Skip to content
Hayatiqحياتيك

Data Processing Agreement

Draft of September 14, 2026

Draft for review. This document has not yet been reviewed by a lawyer and is not in force. It is published so you can read what Hayatiq intends to offer; bracketed items are still to be settled, and the final text will be published before checkout opens.

This Data Processing Agreement (the DPA) is offered to organisations that use Hayatiq Financials to process personal data of their clients, their clients' people or their own staff, and that need a written processor agreement to do so. It supplements the Terms of Service and is explained in plain language by the Privacy Policy.

How to use this document. The DPA is available to customers on the Partner plan and [owner to decide: to Practice customers as well, or to any organisation on request]. To enter into it, print this page to PDF using the button above, complete Annex 4 and send it to hello@hayatiq.ai; Hayatiq countersigns and returns a copy. Until Hayatiq has countersigned, this page is a draft and the DPA is not in force between the parties. [Owner to decide whether the DPA instead takes effect automatically by acceptance of the Terms, in which case Annex 4 becomes an optional countersignature for customers who need a signed copy].

1. Parties

This DPA is between:

  • Hayatiq: [registered name of the FZE that operates hayatiq.ai], a free zone establishment registered in Ajman, United Arab Emirates, at [registered address, Ajman, United Arab Emirates], the Processor; and
  • Customer: the organisation named in Annex 4 that holds the Hayatiq Financials account, the Controller (or, where the Customer is itself a processor for its clients, a processor instructing Hayatiq as sub-processor; the term Controller is used for both below).

2. Definitions

Words defined in the Terms of Service have the same meaning here. In addition:

  • Data Protection Law means every law that applies to the processing of Personal Data under this DPA, including the Saudi Personal Data Protection Law and its Implementing Regulations (PDPL), the EU General Data Protection Regulation and the UK GDPR (GDPR), and any other law the parties identify in Annex 4.
  • Personal Data means any information relating to an identified or identifiable natural person that Hayatiq processes for the Customer through the Service; the categories are in Annex 1.
  • Processing, Controller, Processor, Data Subject, Personal Data Breach and Supervisory Authority have the meanings given in Data Protection Law.
  • Sub-processor means a third party engaged by Hayatiq to process Personal Data for the Customer; the current list is Annex 3.
  • Engagement Data means the Customer Data in an engagement: canonical balance rows, the confirmed mapping, questionnaire answers, the cash-flow worksheet and note tables, and any names of people in them.

3. Scope, roles and precedence

  1. This DPA applies to Personal Data that Hayatiq processes on the Customer's behalf in providing the Service, as described in Annex 1. It does not apply to data of which Hayatiq is the controller (account, billing, waitlist and support data), which the Privacy Policy covers.
  2. The Customer is the Controller and Hayatiq is the Processor of Engagement Data. The Customer warrants that it has a lawful basis, and has given any notice and obtained any consent Data Protection Law requires, for entering Personal Data into the Service and for the transfers in section 12.
  3. If this DPA conflicts with the Terms of Service, this DPA prevails for the processing of Personal Data. If it conflicts with standard contractual clauses incorporated under section 12, those clauses prevail.

4. Details of the processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1. The Service is built so that most processing happens on the Customer's own device: Hayatiq processes Engagement Data only at the four points where the Customer sends it — save, assistant, note narrative, export — as Annex 1 describes.

5. The Customer's instructions

  1. Hayatiq processes Personal Data only on the Customer's documented instructions, which are: the Terms of Service, this DPA, the Customer's use of the Service's features (saving, exporting, the no-storage flag, deleting an engagement, and, once enabled, the assistant), and any further written instruction the parties agree.
  2. Hayatiq will tell the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is resolved.
  3. Hayatiq does not use Personal Data for any purpose of its own, does not sell it, and does not use it to train any model.

6. Hayatiq's obligations

Hayatiq will:

  1. process Personal Data only as section 5 allows, and only for as long as the Customer's account and the retention rules in the Privacy Policy require;
  2. ensure that people authorised to process Personal Data are bound by confidentiality (section 7);
  3. implement the security measures in Annex 2 (section 8);
  4. engage Sub-processors only under section 9;
  5. assist the Customer with Data Subject requests (section 10) and, taking into account the nature of the processing and the information available to Hayatiq, with the Customer's obligations on security, breach notification, data protection impact assessments and prior consultation with a Supervisory Authority (sections 8, 11 and 13);
  6. notify the Customer of Personal Data Breaches (section 11);
  7. delete or return Personal Data at the end of the Service (section 14); and
  8. make available the information needed to demonstrate compliance with this DPA and allow audits (section 13).

