Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between LEINO SYSTEMS SOFTWARE DESIGN FZCO ("Khulasa", "Processor") and the customer ("Customer", "Controller"). Where this DPA conflicts with the Terms of Service on the processing of Personal Data, this DPA prevails.
1Definitions
Terms defined in the Terms of Service have the same meaning here. In addition:
"Applicable Data Protection Law" — Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations, and any other data protection law applicable to the processing, including the Saudi Personal Data Protection Law where relevant.
"Data Subject", "Personal Data", "Processing", "Controller", "Processor" — as defined in Applicable Data Protection Law.
"Sub-processor" — any third party engaged by Khulasa to process Customer Personal Data.
"Customer Personal Data" — Personal Data contained within Customer Data.
2Roles and scope
Customer is the Controller and Khulasa is the Processor in respect of Customer Personal Data. Each party complies with its own obligations under Applicable Data Protection Law.
Customer warrants that it has established and will maintain a valid lawful basis for the Processing, has provided all required transparency information to Data Subjects including Meeting Participants, and has obtained any consent required — including in respect of recording under Article 44 of Federal Decree-Law No. 34 of 2021.
The subject matter, duration, nature, purpose, categories of Personal Data and categories of Data Subject are set out in Annex I.
3Khulasa's processing obligations
Khulasa will:
(a) process Customer Personal Data only on Customer's documented instructions, including as set out in this DPA and the Terms of Service, and as necessary to provide, secure and support the Service;
(b) inform Customer if it believes an instruction infringes Applicable Data Protection Law, and may suspend performance of that instruction pending resolution;
(c) not sell, rent or disclose Customer Personal Data, or process it for its own purposes, except as permitted by Clause 4;
(d) ensure personnel authorised to process Customer Personal Data are subject to written confidentiality obligations and receive appropriate data protection training;
(e) implement and maintain the technical and organisational measures in Annex II;
(f) assist Customer, taking into account the nature of processing and information available to Khulasa, with Customer's obligations regarding security, breach notification, data protection impact assessments and prior consultation with the UAE Data Office;
(g) where legally compelled to disclose Customer Personal Data, notify Customer first unless prohibited by law, and disclose only the minimum required.
4Permitted independent processing
Khulasa may process Customer Personal Data as an independent Controller only for:
(a) billing, account administration and relationship management; (b) compliance with its own legal obligations; (c) detecting, preventing and investigating security incidents, fraud and abuse of the Service; and (d) generating aggregated, anonymised statistics that cannot reasonably be used to identify Customer, any Authorised User or any Data Subject.
Khulasa will not use Customer Personal Data to train, fine-tune or improve machine learning models unless Customer has expressly opted in via the setting described in Terms of Service Clause 7.4. Where Customer opts in, Customer warrants it has obtained the separate, specific consent of affected Data Subjects for that purpose. Khulasa applies de-identification prior to such use. Customer may withdraw the opt-in at any time, effective for future processing.
5Data Subject rights
Khulasa will, taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights, including access, rectification, erasure, restriction, portability and objection.
The Service provides self-service functionality enabling Customer to access, export, correct and delete Customer Personal Data. Where Customer cannot fulfil a request using that functionality, Khulasa will provide reasonable assistance at its then-current professional services rates.
Where Khulasa receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively but will promptly refer the request to Customer, within 10 working days.
6Sub-processors
Customer grants general authorisation for Khulasa to engage Sub-processors. The current list is maintained at https://khulasa.ai/en/legal/subprocessors, showing each Sub-processor's identity, location and processing function.
Khulasa will:
(a) impose data protection obligations on each Sub-processor no less protective than those in this DPA;
(b) remain fully liable to Customer for each Sub-processor's performance;
(c) give Customer at least 30 days' notice before adding or replacing a Sub-processor, by hello@leino.dev; and
(d) allow Customer to object on reasonable data protection grounds within that notice period.
Where Customer objects reasonably and Khulasa cannot provide the Service without the Sub-processor or offer a commercially reasonable alternative, either party may terminate the affected part of the Service, and Customer receives a pro-rata refund of prepaid fees for the unused period.
