انتقل إلى المحتوى

داينمو. محرك الأعمال الأول

هذه الصفحة متاحة حاليًا باللغة الإنجليزية فقط.

Data Processing Agreement

In force

1.0

Last updated:

This Data Processing Agreement (the “DPA”) forms part of the agreement between the Customer and DYNAMO (“Dynamo”) for the DynamoOS Services, which is the Terms of Service or a signed agreement (the “Agreement”). It applies to personal data that Dynamo processes on the Customer’s behalf in the Customer’s workspace. It applies once the Customer accepts the Agreement, and can also be signed separately where the Customer requires it.

1.Parties and background

1.1The Customer (the “Controller”) is the organization that created or uses the DynamoOS workspace, identified in the signup record or in the signature block below.

1.2Dynamo (the “Processor”) is DYNAMO, a company incorporated in the United Kingdom.

1.3The Controller uses the Services to store and process business data that includes personal data. The parties agree this DPA so that the processing meets the requirements of the UK General Data Protection Regulation and the Data Protection Act 2018 and, where they apply to the Controller’s processing, other data protection laws such as the EU General Data Protection Regulation or the Saudi Personal Data Protection Law (PDPL) and its implementing regulations (together, “Data Protection Law”).

1.4This DPA does not cover personal data that Dynamo collects for its own purposes through its website, the signup and the status page, for which Dynamo is the controller under the Privacy Policy.

2.Definitions

2.1“Personal data”, “data subject”, “processing”, “controller”, “processor” and “personal data breach” have the meaning given in Data Protection Law. “Customer Personal Data” means personal data in the Customer Data that Dynamo processes on the Customer’s behalf under the Agreement. “Subprocessor” means a third party that Dynamo engages to process Customer Personal Data. “Services” and “Customer Data” have the meaning given in the Terms of Service.

3.Subject matter, duration, nature and purpose of the processing

3.1Subject matter: providing the Services to the Controller, which means hosting and operating the Controller’s workspace and the apps in its Plan.

3.2Duration: the term of the Agreement, and afterwards until the Customer Personal Data has been returned or deleted under the section “Return and deletion”.

3.3Nature: storing, retrieving, displaying, transmitting, backing up, exporting and deleting data, and the other operations needed to run the Services, including search and, where the Controller has switched it on, Dynamo AI.

3.4Purpose: to provide, secure, support and maintain the Services for the Controller, as the Controller instructs. Annex I gives the details.

4.Roles and responsibilities of the Controller

4.1The Controller decides what personal data it enters into the Services and why. It is responsible for having a lawful basis, for giving the notices and obtaining the consents Data Protection Law requires, for the accuracy and quality of the data, and for the roles, permissions and sharing it configures in its workspace.

4.2The Controller will not enter into the Services categories of data that the Plan or the Agreement does not allow, and will tell Dynamo before it starts processing special categories of personal data (such as health, biometric or religious data) or data about criminal offences in the Services, and is responsible for the additional conditions and safeguards that Data Protection Law requires for such data.

5.Instructions

5.1Dynamo will process Customer Personal Data only on the Controller’s documented instructions, which are: the Agreement, this DPA, the use and configuration of the Services by the Controller and its Authorized Users, and further written instructions that are consistent with the Agreement. Dynamo will not process Customer Personal Data for its own purposes and will not sell it, share it for advertising, or use it to train artificial-intelligence models.

5.2If Dynamo believes an instruction breaches Data Protection Law, it will tell the Controller without delay and may suspend the instruction until the Controller confirms or changes it. If Dynamo is required by law to process Customer Personal Data otherwise, it will tell the Controller before the processing unless the law forbids it.

5.3The Controller’s use of the export function, the role and permission settings, the retention settings and the deletion functions of the workspace are instructions that Dynamo carries out through the Services.

6.Confidentiality of personnel

6.1Dynamo will make sure that the people it authorizes to process Customer Personal Data are bound by a duty of confidentiality, receive appropriate training, and access it only as needed for the purposes of this DPA. Operator actions on workspaces are recorded in an audit trail.

7.Security

7.1Dynamo will apply the technical and organizational measures in Annex II, which are appropriate to the risk, taking into account the state of the art, the cost, the nature of the processing and the risks to data subjects.

7.2Annex II describes what is in place. Dynamo may update the measures if the update does not reduce the overall level of protection, and will not describe a measure as in place before it is.

8.Subprocessors

8.1The Controller authorizes Dynamo to engage Subprocessors under the conditions of this section. Dynamo publishes the current list, with each Subprocessor’s purpose and location, on the Subprocessors page at /legal/subprocessors (and in Annex III).

