This Data Processing Agreement ("DPA") applies where RAIMS Digital Technologies SP LLC ("Processor") processes personal data on behalf of a customer ("Controller") in providing Risper CRM - TAX. It forms part of our Terms & Conditions and takes effect automatically when you open an account — no signature is required, although we will sign a counterpart on request.
It is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its executive regulations.
You give general authorisation for us to engage sub-processors. Each is bound by written terms imposing protections no less onerous than this DPA, and we remain responsible to you for their performance. The categories we use are:
| Category | What they do |
|---|---|
| Cloud hosting and infrastructure | Run the servers, storage and backups on which the Service operates |
| Email delivery | Send transactional and notification email on your behalf |
| Messaging delivery | Send SMS and WhatsApp messages where you enable them |
| Payment processing | Take subscription payments; card details go to them, not to us |
| Error monitoring and logging | Capture diagnostics so faults can be found and fixed |
| AI providers | Process the text you submit to an AI assistant, where you use those features |
The current named list is available on request from privacy@rispercrm.tax. We give at least 30 days' notice before adding or replacing a sub-processor that processes Controller data; if you reasonably object on data-protection grounds within that period, we will work with you on an alternative, and if none is workable you may terminate the affected part of the Service without penalty for the unused period.
Where personal data is transferred outside the UAE, we do so only where the destination is recognised as offering an adequate level of protection, or under appropriate safeguards such as contractual clauses obliging the recipient to maintain the standard the UAE PDPL requires, or with explicit consent, as permitted by Articles 22 and 23 of the PDPL.
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any case in line with the timescales required by the PDPL. The notification will describe, so far as known, the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken. We will cooperate with you in investigating and remediating it. Notification is not an admission of fault.
If we receive a request directly from one of your data subjects, we will not respond to it ourselves except to confirm that the request should be sent to you. We will forward it to you promptly and assist you in answering it using the search, export and deletion features of the Service.
On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this DPA, and where appropriate a summary of our security measures or of any third-party audit report. On-site audits are by prior agreement, at your cost, under confidentiality, and arranged so as not to disrupt other customers.
You may export your data at any time while the account is active. On termination, data is handled under our Data Deletion & Retention Policy: deleted from live systems within 30 days of a verified request or 90 days after the account closes, and from backups within a further 90 days, except where the law requires it to be kept.
Liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.
RAIMS Digital Technologies SP LLC
Data protection contact: privacy@rispercrm.tax