Skip to the content

Data processing agreement

The written contract Article 28 of the GDPR requires between you as controller and us as processor: what we process, on whose instructions, with what security, and what happens to it at the end.

Effective 6 Sep 2026

On this page

This is the full text. A summary of the parts that matter most is on the data processing agreement summary, and every section there opens the section it summarises. The summary is a reading aid. This document is the agreement.

1. What this is, and where it sits

1.1 Dardaris is a product of Techroun LLC, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, trade licence number 2543150.01 issued by Sharjah Media City, tax registration number 105325244900001.

1.2 This document is the DPA the terms of service define and incorporate. It is part of your agreement with us, not a separate contract, and it needs no separate signature.

1.3 It uses the words the terms define. Customer Data, AI Processing, AI Provider, Output, Tenant, Workflow, Order, Usage Data and Service mean here what they mean there.

1.4 It applies to personal data in Customer Data, where you are the controller or a processor for another controller and we act for you. It does not apply to the data we hold as controller in our own right, which is your account, billing, security, abuse and support data. Which role applies to what is set out in the privacy policy.

1.5 Where this document and the privacy policy disagree about Customer Data, this one wins. Where it and the rest of the terms disagree on data protection, this one wins on that subject matter only. Everything else stays where the terms put it, except that the exclusion of a third party's sums in the terms does not apply to a claim you bring against us for our share of a data protection liability.

1.6 Nothing here reduces an obligation the law places on either of us directly. Where a period in this document is shorter than the law allows, the shorter one applies; where the law is stricter, the law applies.

2. What is processed, and for whom

2.1 Subject matter. Running the Service for you: holding your portfolio, reading and filing the documents and messages you put in, answering questions from them, and carrying out the Workflows you configure.

2.2 Duration. For as long as your account is open, and then for the periods in clause 10.

2.3 Nature and purpose. Collection, recording, organisation, structuring, storage, retrieval, consultation, indexing, embedding, classification, extraction, translation, summarisation, generation of Output, transmission, restriction, erasure and destruction, and the AI Processing the terms describe. The purpose is to provide, secure and support the Service for you. We improve the Service from Usage Data and from data that no longer identifies anybody, which is what the terms reserve, and not from personal data in Customer Data.

2.4 Categories of people. The people your portfolio is about: your tenants, occupants and prospective tenants, short stay guests, guarantors and co-signatories, neighbours who come up in a matter, the people at your contractors and suppliers, the people at a managing agent or a co-ownership association, and the people on your own team you invite.

2.5 Types of personal data. Names, postal and email addresses, telephone numbers and the language someone reads in; lease, tenancy and booking details; payment, arrears and bank reference data; correspondence you connect or forward, with whatever it happens to contain; identity and income documents you upload; photographs of a property and of its condition; meter and access details; and the machine-generated representations of all of it described in clause 12.

2.6 Special categories. The terms allow the special categories of data in Article 9 of the GDPR, and criminal offence data, only where the feature you are using expressly supports them and you hold the basis and the conditions the law requires. A document you upload may contain them even where you did not intend it. Where that happens we may suspend AI Processing of it, quarantine it or delete it, as the terms provide, and we will tell you.

2.7 Your obligations and rights. You decide the purposes and means. You warrant in the terms that you collected Customer Data lawfully and hold the rights needed to instruct the processing described here, and it is for you to give the people in your portfolio the information the law requires, to answer them, and to decide whether a breach is notifiable. Your rights are the ones in this document and in Article 28: to instruct, to be told, to be helped, to object to a sub-processor, to inspect, and to have the data returned or deleted.

3. Your instructions

3.1 We process Customer Data only on your documented instructions, including about transfers, unless Union or Member State law to which we are subject requires otherwise. Where that happens we will tell you before processing, unless that law forbids telling you on important grounds of public interest. A demand from any other public authority is handled under clause 9 and is not an instruction.

