VALID8.AE
Back to Home
Legal

Data Processing Agreement

Version 1.0 · Effective January 2026

This Data Processing Agreement ("DPA") forms part of the agreement between FIKA TECHNOLOGIES - FZCO ("Processor", "we", "us") and the Customer ("Controller", "you") under which we provide the Valid8 platform. The DPA applies whenever we process Personal Data on your behalf as part of providing the platform. If you require a counter-signed copy for your records, email legal@valid8.ae.

1.Definitions

  • "Applicable Data Protection Law" means UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL") and any other personal data protection law applicable to the Controller, including (where relevant) the GDPR, UK GDPR, and applicable free-zone regulations such as those of the DIFC and ADGM.
  • "Controller" means the natural or legal person who determines the purposes and means of processing Personal Data — in this DPA, the Customer.
  • "Processor" means the entity that processes Personal Data on behalf of the Controller — in this DPA, FIKA TECHNOLOGIES - FZCO.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller. The current list is published at /subprocessors.
  • "Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.
  • "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, retrieval, use, disclosure, and erasure.
  • "Data Subject" means the natural person to whom Personal Data relates — in the context of Valid8, typically a buyer or seller client of the Controller.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
  • "Services" means the Valid8 platform as described in the Terms of Service.

2.Scope and Roles

2.1 This DPA applies to Personal Data the Controller submits to the Services or that we process on the Controller's behalf in the course of providing the Services.

2.2 In respect of Personal Data processed under this DPA, the parties agree:

  • The Controller is the data controller (typically the brokerage and its individual agents).
  • The Processor is a data processor acting on the documented instructions of the Controller.
  • The Processor processes Personal Data only as permitted by this DPA, the Terms of Service, and the Controller's lawful written instructions.

2.3 Each party complies with Applicable Data Protection Law as it applies to that party's role.

3.Processing Details (Schedule)

Subject matter:

Provision of the Valid8 real estate transaction and compliance platform.

Duration:

For the term of the Controller's Valid8 account, plus retention periods specified in the Privacy Policy (typically 5-10 years for transaction data under UAE real estate and financial regulations; up to 90 days for general account data after closure).

Nature and purpose:

  • Storing buyer and seller property transaction data and supporting documents.
  • Extracting structured data from documents using AI.
  • Tracking compliance gates across Off-Plan and Secondary/Ready property transactions.
  • Generating auto-filled forms, compliance summaries, and audit trail exports.
  • Sending transactional communications (email, notifications).
  • Maintaining audit trails for compliance and dispute resolution.
  • Providing analytics on the Controller's pipeline (aggregate, non-identifying analytics on the platform overall).

Categories of Data Subjects:

  • Buyer and seller clients of the Controller.
  • Co-buyers on Controller-managed cases.
  • Authorised users of the Controller's Valid8 account.
  • Property developers and partners associated with the Controller's transactions.

Categories of Personal Data:

  • Identification: names, dates of birth, nationalities, Emirates ID numbers, passport details, visa status.
  • Contact: addresses, email, phone numbers.
  • Employment and financial: employer, income, liabilities, bank statements, source of funds.
  • Property: property details, unit details, valuations, transaction documentation.
  • Communications: messages and notes exchanged through the platform.
  • Authentication: login credentials, session data.

Special categories (sensitive data):

The platform is not designed to collect sensitive Personal Data (such as data revealing health, religion, or biometric identifiers used for unique identification). The Controller agrees not to upload such data unless strictly necessary for a specific case and only with explicit Data Subject consent.

4.Processor Obligations

The Processor will:

  • 4.1 Process Personal Data only on the Controller's documented instructions, including those embedded in the platform's normal use.
  • 4.2 Ensure that personnel authorised to process Personal Data are bound by contractual confidentiality obligations.
  • 4.3 Implement and maintain the technical and organisational security measures set out in Annex A and at /security.
  • 4.4 Engage Sub-processors only as permitted by section 5 below.
  • 4.5 Assist the Controller, taking into account the nature of the processing, in fulfilling its obligation to respond to Data Subject rights requests.
  • 4.6 Assist the Controller in ensuring compliance with security, breach notification, data protection impact assessments, and prior consultations with supervisory authorities, where applicable.
  • 4.7 On termination of the Services, return or delete Personal Data as instructed by the Controller, except where retention is required by law.
  • 4.8 Make available to the Controller information necessary to demonstrate compliance with this DPA, and allow audits as set out in section 8.
  • 4.9 Inform the Controller without delay if, in our opinion, an instruction infringes Applicable Data Protection Law.

5.Sub-processors

5.1 The Controller authorises the Processor to engage Sub-processors for the purpose of providing the Services. The current list of authorised Sub-processors is published at /subprocessors.

5.2 The Processor will provide at least 30 days' notice before adding or replacing a Sub-processor by updating the page at /subprocessors and emailing users via the platform's standard notification channel. The Controller may object to a new Sub-processor on reasonable data protection grounds within that period.

5.3 If the Controller objects on reasonable grounds, the parties will work in good faith to agree a resolution. If no resolution is found, the Controller may terminate the affected Services without penalty.