7. Personnel and confidentiality

Hayatiq is operated by a small team. Every person with access to Personal Data, including any contractor, is bound by a written confidentiality obligation that survives the end of their engagement, has access only to what their role needs, and accesses production data only for support, security or legal reasons and never for curiosity or testing. Development and testing use synthetic fixture data only; no Personal Data is copied into a development environment. [Owner to confirm who today holds production access and that a written confidentiality undertaking exists for each of them].

8. Security

  1. Hayatiq maintains the technical and organisational measures in Annex 2, which separates the measures implemented at the date of this draft from those planned. Hayatiq does not represent a planned measure as in place. Hayatiq will not save Personal Data of real clients before the planned measures marked "before first real client data" in Annex 2 are in operation.
  2. Hayatiq may update Annex 2 as the product develops, provided the overall level of protection does not fall. The current version is always at financials.hayatiq.ai/en/dpa with its date.
  3. The Customer is responsible for the security of its own devices, browsers and accounts, for the drafts held in its browsers before saving, for who it invites to its organisation and the roles it gives them, and for the choices it makes in the Service (including whether to use the no-storage flag).

9. Sub-processors

  1. The Customer gives Hayatiq general authorisation to engage the Sub-processors in Annex 3 and any replacement or addition under this section.
  2. Hayatiq will give the Customer at least [thirty (30) days'] written notice (by e-mail to the account owner, and by updating Annex 3 at the URL above) before a new or replacement Sub-processor processes Personal Data. The Customer may object in writing, on reasonable data-protection grounds, within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected subscription with a pro-rata refund of prepaid fees for the unused period, as its sole remedy.
  3. Hayatiq will impose on each Sub-processor, by written contract, data-protection obligations that are no less protective than this DPA, and remains liable to the Customer for the Sub-processor's performance.

10. Data Subject requests

If Hayatiq receives a request from a Data Subject relating to Engagement Data (at privacy@hayatiq.ai or otherwise), it will not answer it on the Customer's behalf, will tell the Customer within [five (5) business days], and will help the Customer answer it. Because the Customer can itself view, edit and delete every engagement in the Service, most requests can be met without Hayatiq's involvement; where that is not enough, Hayatiq provides reasonable assistance at no charge, and may charge [a reasonable fee — lawyer to set the basis] for assistance that is excessive or repetitive.

11. Personal Data Breaches

  1. Hayatiq will notify the Customer without undue delay and no later than [forty-eight (48) hours — lawyer to set, noting the 72-hour deadline that applies to a Controller under the GDPR and the timing that applies under the PDPL] after becoming aware of a Personal Data Breach affecting the Customer's Personal Data.
  2. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point; information Hayatiq does not yet have follows as it becomes available.
  3. Hayatiq will cooperate with the Customer's investigation and with any notification the Customer must make to a Supervisory Authority or to Data Subjects. Hayatiq's notice is not an admission of fault.

12. International transfers

  1. Storage. Hayatiq stores Personal Data on Supabase in Frankfurt, Germany. Sub-processors in other countries receive only what Annex 3 describes.
  2. Saudi Arabia. Where the Customer is established in the Kingdom, or the Personal Data relates to people in the Kingdom, the transfer to Hayatiq and its Sub-processors is a transfer outside the Kingdom under the PDPL. The parties enter into the SDAIA Standard Contractual Clauses for that transfer, which are incorporated into this DPA as [Annex 5 — lawyer to attach the current SDAIA SCC text with the parties and the processing details completed, and to confirm any transfer risk assessment and registration or representative obligation. At the draft date the SCCs are not yet executed and are on Hayatiq's launch checklist]. Where the clauses require it, the Customer as data exporter and Hayatiq as data importer complete the annexes to those clauses using Annex 1 and Annex 3 of this DPA.
  3. EU and UK. Where the GDPR applies to the Customer, the transfer from the Customer to Hayatiq (established in the United Arab Emirates) and onward to Sub-processors outside the EEA or the UK relies on: [lawyer to select and attach — the European Commission's Standard Contractual Clauses (Module 2, controller to processor, or Module 3 where the Customer is a processor) with the UK International Data Transfer Addendum where relevant, completed with Annex 1 and Annex 3 — the United Arab Emirates holds no EU or UK adequacy decision as far as Hayatiq is aware at the draft date, lawyer to confirm]. Hayatiq relies on each Sub-processor's own transfer mechanism (EU SCCs, UK addendum or Data Privacy Framework certification) for the onward transfer, as recorded in Annex 3.
  4. Hayatiq will tell the Customer if it can no longer comply with the clauses under this section, and the Customer may then suspend the transfer and terminate the affected subscription.