7International transfers
Khulasa may transfer Customer Personal Data outside the United Arab Emirates only where the transfer complies with Articles 22 and 23 of the PDPL.
Transfer destinations and safeguards are described in Annex III.
Where Customer has elected regional processing under Terms of Service Clause 7.3, Khulasa will not transfer Customer Personal Data outside UAE except as necessary to provide support and with Customer's prior written approval.
8Security incidents
Khulasa will notify Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting Customer Personal Data.
The notification will describe, to the extent known: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, measures taken or proposed, and the contact point for further information. Khulasa will provide updates as further information becomes available and will cooperate with Customer's own notification obligations under Article 33 of the PDPL.
Khulasa's notification is not an acknowledgement of fault or liability.
9Audit
Khulasa will make available to Customer information reasonably necessary to demonstrate compliance with this DPA.
Where that information is insufficient, Customer may audit Khulasa's compliance, subject to:
(a) no more than once per twelve months, unless required by a regulator or following a Personal Data breach; (b) at least 30 days' written notice; (c) conducted during business hours with minimal disruption; (d) an auditor who is not a competitor of Khulasa and who signs confidentiality undertakings; (e) scope limited to Khulasa's processing of Customer Personal Data, excluding other customers' data, and excluding Khulasa's source code, model weights and commercially sensitive information; and (f) Customer bearing its own costs and Khulasa's reasonable costs
Sub-processor facilities are audited by Khulasa, which will share relevant findings; Customer has no direct audit right against Sub-processors.
10Return and deletion
On termination or expiry, Khulasa will, at Customer's election:
(a) make Customer Personal Data available for export for 30 days; and thereafter (b) delete Customer Personal Data from active systems within 30 days and from backups within 90 days.
Khulasa may retain Customer Personal Data where required by law, for the duration of that requirement, subject to continued confidentiality and the security measures in Annex II.
Khulasa will certify deletion in writing on Customer's request.
11Liability
Each party's liability under this DPA is subject to the limitations and exclusions in Clause 12 of the Terms of Service.
12Duration and general
This DPA applies for as long as Khulasa processes Customer Personal Data.
Khulasa may update this DPA to reflect changes in Applicable Data Protection Law — including the publication of the PDPL's Executive Regulations — on 30 days notice, provided the update does not materially reduce the protections afforded to Customer.
This DPA is governed by the law and subject to the dispute resolution mechanism in Clause 15 of the Terms of Service.
ANNEX I — Details of processing
Subject matter. Provision of the Khulasa meeting recording, transcription, summarisation and distribution Service.
Duration. For the term of the Terms of Service, plus the retention and deletion periods in Clause 10.
Nature and purpose. Capture of meeting audio; automated speech recognition; speaker diarisation; machine translation; generation of summaries, action items and insights; storage; and distribution of Output to recipients designated by Customer.
Categories of Data Subject.
- Customer's Authorised Users
- Meeting Participants, including individuals external to Customer's organisation
- Individuals discussed or named during a meeting
Categories of Personal Data.
- Identity data — names, job titles, organisational affiliation
- Contact data — email addresses
- Voice recordings and derived audio characteristics
- Transcripts of spoken content, and any Personal Data contained within that content
- Speaker attribution data
- Calendar metadata — meeting titles, times, invitee lists
- Usage data associated with Authorised Users
Special categories of Personal Data. Not intentionally processed. Customer must not use the Service for meetings in which special category data is a subject of discussion, except as permitted under Terms of Service Clause 5. Where such data is incidentally captured in ordinary business conversation, it is processed under the same measures as all other Customer Personal Data.
Frequency. Continuous, for the duration of each meeting the Meeting Assistant attends, and on an ongoing basis for storage and access.
ANNEX II — Technical and organisational measures
Encryption
- In transit: TLS 1.2 or higher
- At rest: AES-256
Access control
- Role-based access control, least privilege
- Multi-factor authentication for all administrative access
Logging and monitoring
- Audit logging of access to Customer Personal Data
Personnel
- Written confidentiality undertakings
- Background screening
Sub-processor management
- Due diligence before engagement
- Contractual data protection obligations
ANNEX III — Sub-processors and transfer destinations
Maintained and updated at https://khulasa.ai/en/legal/subprocessors.