ahlan hamad

Version 2026-10-v1 · published 7 October 2026 · current sub-processor list · ملخص عربي

Data Processing Agreement

Version: 2026-10-v1 · Published: 7 October 2026 · Processor: AHLAN HAMAD - FZCO

How this document is built. It has two parts that work together:

The current sub-processor list is published at https://ahlanhamad.com/legal/subprocessors/. An Arabic summary of this DPA is published at https://ahlanhamad.com/legal/ar/dpa/ (see clause 16).

Part 1 — Customer Data Processing Agreement

1. Parties and scope

1.1. This Data Processing Agreement (DPA) is between AHLAN HAMAD - FZCO, a free zone company licensed by the Dubai Integrated Economic Zones Authority under licence no. 89875, Dubai Silicon Oasis, Dubai, United Arab Emirates (Ahlan Hamad, the Processor), and the customer that has accepted the Ahlan Hamad Terms of Service (the Customer, the Controller). AHLAN HAMAD - FZCO is the contracting entity for Customers in all six GCC states: Kuwait, Saudi Arabia, the United Arab Emirates, Qatar, Bahrain and Oman.

1.2. It applies to all Personal Data that Ahlan Hamad processes for the Customer when providing the Ahlan Hamad HR, payroll and compliance-tracking service (the Service), as described in Annex 1 (Customer Personal Data).

1.3. It applies together with the Terms of Service. If they conflict on personal data, this DPA prevails.

1.4. It does not cover personal data Ahlan Hamad processes as a controller for its own purposes, such as the Customer’s account and billing contacts, sales and marketing, product analytics and website measurement. That data is covered by the Ahlan Hamad Privacy Policy.

2. Definitions

Applicable Data Protection Law means every data-protection and privacy law that applies to the processing of Customer Personal Data. Personal Data, Processing, Controller, Processor, Data Subject and Sensitive Personal Data (including data of a “special nature” or “sensitive” data) have the meanings given in Applicable Data Protection Law; where laws differ, the stricter meaning applies. Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. Sub-processor means a third party engaged by Ahlan Hamad that processes Customer Personal Data. Partner means a third party that the Customer connects to its account through the Partner API (an API key or an OAuth app). Transfer means making Customer Personal Data accessible in, or moving it to, a country other than the one where it was collected.

3. Roles

3.1. The Customer is the controller of Customer Personal Data, and Ahlan Hamad processes it as the Customer’s processor.

3.2. The Customer is responsible for having a lawful basis for the processing, for giving notices to Data Subjects (including employees, candidates and dependants), for obtaining any consents, permits or registrations it needs (including any permit the law of its country requires for Sensitive Personal Data such as health data or children’s data), and for the lawfulness of its instructions.

3.3. Where a Customer’s affiliate or legal entity in another GCC country uses the Service, the Customer enters this DPA on its own behalf and on behalf of that entity, and confirms it is authorised to do so.

4. Instructions

4.1. Ahlan Hamad processes Customer Personal Data only on the Customer’s documented instructions, unless the law requires otherwise; in that case Ahlan Hamad will tell the Customer first, unless the law forbids it.

4.2. The Customer’s instructions are: this DPA; the Terms of Service; the Customer’s configuration and use of the Service (including running payroll, generating wage-protection and bank files, sending notifications, using the AI assistant, and enabling optional integrations); and any further written instructions agreed by the parties.

4.3. Partner connections are instructions. When an authorised Customer user creates a live API key for a Partner or approves a Partner app’s connection, the Customer instructs Ahlan Hamad to disclose the data covered by the selected scopes to that Partner, and to accept and apply data that the Partner sends (for example clock events), until the Customer revokes the key or connection. Ahlan Hamad is not responsible for the Partner’s processing; the Partner’s obligations are set out in Schedule 1 and in the Partner’s own agreement with the Customer.

4.4. Ahlan Hamad will tell the Customer if, in its opinion, an instruction breaches Applicable Data Protection Law.

5. Confidentiality and personnel

5.1. Ahlan Hamad ensures that persons authorised to process Customer Personal Data are bound by confidentiality, receive appropriate training and have access only as needed.

