NextBayt logo
Wie es funktioniertFunktionenPreise
Anmelden
NextBayt logo
Wie es funktioniertFunktionenPreiseAnmelden
NextBayt logo

KI-gestützte Immobilienintelligenz für den VAE-Markt. Treffen Sie intelligentere Immobilienentscheidungen mit Daten, nicht mit Vermutungen.

Produkt

  • Wie es funktioniert
  • Funktionen
  • Preise

Unternehmen

  • Über uns
  • Kontakt

Rechtliches

  • Datenschutzrichtlinie
  • Nutzungsbedingungen
  • Cookie-Richtlinie
  • Datenverarbeitung
  • Internationaler Datenschutz-Nachtrag

Sprachen

  • English (EN)
  • العربية (AR)
  • Deutsch (DE)

© 2026 NextBayt Analytics FZCO • Dubai, VAE

·

Nicht mit einem Makler verbunden • Daten stammen von Digital Dubai

Legal

Data Processing Agreement

NextBayt's Data Processing Agreement and Sub-Processor Disclosure.

On this page

  • FRONT MATTER
  • ANNEXES
  • VERSION AND CHANGELOG

DATA PROCESSING AGREEMENT AND SUB-PROCESSOR DISCLOSURE

NextBayt Analytics FZCO

Effective Date: 21 August 2026 Last Updated: 21 August 2026

NOTICE — THIS DOCUMENT HAS TWO PARTS WITH DIFFERENT LEGAL EFFECT. Part I (Sections 5–14) is a public disclosure that applies automatically today and requires no signature. Part II (Sections 15–34) is a template that has no legal effect on any party unless separately executed via a signed Order Form, MSA, or Enterprise Agreement. See Section 1 for full detail.

FRONT MATTER

1. Purpose of This Document

This document serves two distinct purposes and is divided accordingly into two parts, which the reader should not conflate:

Part I — Sub-Processor and Cross-Border Transfer Disclosure is a standing public disclosure that applies automatically, today, to every user of the services provided by NextBayt Analytics FZCO ("NextBayt," "we," "us," or "our") through www.nextbayt.com and related applications (the "Service"). Part I requires no signature, no order form, and no separate agreement to take effect. It exists to inform users, regulators, and prospective business customers which vendors process personal data on NextBayt's behalf, where those vendors are located, and on what legal basis any cross-border transfer of personal data occurs. Part I is operative as of the Effective Date above and is updated from time to time as described in Section 12.

Part II — Template Data Processing Agreement is a contractual template intended for use with NextBayt's future business-to-business ("B2B") "Team" or multi-seat offering, which as of the Effective Date has not yet been launched. Part II has no legal effect on its own. It becomes binding only if, and to the extent that, it is expressly incorporated by reference into a signed Order Form, Master Services Agreement, Enterprise Agreement, or equivalent written agreement between NextBayt and a business customer (each, a "Customer"). Until such incorporation occurs, Part II is inert template language, published here for transparency and for the convenience of prospective Customers evaluating NextBayt's data processing commitments in advance of contracting. No provision of Part II should be read as creating a present obligation of NextBayt to any person unless and until the activation condition in Section 15 is satisfied.

This structure allows NextBayt to be fully transparent today about how it processes consumer personal data (Part I) while pre-publishing the terms it is prepared to offer future business customers (Part II), without either part being mistaken for the other.

2. Definitions

For purposes of this document:

  • "Applicable Data Protection Law" means UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, as amended, and its implementing regulations (the "UAE PDPL"), together with any other data protection law that applies to the relevant processing from time to time. [Reserved: this definition may be expanded to include the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR") or other jurisdiction-specific laws if and when NextBayt processes personal data subject to such laws.]
  • "Controller" means the natural or legal person that determines the purposes and means of the Processing of Personal Data.
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
  • "Personal Data" means any information relating to an identified or identifiable natural person, processed in connection with the Service.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • "Processing" (and "Process," "Processed") means any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, transfer, and deletion.
  • "Processor" means the natural or legal person that Processes Personal Data on behalf of, and under the instructions of, a Controller.
  • "Sub-processor" means any Processor engaged by NextBayt to Process Personal Data in the course of providing the Service, whether that Personal Data originates from a consumer user (Part I) or, once applicable, from a Customer under Part II.

