Data Processing Agreement
This Data Processing Agreement (DPA) governs the processing of personal data by Optruss on behalf of the customer when incorporated into a signed commercial service agreement.
1. Preamble & Legal Applicability
This online DPA reflects Optruss’s standard data protection framework. It enters into legal force only when referenced and incorporated into a signed commercial contract, order form, or Master Subscription Agreement (MSA) executed between Optruss and the purchasing customer organization.
This Agreement ensures compliance with applicable data protection laws, including the Saudi Personal Data Protection Law (PDPL) and relevant international data privacy principles.
2. Roles: Controller & Processor
The parties acknowledge and agree that with respect to customer personal data processed through the platform:
- Customer is the Data Controller: Customer determines the lawful purposes and means of processing personal data and warrants that all necessary consents and legal bases have been established.
- Optruss is the Data Processor: Optruss processes customer personal data solely on behalf of and under the documented instructions of the Customer to deliver the services.
3. Scope, Nature & Categories of Processing
Processing covers personal data submitted by or collected on behalf of Customer in connection with using the Optruss platform. Categories typically include user profile data (names, corporate emails, user credentials), work order execution logs, technician digital signatures, and machine maintenance records.
Optruss does not knowingly solicit or require sensitive personal data categories unrelated to physical asset maintenance operations.
4. Documented Instructions & Compliance
Optruss processes customer personal data exclusively in accordance with Customer’s documented instructions, including transfers, unless required to do so by applicable laws of the Kingdom of Saudi Arabia or relevant regulatory mandates.
5. Personnel Confidentiality & TOMs
Optruss ensures that persons authorized to process customer personal data are committed to confidentiality through legally binding agreements and undergo regular security awareness training.
Technical and organizational measures (TOMs) implemented include:
- TLS 1.3 cryptographic transit protection and AES-256 at-rest storage encryption.
- Role-based access controls (RBAC) and enforced multi-factor authentication (MFA).
- Strict network segregation and optional air-gapped sovereign deployment for high-criticality assets.
6. Subprocessors & Regional Infrastructure
Customer provides general authorization for Optruss to engage subprocessors to support platform infrastructure. Optruss maintains a list of approved infrastructure vendors and provides options for dedicated in-kingdom data residency within certified Saudi cloud regions.
7. Security Incident & Breach Notification
In the event of a confirmed personal data breach impacting customer data, Optruss will notify Customer without undue delay in accordance with statutory reporting timelines under the Saudi PDPL, detailing the nature of the breach, affected data categories, and immediate mitigation actions taken.
8. Data Subject Requests & Regulatory Assistance
Taking into account the nature of the processing, Optruss assists Customer through appropriate technical and organizational measures in fulfilling its obligation to respond to data subjects exercising their statutory rights.
9. Data Deletion & Return Upon Termination
Upon termination or expiration of the service agreement, Optruss will, at Customer’s written election, securely delete or return all customer personal data in industry-standard formats, unless retention is mandated by applicable law.
10. Audit Framework & Cross-Border Transfers
Optruss makes available to Customer all information reasonably necessary to demonstrate compliance with this DPA, including third-party security audit summaries and compliance certifications.
Any transfer of customer personal data outside the Kingdom of Saudi Arabia complies strictly with the criteria, approved standard contractual clauses, and safeguards established by the Saudi Personal Data Protection Law (PDPL) and SDAIA regulatory frameworks.
Enterprise data processing with verified control.
Need an execution-ready DPA aligned with your organization's legal and regional compliance requirements? Reach out directly to our team.