13. Audit and information

  1. On written request, no more than [once in any twelve (12) months] unless a Supervisory Authority requires otherwise or a Personal Data Breach has occurred, Hayatiq will answer a reasonable written security questionnaire and provide the documentation listed in Annex 2 (including the results of the automated row-level-security suite for the current release) and the security documentation its Sub-processors publish.
  2. Where that information is not enough to demonstrate compliance with this DPA, the Customer (or an independent auditor bound by confidentiality) may audit Hayatiq's processing, on [thirty (30) days'] notice, during business hours, at the Customer's cost, without access to other customers' data and without disrupting the Service. Hayatiq's infrastructure is operated by its Sub-processors; an audit of their facilities is limited to the reports and certifications they make available.

14. Return and deletion

  1. The Customer can delete any engagement, and with it its Engagement Data, at any time in the Service. The no-storage flag, once the purge job is in operation (Annex 2), removes an engagement's snapshots, mappings, worksheets, answers, review notes and export files after generation while keeping the engagement record, upload metadata, export records and the mapping template.
  2. On termination of the Service, Hayatiq will, at the Customer's choice made within [thirty (30) days], return the Customer's saved engagements as exported files and then delete them, or delete them without return. After that period Hayatiq deletes all Personal Data and existing copies, except what Data Protection Law or the Customer's billing history requires Hayatiq to keep, which remains subject to this DPA. Deleted rows may persist in database backups for the recovery window stated in Annex 2 and are then overwritten.

15. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, which apply in aggregate across the Terms and this DPA, [lawyer to confirm whether any liability under the standard contractual clauses in section 12, or towards Data Subjects, must be carved out of the cap under the applicable law].

16. Term and termination

This DPA takes effect on the date in Annex 4 (or, if the owner elects automatic effect, on the Customer's acceptance of the Terms) and lasts as long as Hayatiq processes Personal Data for the Customer, including the return-and-deletion period in section 14.

17. Governing law

This DPA is governed by the law and subject to the courts or arbitration chosen in the Terms of Service, [lawyer to confirm; the SDAIA SCCs and the EU SCCs carry their own governing-law clauses that prevail for the transfers they cover].

Annex 1 — Details of the processing

ItemDescription
Subject matterProviding Hayatiq Financials: turning the Customer's trial balances into draft financial statements for professional review, storing the Customer's saved engagements, and rendering exports
DurationThe life of the Customer's account, plus the return-and-deletion period in section 14
Nature of the processingStorage (saved snapshots, upload metadata, export files), retrieval on the Customer's request, server-side rebuilding of statements from a snapshot at export, and — once enabled — transmission of account names or a facts object to the assistant's model provider. Parsing, mapping, statement building, tie-outs and the checklist run in the Customer's browser and are not processing by Hayatiq
PurposePerformance of the Terms of Service for the Customer; no other purpose
Types of Personal DataNames of natural persons where they appear in Engagement Data: in account names (for example a director's loan account), in related-party, key-management, employee-benefit and going-concern answers, in note worksheet tables, and in the entity name of a sole proprietorship. Amounts associated with those names. Names and e-mail addresses of the Customer's users appear in the confirmation trail of a mapping ("who confirmed it"). No special-category data is expected; the Customer must not enter any
Categories of Data SubjectsDirectors, shareholders, partners, key management, related parties and employees of the Customer's client entities (or of the Customer itself); the Customer's own users
FrequencyContinuous while an engagement is saved; event-driven at save, assistant, narrative and export
RetentionPrivacy Policy section 10 and section 14 above

Annex 2 — Security measures

Hayatiq does not represent a planned measure as in place. Dated 14 September 2026.

Implemented today

MeasureDetail
Row-level security on every tableEvery tenant table carries the organisation identifier and a policy that checks membership of that organisation; organisations and members are created only through controlled database functions. The public (unauthenticated) database role holds no table grants. An automated test suite proves, on every change and in continuous integration, that a user in one organisation cannot read or write another's rows
Processing on the Customer's device by defaultThe engine runs in the browser in a Web Worker; Engagement Data reaches Hayatiq only at the four explicit actions in Annex 1. Uploaded files are never received: only a file name, size, content hash, layout and row counts are kept as metadata
No client financial data in logs or analyticsLogging accepts reason codes and counts only, enforced by a lint rule that bans console output everywhere except one reviewed module; analytics events carry counts, category values and flags only; billing-event records hold only the fields acted on, never names, addresses or amounts
Assistant payload controlThe mapping-suggestion request carries a fixed set of fields (codes, names, a category label — no balances) and scrubs figure-shaped tokens and currency codes from free-text labels before sending; the assistant is disabled until zero data retention is confirmed (below)
Encryption in transitHTTPS between the browser, Hayatiq and every Sub-processor; encryption at rest of database and storage volumes as provided by Supabase's infrastructure
Secrets managementNo secret is committed to source control; credentials live in the hosting provider's encrypted environment configuration; an automated guard blocks tooling from writing secret files; production database changes are applied only by a reviewer, never by automation
Change controlEvery change goes through a pull request with required automated checks (type-check, lint, tests including the row-level-security suite, build) and a protected main branch; a security review of parsing, storage, logging, authentication and third-party calls is part of the release process
Synthetic data in development and testDevelopment, tests and the assistant's own tests use synthetic fixture data only; no real client data is copied into a development environment