Additional terms used only in Part II — including "Customer," "Order Form," "Principal Agreement," "Team User," and "End-Client" — are defined at first use in Sections 15, 17, and 18 and incorporated here by reference. Note that the party acting as "Controller" differs between Part I (NextBayt, for B2C Personal Data — see Section 5) and Part II (Customer, as defined in Section 15) — see the respective Parts for the applicable allocation of roles.

3. Relationship to the Privacy Policy

This document supplements, and does not replace, NextBayt's Privacy Policy. Where a conflict exists regarding NextBayt's consumer-facing representations — including the description of what data is collected, how it is used, user rights, and retention periods — the Privacy Policy governs. This document governs the mechanics of sub-processing, cross-border transfer disclosure, and (once Part II is activated as described above) the terms of NextBayt's processing relationship with a B2B Customer. Users should read the Privacy Policy for a plain-language description of NextBayt's data practices and this document for the technical and legal detail concerning sub-processors and, where applicable, B2B contractual terms.

4. Scope and Applicability

  • Part I applies automatically, to all users of the Service, as of the Effective Date, without any further action required. No signature or acceptance is needed for Part I to take effect; it is a disclosure, not a bargained-for contract.
  • Part II applies only to a Customer that has executed an Order Form, Master Services Agreement, or equivalent written agreement that expressly incorporates Part II by reference. Absent such incorporation, Part II creates no rights or obligations for any party.

PART I — SUB-PROCESSOR AND CROSS-BORDER TRANSFER DISCLOSURE

This Part I is effective as of the Effective Date and applies to all users of the Service.

5. Roles of the Parties

In connection with the Service as offered to individual consumer users ("B2C"), NextBayt acts as the Controller of Personal Data collected through the Service. NextBayt engages the vendors listed in Section 9 as its own Processors or Sub-processors, each of which Processes Personal Data solely on NextBayt's instructions and for the purposes described below. NextBayt does not, in its current B2C offering, act as a Processor for any third party.

6. Categories of Personal Data Processed

NextBayt Processes the following categories of Personal Data in connection with the Service:

  • Account and identity data: name, email address, phone number (where provided), authentication credentials, and account preferences.
  • Usage and device data: log data, IP address, device and browser identifiers, session data, and interaction data with the Service.
  • Payment data (Web only): billing details and transaction metadata processed via Stripe (NextBayt does not itself store full payment card numbers).
  • User-submitted content: queries, prompts, documents, and other content that a user submits to the Service's AI-assisted chat and analysis features, including where such content may itself contain personal or sensitive information the user chooses to submit.
  • Analytics and marketing identifiers: cookies, pixel identifiers, and derived usage analytics.

7. Categories of Data Subjects

As of the Effective Date, the category of Data Subjects whose Personal Data is Processed under Part I consists of registered individual consumer users of the Service ("Users"). This document will be updated if and when additional categories of Data Subjects become relevant to NextBayt's B2C operations.

8. Purposes of Processing

Data Category

Purpose(s) of Processing

Account and identity data

Account creation and authentication, customer support, service communications

Usage and device data

Service delivery, security, fraud prevention, performance monitoring

Payment data

Processing subscription/purchase transactions (Web only)

User-submitted content

Generating AI-assisted responses, analysis, and chat functionality requested by the User

Analytics and marketing identifiers

Product analytics, service improvement, and (where applicable) marketing measurement

9. Sub-Processor Table

NextBayt engages the following Sub-processors in connection with the Service. This table will be kept current in accordance with the change notice mechanism in Section 12.

Sub-processor

Role

Location(s)

Data Category Processed

Cross-Border Transfer?

Google Cloud Platform (Google LLC)

Cloud hosting and infrastructure

United States (with global infrastructure)

Account/identity data, usage data, user-submitted content

Yes

Supabase, Inc.