5.2. Ahlan Hamad personnel can, for support and operations, technically access Customer Personal Data. A support session in which an Ahlan Hamad operator acts inside a Customer’s account requires a stated reason and a recent sign-in, lasts at most 30 minutes, and its start and end are recorded in Ahlan Hamad’s internal platform audit log. Changes made during such a session appear in the Customer’s audit log under the user being assisted. Operator reads of Customer Personal Data are not individually logged.

6. Security

6.1. Ahlan Hamad implements the technical and organisational measures in Annex 2 and will keep them at a level appropriate to the risk.

6.2. Ahlan Hamad may update the measures, provided the overall level of protection is not reduced.

6.3. The Customer is responsible for the security of its own accounts, including choosing who receives which role, protecting its users’ sign-in methods, and choosing which Partners to connect.

7. Sub-processors

7.1. The Customer gives general authorisation for Ahlan Hamad to engage the Sub-processors listed in Annex 3 and on the published sub-processor list.

7.2. Ahlan Hamad will (a) impose on each Sub-processor data-protection terms that protect Customer Personal Data to the standard of this DPA; and (b) remain responsible to the Customer for each Sub-processor’s performance.

7.3. Changes. Ahlan Hamad will give at least 30 days’ notice of a new or replacement Sub-processor by emailing the Customer’s account owner and updating the published sub-processor list at https://ahlanhamad.com/legal/subprocessors/. The Customer may object on reasonable data-protection grounds within that period. The parties will discuss the objection in good faith. If it is not resolved, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for it.

7.4. Optional integrations the Customer turns on. Some services listed in Annex 3 (Part B) receive data only if the Customer enables them (for example an accounting system, Slack, a payment provider or a government portal). When the Customer enables one, it instructs Ahlan Hamad to send the data that integration needs. Where the provider is the Customer’s own vendor (for example the Customer’s own accounting software account), that provider acts under its own contract with the Customer and is not Ahlan Hamad’s Sub-processor.

7.5. Partners are not Sub-processors. Partners connected by the Customer under clause 4.3 are not Ahlan Hamad’s Sub-processors.

8. International transfers

8.1. Customer Personal Data is stored and processed by the Sub-processors in Annex 3. The Service’s database, server logic and file storage run on Convex, a managed cloud platform that Convex states is hosted on Amazon Web Services. Convex’s cloud regions are in the United States, Europe, Asia Pacific and Canada, none of them in the GCC, so storing Customer Personal Data in the Service is a Transfer out of the GCC. The web application is delivered through Cloudflare’s global network. Annex 3 states the processing location of each Sub-processor where Ahlan Hamad has established it.

8.2. Ahlan Hamad will Transfer Customer Personal Data only in line with Applicable Data Protection Law, using the safeguards of this DPA and, where a law requires it, a transfer mechanism that law recognises (see Annex 4).

8.3. Where a transfer mechanism requires standard contractual clauses issued by a competent authority, the parties agree that the clauses identified in Annex 4 are incorporated by reference and form part of this DPA, and Ahlan Hamad will put corresponding clauses in place with its Sub-processors.

8.4. Ahlan Hamad will provide reasonable information the Customer needs to carry out a transfer risk assessment.

8.5. In-country hosting. Any in-country hosting arrangement is agreed separately in writing.

9. Personal Data Breach

9.1. Ahlan Hamad will notify the Customer without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2. The notice will include, as far as then known: the nature of the breach; the categories and approximate number of Data Subjects and records; the likely consequences; the measures taken or proposed; and a contact point. Ahlan Hamad will provide further information as it becomes available.

9.3. Ahlan Hamad will take reasonable steps to contain and remedy the breach, and will help the Customer meet its obligations to notify regulators and Data Subjects. Ahlan Hamad will not notify regulators or Data Subjects on the Customer’s behalf without the Customer’s instruction, unless the law requires it to.

