Intercom R&D Unlimited Company | 2nd Floor, Stephen Court, 18-21 St. Stephen's Green, Dublin 2, Ireland | Customer support platform, chat, ticketing | Ireland / EU (Adequate Jurisdictions) |
| Highlight.io | Highlight Run, Inc. | 2261 Market Street #4242, San Francisco, CA 94114, USA | Application monitoring, error tracking, performance analytics | EU hosting; US entity access under DIFC SCCs |
A3.2 Sub-processor Details
Scaleway
| Field | Details |
|---|---|
| Purpose | Primary cloud infrastructure provider for all customer data processing |
| Data Location | Paris, France and Amsterdam, Netherlands |
| Entity Country | France |
| Transfer Mechanism | Adequate Jurisdictions under Article 26(2) of the DP Law (Appendix 3 of the DP Regulations) — no additional mechanism required |
| Note | All Customer Data is hosted on Scaleway infrastructure in France and the Netherlands. |
Microsoft
| Field | Details |
|---|---|
| Purpose | Business email and productivity tools for internal communications |
| Data Location | EU (configured for EU Data Boundary) |
| Entity Country | Ireland |
| Transfer Mechanism | Adequate Jurisdiction under Article 26(2) of the DP Law; DIFC SCCs or other Article 27 safeguards where data is accessed from a non-Adequate Jurisdiction |
| Note | Microsoft 365 is configured for EU data residency. Customer data may be referenced in support communications. |
Intercom
| Field | Details |
|---|---|
| Purpose | Customer support platform for chat and ticketing |
| Data Location | EU data hosting |
| Entity Country | Ireland |
| Transfer Mechanism | Adequate Jurisdiction under Article 26(2) of the DP Law; DIFC SCCs or other Article 27 safeguards where support data is processed in or accessed from a non-Adequate Jurisdiction (for example, the United States) |
| Note | Intercom is configured for EU data residency. Processes customer support interactions which may include limited personal data. |
Highlight.io
| Field | Details |
|---|---|
| Purpose | Application monitoring and error logging |
| Data Location | EU hosting |
| Entity Country | United States |
| Transfer Mechanism | DIFC SCCs for access from the United States (a non-Adequate Jurisdiction); data stored in the EU |
| Note | Used for platform monitoring; may process limited technical identifiers. Configured for EU data hosting. |
A3.3 Excluded Services
The following services are not considered Sub-processors under this DPA because they do not Process Customer Data:
| Service | Purpose | Reason for Exclusion |
|---|---|---|
| Vercel | Website hosting | Hosts only the marketing website; no Customer Data is processed |
A3.4 Current Sub-processor List
The current and complete list of Sub-processors is set out in this Annex 3; the latest version is available upon request to hello@enigmalab.io.
A3.5 Sub-processor Changes
Enigma Labs will provide thirty (30) days' advance notice before engaging any new Sub-processor in accordance with Section 6.4 of this DPA.
Annex 4: Standard Contractual Clauses
A4.1 DIFC Standard Contractual Clauses
For the purposes of Article 27(2)(c) of the DP Law, the Commissioner has approved and published standard contractual clauses that may be used for transfers of Personal Data outside the DIFC to a jurisdiction that is not an Adequate Jurisdiction (Regulation 5 of the DP Regulations). The DIFC SCCs, as updated by the Commissioner from time to time, are available on the Data Protection section of the DIFC website (difc.ae).
A4.2 Application
(a) Transfers of Customer Data to Adequate Jurisdictions (including the hosting locations described in Section 10.1) do not require the DIFC SCCs or any other additional transfer mechanism.
(b) Where Enigma Labs transfers Customer Data to a recipient (including a Sub-processor) in a jurisdiction that is not an Adequate Jurisdiction, Enigma Labs shall enter into the DIFC SCCs with that recipient, in the form appropriate to the roles of the parties to the transfer, unless another valid transfer mechanism under Article 27 of the DP Law applies.
(c) Copies of the DIFC SCCs executed with Sub-processors (redacted for commercially sensitive terms) shall be made available to the Customer upon reasonable request.