Managed database and backend services

United States / distributed cloud regions

Account/identity data, usage data

Yes

Cloudflare, Inc.

Content delivery network, DNS, and security/DDoS protection

Global (edge network); United States (corporate)

Usage and device data (network/traffic metadata)

Yes

Anthropic, PBC (Claude)

AI chat and analysis functionality

United States

User-submitted content (queries/prompts)

Yes

OpenAI, L.L.C. (ChatGPT)

AI chat and analysis functionality

United States

User-submitted content (queries/prompts)

Yes

Moonshot AI (Kimi)

AI chat and analysis functionality

China

User-submitted content (queries/prompts)

Yes

DeepSeek

AI chat and analysis functionality

China

User-submitted content (queries/prompts)

Yes

Stripe, Inc.

Payment processing (Web only)

United States (global payment infrastructure)

Payment data, billing details

Yes

Google Analytics (Google LLC)

Product and usage analytics

United States

Usage and device data, analytics identifiers

Yes

Microsoft Clarity (Microsoft Corporation)

Product usage analytics (session/behavior analysis)

United States

Usage and device data, analytics identifiers

Yes

Meta Pixel (Meta Platforms, Inc.)

Marketing measurement and analytics

United States

Usage and device data, analytics/marketing identifiers

Yes

Prighter GmbH

EU Representative (Art. 27 GDPR); channels data subject requests and data breach notifications via its Privacy Rights Manager (PRM) and Data Breach Tool

Austria (Prighter); Germany (Hetzner Online GmbH, underlying infrastructure)

Data subject contact/identification details, request content

N/A (within EU)

10. Cross-Border Transfer Mechanism (Part I / B2C)

Several of the Sub-processors listed in Section 9 are located, or Process Personal Data, outside the United Arab Emirates, including in the United States and China. NextBayt's basis for these cross-border transfers, for its current B2C User base, is the individual User's own consent, obtained at the time of signup and through NextBayt's Privacy Policy and Terms of Service, in reliance on the consent pathway for cross-border transfer recognized under the UAE PDPL. By creating an account and using the Service, a User consents to NextBayt's Processing of their Personal Data, and to the transfer of that Personal Data to the Sub-processors identified above, including to jurisdictions that may not have been the subject of an adequacy determination under Applicable Data Protection Law. Users who do not wish to consent to this transfer should not create an account or use the affected features of the Service.

This consent-based mechanism is specific to Part I and to NextBayt's direct relationship with individual consumer Users. It does not apply, and is not restated, in Part II — see Section 25 below for the transfer mechanism applicable to NextBayt's future B2B relationships, which necessarily differs because a corporate Customer cannot consent on behalf of its own end-clients.

Separate basis for EU/EEA Users: for Users located in the European Union or European Economic Area, NextBayt does not rely on consent as the primary basis for the routine, ongoing transfers described in this Section 10. Instead, NextBayt relies on Standard Contractual Clauses and, where applicable, adequacy decisions under Article 45 GDPR, as described in Section 5 of the International Data Protection Addendum (Part A - EU/EEA), which governs cross-border transfers for EU/EEA Users in place of this Section.

11. Underlying Contractual and Security Assurances

NextBayt has entered into, or relies upon, the commercial data processing terms, data protection addenda, and/or security commitments made generally available by each of the Sub-processors listed in Section 9 (including, where offered, standard contractual clauses, data processing addenda, or equivalent commitments published by that vendor). These arrangements require each Sub-processor to implement appropriate technical and organizational measures and to Process Personal Data only for the purposes for which it has been engaged. Copies of the relevant vendor terms are maintained by NextBayt and are available for review by regulators or, on reasonable request and subject to confidentiality, by prospective business customers.

12. Sub-Processor Change Notice Mechanism

NextBayt will maintain the current version of the sub-processor table in Section 9 at www.nextbayt.com (or a successor URL referenced from the Privacy Policy) and will update this document to reflect material changes. For the addition of a new Sub-processor that will Process Personal Data in a materially new category, purpose, or jurisdiction, NextBayt will post an updated version of this disclosure and, where practicable, provide advance notice of not less than fifteen (15) days via the Service or by email prior to the new Sub-processor beginning to Process Personal Data, except where a shorter period is necessary for security, legal, or operational reasons. Continued use of the Service after such notice constitutes User's acknowledgment that the updated disclosure applies to their use of the Service going forward. This acknowledgment does not convert Part I into a bargained-for contract; Part I remains a disclosure governed by Section 4.