8.2Dynamo will add each Subprocessor to the list before it is switched on and will give the Controller at least 30 days’ notice before a new or replacement Subprocessor starts to process Customer Personal Data, by e-mail to the Account Owner or by notice in the workspace.

8.3The Controller may object on reasonable data-protection grounds within the notice period. The parties will then try in good faith to resolve the objection. If they cannot, the Controller may end the affected Services and receive a refund of the prepaid Fees for the period after they end.

8.4Dynamo will bind each Subprocessor to data-protection obligations no less protective than this DPA and remains responsible for the Subprocessor’s performance. A cloud, storage, e-mail or other provider that the Controller itself connects to its workspace is not Dynamo’s Subprocessor.

9.International transfers

9.1Dynamo will process Customer Personal Data only in the locations stated for the Controller’s workspace and in Annex III. The platform runs on servers that Dynamo operates, in Germany, and the Controller’s workspace files are stored in the storage location configured for the workspace.

9.2If Customer Personal Data is transferred outside the United Kingdom, or outside the country whose law governs the Controller’s processing, Dynamo will do so only where Data Protection Law allows it and the safeguards it requires are in place, such as an adequacy decision, appropriate contractual clauses or another mechanism recognized by the competent authority. Dynamo will tell the Controller before the transfer starts.

10.Assistance with data subject requests and compliance

10.1Taking into account the nature of the processing, Dynamo will help the Controller meet its duty to answer requests from data subjects (access, correction, deletion, restriction, objection and portability), mainly through the functions of the Services: search, export and deletion. If a data subject contacts Dynamo about Customer Personal Data, Dynamo will pass the request to the Controller and will not respond except as the Controller instructs or the law requires.

10.2Dynamo will give reasonable help with the Controller’s data protection impact assessments, consultations with the authority, and records of processing, with information about the Services that the Controller needs and does not already have. Help that goes beyond what the Services and documentation provide may be charged at reasonable rates agreed in advance.

11.Personal data breach

11.1Dynamo will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 48 hours.

11.2The notice will describe, as far as known: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed. Dynamo will give further information as it becomes available, will take reasonable steps to contain and remedy the breach, and will help the Controller with its own notices to the authority and to data subjects.

11.3Dynamo publishes incidents that affect the Services on its status page. A notice of a personal data breach is sent to the Controller directly, to the Account Owner’s e-mail address, and is not made only on the status page.

12.Return and deletion

12.1During the term the Controller can export its Customer Personal Data at any time using the export function of the workspace.

12.2When the Agreement ends, a trial ends, or the subscription is cancelled or expires, the workspace becomes read-only or closed and the Customer Personal Data is kept. Dynamo opens an export window (30 days unless another period is agreed in writing) in which the Controller can sign in and export its data.

12.3After the export window ends, or earlier on the Controller’s written request, Dynamo will delete the workspace. Final deletion requires a request and the approval of a second, different member of Dynamo’s staff, and is never carried out automatically. It destroys the workspace database, the site files and the objects in storage, and no archived copy of the workspace is kept for restoration.

12.4Copies in Dynamo’s backups expire under its backup retention schedule, which keeps daily copies for 7 days, weekly copies for 4 weeks and monthly copies for 12 months, so the last copy expires about twelve months after deletion. A deleted workspace is not restored from backups except at the Controller’s documented request. Dynamo’s own tenant record, audit entries and invoices, which do not hold the Controller’s business content, are kept as required for legal and accounting purposes.

12.5Dynamo may keep Customer Personal Data for longer where the law requires it, and will then protect it and process it only for that purpose.

13.Audits and information

13.1Dynamo will make available to the Controller the information needed to show compliance with this DPA, including the Security page, the Subprocessors list and the audit-trail extracts that relate to the Controller’s workspace.

13.2Dynamo will allow and contribute to audits by the Controller or an auditor it appoints, no more than once a year (or after a personal data breach, or where the competent authority requires it), on at least 30 days’ written notice, during business hours, subject to confidentiality duties and in a way that does not disturb other customers or put their data at risk. The Controller bears the cost of the audit. Where Dynamo holds an audit report from an independent party, it may provide that report in place of an audit.

14.Liability

14.1Each party’s liability under this DPA is subject to the limits and exclusions in the Agreement, except where the law does not allow them. A data subject’s rights against either party are not affected.

15.Term, precedence and changes

15.1This DPA takes effect when the Controller accepts the Agreement (or signs this DPA) and lasts as long as Dynamo processes Customer Personal Data. If this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails. If it conflicts with a signed standard contractual clause or a mandatory requirement of Data Protection Law, that clause or requirement prevails.

15.2Dynamo may update this DPA to reflect changes in Data Protection Law or in the Services, with notice to the Controller under the Agreement. The Controller may object as described in the Terms of Service.