3.2 Your instructions are: this document, the terms, any Order, the settings and Workflows you configure in the product, and anything else you tell us in writing that we accept. Keeping the Service secure and investigating abuse of it are instructed by the terms themselves.

3.3 Configuring the product is instructing us. Turning on a Workflow, setting a spend limit, connecting a mailbox and choosing what happens without your approval are all documented instructions.

3.4 If we believe an instruction infringes the GDPR or another data protection law, we will tell you immediately and may pause that processing until it is resolved. We do not have to carry out an instruction we consider unlawful.

4. Confidentiality

4.1 Everyone we allow to process Customer Data is bound to confidentiality, by contract of employment or by a written undertaking, and that duty survives their leaving.

4.2 Access is limited to the people who need it to run, secure or support the Service, and to what each of them needs. Our professional advisers and auditors, and a buyer in a sale of the business, are bound to confidentiality on no weaker terms.

4.3 We do not look at your content to satisfy curiosity. A person reads it when you ask for support that requires it, when we are investigating an incident or abuse, or when the law requires it.

5. Security

5.1 We keep the measures below, and we may change them, but not so that protection drops below what is described here.

5.2 In transit and at rest. Connections between you and the Service, and between the Service and its providers, are encrypted. Stored data and uploaded files are encrypted at rest by the platform the Service runs on. Mail we send on your behalf leaves over an encrypted connection, and we cannot control how the receiving system carries it onward.

5.3 Separation. Every read is scoped to the team it belongs to at the point the data is fetched, not by a filter applied afterwards, and an identifier from another team is refused rather than answered emptily. Uploaded files are addressed by an identifier that cannot be guessed from a neighbouring one.

5.4 Access. Sign-in requires a verified address and a password held only as a one-way hash, never the password itself, or a passkey. Rate limits are applied to the endpoints that take a credential. Administrative access to production is limited to named people.

5.5 Resilience. The database can be restored to a point in time within the platform's recovery window. Uploaded files are stored redundantly by the platform.

5.6 Change. A change passes an automated test suite before it is released, and that suite includes tests that prove one customer cannot read another's rows.

5.7 Your own copy. The product keeps a working copy of your portfolio in the browser you use, so a screen can draw before the network answers. Signing out and clearing site data removes it, and what happens on a device you control is yours to manage. The privacy policy says more.

5.8 Keeping them under review. We review these measures and the risks they answer, and we act on a vulnerability we find or are told about. Section 8.2 of this document is how to tell us about one.

5.9 Assessing them. These measures are what we consider appropriate for the risk, given the kinds of data in clause 2. You are entitled to disagree, and clause 11 is how you look for yourself. Where a measure is provided by a sub-processor rather than by us, clause 11 is also how you reach its own assurances.

6. Sub-processors

6.1 You give us a general written authorisation to engage sub-processors. The ones engaged today are listed at processors and sub-processors. That list is part of this agreement for the purpose of this clause, whatever the terms say about the privacy policy generally.

6.2 Before a new or replacement sub-processor starts processing Customer Data, we publish it on that list and tell the administrative contact on your account. You get at least 30 days between that notice and it starting.

6.3 You may object during those 30 days, in writing to support@dardaris.com, on reasonable data protection grounds. Tell us what the ground is.

6.4 If you object we will try to offer a change that meets it. If we cannot, you may end the affected part of the Service, or the Service, by written notice before the sub-processor starts, and we will refund fees paid for the period after it ends. That is your remedy for an objection we cannot meet.

6.5 Each sub-processor is engaged under written terms that bind it to data protection and confidentiality obligations, and we remain fully liable to you for its performance.

6.6 A sub-processor engages its own providers. Where its published list is named on ours, a change it makes there does not go through clause 6.2, and what you get instead is our undertaking in clause 6.5 and the assurances in clause 11.

6.7 A change made to answer an emergency security need may shorten the 30 days, but not the publication and the notice, which still come before the sub-processor starts. Your right to object and to end is unaffected.

