Data Processing Addendum

This Data Processing Addendum (DPA) forms part of the SKYL Terms & Conditions for Customers acting as data controllers under Saudi PDPL, EU/UK GDPR, or comparable data-protection regimes.

Last updated: 4 July 2026

1. Roles

The Customer is the data controller. SKYL is the data processor and processes personal data on behalf of the Customer strictly to provide the SKYL service as documented in the Terms and this DPA.

2. Subject matter and duration

Subject matter: providing the SKYL workspace platform to the Customer. Duration: the term of the subscription plus the retention window described in the Privacy Policy.

3. Nature and purpose

Hosting, storing, transmitting and displaying Customer Content; sending operational notifications; providing support; securing the service; billing.

4. Categories of data subjects

Customer's employees, contractors, invited manufacturers, agencies, designers, creators and any other individual invited into the Customer's workspace.

5. Categories of personal data

Contact details, professional role, workspace activity, messages, tasks, uploaded files, images and documents, and any other personal data the Customer or its invited Users choose to submit into the workspace.

6. Sub-processors

SKYL uses a limited set of sub-processors for cloud hosting, database, file storage, transactional email, payments, analytics, authentication and error monitoring. Each sub-processor is bound by written commitments providing at least the same protection as this DPA. An up-to-date list is available on request from contact@skyl.solutions.

7. Security

SKYL implements the technical and organisational measures described in the Security Policy, including encryption in transit and at rest, access controls, monitoring, backups and incident response.

8. Confidentiality

All SKYL personnel with access to Customer personal data are bound by written confidentiality obligations.

9. Assistance to the Customer

SKYL will provide reasonable assistance to the Customer for responding to data subject requests, conducting data protection impact assessments, and handling regulator inquiries, taking into account the nature of processing and the information available to SKYL.

10. Personal data breach notification

SKYL will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and will provide the information reasonably required by the Customer to meet its own notification obligations.

11. International transfers

Where personal data is transferred across borders, the parties will rely on the transfer mechanisms recognised by the applicable law (including Standard Contractual Clauses under GDPR for EU/UK data, and equivalent safeguards for Saudi PDPL and other jurisdictions).

12. Deletion and return

On termination of the subscription, SKYL will delete or return Customer personal data in accordance with the retention windows described in the Privacy Policy, unless continued retention is required by law.

13. Audits

SKYL will make available on request the information reasonably necessary to demonstrate compliance with this DPA. Audits by the Customer or an independent auditor may be arranged on reasonable prior notice, subject to appropriate confidentiality commitments and scheduling.

14. Signing

For a countersigned copy of this DPA for enterprise procurement, contact contact@skyl.solutions.