16.Governing law

16.1This DPA is governed by the laws of England and Wales, and disputes are decided as the Agreement provides, subject to the mandatory rules of Data Protection Law.

17.Annex I: details of the processing

ItemDescription
ControllerThe Customer (the organization that holds the workspace).
ProcessorDYNAMO.
Data subjectsThe Controller’s employees, applicants, contractors and other workers; its customers, suppliers, leads and business contacts; and any other individuals whose data the Controller enters into the Services.
Categories of personal dataIdentification and contact details (names, e-mail addresses, telephone numbers, addresses); employment and payroll data where the People and Payroll apps are used (for example identity or residency numbers, salary, attendance, leave); transaction and account data (invoices, payments, bank details); business correspondence and notes; files and attachments; user account data (user name, e-mail, role, activity history); and anything else the Controller chooses to store.
Special categories and sensitive dataNone required by the Services. The Controller decides what it stores and must tell Dynamo before processing special categories, as set out above.
Nature and purposeHosting, storage, retrieval, backup, export and deletion of the data to run the Services as described in the Agreement; search; and Dynamo AI where the Controller has switched it on.
FrequencyContinuous for the term of the Agreement.
RetentionAs the Controller decides during the term. After the term, as set out in the section “Return and deletion”.
LocationAs in Annex III and the storage location configured for the workspace.

18.Annex II: technical and organizational measures

18.1This Annex states the measures in place at the date of this version.

AreaMeasure
Access controlRole-based permissions in each workspace, per-company access, and an activity history. Subscription rules and Dynamo AI can only remove access, never add it.
Identity and authenticationPassword sign-in with account lockout after repeated failures. Two-factor authentication for password sign-in, with a limit on wrong codes. Single sign-on through Microsoft Entra ID, Google Workspace or any OpenID Connect provider, with the option to enforce it for a domain. SCIM provisioning and deprovisioning, which ends open sessions. Service accounts with rotating keys. SAML-only identity providers connect through an OpenID Connect broker. These depend on the Controller configuring them with its own identity provider.
Workspace separationEach customer has its own workspace with its own database and storage area. Storage keys are forced under the workspace’s own prefix.
Encryption in transitHTTPS (TLS) for every connection to the website, the workspaces and the administration system.
Credential handlingCredentials and integration secrets are stored encrypted per workspace or hashed. Entitlements are digitally signed. Passwords are not included in exports.
Encryption at restBackups are encrypted with AES-256 and integrity-checked. Live data is protected by the workspace separation and the access controls in this Annex.
Files and storagePrivate storage buckets, access only through short-lived signed links after a permission check, content-type and size validation, checksums, versioning and a trash with a retention period. Malware scanning, where a scanner is connected, fails closed.
BackupsDaily automatic backups of every workspace, encrypted (AES-256) and integrity-checked, with restores tested into a scratch copy. Copies are kept for up to twelve months (daily for 7 days, weekly for 4 weeks, monthly for 12 months). Restores are carried out by Dynamo’s operators.
Logging and auditAn audit trail of operator actions in the administration system. File events (download, upload, share, delete) are logged and kept for 365 days.
PersonnelAccess to workspaces by Dynamo staff is limited to what is needed. Deletion of a workspace requires two different operators.
Release managementReleases are a closed, pinned set. Nothing in a release looks for or installs updates by itself. Dependencies are checked for known advisories before a release is cut. Product usage telemetry and update checks are switched off in the current release.
Incident managementIncidents that affect the Services are published on the status page with updates until they are resolved. Personal data breaches are notified to the Controller as set out in this DPA.
Data protection by designDynamo AI uses only data the asking user may already read and keeps its index, conversations and drafts in the workspace’s own database.
DeletionWorkspace deletion removes the database, the site files and the storage objects, and keeps no archived copy, as described in the section “Return and deletion”.

19.Annex III: Subprocessors

19.1The current list is published at /legal/subprocessors, and any new Subprocessor is added there, with its purpose, the data concerned and its location, before it is switched on.

SubprocessorPurposeDataLocation
Contabo GmbHProvides the servers in the data centre where Dynamo runs the platformAll Customer Personal Data stored in the workspaceGermany

20.Signature

20.1Where the Controller requires a signed copy, Dynamo provides this DPA for signature by authorised representatives of both parties, completed with the Controller’s legal name, company number and address. Without signatures, this DPA applies by the Controller’s acceptance of the Agreement.

Company details

Company
DYNAMO
Incorporated in
United Kingdom
Sales and general e-mail
sales@dynamoos.com
Privacy e-mail
privacy@dynamoos.com
Security e-mail
security@dynamoos.com