UK Data Processing Addendum
This UK Data Processing Addendum (DPA) forms part of the agreement between Savari L.L.C-FZ and the customer identified in the applicable Order Form. It applies when Savari processes Customer Personal Data as processor for that customer and becomes binding only when incorporated into, or otherwise validly accepted with, the parties’ agreement.
Savari L.L.C-FZ is a limited liability company formed under Meydan Free Zone regulations in the United Arab Emirates, formation number 2528797 and business licence number 2528797.01, with its registered office at Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates.
1. Definitions
Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, UAE Federal Decree-Law No. 45 of 2021 where applicable, and any other data-protection law identified in the Order Form. Customer Personal Data means personal data in Customer Data that Savari processes as processor. Controller, Processor, Personal Data Breach, Processing, Data Subject, and Supervisory Authority have the meanings given by applicable law.
2. Roles and scope
The Customer is controller and Savari is processor for Customer Personal Data, except where the parties document a different role for a specific activity. Savari is an independent controller for its own account administration, contracting, billing, security, compliance, fraud prevention, customer relationship management, and appropriately configured product analytics; that processing is described in the Privacy Policy.
3. Documented instructions
Savari will process Customer Personal Data only to provide, secure, support, and maintain the configured Service; follow the agreement, Order Form, authorised configuration, and other documented Customer instructions; or comply with applicable law. Where law requires processing, Savari will inform the Customer first unless prohibited.
Savari will inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law and may pause the affected processing while the parties resolve the issue. The Customer remains responsible for the lawfulness of its instructions, collection, notices, permissions, disclosures, and use of the Service.
4. Confidentiality and personnel
Savari will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality, receive appropriate privacy and security guidance, and access the data only where needed for their role. Savari remains responsible for its personnel’s compliance with this DPA.
5. Security measures
Taking account of the state of the art, implementation cost, scope, context, and risks to individuals, Savari will maintain technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, disclosure, or access.
Measures are risk-based and include access restriction, operator and permission controls appropriate to the configured Service, encrypted transport, provider-managed encryption at rest for core data, secrets kept outside source control, source-controlled development and change review, security logging and incident handling, backups where configured, and supplier oversight. Controls may evolve provided the overall level of protection is not materially reduced.
Customer data is hosted on Convex Cloud in the United States. Static site content is delivered through Vercel’s global network. Application functions run in configured regional infrastructure.
The Customer is responsible for its users, devices, identity lifecycle, permissions, configurations, downloaded exports, and integrations it enables.
6. Subprocessors
The Customer gives Savari general written authorisation to use the subprocessors in the current Subprocessor Register. Core providers support the hosted Service; feature-dependent providers process Customer Personal Data only when the relevant feature is enabled or used.
Savari will require each subprocessor to protect Customer Personal Data under written terms appropriate to its role and will remain responsible to the Customer for the subprocessor’s performance of those obligations, subject to the agreement’s liability terms.
Savari will give at least 30 days’ prior notice of a new subprocessor that will materially process Customer Personal Data. The Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith to address the objection. Urgent changes needed for security, continuity, or law may be made on shorter notice, with an explanation and notice as soon as reasonably practicable.
7. Data-subject requests
Taking account of the nature of processing, Savari will provide reasonable technical and organisational assistance for the Customer to respond to Data Subject requests. If Savari receives a request about Customer Personal Data, it will refer it to the Customer without undue delay where the requester and Customer can reasonably be identified, unless law requires another response. The Customer remains responsible for the decision and reply.
8. Personal Data Breaches
Savari will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will provide information reasonably available about the nature of the breach, affected data and people, likely consequences, containment and mitigation, a contact, and further updates. The Customer remains responsible for deciding and making any required regulator or individual notification, and Savari will provide reasonable cooperation.
9. Compliance assistance
Taking account of the nature of processing and information available, Savari will reasonably assist the Customer with security obligations, breach assessment and notification, data-protection impact assessments, regulator consultation, and demonstrating compliance relevant to Savari’s processing. Unusually extensive or repetitive assistance may be charged at agreed professional-services rates unless required because of Savari’s breach.
10. Information and audit rights
Savari will make available information reasonably necessary to demonstrate compliance with this DPA. Subject to confidentiality and availability, this may include provider assurance materials and a description of Savari’s controls.
The Customer may conduct one audit in any 12-month period, plus an audit following a material Personal Data Breach or regulator requirement. Audits must use a qualified independent auditor bound by confidentiality, give reasonable notice, avoid unreasonable disruption or exposure of another customer’s data, and begin with documentary or remote evidence. Each party bears its own costs unless otherwise agreed or required by law.
11. Return and deletion
On termination or the Customer’s written instruction, Savari will return, restrict, delete, or de-identify Customer Personal Data as required by the accepted agreement and applicable law. The available export scope and any assisted service, delivery target, active-system deletion timetable, backup handling, and deletion confirmation must be agreed for the Customer’s configured modules and providers and supported by verified procedures.
Data retained because of law, legal hold, fraud prevention, security investigation, dispute, or legal claims will remain restricted and will be deleted when the reason ends.
12. International transfers
Savari will not make a restricted transfer unless the Customer has instructed it and the parties have put in place a valid, legally binding transfer safeguard together with any required transfer assessment and supplementary measures.
The Order Form or a separate transfer schedule must identify the mechanism for the specific transfer and complete the required party, transfer, security, and subprocessor information. If the parties rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, the required tables and mandatory clauses must be completed or properly incorporated and made binding. This public DPA page does not, by itself, execute or complete a UK transfer instrument.
Savari will use role-appropriate terms for onward restricted transfers to subprocessors and will not rely on controller-to-processor clauses where processor-to-processor terms are required.
13. Records and regulator cooperation
Savari will maintain records required for its processor role and cooperate with a competent Supervisory Authority as required by law. Each party will notify the other of a regulator enquiry specifically concerning the other party’s obligations or Customer Personal Data unless prohibited.
14. Liability, precedence, and term
Liability under this DPA is subject to the agreement’s liability terms except where Applicable Data Protection Law or an executed transfer mechanism prohibits that limitation. Mandatory transfer terms prevail, followed by this DPA, then any Order Form provision that gives greater protection, and then the Terms of Service.
This DPA begins when it is validly incorporated or accepted and remains effective while Savari processes Customer Personal Data. Savari may update it where required by law or to improve protection but will not materially reduce the Customer’s rights during an active term without agreement.
Schedule 1 — Processing details
Subject matter and duration: provision, hosting, support, security, and maintenance of the configured Service during the agreement, plus any agreed exit, legal-hold, and deletion periods.
Nature and purpose: collection, recording, organisation, storage, retrieval, use, transmission, display, reconciliation, reporting, export, backup, support access, security monitoring, restriction, deletion, and other processing initiated through the Service.
Data subjects may include customer administrators and users; passengers and customer contacts; drivers, technicians, employees, contractors, and applicants; suppliers and business contacts; vehicle owners and policyholders; and other individuals whose data the Customer lawfully submits.
Personal data may include identity, contact, address, account, booking, journey, route, employment, scheduling, licence, vehicle, telematics, location, mileage, maintenance, inspection, contract, invoice, payment-status, communications, file, device, IP, authentication, access, audit, security, integration, analytics, and optional artificial-intelligence data.
Depending on Customer use, data may include accessibility or health information, children’s passenger data, precise location, employee-monitoring data, photographs, signatures, or criminal-offence and compliance information. The Customer must identify such processing, complete required impact assessments, and configure access and retention appropriately.
Questions about this DPA may be sent to hello@savari.io.