DATA PROCESSING AGREEMENT (DPA)
Esyana Field Maintenance Management Platform
Document Version: 1.0
Effective Date: 26 July 2026
Last Updated: 26 July 2026
DATA PROCESSING AGREEMENT (DPA)
This Data Processing Agreement ("DPA") forms part of the Terms of Service and SaaS Subscription Agreement between:
Sadeid, a company registered in the Hashemite Kingdom of Jordan under Registration Number 1210822026 ("Processor", "Sadeid", "we", "our", or "us"),
and
The customer purchasing or using the Esyana Field Maintenance Management Platform ("Controller", "Customer", "you", or "your").
This DPA governs the processing of Personal Data by Sadeid on behalf of the Customer when providing the Esyana software services.
1. Purpose
The purpose of this Agreement is to define:
The responsibilities of each party regarding Personal Data.
The safeguards applied to Customer Data.
Security obligations.
International data transfers.
Data subject rights.
Incident notification procedures.
Data deletion and return.
2. Definitions
For this Agreement:
Controller means the Customer that determines the purposes and means of processing Personal Data.
Processor means Sadeid, which processes Personal Data on behalf of the Customer.
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on Personal Data including collection, storage, organization, transmission, retrieval, deletion, or destruction.
Subprocessor means a third party engaged by Sadeid to process Personal Data on behalf of the Customer.
Data Subject means the individual whose Personal Data is processed.
Applicable Data Protection Law means any privacy or data protection legislation applicable to the parties, including, where applicable, the GDPR or equivalent laws.
3. Scope
This DPA applies whenever Sadeid processes Personal Data on behalf of the Customer while providing the Esyana Platform.
Examples include:
User accounts
Employee information
Technician information
Customer contact details
Maintenance requests
Work orders
Asset records
Uploaded documents
Photographs
Digital signatures
Support tickets
4. Roles of the Parties
Unless otherwise agreed in writing:
The Customer acts as the Data Controller.
Sadeid acts as the Data Processor.
The Customer determines:
What data is collected.
Why it is collected.
How long it should be retained (subject to technical and legal limitations).
Sadeid processes Personal Data only as instructed by the Customer and as necessary to provide the Service.
5. Categories of Personal Data
Depending on Customer use of Esyana, Personal Data processed may include:
Identification Data
Full name
Employee ID
Username
Job title
Contact Information
Email address
Telephone number
Business address
Business Information
Company
Department
Client information
Assigned assets
Operational Information
Work Orders
Technician reports
Maintenance requests
Checklists
Notes
Location Data (Optional)
If enabled by the Customer:
GPS coordinates
Travel history
Technician location during work
Uploaded Content
Images
Documents
PDF files
Maintenance reports
Contracts
Signatures
6. Nature of Processing
Sadeid processes Personal Data for purposes including:
Hosting
Storage
Authentication
User management
Technical support
Reporting
Backups
Security monitoring
Synchronization
API services
Mobile application services
7. Customer Instructions
Sadeid shall process Personal Data only:
According to Customer instructions.
As required to provide the Service.
As required by applicable law.
If Sadeid believes an instruction violates applicable law, it may notify the Customer before processing, unless prohibited by law.
8. Confidentiality
Sadeid shall ensure that:
Employees with access to Personal Data are subject to confidentiality obligations.
Access is limited to personnel with a legitimate business need.
Contractors and subprocessors are bound by appropriate confidentiality commitments.
9. Security Measures
Sadeid implements reasonable technical and organizational measures designed to protect Personal Data.
These measures may include:
Access Control
Role-Based Access Control (RBAC)
Multi-factor authentication for administrative accounts (where supported)
Least-privilege access
Authentication
Password hashing
Secure login procedures
Session management
Encryption
TLS encryption for data in transit
Encryption of backups where applicable
Encryption of sensitive data at rest where appropriate
Infrastructure Security
Firewalls
Network segmentation
Security monitoring
Vulnerability management
Patch management
Logging
Audit logs
Security event monitoring
Administrative activity logs
10. Customer Responsibilities
The Customer is responsible for:
Obtaining any necessary consents.
Providing privacy notices to its users where required.
Configuring user permissions appropriately.
Ensuring the lawful collection of Personal Data.
Maintaining accurate records.
Complying with applicable data protection laws.
The Customer remains responsible for the content of Customer Data uploaded to the Platform.
11. Subprocessors
Sadeid may engage trusted subprocessors to provide services such as:
Cloud hosting
Backup services
Email delivery
SMS delivery
Payment processing
Customer support tools
Monitoring services
Sadeid remains responsible for the performance of its subprocessors as required by applicable law and contractual obligations.