13. Retention and Deletion

NextBayt retains Personal Data in accordance with the retention schedule set out in the Privacy Policy. Upon a valid deletion request from a User (or upon automated deletion under the retention schedule), NextBayt will propagate the deletion request to its Sub-processors, including the AI vendors listed in Section 9, to the extent technically feasible and subject to each vendor's own data retention and deletion mechanisms and any legally mandated retention period. Users should consult the Privacy Policy for the applicable retention periods per data category and for instructions on submitting a deletion request.

14. AI-Vendor-Specific Disclosure

When a User interacts with the Service's AI-assisted chat, analysis, or similar features, the content of that interaction — including the User's queries, prompts, and any documents or data submitted as part of that interaction — may be transmitted to one or more of the following AI vendors for processing: Anthropic (Claude), OpenAI (ChatGPT), Moonshot AI (Kimi), and/or DeepSeek, depending on which model or feature the User selects or which the Service routes the request to. Users should assume that content submitted to these AI-assisted features will be transmitted outside the United Arab Emirates, including to the United States (Anthropic, OpenAI) and to China (Moonshot AI, DeepSeek).

EU/EEA-specific routing restriction: for Users located in the European Union or European Economic Area, the Service routes AI-assisted features only to Anthropic and OpenAI. Moonshot AI and DeepSeek are not used to process EU/EEA Users' queries, consistent with Section 5 of the International Data Protection Addendum (Part A - EU/EEA).

Position on model training use: NextBayt seeks, and where commercially available enters into, contractual terms with each AI vendor that restrict or prohibit the use of NextBayt customer data to train that vendor's underlying third-party models, consistent with the commercial and enterprise-tier terms each vendor makes available. NextBayt's ability to obtain such protection varies by vendor and by service tier, and NextBayt does not represent that every vendor listed above currently offers a contractual no-training commitment on every tier NextBayt uses. NextBayt will update this disclosure if its position or its contractual protections with any listed AI vendor materially change.

PART II — TEMPLATE DATA PROCESSING AGREEMENT FOR FUTURE B2B/ENTERPRISE CUSTOMERS

Part II is a template only. It has no legal effect and imposes no obligation on any party unless and until it is expressly incorporated by reference into a signed Order Form, Master Services Agreement, or equivalent written agreement between NextBayt and a Customer, as described in Section 15. All obligations described in this Part II are expressed conditionally and take effect, if at all, only upon such incorporation.

Running header convention: Every section of Part II below should be read as carrying the heading "PART II — TEMPLATE, INERT UNLESS EXECUTED," reflecting that no provision in this Part creates a binding obligation absent the incorporation event described in Section 15. Where a section below contains lettered sub-paragraphs, the governing conditional phrase at the start of that section applies to every sub-paragraph within it — no sub-paragraph should be read or excerpted as a standalone, unconditioned obligation.

15. Parties and Incorporation

This template Data Processing Agreement ("this DPA") is made available by NextBayt Analytics FZCO, a Free Zone company registered in Dubai, United Arab Emirates (IFZA, Dubai Silicon Oasis) ("Processor"), for incorporation by reference into a written Order Form, Master Services Agreement, Enterprise Agreement, or equivalent agreement (the "Principal Agreement") to be entered into between NextBayt and a business customer identified in such Principal Agreement as [Customer Legal Name] ("Controller" or "Customer").

This DPA has no legal effect and creates no obligation on either party unless and until the Principal Agreement expressly incorporates this DPA by reference, and shall only take effect, in that event, from the effective date of the Principal Agreement or such other date as the Principal Agreement specifies. Upon such incorporation, the provisions of this Part II (Sections 15–34) and Annexes 1 and 2 shall become binding as between Processor and Customer, subject to Section 33 (order of precedence).