Planned

MeasureStatus
Save boundary and sign-in (built, in review at the draft date; not yet deployed)A save stores canonical balance rows and a rebuildable snapshot of confirmed choices with version numbers — never the file bytes, never per-suggestion rows, never a generated statement set (statements are rebuilt from the snapshot at export). Sign-in to Hayatiq ID is by one-time e-mailed link; no password store exists
Column-level encryption of questionnaire answers and engagement snapshotsUsing the database's vault (Supabase Vault / pgsodium). Before first real client data: real client data is not saved until this is in operation
Zero data retention with the assistant's model providerRequested from Anthropic; the assistant is disabled until confirmed in writing. Before first real client data reaches the model
No-storage purge jobThe flag is stored today; the job that deletes an engagement's snapshots, mappings, worksheets, answers, review notes and export files after generation is not yet running. Until it is, a snapshot saved with the flag stays until the engagement is deleted
Point-in-time recovery on the databaseTo be enabled at launch; recovery window intended to be [seven (7) days — owner to confirm]. Deleted rows persist in backups for that window
SDAIA Standard Contractual Clauses and transfer risk assessmentOn the launch checklist; see section 12
Credential rotation of the pre-launch development projectBefore any real client data reaches it
Preview-deployment protectionPre-launch previews are reachable without sign-in by owner decision (no real data exists); protection is re-enabled in the same step that adds sign-in, before any beta user is given a preview link
Export filesDOCX and XLSX export is not yet built; when it is, files are rendered on the server from the snapshot, stored under the same row-level security, and delivered by short-lived signed link
Independent security assessment[Owner to decide whether and when a third-party penetration test or assessment is commissioned, and whether a report will be made available under section 13]

Annex 3 — Sub-processors

Notice of changes: section 9. Dated 14 September 2026.

Sub-processorPurposeLocation of processingPersonal Data receivedTransfer mechanism (EU/UK)
Supabase, Inc.Database, authentication, file storageFrankfurt, Germany (AWS eu-central-1)All stored Personal Data: saved snapshots, upload metadata, user e-mail addresses and roles, export files once export ships[lawyer to record — data stays in the EEA; Supabase's DPA covers support access from elsewhere]
Vercel, Inc.Hosting of the web application, serverless functions, edge network, product analyticsGlobal edge network; function region [owner to pin and state — not pinned at the draft date, which means Vercel's default US region]Personal Data in transit through the application at save, assistant, narrative and export; connection logs; analytics events (counts and flags only)[lawyer to record — Vercel's DPA with EU SCCs / DPF]
Anthropic, PBCThe assistant's language modelUnited StatesAccount codes, account names and a category label (mapping); the facts object (narrative). Nothing until zero data retention is confirmed[lawyer to record — Anthropic's commercial terms and DPA; ZDR addendum]
Resend, Inc.Transactional e-mail (sign-in links, service notices)United States [owner to confirm whether the EU region is selected]The user's e-mail address and the e-mail content[lawyer to record]
Paddle.com Market LtdMerchant of record: checkout, payment, tax, invoices, refundsUnited Kingdom, with global payment processingBilling contact and payment data of the Customer's buyer, as a controller under Paddle's own notice; Hayatiq receives identifiers, plan and status onlyNot a processor for Hayatiq; [lawyer to confirm the characterisation]
Cloudflare, Inc.DNS for the hayatiq.ai domain [owner to confirm whether the proxy is on for financials.hayatiq.ai; if so add "and network edge"]Global network, United StatesConnection metadata (IP address, hostname requested); no Engagement Data[lawyer to record]

Each Sub-processor's published security and privacy documentation: Supabase, Vercel, Anthropic, Resend, Paddle, Cloudflare.

Annex 4 — Execution

FieldCustomerHayatiq
Legal name[Customer to complete][registered name of the FZE that operates hayatiq.ai]
Registered address[Customer to complete][registered address, Ajman, United Arab Emirates]
Hayatiq Financials account (owner e-mail, organisation)[Customer to complete]
Applicable Data Protection Law (tick all that apply)PDPL (Saudi Arabia) · GDPR (EU) · UK GDPR · [other]
Contact for data-protection matters[Customer to complete]privacy@hayatiq.ai
Signed by (name, title)[Customer to complete][Hayatiq signatory name and title]
Signature and date[Customer to complete][Hayatiq signature and date]

[Annex 5 — SDAIA Standard Contractual Clauses (lawyer to attach; see section 12.2)]. [Annex 6 — EU Standard Contractual Clauses and UK Addendum, if selected (lawyer to attach; see section 12.3)].