5.4 The Processor enters into written agreements with each Sub-processor imposing data protection obligations no less protective than those in this DPA, and remains liable to the Controller for the acts and omissions of its Sub-processors.

6.International Transfers

6.1 Personal Data may be transferred to, and processed in, jurisdictions outside the UAE, including (currently) the United States and the European Union, where Sub-processors operate.

6.2 The Processor ensures such transfers comply with Applicable Data Protection Law, including by implementing appropriate safeguards such as contractual clauses requiring equivalent levels of protection, encryption of data in transit and at rest, and minimisation of data transferred to that necessary for the specified processing purpose.

6.3 Where the GDPR applies to a transfer, the parties agree to the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor, dated 4 June 2021), incorporated by reference into this DPA. The Controller is the data exporter; the Processor is the data importer.

7.Personal Data Breaches

7.1 The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data Breach affecting the Controller's Personal Data.

7.2 The notification will include, to the extent then known: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; measures taken or proposed to address the breach and mitigate its effects.

7.3 The Processor will assist the Controller in meeting any obligations to notify supervisory authorities or affected Data Subjects.

8.Audits

8.1 The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, including, on request, the most recent third-party audit reports of our infrastructure providers and a description of our internal security controls.

8.2 If the Controller requires further assurance, the Controller may, at its own cost and not more than once per year (unless required by a supervisory authority), audit the Processor's compliance with this DPA on 30 days' written notice. Audits must be conducted during business hours, must not unreasonably interfere with our business, and are subject to confidentiality obligations.

8.3 The parties may agree that an audit is satisfied by the Processor providing a written self-assessment or third-party attestation.

9.Data Subject Rights

9.1 The platform provides the Controller with self-service tools to respond to Data Subject access, correction, deletion, and portability requests, including in-platform export of case data, document download, and account deletion functionality.

9.2 Where a Data Subject contacts the Processor directly, the Processor will not respond substantively without the Controller's instruction (except to confirm receipt and direct the Data Subject to the Controller).

9.3 The Processor will assist the Controller, taking into account the nature of the processing, with appropriate technical and organisational measures to fulfil the Controller's obligations to respond to Data Subject requests within applicable statutory time limits.

10.Liability

The liability provisions in the Terms of Service apply to this DPA. Neither party limits liability for breaches of Applicable Data Protection Law where such limitation is not permitted by law.

11.Term and Termination

11.1 This DPA is in effect for the duration of the Controller's Valid8 account.

11.2 On termination, the Processor will return or delete Personal Data on the Controller's instruction, subject to retention obligations under Applicable Data Protection Law and as set out in the Privacy Policy.

11.3 Sections of this DPA which by their nature survive termination (including 4.7, 7, 9, 10, and this section) continue to apply.

12.Governing Law

This DPA is governed by the laws of the United Arab Emirates, as applicable in the Emirate of Dubai. Disputes are resolved as set out in the Terms of Service.

13.Order of Precedence

If there is a conflict between this DPA and the Terms of Service, this DPA prevails to the extent of the conflict in respect of the processing of Personal Data. If there is a conflict between this DPA and a counter-signed addendum agreed bilaterally between the parties, the counter-signed addendum prevails.

A.Annex A: Technical and Organisational Measures

  • Encryption: TLS 1.2+ in transit; AES-256 at rest. Document files served via short-lived signed URLs.
  • Access controls: PostgreSQL Row-Level Security on every query; role-based access control including project-scoped restrictions for Developer accounts; multi-factor authentication required for admin accounts; logged access for production data.
  • Authentication: bcrypt-hashed passwords; short-lived JWT session tokens with refresh rotation; OAuth integration available.
  • Infrastructure: Multi-availability-zone deployment; daily encrypted backups with point-in-time recovery; SOC 2 Type II / ISO 27001 certified infrastructure providers.
  • Monitoring: immutable audit tables for authentication, gate sign-offs, overrides, and admin actions; rate-limited login attempts; 90-day application log retention with anomaly review.
  • Application security: parameterised queries; CSP, HSTS and security headers; OWASP-aligned secure development.
  • Incident response: documented response plan; 72-hour breach notification commitment; security@valid8.ae acknowledgement within one business day.
  • Personnel: contractual confidentiality obligations; restricted production access; acceptable-use training.

B.Annex B: Sub-processors

The current list of Sub-processors is maintained at /subprocessors. Categories include database and authentication infrastructure, AI inference, transactional email, and infrastructure hosting. Each Sub-processor is engaged under a written contract with data protection obligations no less protective than this DPA.

.Counter-Signed Copies

Most brokerages do not require a counter-signed DPA — accepting this version at signup is legally sufficient under UAE law and most equivalent regimes. If your compliance team requires a counter-signed copy on company letterhead, email legal@valid8.ae with the legal entity name to be inserted as Controller. We will return a counter-signed PDF within 5 business days.

.Contact

FIKA TECHNOLOGIES - FZCO
Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates
Trade Licence 10731 · Dubai Integrated Economic Zones Authority (DIEZ)
DPA enquiries: legal@valid8.ae
Privacy enquiries: privacy@valid8.ae