16. Subject Matter and Duration of Processing

Upon execution of an applicable Order Form incorporating this DPA: (a) the subject matter of Processing shall be Processor's provision of the Service to Customer's authorized team-seat users under the Principal Agreement; and (b) the duration of Processing shall be co-extensive with the term of the Principal Agreement, plus any period reasonably necessary for Processor to complete deletion or return of Customer Personal Data in accordance with Section 30.

17. Nature and Purpose of Processing

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall Process Personal Data solely for the purpose of providing the Service to Customer, including (i) enabling Customer's authorized personnel ("Team Users") to access and use the Service, and (ii) Processing Personal Data relating to Customer's own end-clients, leads, or prospects ("End-Clients") that Team Users input into, upload to, or generate through the Service in the course of Customer's business (for example, a brokerage firm's client and lead records); and (b) Processor shall not Process such Personal Data for any purpose other than as instructed by Customer under this DPA and the Principal Agreement, or as required by Applicable Data Protection Law.

18. Types of Personal Data and Categories of Data Subjects (B2B)

Upon execution of an applicable Order Form incorporating this DPA: (a) the categories of Personal Data and Data Subjects Processed under this Part II are expected to include (i) Team Users: name, work email, role/title, login credentials, and usage data of Customer's own personnel who are provisioned as seats under the Principal Agreement, and (ii) End-Clients: name, contact details, transaction or engagement history, communications, and other Personal Data that Team Users input into or generate through the Service in respect of Customer's own clients, leads, or prospects (for example, prospective or existing brokerage clients); and (b) the precise categories applicable to a given Customer will be further specified in the relevant Order Form or an Annex thereto, as appropriate.

19. Customer's Instructions

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall Process Personal Data only on the documented instructions of Customer, including with regard to international transfers of Personal Data, unless required to do so by Applicable Data Protection Law to which Processor is subject, in which case Processor shall inform Customer of that legal requirement before Processing, unless prohibited from doing so; (b) the Principal Agreement, this DPA, and Customer's configuration of the Service through Customer's account shall together constitute Customer's documented instructions; and (c) Processor shall promptly inform Customer if, in Processor's opinion, an instruction infringes Applicable Data Protection Law.

20. Confidentiality and Personnel Commitments

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall ensure that any person authorized to Process Personal Data on its behalf (including employees, contractors, and Sub-processor personnel) is subject to an appropriate obligation of confidentiality, whether contractual or statutory; and (b) each such person shall Process Personal Data only as instructed.

21. Security Measures

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against Personal Data Breach, as further described in Annex 2 (Technical and Organizational Security Measures); and (b) Processor may update these measures from time to time, provided that any such update does not materially reduce the overall level of protection.

22. Sub-Processor Authorization

Upon execution of an applicable Order Form incorporating this DPA: (a) Customer provides Processor with a general written authorization to engage Sub-processors to Process Personal Data in connection with the Service, subject to this Section 22 and Section 23; (b) the Sub-processors listed in Annex 1 as of the date of the applicable Order Form shall be deemed pre-approved for purposes of sub-paragraph (a); and (c) Processor shall remain responsible for the acts and omissions of its Sub-processors to the same extent Processor would be liable if performing the services of each Sub-processor directly, subject to Section 31.

23. Sub-Processor Change Notice and Objection Right

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall provide Customer with not less than thirty (30) days' advance written notice (which may be by email or through the Service's administrative console) before engaging any new Sub-processor or materially changing the role of an existing Sub-processor; (b) Customer may object to such a change, on reasonable data-protection grounds, by written notice to Processor within the notice period; and (c) if Customer objects, the parties shall discuss in good faith a reasonable resolution, and if no resolution is reached within a further thirty (30) days, Customer's sole and exclusive remedy shall be to terminate, without penalty, the specific feature or component of the Service that requires use of the objected-to Sub-processor, or, if such feature or component is not severable and its loss would materially deprive Customer of the benefit of the Service, to terminate the Principal Agreement on written notice, in either case without prejudice to fees accrued prior to termination.

