Juridique
Accord de Traitement des Données
Découvrez comment Staff Finder traite les données employeurs de manière sécurisée et conforme à la PDPL des EAU.
1. Introduction
This Data Processing Agreement (“DPA”) governs the processing of personal data by Staff Finder on behalf of employers using the platform. It forms part of the Employer Terms and Conditions and applies wherever applicable data protection law, including Federal Decree-Law No. 45/2021 on the Protection of Personal Data (“PDPL”) and its Executive Regulations, requires a formal data processing arrangement between a controller and a processor.
2. Roles of the Parties
360 Agency Middle East FZ LLC (“Processor”) acts as data processor for personal data processing activities carried out on behalf of employers through the platform.
Employers (“Controller”) act as independent data controllers with respect to their recruitment decisions, candidate interactions, and any further use of personal data accessed via the platform.
3. Scope of Processing
Personal data is processed for the following purposes:
- Candidate profile hosting and display.
- Recruitment matching and search.
- Communication facilitation between employers and candidates.
- Payment processing.
- Operational platform functions including security and analytics.
4. Types of Data Processed
Data processed may include personal identification data, employment history, professional qualifications, uploaded documents, communication records, and platform activity logs. Data subjects are candidates registered on the platform and, to a limited extent, employer-side users.
5. Processor Obligations
The Processor shall:
- (a) Process personal data only on documented instructions from the Controller, including with respect to transfers, unless required to do so by applicable law, in which case the Processor shall inform the Controller before processing unless prohibited by law.
- (b) Not process personal data for any purpose other than those specified in this DPA and the Employer Terms, and shall not sell, rent, or otherwise use personal data for its own commercial purposes beyond platform operation.
- (c) Ensure that all personnel authorised to process personal data are subject to binding confidentiality obligations.
- (d) Assist the Controller, insofar as reasonably possible and taking into account the nature of processing, in responding to data subject rights requests (access, rectification, erasure, restriction, portability) under applicable law.
- (e) Assist the Controller in ensuring compliance with security obligations, breach notification requirements, data protection impact assessments, and prior consultation obligations under applicable law.
- (f) Maintain records of processing activities carried out on behalf of the Controller as required by Article 8(7) of the PDPL.
- (g) Make available to the Controller all information necessary to demonstrate compliance with this DPA, and permit and contribute to audits and inspections conducted by or on behalf of the Controller, upon reasonable prior written notice of no less than 10 business days.
6. Security Measures
The Processor implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration, or misuse. These include access controls, encryption in transit and at rest, regular security reviews, and secure infrastructure provided by certified cloud hosting services. Measures are reviewed and updated periodically in line with evolving risks.
7. Personal Data Breach Notification
Upon becoming aware of a personal data breach affecting data processed under this DPA, the Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware. The notification shall include, to the extent available:
- The nature of the breach.
- The categories and approximate number of data subjects and records affected.
- The likely consequences.
- The measures taken or proposed to address the breach.
The Processor shall cooperate with the Controller in any required notifications to regulatory authorities or affected data subjects.
8. Subprocessors
The Processor may engage subprocessors to assist in delivering platform services. Current subprocessors are listed in Schedule A to this DPA. The Processor shall impose data protection obligations on all subprocessors that are no less protective than those set out in this DPA, and shall remain liable to the Controller for the acts and omissions of its subprocessors.
The Processor shall notify the Controller of any intended changes to the subprocessor list (additions or replacements) by updating Schedule A and providing notice via the platform or email. The Controller may object to any new subprocessor within 14 days of notification on reasonable data protection grounds by writing to admin@stafffinder.io. If the parties cannot resolve the objection, the Controller may terminate the affected services without penalty.
9. International Transfers
Personal data may be transferred to and processed in jurisdictions outside the UAE where subprocessors operate, including countries that may not have been deemed adequate by the UAE Data Office. All such transfers are carried out using appropriate safeguards, which may include:
- Standard contractual clauses or equivalent mechanisms recognised or approved under the PDPL and its Executive Regulations.
- Contractual data protection terms with the relevant subprocessors.
- Other safeguards that provide an essentially equivalent level of protection.
Details of the transfer mechanisms applicable to each subprocessor are available on request by contacting admin@stafffinder.io.
10. Data Retention and Post-Termination
Personal data is retained only for as long as necessary to provide the platform services, comply with legal obligations, and resolve disputes. Upon termination of the employer’s account or written request from the Controller, the Processor shall, at the Controller’s election, securely delete or return all personal data processed on behalf of the Controller within 30 days, unless retention is required by applicable law. Any data retained for legal compliance purposes will be held securely and not used for any other purpose.
11. Data Subject Rights
Users may request access, correction, restriction, or deletion of their personal data in accordance with the PDPL and other applicable data protection laws. Such requests should be directed to admin@stafffinder.io. The Processor will assist the Controller in responding to requests within the timeframes required by applicable law.
12. Liability and Indemnity
Each party shall be liable for any damage caused to data subjects or third parties resulting from its own breach of this DPA or applicable data protection law. The Processor shall indemnify the Controller against any fines, penalties, claims, or losses arising directly from the Processor’s failure to comply with its obligations under this DPA, to the extent such failure is attributable solely to the Processor. The Controller shall indemnify the Processor against losses arising from the Controller’s unlawful instructions or misuse of personal data accessed through the platform.
Neither party’s liability under this clause is excluded for breaches of the PDPL or other mandatory applicable law. Total liability of either party under this DPA is subject to the limitations set out in the Employer Terms and Conditions, except to the extent prohibited by law.
13. Duration
This DPA remains in force for the duration of the employer’s use of the platform and the associated Employer Terms and Conditions. Clauses relating to confidentiality, post-termination data handling, liability, and governing law survive termination of this DPA.
14. Governing Law
This agreement is governed by the laws of the United Arab Emirates with jurisdiction of the courts of Fujairah.
Schedule A — Subprocessors
The following subprocessors are currently engaged by the Processor. This list may be updated from time to time in accordance with Section 8.
Infrastructure and Hosting
Amazon Web Services (AWS) — cloud hosting and storage (Frankfurt, EU and other regions); Supabase — database and backend services.
AI and Platform Services
OpenAI / Anthropic — AI-assisted features (United States); additional AI service providers as applicable.
Payments
Stripe — payment processing (United States / EU).
Analytics
Google Analytics (Google LLC) — usage analytics (United States).
Messaging and Communications
Email and notification service providers as applicable to platform operations.
All subprocessors listed above are subject to data processing agreements with the Processor that impose obligations no less protective than those in this DPA. Transfer mechanisms applicable to US-based providers include standard contractual clauses or equivalent safeguards. Details are available on request.