9.4. A notice is not an admission of fault.

10. Data Subject requests and assistance

10.1. The Service lets the Customer access, correct, export and delete Customer Personal Data. Employees can delete their own user account from the employee app or the account-deletion page; after a 30-day grace period their sign-in, contact details, profile, AI assistant chats, personal document locker, notifications, devices and the GPS location on clock-ins are erased, while the employer’s statutory employment, payroll and attendance records are kept for the Customer as controller.

10.2. If Ahlan Hamad receives a request from a Data Subject about Customer Personal Data, it will pass it to the Customer without undue delay and will not respond itself except to direct the person to the Customer, unless the Customer instructs otherwise.

10.3. Ahlan Hamad will provide reasonable assistance with data protection impact assessments, prior consultations with regulators, regulator enquiries and Data Subject requests, taking into account the nature of the processing.

11. Audits and records

11.1. Ahlan Hamad will make available information reasonably necessary to demonstrate compliance with this DPA, including this DPA’s annexes, its sub-processor list and answers to a reasonable security questionnaire once a year.

11.2. Ahlan Hamad does not currently hold an ISO 27001 or SOC 2 certification or an independent audit report. Where the information in 11.1 is not enough to meet a Customer’s legal obligation, the Customer may, on 30 days’ written notice and no more than once every 12 months (or after a Personal Data Breach, or where a regulator requires), carry out an audit itself or through an independent auditor bound by confidentiality, during business hours, at the Customer’s cost, in a way that does not compromise other customers’ data or Ahlan Hamad’s security. Audits of Sub-processors are satisfied by their own reports.

11.3. Ahlan Hamad will keep records of processing as Applicable Data Protection Law requires of a processor.

12. Return and deletion

12.1. During the subscription, the Customer can export its data from the Service.

12.2. After the subscription ends, the Customer has 30 days to export its data. Ahlan Hamad will then delete Customer Personal Data from the live Service, unless the law requires Ahlan Hamad to keep it. Copies held in the hosting platform’s backups are removed when those backups expire on the platform’s own schedule. Ahlan Hamad will confirm deletion in writing on request.

12.3. Records that Ahlan Hamad keeps under law (for example invoices) are kept only as long as required and protected under this DPA.

13. Liability

Each party’s liability under this DPA is subject to the limitations in the Terms of Service.

14. Term

This DPA applies for as long as Ahlan Hamad processes Customer Personal Data.

15. Governing law

15.1. Part 1 of this DPA is governed by the law and dispute-resolution clause of the Terms of Service for the Customer’s country, except where Applicable Data Protection Law or a transfer mechanism in Annex 4 requires another law to govern particular clauses.

15.2. Schedule 1 is governed by the governing-law and arbitration clause of the Partner API & Developer Terms (UAE law; DIAC arbitration seated in Dubai, in English).

16. Language

This DPA is made in English. The Arabic summary published at /legal/ar/dpa/ is for convenience only and does not change this DPA. Where the law of a GCC state requires an Arabic version for proceedings before its courts or authorities, the Arabic version prevails for those proceedings; otherwise the English version prevails.

Annex 1 — Details of the processing (Customer DPA)