24. Flow-Down to Sub-Processors

Upon execution of an applicable Order Form incorporating this DPA, Processor shall impose on each Sub-processor, by written contract, data protection obligations that are materially equivalent to those set out in this DPA, to the extent applicable to the nature of the services provided by that Sub-processor.

25. International Transfer Mechanism (B2B) — Contractual Safeguards, Not Consumer Consent

This Section 25 governs international transfers of Personal Data under Part II and is deliberately distinct from, and does not restate, the consent-based mechanism described in Section 10 of Part I. Section 10's basis — an individual User's own consent obtained at signup — is valid for NextBayt's direct B2C relationship with a consumer consenting to the Processing of their own Personal Data. It is not a valid basis for a corporate Customer's End-Client Personal Data, because a Customer cannot itself consent to onward international transfer on behalf of its own End-Clients, nor can Processor rely on a consent Processor never obtained from those End-Clients.

Accordingly, upon execution of an applicable Order Form incorporating this DPA, any transfer of Customer Personal Data (including Team User and End-Client Personal Data) by Processor to a Sub-processor located outside the United Arab Emirates shall be conducted on the basis of one or both of the following, as applicable:

(a) Appropriate contractual safeguards entered into between Processor and the relevant Sub-processor (and, where necessary, flowed down to Customer's benefit or made available for Customer's review under Section 24 and Annex 1), designed to provide a level of protection for the transferred Personal Data materially equivalent to that required under Applicable Data Protection Law; and/or

(b) Customer's own documented lawful basis for the transfer of its End-Clients' Personal Data (for example, contractual necessity, a legitimate interest assessment, or consent validly obtained by Customer from its own End-Clients), which Customer represents and warrants it holds and will maintain for the duration of the Principal Agreement. Processor shall provide Customer with the information reasonably necessary — including the Sub-processor list at Annex 1, the safeguards described in sub-paragraph (a), and the categories of transfer described in this DPA — to enable Customer to establish, document, and rely upon such lawful basis, and to make appropriate disclosures to its own End-Clients. For the avoidance of doubt, transfers of Team User Personal Data are governed by sub-paragraph (a) above.

(c) Processor shall not represent to Customer's End-Clients, and Customer shall not represent to its End-Clients, that transfer of End-Client Personal Data to Processor's Sub-processors occurs on the basis of consent obtained by Processor; any such consent, if relied upon, must be obtained and documented by Customer as controller of its End-Clients' Personal Data.

26. Reserved: EU/EEA Transfer Annex

Annex 3 is reserved for EU/EEA Standard Contractual Clauses (or successor transfer mechanism), to be added to this DPA if and when the Service is offered to EU-based Customers or EU/EEA-based Data Subjects. Until such time, Annex 3 has no content and no provision of this DPA should be read as implying that EU GDPR transfer mechanisms are currently in place.

27. Assistance with Data Subject Rights Requests

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall, taking into account the nature of the Processing, provide Customer with reasonable assistance (including by appropriate technical and organizational measures, insofar as possible) to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law; (b) Processor shall notify Customer without undue delay, and in any event within five (5) business days, if Processor receives a Data Subject rights request directly relating to Customer's Personal Data; and (c) Processor shall not respond to such request itself except to acknowledge receipt and redirect the Data Subject to Customer, unless otherwise required by law.

28. Personal Data Breach Notification

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall notify Customer without undue delay, and in any event within seventy-two (72) hours of Processor's own confirmed awareness of a Personal Data Breach affecting Customer's Personal Data; (b) Customer acknowledges that this window runs from Processor's own confirmed awareness of the breach and is necessarily dependent, in part, on the notification chains and timeliness of Processor's own Sub-processors, and Processor shall use commercially reasonable efforts to obtain prompt notice from its Sub-processors and to pass on relevant information without undue delay; (c) Processor shall not unreasonably delay its determination of whether an event constitutes a confirmed Personal Data Breach, and shall treat a Personal Data Breach as confirmed as soon as Processor has a reasonable degree of certainty that one has occurred, without waiting for full details; (d) such notification shall, to the extent then known, include (i) the nature of the Personal Data Breach, (ii) the categories and approximate number of Data Subjects and Personal Data records concerned, (iii) the likely consequences of the breach, (iv) the measures taken or proposed to address the breach and mitigate its effects, and (v) a contact point from which further information may be obtained; and (e) where not all such information is available within the notification window, Processor shall provide it in phases without further undue delay as it becomes available.