7. Helping you answer the people in your portfolio

7.1 Given the nature of the processing, we help you meet your duty to answer requests under Chapter III of the GDPR, by appropriate technical and organisational measures and as far as is possible.

7.2 Much of it you can do yourself. You can export the whole portfolio as a single machine-readable file at any time, and find, correct and delete records in the product.

7.3 If a person asks us directly, we will not answer for you. We will tell you promptly, and point them to you, unless the law requires otherwise.

7.4 For anything you cannot do in the product, ask at support@dardaris.com. We will acknowledge within 3 working days and give you what you need in time for the month Article 12 gives you, unless the request is one neither of us can meet in that time, in which case we will say so at once. We do not charge for help that is proportionate to the request.

8. Incidents, and helping you with your own duties

8.1 We tell you about a personal data breach affecting Customer Data without undue delay after becoming aware of it, and in any case within 48 hours. Becoming aware includes a sub-processor telling us, and clause 6.5 is how we require them to. Nothing in that period displaces the law, which requires us to tell you without undue delay.

8.2 The notice will say what we know: what happened, the categories and approximate number of people and records involved as far as we can tell, the likely consequences, what we are doing about it, and where to ask for more. If we cannot say everything at once we will say what we can and follow it.

8.3 Telling you is not us deciding for you. Whether the breach is notifiable to a supervisory authority or to the people affected is yours to decide, because you are the controller.

8.4 We help you with your own obligations under Articles 32 to 36 of the GDPR, as far as is possible and taking into account what we know that you do not. That includes an impact assessment, a prior consultation, and, where you have to tell the people affected, the records and the contact details you need to reach them.

9. Where the data goes

9.1 Your content sits on the infrastructure the privacy policy describes and is not copied into a second database at our own seat. We are established in Sharjah, the United Arab Emirates, outside the European Economic Area, and we reach that infrastructure from there, which is a transfer. The Service runs on globally distributed infrastructure and we make no residency promise beyond what the terms and the privacy policy say.

9.2 For personal data coming from the European Economic Area, the standard contractual clauses adopted by the European Commission in Decision 2021/914 apply to that transfer and to the onward transfers to our sub-processors, and are incorporated into this agreement. Module Two applies where you are a controller and Module Three where you are yourself a processor. Where the United Kingdom applies, the international data transfer addendum issued under section 119A of the Data Protection Act 2018 applies to the same clauses. Where Switzerland applies, the clauses are read with the adaptations the Swiss authority requires.

9.3 For those clauses: you are the data exporter and we are the data importer; the transfer is continuous for as long as your account is open; the description of the transfer is in clause 2; the technical and organisational measures are in clause 5; and the sub-processors are the list named in clause 6. The optional docking clause applies.

9.4 The clauses are governed by the law of Ireland and disputes under them go to the courts of Ireland, and we submit to those courts. The governing law and the forum in the terms do not displace this clause, and where those clauses and anything else in your agreement conflict, the clauses prevail on their own subject matter.

9.5 We assess whether the law where we are lets us keep those commitments, and we tell you if we conclude it does not. UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies to us at home, and where it and the GDPR both reach the same processing we apply whichever gives the stronger protection.

9.6 If we receive a demand from a public authority for Customer Data, we will tell you unless we are legally forbidden, we will challenge a demand that appears unlawful or excessive, and we will disclose only the minimum required. We keep a record of what we disclose.

9.7 On a representative in the European Economic Area and in the United Kingdom, the position is the one stated in the privacy policy. A request or a notice under this agreement reaches us at support@dardaris.com.

10. Deletion and return

10.1 At the end, you choose whether Customer Data is returned or deleted. If you do not choose, we delete it. Return is effected by the export in clause 7.2, which is the mechanism this agreement provides.

10.2 Take the export before you close the account. Closing it erases the portfolio at once, and the terms do not oblige us to keep access open or to build an export afterwards. Where an Order sets a retrieval period, that period applies instead and we will say so.

