Data Processing Agreement

Draft effective date: 12 August 2026 · Attach this to the signed commercial agreement after legal review and completion of the legal-entity and governing-law details.

1. Roles and purpose

This Data Processing Agreement (DPA) forms part of the Shareek Terms of Service or other service agreement between Customer and Shareek. For Customer Data containing personal data, Customer is the controller (or responsible business) and Shareek is the processor (or service provider), except where applicable law requires a different role.

Shareek may process personal data only on Customer's documented instructions and as needed to provide, secure, support, and improve the Service, comply with law, or act on a documented instruction from Customer. The details of processing are in Schedule 1.

2. Customer responsibilities

Customer confirms it has a lawful basis to use the personal data and to instruct Shareek to process it. Customer is responsible for privacy notices, individual rights requests, WhatsApp opt-in, call-recording consent, message content, and instructions it gives to Shareek. Customer must not instruct Shareek to process data unlawfully.

3. Shareek commitments

Shareek will: (a) process personal data confidentially; (b) ensure people authorised to process it are bound by confidentiality duties; (c) use reasonable technical and organisational measures to protect it; (d) help Customer reasonably respond to verified individual-rights requests and security obligations; and (e) promptly tell Customer if Shareek believes an instruction violates applicable data-protection law.

4. Security measures

Shareek will maintain safeguards appropriate to the risks, including encrypted HTTPS communications, authentication, role-based permissions, separation of customer workspaces, restricted staff access, and reasonable logging and backup controls. Customer acknowledges that no system is perfectly secure and must protect its accounts, authorised-user access, and devices.

5. Sub-processors

Customer authorises Shareek to use carefully selected sub-processors where reasonably needed to host, secure, communicate through, or support the Service. Shareek will require sub-processors to protect personal data under written obligations no less protective than the relevant parts of this DPA. On request, Shareek will provide Customer with a current list of material sub-processors. Customer may raise a reasonable data-protection objection within 10 business days of notice of a new material sub-processor; the parties will work in good faith on a solution, and Customer may end the affected Service if none is available.

6. International transfers

Customer understands that service providers, including Meta/WhatsApp where Customer connects that platform, may process data in countries other than Iraq. Where a cross-border transfer requires a legal safeguard, the parties will use an appropriate lawful transfer mechanism. Customer remains responsible for its own direct use of third-party platforms.

7. Security incidents

If Shareek becomes aware of a confirmed personal-data breach affecting Customer Data, it will notify Customer without undue delay and provide reasonably available information to help Customer meet its legal duties. Shareek's notice is not an admission of fault. Customer is responsible for deciding whether to notify regulators or affected people, unless law requires Shareek to do so.

8. Requests, audits, and records

Shareek will promptly forward to Customer any direct request from an individual about Customer Data, unless law prevents it. Shareek will make information reasonably necessary to show compliance available on written request, subject to confidentiality and security. No more than once a year, Customer may request a reasonable remote audit or, where that is insufficient, an on-site audit on 30 days' notice during business hours, at Customer's cost, without access to other customers' data or Shareek's confidential security information.

9. Deletion and return

At the end of the Service and on Customer's written instruction, Shareek will delete or return Customer Data within 30 days where technically feasible, unless it must retain it by law, for a documented dispute, or in secure backups until their normal rotation. Retained data remains protected and will not be actively used except for the retention reason.

10. Priority and legal review

This DPA controls over conflicting terms about processing personal data. The governing law, dispute venue, legal entity names, and any mandatory local clauses must be completed in the signed version. This draft is not legal advice and should be reviewed by qualified counsel before use.

Schedule 1 — Processing details

  • Subject matter: operation and support of Shareek's lead, call, authorised business messaging, reporting, and dashboard services.
  • Duration: the subscription term plus the deletion/retention period in this DPA.
  • Nature and purpose: collecting, storing, organising, retrieving, displaying, transmitting, supporting, securing, and deleting Customer Data as needed to provide the Service.
  • Data subjects: Customer's employees, representatives, leads, customers, prospects, callers, and authorised users.
  • Data categories: business contact details, account and permission data, lead records, call metadata and recordings where consented, business messages, delivery status, and operational notes.
  • Special or sensitive data: Customer must not intentionally submit sensitive personal data unless agreed in writing and legally permitted.