29. Audit and Inspection Rights

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall make available to Customer, on reasonable written request, information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied through the provision of relevant security certifications, audit reports, summaries of penetration testing, or other documentation then maintained by Processor in lieu of an on-site audit, given the current stage of Processor's operations; (b) if such documentation does not reasonably address Customer's request, Customer may conduct, or appoint a mutually agreed independent third-party auditor (subject to a confidentiality agreement) to conduct, an on-site audit of Processor's relevant Processing activities, no more than once per twelve (12)-month period, on no less than thirty (30) days' prior written notice, during normal business hours, and without unreasonably disrupting Processor's operations; and (c) Customer shall bear its own costs of any such audit unless the audit reveals a material breach of this DPA, in which case Processor shall bear the reasonable cost of that audit.

30. Deletion or Return of Data on Termination

Upon execution of an applicable Order Form incorporating this DPA: (a) Processor shall, upon termination or expiry of the Principal Agreement and at Customer's election, either delete or return to Customer all Personal Data Processed on Customer's behalf, within ninety (90) days of such termination or expiry, except to the extent Processor is required by Applicable Data Protection Law or other applicable law to retain some or all of such Personal Data, in which case Processor shall isolate and protect such retained data from further Processing except as required by that law; and (b) Processor shall, on Customer's written request, provide written certification of deletion following completion of this process.

31. Liability and Indemnity

Upon execution of an applicable Order Form incorporating this DPA: (a) each party's liability arising out of or in connection with this DPA, including any indemnity obligations relating to Processing of Personal Data, shall be subject to, and aggregated with, the limitations and exclusions of liability set out in the Principal Agreement; and (b) this DPA does not create a separate, uncapped liability regime, and any reference in this DPA to indemnification or liability shall be read as cross-referenced to and capped by the corresponding provisions of the Principal Agreement.

32. Governing Law and Dispute Resolution

Upon execution of an applicable Order Form incorporating this DPA, this DPA shall be governed by the laws of the United Arab Emirates, and any dispute arising out of or in connection with this DPA shall be resolved in accordance with the governing law and dispute resolution provisions (including choice of the Dubai courts, or arbitration under DIFC-LCIA or DIAC rules, as applicable) set out in the Principal Agreement.

33. Order of Precedence

Upon execution of an applicable Order Form incorporating this DPA: (a) in the event of a conflict between this DPA and the Principal Agreement (including any Order Form or Master Services Agreement) regarding the Processing of Personal Data, this DPA shall prevail to the extent of that conflict, solely with respect to data protection matters, and for all other matters, the Principal Agreement shall prevail; and (b) in the event of a conflict between Part I of this document and this Part II, Part II shall govern the relationship between Processor and the Customer that has validly incorporated it, and Part I shall continue to govern NextBayt's direct B2C relationships with individual Users.

34. Signature and Execution

This Part II is not signed on a standalone basis. It is executed, and becomes binding, only through: (a) an Order Form or Master Services Agreement between NextBayt and Customer that expressly states that this DPA (or a specified version of it) is incorporated by reference; or (b) a separate signature page appended to this document and signed by authorized representatives of both parties, referencing the applicable Order Form.

Where execution occurs by way of a separate signature page, the following block applies:

Processor

Customer

Legal Entity

NextBayt Analytics FZCO

[Customer Legal Name]

Signatory Name

Title

Signature

Date

Order Form Reference

[Order Form reference]

ANNEXES

Annex 1 — Sub-Processor List

Incorporated by reference into Part II, Sections 22–25. This is the same table published at Section 9 of Part I; the version applicable to a given Customer for purposes of Section 22 is the version current as of the date of the relevant Order Form, subject to updates under Section 23.

