Data Processing Addendum
Processor terms under the Personal Data Privacy Protection Law, for customers who are controllers of personal data we process on their behalf.
- Version
- 1.1
- Effective
- 16 September 2026
- Applies to
- Vorniqe
- History
- 2 versions
When this applies
This addendum applies where you use our service to process personal data about your own users, customers or staff. In that arrangement you are the controller and Drentova Group W.L.L is your processor. It forms part of our Terms of Service and takes effect automatically — you do not need to sign a separate copy, though we will countersign one on request to [email protected].
Where we determine the purposes of processing ourselves — for example your own account and billing data — we are the controller and our Privacy Policy applies instead.
Definitions
- PDPPL
- Law No. 13 of 2016 Concerning Personal Data Privacy Protection of the State of Qatar, together with the decisions and guidelines issued under it.
- Controller, processor, personal data, processing
- As defined in the PDPPL.
- Customer Personal Data
- Personal data we process on your behalf under this addendum.
Subject matter and duration
We process Customer Personal Data to provide the service described in our Terms of Service, for as long as your account is active and for the retention period stated in our Privacy Policy afterwards. The categories of data subject and of personal data are determined by you, through what you choose to put into the service.
Our obligations
We will:
- process Customer Personal Data only on your documented instructions, including as to transfers, unless required otherwise by law — in which case we will tell you first unless the law prohibits it;
- ensure that people authorised to process it are bound by confidentiality;
- take the technical and organisational measures set out below;
- engage a subprocessor only under the conditions in the next section;
- assist you, taking into account the nature of the processing, in responding to requests from data subjects exercising their rights;
- assist you with data protection impact assessments and with any prior consultation or notification the PDPPL requires of you;
- on termination, delete or return Customer Personal Data at your choice, and delete existing copies unless the law requires us to keep them;
- make available the information needed to demonstrate compliance with this addendum, and allow and contribute to audits as set out below.
Technical and organisational measures
We take the measures below to protect personal data, as the Personal Data Privacy Protection Law requires. They are reviewed as the service changes, and we publish the current position in our Trust Centre rather than describing a state we hope to reach.
- Data in transit is encrypted using TLS. Data at rest is encrypted by our hosting and database providers.
- Access to production systems is restricted to the people who need it, protected by multi-factor authentication, and removed when it is no longer needed.
- Administrative access to customer data is limited to what is necessary to operate and support the service.
- Backups are taken by our database provider and restoration is tested.
- Changes to production go through review and automated checks before release.
- Third parties are assessed before they process personal data on our behalf, and are engaged under written terms that hold them to the standard the PDPPL requires of us.
No service can promise perfect security. If we become aware of a personal data breach we will assess it without undue delay, notify the competent authority as soon as the breach is found to be notifiable, and tell affected people directly where the breach is likely to result in a high risk to them.
Subprocessors
You give general authorisation for us to engage the subprocessors listed below. We impose data protection obligations on each of them that are no less protective than those in this addendum, and we remain fully liable to you for their performance.
We will give at least 30 days’ notice before adding or replacing a subprocessor, by publishing the change here and notifying you by email if you have asked us to. If you have a reasonable objection on data protection grounds, tell us within that period; we will work with you to resolve it, and if we cannot you may terminate the affected part of the service without penalty and receive a refund for the unused period.
Subprocessors
| Subprocessor | Purpose | Location | Transfer safeguard | Data |
|---|---|---|---|---|
| Resend | Transactional email delivery | United States | Contractual safeguards binding the recipient | Recipient email address and message content |
| Supabase | Managed PostgreSQL database hosting | United Kingdom | Contractual safeguards binding the recipient | All application data, including account details and submitted content |
| Vercel | Application hosting, content delivery and file storage | United States | Contractual safeguards binding the recipient | IP address, request metadata and server logs; uploaded media stored in Vercel Blob |
International transfers
We are based in the State of Qatar and process personal data here wherever we can. Some of the providers we rely on operate outside Qatar.
Where personal data is transferred outside Qatar, we do so only on a basis the Personal Data Privacy Protection Law permits: the destination affords an adequate level of protection, the recipient is bound by contractual safeguards, you have given explicit consent, or a statutory exception applies. The basis applying to each provider is named in the subprocessor table, and we assess the risk of a transfer before relying on any of them.
You can ask us for a copy of the safeguards in place for a particular transfer by writing to [email protected].
Breach notification
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken or proposed. We will not notify your data subjects or a supervisory authority on your behalf unless you ask us to or the law requires it of us.
Audits
On reasonable notice, and no more than once in any twelve months unless a supervisory authority requires otherwise or a breach has occurred, you may audit our compliance with this addendum. In the first instance we will respond with our security documentation and a completed security questionnaire; where that is genuinely insufficient we will accommodate an audit, conducted during business hours, without unreasonable disruption, and subject to confidentiality. You bear your own costs.
Liability
Each party’s liability under this addendum is subject to the limitations in our Terms of Service, except where the PDPPL provides otherwise.
How to contact us
- Legal notices
- [email protected]
- Privacy and data protection
- [email protected]
Change log
- v1.1 · 16 September 2026Re-registered in the State of Qatar as Drentova Group W.L.L. Governing law, jurisdiction and the applicable data protection regime have changed.material change
- v1.0 · 26 July 2026First published version.