Item Details
Subject matter Providing the Ahlan Hamad HR, payroll and compliance-tracking Service to the Customer.
Duration The subscription, plus the 30-day export period, plus the expiry of hosting-platform backups.
Nature and purposes Storing and organising employee records; calculating payroll, allowances, deductions, social-insurance contributions and end-of-service benefits; producing payslips, wage-protection (WPS) and bank files for the Customer to submit; leave and attendance management; visa, residency and document expiry tracking; statutory reminders; recruitment (job applications); document generation; notifications by email, WhatsApp and in-app; an AI assistant answering the Customer’s users’ questions over the Customer’s data, and AI reading of documents the Customer’s users upload (for example an ID card or a medical certificate); optional integrations the Customer enables; disclosure to Partners the Customer connects; security, audit logging and support.
Data Subjects The Customer’s employees (current and former), including probation staff and contractors recorded in the Service; job applicants/candidates; employees’ dependants and emergency contacts; the Customer’s own users (managers, HR, finance).
Categories of Personal Data Identity and contact: names (EN/AR), employee code, job title, department, manager, work location, email, phone, gender, nationality, profile photo. Employment: contract details, hire and termination dates, status, exit details. Government identifiers: civil ID / national ID / iqama, passport number, visa and residency details, labour-card number, social-insurance number (e.g. GOSI). Financial: base salary, salary components and allowances, deductions, IBAN and bank code, payment account number, social-insurance contributions, end-of-service accruals, salary advances and employee loans with their repayments. Attendance: clock-in/out times, breaks, worked minutes, and for clock-ins in the app, a GPS location; clock events received from Partners (including the identifier the Partner used, such as an email or phone). Leave: leave records including sick leave, and supporting documents the Customer uploads. Dependants: details of family members recorded for benefits, visas or insurance. Recruitment: CVs and application data. Documents: files uploaded to the employee record or the employee’s personal locker. Usage: sign-in records, device records, AI assistant conversations, notifications, audit logs.
Sensitive Personal Data Health data: sick-leave records and the medical certificates uploaded for them (which may show a diagnosis), and medical-insurance details. Children’s data: dependants, recorded with name, relationship, date of birth, gender, nationality and identity documents. Nationality (treated as sensitive in some regimes). Leave types that can indirectly reveal religion or family status, such as Hajj leave or Iddah leave; the Service has no religion or marital-status field. Financing data: salary advances and employee loans. The Service stores no fingerprint, face or iris templates; for device biometric sign-in it records only device and enrolment details.
Frequency Continuous.
Retention As configured by the Customer during the subscription; see clause 12 after it ends.

Annex 2 — Technical and organisational measures

Every measure below is in place in the product today. The final section lists what is not in place, so that Customers are not misled.

Hosting and environments

Encryption

Access control and tenancy

Logging and monitoring

Partner API safeguards

Data minimisation and erasure

Browser hardening

Not in place today

Annex 3 — Sub-processors

This annex is generated from the product’s data-flow inventory, which an automated test keeps in step with the outbound services the code calls. Convex and Cloudflare are the platform itself and are listed first. The live list, including any change notified under clause 7.3, is published at https://ahlanhamad.com/legal/subprocessors/. Where a processing location is “Not yet stated”, Ahlan Hamad has not yet established it from that provider’s terms; it will be added to the published list when established.

Part A — Core sub-processors (used for every Customer)

Sub-processor Purpose Data categories Processing location
Convex, Inc. Database, server logic, file storage All categories in Annex 1 Outside the GCC (a Convex cloud region on Amazon Web Services)
Cloudflare, Inc. Web delivery, network security Data in transit; request metadata Cloudflare’s global network
Anthropic, PBC AI assistant and AI document reading Identity, financial, health (whatever the user’s question, document and its context carry) Not yet stated
Resend Transactional email Identity, financial (e.g. payslip notifications) Not yet stated
Meta Platforms (WhatsApp Business / Cloud API) Employee notifications and support messages Identity, financial (leave and payroll messages) Not yet stated
Ahlan Hamad first-party error reporting Error diagnostics May include identifiers in error context Within the Service (Convex)

Part B — Optional, only when the Customer enables the feature

Service Purpose Data categories Processing location
OpenAI Alternative AI provider Identity, financial, health Not yet stated
Stripe; Moyasar Subscription payments Customer billing identity and payment data Not yet stated
Lean Technologies Bank payments / account connection Identity, financial Not yet stated
Mudad; Qiwa; Nitaqat (Saudi government platforms) Government filing Identity, government ID, financial; special category (Nitaqat) Saudi Arabia
Google Identity / Google Workspace / Google APIs Sign-in and directory sync Identity Not yet stated
Microsoft Graph (Microsoft 365 / SharePoint) Document storage / directory Identity Not yet stated
Slack Approver messages from the Slack app (leave and expense approvals) Identity, financial, health (leave reason) Not yet stated
Wafeq Accounting journals (totals only; no per-employee lines) Financial Not yet stated
Xero; QuickBooks (Intuit); Zoho / Zoho Books; Qoyod; Sage; SAP Accounting sync Identity, financial Not yet stated

