Data Processing Agreement
Last updated August 2, 2026
Where Presagon processes personal data on your behalf, these processor terms apply. They set out what we process and why, the security we commit to, the subprocessors we use and how changes to them are announced, how international transfers are covered, and what happens to your data when you leave. This agreement takes effect automatically with the Terms of Service; no signature is needed.
1. Parties and how this agreement is entered into
This Data Processing Agreement ("DPA") is between SPATARI DANIEL CONSULTANCY - FZCO, Dubai, United Arab Emirates("Processor", "we") and the customer identified by the account using Presagon("Controller", "you").
It forms part of the Terms of Service and takes effect when you accept those terms. No signature is required for it to apply. If your procurement process needs a countersigned copy, write to hello@presagon.com.
This DPA applies only where you are subject to a data protection law that requires it and we process personal data on your behalf. It does not apply to data for which we are the controller, which is described in the Privacy Policy: your own account details, your session records, your billing status, and our site analytics.
2. Definitions
"Data Protection Law" means any law applicable to the processing under this DPA, including the UK GDPR, the EU General Data Protection Regulation, and the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. "Personal Data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the applicable Data Protection Law. "Customer Personal Data" means personal data we process on your behalf under the Terms of Service. Other capitalised terms have the meaning given in the Terms of Service.
3. Roles of the parties
You are the controller of Customer Personal Data and we are your processor. You are responsible for the lawfulness of the data you put into the service, for having a lawful basis for it, and for giving whatever notices and obtaining whatever consents your own data subjects are owed. We are responsible for processing it only as described here.
4. Subject matter, duration, nature, and purpose
| Item | Detail |
|---|---|
| Subject matter | Provision of the Presagon competitor-monitoring service under the Terms of Service. |
| Duration | For as long as your account exists, plus the deletion period in clause 12. |
| Nature and purpose | Hosting, storage, retrieval, organisation, transmission, AI interpretation of monitored content, delivery of notifications, and support and troubleshooting, in each case to operate the service for you. |
| Types of personal data | The names and email addresses of the users you add to your workspace and of the recipients you configure for notifications; and any personal data you choose to include in free-text fields such as your product description or your notes. |
| Categories of data subject | Your personnel and anyone else you give workspace access to or configure as a notification recipient; and any individual you choose to reference in free-text fields. |
| Special categories | None. The service is not designed for special-category or criminal-offence data and you must not put such data into it. |
The service is built to monitor the published activity of businesses. It does not require personal data about third parties to work, and the Acceptable Use Policy forbids using it to build profiles of individuals.
5. Our obligations
We will:
- (a)process Customer Personal Data only on your documented instructions, which are the Terms of Service, this DPA, and your use of the features of the service, unless a law we are subject to requires otherwise, in which case we will tell you first unless that law forbids it;
- (b)tell you if, in our opinion, an instruction breaches Data Protection Law;
- (c)ensure that anyone authorised to process Customer Personal Data is bound by an obligation of confidentiality;
- (d)implement and maintain the technical and organisational measures described in clause 6;
- (e)not sell Customer Personal Data, use it for advertising, or use it to train AI models, and not use it for any purpose other than providing the service to you; and
- (f)assist you as set out in clauses 8, 10, and 11.
6. Security
We will implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing as well as the risks involved. The measures in force are described in the security overview, which forms part of this DPA. We may change them, provided the level of protection is not reduced.
7. Subprocessors
You give us general authorisation to engage subprocessors. Those currently engaged are listed on the subprocessors page.
We will give at least 30days' notice before adding or replacing a subprocessor that processes personal data, by updating that page and, if you have asked to be notified by email, by email. You may object on reasonable, documented data-protection grounds within the notice period; if we cannot offer an alternative, you may terminate the affected subscription and receive a refund of the unused remainder of your current period.
We will impose on each subprocessor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for each subprocessor's performance.
8. Data subject requests
The service lets you access, correct, export, and delete the data in your workspace yourself, which will usually be enough to answer a data subject. Where it is not, we will provide reasonable assistance, taking into account the nature of the processing, so that you can meet your obligations. If a data subject contacts us directly about Customer Personal Data, we will not respond substantively; we will tell them to contact you, and pass the request on where we can identify the workspace it relates to.
9. International transfers
We operate from the United Arab Emirates and engage subprocessors established in the United States and the United Kingdom, so Customer Personal Data is transferred internationally. Where Customer Personal Data protected by UK or EU law is transferred outside those areas, the parties agree that the European Commission's standard contractual clauses for controller-to-processor transfers, and the UK international data transfer addendum where the UK GDPR applies, are incorporated into this DPA and apply to that transfer, with you as data exporter and us as data importer, completed by reference to the details in clause 4, the security measures in clause 6, and the subprocessor list in clause 7. Where the applicable law recognises a different valid mechanism, that mechanism applies instead.
10. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event soon enough for you to meet your own notification deadlines. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses, and reasonable assistance with your own notifications. Notifying you is not an admission of fault.
11. Impact assessments and prior consultation
On request, and taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that relates to our processing of Customer Personal Data. The material on this page, the security overview, and the subprocessors page are intended to supply most of what such an assessment needs.
12. Deletion and return
You can export your data at any time while your subscription is active. When you close your account, or on your written instruction, we will delete Customer Personal Data. Copies held in routine backups are not individually purged; they are overwritten on their ordinary expiry cycle, and remain subject to this DPA until they are. We may retain data where a law we are subject to requires it, in which case we will keep only what that law requires and continue to protect it. On request we will confirm deletion in writing.
13. Audit
On reasonable written request, and no more than once in any twelve-month period unless a supervisory authority requires otherwise or a personal data breach has occurred, we will make available the information necessary to demonstrate compliance with this DPA. We will answer a reasonable security questionnaire and provide the documentation we hold, including any third-party reports our providers publish. An on-site inspection is available only where the information provided is genuinely insufficient, must be arranged with reasonable notice, must not disrupt the service or compromise the confidentiality of other customers, and is at your cost.
14. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, which apply to all claims under the Terms of Service and this DPA in aggregate rather than separately. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where it conflicts with the standard contractual clauses, those clauses prevail.
15. Term and changes
This DPA runs for as long as we process Customer Personal Data. We may update it to reflect a change in law, in the service, or in our providers; if a change materially reduces your protection we will notify account holders by email before it takes effect. The date at the top of this page records the current version, and superseded versions are available on request.
16. Contact
Data protection enquiries, countersignature requests, security questionnaires, and subprocessor notification requests: hello@presagon.com.
Related: Subprocessors · Security Overview · Privacy Policy · Terms of Service