Sub-processor

Role

Location(s)

Data Category Processed

Cross-Border Transfer?

Google Cloud Platform (Google LLC)

Cloud hosting and infrastructure

United States (with global infrastructure)

Account/identity data, usage data, user-submitted content

Yes

Supabase, Inc.

Managed database and backend services

United States / distributed cloud regions

Account/identity data, usage data

Yes

Cloudflare, Inc.

Content delivery network, DNS, and security/DDoS protection

Global (edge network); United States (corporate)

Usage and device data (network/traffic metadata)

Yes

Anthropic, PBC (Claude)

AI chat and analysis functionality

United States

User-submitted content (queries/prompts)

Yes

OpenAI, L.L.C. (ChatGPT)

AI chat and analysis functionality

United States

User-submitted content (queries/prompts)

Yes

Moonshot AI (Kimi)

AI chat and analysis functionality

China

User-submitted content (queries/prompts)

Yes

DeepSeek

AI chat and analysis functionality

China

User-submitted content (queries/prompts)

Yes

Stripe, Inc.

Payment processing (Web only)

United States (global payment infrastructure)

Payment data, billing details

Yes

Google Analytics (Google LLC)

Product and usage analytics

United States

Usage and device data, analytics identifiers

Yes

Microsoft Clarity (Microsoft Corporation)

Product usage analytics (session/behavior analysis)

United States

Usage and device data, analytics identifiers

Yes

Meta Pixel (Meta Platforms, Inc.)

Marketing measurement and analytics

United States

Usage and device data, analytics/marketing identifiers

Yes

Prighter GmbH

EU Representative (Art. 27 GDPR); channels data subject requests and data breach notifications via its Privacy Rights Manager (PRM) and Data Breach Tool

Austria (Prighter); Germany (Hetzner Online GmbH, underlying infrastructure)

Data subject contact/identification details, request content

N/A (within EU)

Annex 2 — Technical and Organizational Security Measures

Processor maintains the following categories of technical and organizational measures, as applicable to the Service:

Encryption

  • Encryption of Personal Data in transit using TLS 1.2 or higher.
  • Encryption of Personal Data at rest within cloud infrastructure providers' storage and database services.

Access Control

  • Role-based access control limiting internal access to Personal Data on a need-to-know basis.
  • Multi-factor authentication required for administrative and privileged access to production systems.
  • Periodic review and revocation of access credentials, including prompt revocation upon personnel departure or role change.

Infrastructure and Network Security

  • Use of reputable cloud infrastructure providers (as listed in Annex 1) with their own independently certified physical and network security controls.
  • Web application firewall, DDoS mitigation, and edge security controls (via Cloudflare) in front of production services.
  • Network segmentation between production, staging, and development environments.

Backup and Business Continuity

  • Regular automated backups of production databases.
  • Periodic testing of backup restoration procedures.
  • Redundancy across cloud provider availability zones for core infrastructure, subject to the underlying provider's architecture.

Incident Response

  • A documented incident response process for identifying, containing, investigating, and remediating Personal Data Breaches.
  • Escalation procedures designed to identify a Personal Data Breach and inform affected parties within the timeframes described in Section 28.

Organizational Measures

  • Confidentiality obligations applicable to personnel with access to Personal Data.
  • Vendor due diligence and contractual data protection terms with Sub-processors, as described in Section 11 and Section 24.
  • Periodic internal review of the sub-processor list and applicable security commitments.

Annex 3 — Reserved

Reserved for EU/EEA Standard Contractual Clauses, to be added if and when the Service is offered to EU-based Customers or data subjects. No content is currently included in this Annex 3, and its inclusion in this document as a placeholder does not imply that EU GDPR transfer mechanisms are presently in effect.

VERSION AND CHANGELOG

Version

Effective Date

Summary of Changes

1.0

21 August 2026

Initial publication of Part I (Sub-Processor and Cross-Border Transfer Disclosure) and Part II (Template DPA for future B2B/Enterprise Customers).

Last Updated: 21 August 2026