Upon reasonable request, Sadeid may provide Customers with information about the categories of subprocessors used.
12. International Transfers
Where Personal Data is transferred across national borders, Sadeid will implement appropriate safeguards required by applicable law.
Transfers may occur where necessary for:
Cloud hosting
Disaster recovery
Customer-selected hosting regions
Global support operations
13. Data Subject Requests
If Sadeid receives a request directly from a Data Subject concerning Personal Data processed on behalf of a Customer, Sadeid will, where appropriate:
Promptly notify the Customer.
Not respond directly unless legally required or authorized by the Customer.
Provide reasonable assistance to enable the Customer to respond.
14. Personal Data Breach
If Sadeid becomes aware of a Personal Data breach affecting Customer Data, Sadeid will:
Investigate the incident.
Take reasonable steps to contain and mitigate the breach.
Notify the affected Customer without undue delay after confirming the breach.
Provide available information regarding:
Nature of the incident
Categories of data involved
Likely impact
Measures taken
Recommended actions for the Customer
The Customer remains responsible for determining whether notifications to regulators or affected individuals are required.
15. Data Retention
Sadeid retains Personal Data only for as long as necessary:
To provide the Service.
To meet contractual obligations.
To comply with applicable law.
To maintain backups.
To resolve disputes.
To enforce legal rights.
Retention periods may vary depending on legal, technical, and operational requirements.
16. Return or Deletion of Data
Upon termination of the subscription, and subject to any applicable retention period:
The Customer may:
Export Customer Data using available export tools.
Request deletion of Customer Data.
Following the applicable retention period, Sadeid will securely delete Customer Data from production systems, except where continued retention is required by law or necessary for legitimate legal purposes.
Backup copies may persist for a limited period until overwritten in accordance with Sadeid's backup retention procedures.
17. Audit and Compliance
Upon reasonable written notice, and subject to appropriate confidentiality obligations, Sadeid may provide information reasonably necessary to demonstrate compliance with this DPA.
To protect the security and confidentiality of other customers, audits may be satisfied through:
Security certifications (if obtained)
Independent audit reports
Security questionnaires
Documentation reviews
Virtual meetings
On-site audits are subject to mutual agreement and reasonable limitations.
18. Assistance
Where reasonably requested and taking into account the nature of the processing, Sadeid will provide reasonable assistance to the Customer regarding:
Data subject requests
Security assessments
Privacy impact assessments
Incident investigations
Regulatory inquiries
Additional services beyond standard support may be subject to separate fees.
19. Liability
Each party remains responsible for its own compliance with applicable privacy and data protection laws.
Nothing in this DPA limits liability where such limitation is prohibited by applicable law.
Otherwise, liability is governed by the Terms of Service and the SaaS Subscription Agreement.
20. Changes to this DPA
Sadeid may update this DPA to reflect:
Changes in law
New security practices
Operational improvements
New services
Changes in subprocessors
Material changes will be communicated before they become effective.
21. Governing Law
This DPA shall be governed by the laws of the Hashemite Kingdom of Jordan, unless otherwise required by mandatory data protection laws applicable to a particular Customer.
22. Contact Information
Questions regarding this DPA may be directed to:
Sadeid
Registration Number: 1210822026
Hashemite Kingdom of Jordan
Website: https://esyana.com
Email: privacy@esyana.com
Appendix A – Summary of Processing Activities
| Category | Examples |
|---|---|
| Data Subjects | Customer employees, technicians, client contacts, portal users |
| Personal Data | Names, emails, phone numbers, job titles, login information |
| Business Data | Work orders, assets, maintenance records, inventory, invoices |
| Processing Activities | Collection, storage, retrieval, reporting, backup, deletion |
| Processing Purpose | Providing and supporting the Esyana platform |
| Retention | During subscription plus applicable retention period |
| Security Measures | Encryption, RBAC, logging, backups, monitoring |
Appendix B – Recommended Technical Security Controls
Sadeid should aim to implement and maintain controls such as:
TLS 1.2 or higher for all network communications.
Strong password policies and support for multi-factor authentication.
Role-Based Access Control (RBAC) with least-privilege principles.
Comprehensive audit logging of administrative actions.
Routine vulnerability scanning and timely patch management.
Regular, encrypted backups with tested restoration procedures.
Secure software development lifecycle (SSDLC) practices, including code review and security testing.
Incident response procedures and internal security awareness training.