Data Processing Agreement
Last updated: June 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the merchant ("Controller") and Restware ("Processor") governing the processing of personal data carried out by Restware on the Controller's behalf. A countersigned copy is available on request at [email protected].
1. Definitions
- Controller: the merchant that determines the purposes and means of processing personal data and that connects its store and business systems to Zid Integrations.
- Processor: Restware, which processes personal data on behalf of and on the documented instructions of the Controller.
- Personal Data: any information relating to an identified or identifiable natural person processed through the service (for example, a customer's name, phone number, or address contained in an order).
- Data Subject: the individual to whom Personal Data relates, typically the Controller's end customer.
- Sub-processor: a third party engaged by the Processor to assist in providing the service.
- Applicable Law: the Saudi Personal Data Protection Law (PDPL) and any other data protection laws applicable to the Controller's use of the service.
2. Roles and scope of processing
The Controller is the controller of the Personal Data, and Restware is the processor. Restware processes Personal Data only to provide and support the service and only on the Controller's documented instructions, including as set out in this DPA and the main agreement.
- Subject matter: synchronisation of commerce data between the Controller's store and its ERP or accounting systems.
- Duration: for as long as the Controller uses the service, plus the deletion period described in Section 7.
- Nature and purpose: receiving order, invoice, inventory, and related events and writing them into the Controller's connected systems.
- Types of Personal Data: limited to data contained in commerce events. Restware minimises this data: directly identifying customer fields are stripped at ingestion and redacted from stored execution records.
- Categories of Data Subjects: the Controller's end customers.
3. Processor obligations
- Process Personal Data only on the Controller's documented instructions, unless required by Applicable Law.
- Ensure that personnel authorised to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational security measures, as described in the Restware Security page, including encryption at rest and in transit, data minimisation and redaction, row-level isolation, and access controls.
- Assist the Controller, taking into account the nature of processing, in fulfilling its own compliance obligations.
4. Sub-processors
The Controller authorises Restware to engage Sub-processors to deliver the service. Each Sub-processor is bound by data protection obligations no less protective than those in this DPA. Current categories of Sub-processors include:
- Cloud hosting and managed database infrastructure
- Durable workflow and execution orchestration
- Webhook delivery and edge processing
- Transactional email and notification delivery
Restware will inform the Controller of any intended change to its Sub-processors and give the Controller the opportunity to object on reasonable data-protection grounds. A current list is available at [email protected].
5. Data subject rights
Taking into account the nature of the processing, Restware will assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests from Data Subjects to exercise their rights — including access, correction, deletion, and portability — under Applicable Law.
6. Personal data breach notification
Restware will notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data breach affecting the Controller's data. The notification will describe the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
7. Return and deletion of data
On termination of the service, or on the Controller's written request, Restware will delete or return the Controller's Personal Data and delete existing copies within 30 days, unless retention is required by Applicable Law. Routine customer-bearing records are additionally subject to automatic retention purges during normal operation.
8. International transfers and data residency
Restware processes and stores data on infrastructure selected to meet the Controller's data-residency requirements. Where any transfer outside the Controller's jurisdiction is necessary, Restware will ensure an appropriate safeguard recognised under Applicable Law is in place.
9. Audits
On reasonable written notice, and subject to confidentiality, Restware will make available to the Controller the information necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by the Controller or an auditor it mandates.
10. Governing law
This DPA is governed by the laws of the Kingdom of Saudi Arabia, including the PDPL. In the event of a conflict between this DPA and the main agreement on data-protection matters, this DPA prevails.
11. How to execute this DPA
To request a countersigned copy of this DPA, or to discuss specific data-protection requirements, contact [email protected].