10.3 Erasure covers Customer Data in active systems, including the machine-generated representations in clause 12, which go with the material they came from. What is kept beyond it, and for how long, is the schedule in the privacy policy.

10.4 A copy may remain in an isolated backup or in database history until it is overwritten on the ordinary cycle. It is not used for anything, and if a backup is restored we reapply the deletion where it is reasonably feasible.

10.5 We keep what Union or Member State law requires us to keep, for no longer than it requires, and we will tell you what and why if you ask.

10.6 We will confirm in writing that deletion has been done, if you ask for confirmation.

11. What you can inspect

11.1 We make available the information you need to show that this agreement is being kept, and we submit to audits and inspections carried out by you or by an auditor you appoint.

11.2 In practice, start by asking at support@dardaris.com. We will answer a reasonable set of questions in writing, and give you what we have: the current sub-processor list, the description of measures in clause 5, and the certifications and audit reports our sub-processors publish or make available to us, so far as we are allowed to pass them on.

11.3 If that does not satisfy you, you may audit. You choose the auditor. Give us reasonable notice, keep what you learn confidential, and do it in a way that does not disturb other customers or the security of the Service. Once in any 12 months is ordinarily enough, and an audit after a breach or at a regulator's requirement is not counted against that.

11.4 We bear our own cost of one audit in 12 months. We may charge for our reasonable time beyond that, at a rate we tell you before you commit to it, and not at a level that makes the right theoretical.

12. What the models are given, and what comes back

12.1 AI Processing is part of the Service, not an optional extra, and the terms describe what it does. Using it is one of your instructions under clause 3.

12.2 The models are run by the platform the rest of the Service runs on, named on the sub-processor list. Customer Data is not sent to any other model provider. If that changes, clause 6 governs it and the list is updated before anything reaches a new one.

12.3 Indexes, embeddings, extracted fields, classifications and summaries are made from your content and held for your account. Where they contain personal data or can be linked to it they are Customer Data, they fall under this agreement, and clause 10 deletes them.

12.4 We do not use personal data in Customer Data to train a general purpose or shared model for anybody else, and we contractually restrict our AI Providers from using Customer Data to train theirs. The terms say the same, and neither of us may read this agreement as permission to do otherwise.

12.5 Output is generated text and it can be wrong. What the product does with it, and what waits for you, is the subject of the terms, not of this agreement.

13. Records, and cooperation

13.1 We keep a record of the processing we carry out for you, as Article 30 of the GDPR requires of a processor. It names us and the categories of processing we carry out for each controller, the transfers out of the European Economic Area and the safeguard applied to them, and a general description of the measures in clause 5. On request we will tell you the recipients, the third countries and the safeguards that apply to your own data.

13.2 We cooperate with a supervisory authority on request in the performance of its tasks.

13.3 On a data protection officer, the position is the one stated in the privacy policy. A question that would go to one reaches us at support@dardaris.com.

14. Changing this agreement, and reaching us

14.1 We may change this document to reflect a change in the Service, in our sub-processors, or in the law. We publish the new version here with a new date at the top.

14.2 A change that materially reduces your protection takes effect at least 30 days after we publish it, and we will tell you before it does. If you do not accept it you may end the Service before it takes effect.

14.3 A change made to comply with the law, or to answer a security need, may take effect sooner where it has to.

14.4 Anything under this agreement, including a question, an objection, a rights request or a notice, goes to support@dardaris.com.

15. Language

15.1 This document is written in English, and the English text is the operative version to the extent the law permits. We publish translations of it so that it can be read in the language you work in. A translation is an approximation offered as a reading aid, it is not a second original, nobody is bound by its wording, and where it differs from the English text the English text is the one that applies.

15.2 If English is not a language you read comfortably and something here matters to you, write to support@dardaris.com and we will explain the passage. That is help with reading this document, not a change to what it says.