A4.3 Competent Supervisory Authority
The supervisory authority competent for the oversight of transfers of Personal Data by Enigma Labs out of the DIFC is the Commissioner of Data Protection (see Section 17.3 for contact details).
A4.4 Foreign-Regime Clauses
Where the Customer's own regulatory position requires the use of standard contractual clauses approved under a data-protection regime other than the DP Law, the parties may execute such clauses as an addendum to this DPA in accordance with Section 2.4. Such clauses supplement, and do not replace, the protections of this DPA.
A4.5 Conflict Resolution
In the event of any conflict between the provisions of the DIFC SCCs and other provisions of this DPA in respect of a transfer governed by the DIFC SCCs, the provisions of the DIFC SCCs shall prevail.
Document Information
| Field | Details |
|---|---|
| Document Title | Data Processing Agreement |
| Company | Enigma Labs Technology Limited |
| DIFC License Number | CL13349 |
| Legal Entity | Limited Liability Company (DIFC) |
| Registered Address | IH-00-01-01-OF-01, Level 1, Innovation One, Dubai International Financial Centre, Dubai, United Arab Emirates |
| Country of Incorporation | United Arab Emirates |
| Governing Law | Laws applicable in the Dubai International Financial Centre |
| Supervisory Authority | Commissioner of Data Protection (DIFC) |
| Website | https://www.enigmacyber.com |
| DPA URL | https://www.enigmacyber.com/dpa |
| Sub-processor List | Annex 3; latest version available upon request to hello@enigmalab.io |
| Privacy Policy URL | https://www.enigmacyber.com/privacy |
| Terms of Service URL | https://www.enigmacyber.com/tos |
| DPA Contact Email | hello@enigmalab.io |
| DPO Email | hello@enigmalab.io |
| Security Contact Email | hello@enigmalab.io |
| Data Hosting Location | France and Netherlands (Adequate Jurisdictions under the DP Law) |
| Effective Date | August 3, 2026 |
| Last Updated | August 3, 2026 |
| Version | 2.0 |
Version History
| Version | Date | Changes |
|---|---|---|
| 1.0 | January 22, 2026 | Initial release |
| 1.1 | January 28, 2026 | Minor administrative updates |
| 1.2 | May 19, 2026 | Contact and document-information updates |
| 2.0 | August 3, 2026 | Rewrite to align the DPA with the DIFC Data Protection Law, DIFC Law No. 5 of 2020 (as amended by DIFC Law No. 2 of 2022 and the DIFC Laws Amendment Law, DIFC Law No. 1 of 2025) and the DIFC Data Protection Regulations (Consolidated Version No. 2, in force 1 September 2023). Replaced GDPR-based definitions, obligations, and annexes with their DP Law equivalents; changed the governing law to the laws applicable in the DIFC and dispute resolution to the DIFC Courts (aligned with the Terms of Service); designated the Commissioner of Data Protection as supervisory authority; reframed international transfers around the Commissioner's adequacy list (Article 26) and the Commissioner-approved standard contractual clauses (Article 27 and Regulation 5); added a disclosure-requests provision reflecting Article 28; restated liability in line with Articles 64 and 64A; extended Sub-processor change notice from 7 to 30 days for consistency with the Privacy Policy; corrected the postal addresses in Section 17. |
Related Documents
| Document | URL | Description |
|---|---|---|
| Privacy Policy | https://www.enigmacyber.com/privacy | How Enigma Labs processes personal data as a Controller |
| Terms of Service | https://www.enigmacyber.com/tos | General terms governing use of the Services |
| Cookie Policy | https://www.enigmacyber.com/cookies | How Enigma Labs uses cookies on its website |
| Sub-processor List | Available upon request to hello@enigmalab.io | Current list of approved Sub-processors |
This Data Processing Agreement is designed to meet the requirements of the DIFC Data Protection Law, DIFC Law No. 5 of 2020 (as amended), and other applicable data protection laws. For questions or concerns, please contact us at hello@enigmalab.io.
© 2026 Enigma Labs Technology Limited. All rights reserved.