Part C — Services that are not sub-processors for Customer Personal Data. The data-flow inventory also lists Clay, Apollo, HubSpot, Instantly, LinkedIn and Google Ads. They process Ahlan Hamad’s own sales and marketing data: sales prospects, and for LinkedIn and Google Ads, hashed contact identifiers of prospects and of the person who signs a Customer up, used to measure Ahlan Hamad’s advertising. They receive no data about a Customer’s employees. They are covered by the Privacy Policy, not this DPA.

Annex 4 — International transfers

  1. Safeguards. Every Transfer is protected by the obligations in this DPA, including clauses 6, 7, 9 and 12 and Annex 2, which Ahlan Hamad also imposes on its Sub-processors.
  2. Standard contractual clauses. Where Applicable Data Protection Law requires standard contractual clauses issued by a competent authority for a Transfer from the Customer’s country, including the standard contractual clauses issued by the Saudi Data & AI Authority (SDAIA) for Saudi Arabia, and those issued for the DIFC or ADGM where a Customer is established there, the controller-to-processor clauses are incorporated into this DPA by reference under clause 8.3, with the Customer as data exporter and Ahlan Hamad as data importer.
  3. Other mechanisms. Where a law instead requires a permit, a notification, a transfer assessment or the data subject’s consent, the Customer is responsible for it as controller (clause 3.2), and Ahlan Hamad will give the information the Customer reasonably needs (clause 8.4).

Annex 5 — Breach notification contacts

Ahlan Hamad Customer
Email privacy@ahlanhamad.com (copy support@ahlanhamad.com) The Customer’s account owner email, unless the Customer names another
Data protection contact privacy@ahlanhamad.com As named by the Customer

Schedule 1 — Partner Data Processing Terms

These terms form part of the Ahlan Hamad Partner API & Developer Terms and bind every partner (“you”) that receives Customer Data from, or sends it to, the Partner API under a Live connection.

P1. Roles

P1.1. For Customer Data you receive from or send to the API, the Customer is the controller. You process that data on the Customer’s behalf as its processor, under your own agreement with the Customer (Partner Terms clause 5.2). You are not Ahlan Hamad’s sub-processor, and Ahlan Hamad is not your processor.

P1.2. You must not process Customer Data received from, or sent to, the API for your own purposes as a controller. This does not apply to data you hold independently of the API from your own service to the Customer (for example your own system’s staff log-ins), which your own agreement with the Customer governs.

P1.3. Ahlan Hamad’s role towards you is limited to operating the API on the Customer’s instructions. Ahlan Hamad may enforce these terms directly against you.

P2. Minimum processor obligations

As the Customer’s processor you must, in addition to anything your agreement with the Customer requires:

P3. Data you send to Ahlan Hamad

When you send data to the API (for example clock events under attendance:write), you collect and transmit it as the Customer’s processor, and you warrant that you are authorised by the Customer to do so and that the data is accurate (Partner Terms clause 5.4). Free-form metadata fields (such as attendance meta) must not contain Sensitive Personal Data, photographs, biometric data or precise location.

P4. International transfers

You must not Transfer Customer Data to, or allow access from, any country unless you comply with the transfer rules of the country where the Customer and the Data Subjects are located, including, where required, signing the relevant standard contractual clauses with the Customer. You must tell the Customer and us where you store and process Customer Data, and keep that information current.

P5. Breach notification

You must notify the Customer and Ahlan Hamad (privacy@ahlanhamad.com) within 24 hours of becoming aware of a Personal Data Breach affecting Customer Data (Partner Terms clause 9.7), with the information in clause 9.2 of this DPA, and keep both updated.

P6. Termination

Partner Terms clause 18 applies. These Partner Data Processing Terms survive for as long as you hold any Customer Data.