Risper Tax

Data Processing Agreement

Last updated 13 Sep 2026

This Data Processing Agreement ("DPA") applies where RAIMS Digital Technologies SP LLC ("Processor") processes personal data on behalf of a customer ("Controller") in providing Risper CRM - TAX. It forms part of our Terms & Conditions and takes effect automatically when you open an account — no signature is required, although we will sign a counterpart on request.

It is written to meet Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its executive regulations.

1. Roles

  • You are the Controller of the personal data you put into your account — your clients, employees, leads, suppliers and contacts. You decide why it is held and what is done with it.
  • We are the Processor of that data. We act only on your documented instructions.
  • We are an independent Controller for our own account, billing, security and support data, which is governed by our Privacy Policy, not by this DPA.

2. Subject matter and scope

  • Subject matter — provision of the Service under the Terms.
  • Duration — for as long as your account exists, plus the retention windows in our Data Deletion & Retention Policy.
  • Nature and purpose — hosting, storage, structuring, retrieval, transmission, backup and deletion of records, so that you can run your business.
  • Types of personal data — as determined by you. Typically: names, job titles, email addresses, telephone numbers, addresses, identity and licence document details, employment and payroll details where you use those modules, and the content of documents you upload.
  • Categories of data subject — your clients, employees, job applicants, leads, suppliers and other contacts.

3. Our obligations as Processor

  • Process personal data only on your documented instructions, which the Terms, this DPA and your use of the Service constitute — unless UAE law requires otherwise, in which case we will tell you before processing unless the law forbids it.
  • Tell you if, in our opinion, an instruction breaches applicable data protection law.
  • Ensure that everyone authorised to access the data is bound by confidentiality.
  • Implement and maintain appropriate technical and organisational security measures (section 5).
  • Assist you, so far as reasonably possible, with responding to data-subject requests, with security, with breach notification, and with impact assessments.
  • On termination, delete or return the data in accordance with the Data Deletion & Retention Policy.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA.

4. Your obligations as Controller

  • Ensure you have a lawful basis for the data you upload, and have given the notices and obtained the consents your own data subjects require.
  • Give lawful instructions, and do not use the Service in a way that breaches data protection law.
  • Configure the Service correctly — roles, permissions, who can see what, retention settings, and which integrations you enable.
  • Keep account credentials secure, and remove users who should no longer have access.
  • Answer data-subject requests about your own data. We will support you; the obligation is yours.

5. Security measures

  • Encryption in transit (TLS) for all traffic.
  • Per-account tenancy separation, with every read and write scoped to the account and company that owns it.
  • Role-based access control, and least-privilege administrative access.
  • Passwords stored only as salted one-way hashes; application secrets held outside the code.
  • Activity logging on business records — who changed what, when and from where.
  • Regular encrypted backups, and tested restoration.
  • Patching of the application and its dependencies, and monitoring for errors and abuse.

6. Sub-processors

You give general authorisation for us to engage sub-processors. Each is bound by written terms imposing protections no less onerous than this DPA, and we remain responsible to you for their performance. The categories we use are:

CategoryWhat they do
Cloud hosting and infrastructureRun the servers, storage and backups on which the Service operates
Email deliverySend transactional and notification email on your behalf
Messaging deliverySend SMS and WhatsApp messages where you enable them
Payment processingTake subscription payments; card details go to them, not to us
Error monitoring and loggingCapture diagnostics so faults can be found and fixed
AI providersProcess the text you submit to an AI assistant, where you use those features

The current named list is available on request from privacy@rispercrm.tax. We give at least 30 days' notice before adding or replacing a sub-processor that processes Controller data; if you reasonably object on data-protection grounds within that period, we will work with you on an alternative, and if none is workable you may terminate the affected part of the Service without penalty for the unused period.

7. International transfers

Where personal data is transferred outside the UAE, we do so only where the destination is recognised as offering an adequate level of protection, or under appropriate safeguards such as contractual clauses obliging the recipient to maintain the standard the UAE PDPL requires, or with explicit consent, as permitted by Articles 22 and 23 of the PDPL.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any case in line with the timescales required by the PDPL. The notification will describe, so far as known, the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken. We will cooperate with you in investigating and remediating it. Notification is not an admission of fault.

9. Data-subject requests

If we receive a request directly from one of your data subjects, we will not respond to it ourselves except to confirm that the request should be sent to you. We will forward it to you promptly and assist you in answering it using the search, export and deletion features of the Service.

10. Audit

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this DPA, and where appropriate a summary of our security measures or of any third-party audit report. On-site audits are by prior agreement, at your cost, under confidentiality, and arranged so as not to disrupt other customers.

11. Return and deletion

You may export your data at any time while the account is active. On termination, data is handled under our Data Deletion & Retention Policy: deleted from live systems within 30 days of a verified request or 90 days after the account closes, and from backups within a further 90 days, except where the law requires it to be kept.

12. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.

13. Contact

RAIMS Digital Technologies SP LLC

Data protection contact: privacy@rispercrm.tax

← Back to sign in
© 2026 Risper Tax. All rights reserved.