Data Processing Addendum
This Data Processing Addendum (DPA) forms part of the SKYL Terms & Conditions for Customers acting as data controllers under Saudi PDPL, EU/UK GDPR, or comparable data-protection regimes.
Last updated: 4 July 2026
1. Roles
The Customer is the data controller. SKYL is the data processor and processes personal data on behalf of the Customer strictly to provide the SKYL service as documented in the Terms and this DPA.
2. Subject matter and duration
Subject matter: providing the SKYL workspace platform to the Customer. Duration: the term of the subscription plus the retention window described in the Privacy Policy.
3. Nature and purpose
Hosting, storing, transmitting and displaying Customer Content; sending operational notifications; providing support; securing the service; billing.
4. Categories of data subjects
Customer's employees, contractors, invited manufacturers, agencies, designers, creators and any other individual invited into the Customer's workspace.
5. Categories of personal data
Contact details, professional role, workspace activity, messages, tasks, uploaded files, images and documents, and any other personal data the Customer or its invited Users choose to submit into the workspace.
6. Sub-processors
SKYL uses a limited set of sub-processors for cloud hosting, database, file storage, transactional email, payments, analytics, authentication and error monitoring. Each sub-processor is bound by written commitments providing at least the same protection as this DPA. An up-to-date list is available on request from contact@skyl.solutions.
7. Security
SKYL implements the technical and organisational measures described in the Security Policy, including encryption in transit and at rest, access controls, monitoring, backups and incident response.
8. Confidentiality
All SKYL personnel with access to Customer personal data are bound by written confidentiality obligations.
9. Assistance to the Customer
SKYL will provide reasonable assistance to the Customer for responding to data subject requests, conducting data protection impact assessments, and handling regulator inquiries, taking into account the nature of processing and the information available to SKYL.
10. Personal data breach notification
SKYL will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and will provide the information reasonably required by the Customer to meet its own notification obligations.
11. International transfers
Where personal data is transferred across borders, the parties will rely on the transfer mechanisms recognised by the applicable law (including Standard Contractual Clauses under GDPR for EU/UK data, and equivalent safeguards for Saudi PDPL and other jurisdictions).
12. Deletion and return
On termination of the subscription, SKYL will delete or return Customer personal data in accordance with the retention windows described in the Privacy Policy, unless continued retention is required by law.
13. Audits
SKYL will make available on request the information reasonably necessary to demonstrate compliance with this DPA. Audits by the Customer or an independent auditor may be arranged on reasonable prior notice, subject to appropriate confidentiality commitments and scheduling.
14. Signing
For a countersigned copy of this DPA for enterprise procurement, contact contact@skyl.solutions.