Data Processing Addendum

Effective Date: May 8, 2026

Last Updated: August 15, 2026

Last Reviewed: August 15, 2026

Next Review Due: February 15, 2027

This Data Processing Addendum ("DPA") forms part of the agreement between Parkberry Marketing Services - FZCO ("Processor," "we," "us," or "our") and the business entity using our Services ("Controller," "you," or "your") and applies where we process personal data on your behalf in connection with the Services. This DPA supplements your agreement with us, our Terms of Service, and our Privacy Policy, and is governed by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL").

1. Definitions

  • Applicable Privacy Laws — UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, its Executive Regulations, and any other data protection law applicable to the processing described in this DPA.
  • Controller — the entity that determines the purposes and means of processing Personal Data, in this case, you.
  • Personal Data — any information relating to an identified or identifiable natural person, as defined under the PDPL.
  • Processor — the entity that processes Personal Data on behalf of the Controller, in this case, Parkberry.
  • Processing — any operation performed on Personal Data, including collection, use, storage, disclosure, analysis, deletion, or disposal.
  • Services — the products and services we provide to you under our agreement, including the Platform, websites, communications tools, and related support.

2. Roles and Scope

You are the Controller of Personal Data you submit to the Services about your customers, leads, or personnel. We act as your Processor and will process that Personal Data only on your documented instructions and as described in this DPA and our agreement, unless otherwise required by UAE law.

3. Processing Instructions and Restrictions

  • We will process Personal Data only to provide the Services, comply with law, or as otherwise agreed with you in writing.
  • We will not use, disclose, or retain Personal Data outside the scope of our direct business relationship with you, except as permitted by Applicable Privacy Laws or our agreement.
  • We will not combine Personal Data received in connection with the Services with Personal Data we receive from other sources, except as necessary to provide or improve the Services, detect security incidents, or as permitted by law.
  • If we believe an instruction from you would violate Applicable Privacy Laws, we will notify you before carrying it out.

4. Confidentiality and Personnel

We ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory, and receive training on data protection appropriate to their role.

5. Sub-processors

You authorize us to engage the sub-processors listed below to process Personal Data on your behalf. We remain responsible for each sub-processor's performance of its obligations consistent with this DPA.

Sub-processorService providedLocation
HighLevel LLC (GoHighLevel)CRM, website platform, SMS/WhatsApp messaging, marketing automation, client portalUnited States
Stripe, Inc.Payment processing and billingUnited States
Meta Platforms, Inc.Advertising delivery and measurement (where you have engaged us for social media advertising)United States
Google LLCGoogle Ads, Google Analytics, and Local Service Ads management (where applicable to your plan)United States

We will provide you at least 30 days' advance notice before adding a new sub-processor or making a material change to an existing sub-processor arrangement, unless legal or security reasons prevent advance notice, in which case we will notify you as soon as reasonably practicable. If you object on reasonable data-protection grounds, we will work with you in good faith to resolve the objection.

6. Security

We implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, loss, or alteration, taking into account the nature of the processing and the risks involved. These measures may include access controls, encryption in transit, activity logging, vendor due diligence, and incident response procedures.

7. Data Subject Requests and Assistance

Taking into account the nature of the processing, we will assist you, insofar as reasonably possible, to fulfill your obligation to respond to data subject requests under the PDPL, including requests to access, correct, or delete Personal Data. Where a request is submitted directly to us, we will direct the requester to contact you, unless we are legally required to respond directly.

8. Personal Data Breach Notification

If we become aware of a breach affecting Personal Data we process on your behalf, we will notify you without undue delay after becoming aware of the breach, and will provide the information reasonably available to us to help you assess the breach and meet any notification obligations you may have to the UAE Data Office or affected individuals under the PDPL.

9. Data Retention and Deletion

We retain Personal Data only as long as necessary to provide the Services and as described in our Privacy Policy. Upon termination of the Services, or upon your written request, subject to any legal retention requirements, we will delete or return Personal Data in our possession.

10. Audits

Upon reasonable written request, we will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security practices or a completed security questionnaire. Where an on-site audit is required by Applicable Privacy Laws, it will be conducted during business hours, with reasonable advance notice, and subject to confidentiality and security controls.

11. International Transfers

Personal Data we process on your behalf may be transferred to and processed in the United States or other countries outside the United Arab Emirates by our sub-processors listed in Section 5. Where we transfer Personal Data outside the UAE, we rely on sub-processors that maintain contractual, technical, and organizational safeguards intended to protect Personal Data to a standard consistent with the PDPL's cross-border transfer requirements.

12. Liability

Liability arising from our processing of Personal Data under this DPA is subject to the limitations and exclusions in your agreement with us, except where such limitations are prohibited under UAE law, including liability arising from gross negligence, fraud, or intentional misconduct.

13. Contact

For questions about this DPA or our processing of Personal Data on your behalf, contact:

Parkberry Marketing Services - FZCO

License No. 84161

Registered Office: IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates

Email: bp@parkberrygroup.com

Phone: +971 50 318 3259

This document was drafted with the assistance of AI and researched against publicly available UAE legal sources, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. It is not a substitute for review by a UAE-licensed lawyer before publication or use. The sub-processor list in Section 5 should be confirmed and updated to reflect the exact tools used for each client engagement.