Data Processing Addendum

Last updated: 30 June 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Terms”) between HAANK for Computer Systems & Communication Equipment Software Trading (“HAANK”, “we”, “us”, the “Processor”), of Dubai, United Arab Emirates, and the Subscriber (the café, the “Controller”, “you”). It governs our processing of personal data that you, as controller, place in the Service about your own customers and contacts (“Controller Personal Data”). It applies where, and to the extent that, we process Controller Personal Data on your behalf, and is in addition to our Privacy Policy. It is entered into by your acceptance of the Terms; if your compliance team requires a separately signed copy, contact us at support@midaone.com. Terms used here have the meaning given in the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the “PDPL”).

1. Roles

For Controller Personal Data, you are the controller and we are your processor. You are responsible for the lawfulness of that data, for having a lawful basis to collect and use it, and for any notices or consents required from the individuals. (Separately, for your own account and business data, HAANK is the controller, as described in the Privacy Policy.)

2. Scope of processing

Subject matter & duration. Our provision of the Service to you, for as long as your account is active and during any wind-down described in Section 8.
Nature & purpose. Hosting, storing, organising, displaying, backing up, and otherwise processing Controller Personal Data only to provide and support the Service.
Types of personal data.The data you choose to record — typically your customers' names, phone numbers, loyalty activity, and order history.
Categories of data subjects. Your customers and contacts.

3. Our obligations as processor

We will: (a) process Controller Personal Data only on your documented instructions, which include the Terms, this DPA, your configuration and use of the Service, and any further written instruction you give — unless the law requires otherwise, in which case we will tell you unless legally prohibited; (b) ensure that people authorised to process the data are bound by confidentiality; (c) implement appropriate technical and organisational security measures (see Section 5); and (d) not sell Controller Personal Data or use it for our own purposes. If we believe an instruction breaches the PDPL or other data-protection law, we will inform you.

4. Sub-processing

You give general authorisation for us to engage the sub-processors listed in our Privacy Policy (currently Vercel and Neon for hosting and database, Vercel Blob for images, Resend for email, Sentry for error monitoring, and Stripe for payments) to process Controller Personal Data to provide the Service. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Before we add or replace a sub-processor that processes Controller Personal Data, we will give at least 30 days' notice (by email or in the app); if you reasonably object on data-protection grounds and we cannot resolve it, you may terminate the affected Service.

5. Security

We maintain appropriate technical and organisational measures to protect Controller Personal Data, including encryption in transit (HTTPS), hashed passwords, optional two-factor authentication for admin accounts, access controls, rate limiting, and regular backups. We review these measures and may update them, provided the level of protection is not materially reduced.

6. Assistance

Taking into account the nature of the processing and the information available to us, we will reasonably assist you to: (a) respond to requests from individuals exercising their rights over Controller Personal Data — where an individual contacts us, we will refer them to you and not respond directly except on your instruction; (b) keep the data secure, notify breaches, and carry out any data-protection impact assessment or prior consultation; and (c) meet your own obligations under the PDPL. Breach notification: we will notify you without undue delay, and in any event as soon as reasonably practicable after we become aware of a personal-data breach affecting Controller Personal Data, and give you the information you reasonably need to meet your own notification duties to the UAE Data Office and affected individuals.

7. International transfers

The Service is currently hosted in the United States, and some sub-processors operate outside the UAE. Where we transfer Controller Personal Data outside the UAE, we do so under appropriate contractual safeguards with the recipient pursuant to Article 23 of the PDPL, and not on the basis of your or any individual's consent for transfers that are necessary to provide the Service.

8. Return & deletion

You can export Controller Personal Data at any time while your account is active. On termination, you have 30 days to export it; after that we may delete or anonymise it within a further 90 days. These periods are maximums: on your instruction, on a verified deletion request, or on permanent deletion of the account, we may delete sooner — except where we must retain certain records to meet a legal, tax, or accounting obligation, in which case we keep them only as long as required and keep them protected. We will confirm deletion in writing on request.

9. Audit & information

On reasonable written request, we will make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits take place on reasonable advance notice, during business hours, subject to confidentiality, no more than once per year unless required by a regulator or following a breach, and without disrupting our other customers or compromising their data.

10. Liability

Each party's liability under or in connection with this DPA is subject to the limitation of liability in the Terms.

11. Term, conflict & governing law

This DPA takes effect when you accept the Terms and continues while we process Controller Personal Data. If there is a conflict between this DPA and the rest of the Terms about the processing of Controller Personal Data, this DPA prevails. This DPA is governed by the same law and subject to the same courts as the Terms (the laws of the United Arab Emirates as applied in the Emirate of Dubai).

12. Contact

Questions about this DPA, or to request a signed copy, contact us at support@midaone.com.

This document is not legal advice. HAANK should have it reviewed by a qualified UAE lawyer before relying on it.