This Data Processing Addendum ("DPA") forms part of the Terms of Service between Ihjiz and each business that uses the platform ("you", the "Business"). It sets out how we process the personal data you store on Ihjiz on your behalf. It applies automatically when you accept the Terms; a countersigned copy is available on request from privacy@ihjiz.co.

1.Roles and scope

  • For the personal data of your customers, patients, students, their dependants and your staff that you enter into or collect through the platform ("Business Data"), you are the controller and Ihjiz is the processor.
  • For the account data of the people who sign in to run your business, and for our own billing and security records, Ihjiz is a controller, as described in the Privacy Policy. This DPA does not cover that data.
  • If this DPA conflicts with the Terms on a matter concerning Business Data, this DPA prevails.

2.Details of the processing

Subject matterRunning your bookings, queues, customer records, messaging, invoicing and reporting on the Ihjiz platform.
DurationFor as long as you have an account, plus the deletion period in section 9.
Nature and purposeStorage, retrieval, display, transmission of messages and notifications, scheduling computations, payment record-keeping, report generation, and — where you enable it — automated replies by the AI agent. Always on your instructions, never for our own purposes.
Data subjectsYour customers and their dependants; your staff and contractors; people who message your connected channels.
Categories of dataNames, phone numbers, email addresses, addresses, dates of birth; appointment and visit history; notes and custom fields you define; intake-form answers; consent records; invoices, payment status and amounts (never full card numbers); message content and metadata; uploaded files; reviews.
Special categoriesOnly where you choose to collect them — for example health information in a clinic's intake forms or notes. You are responsible for the lawful basis. We apply the same technical measures to all Business Data.

3.Our obligations as processor

  • Instructions. We process Business Data only on your documented instructions: the Terms, this DPA, and the settings you configure in the platform. If we believe an instruction breaks the law, we tell you before acting on it.
  • Confidentiality. Everyone we allow to access Business Data is bound by confidentiality obligations and given access only as needed to run and support the platform.
  • Security. We maintain the technical and organisational measures in section 6, and we improve them over time. We will not reduce the overall level of protection during the term.
  • Sub-processors. We use the sub-processors listed on the Sub-processors page, under written contracts that impose data-protection obligations no less protective than this DPA. We notify you at least 30 days before adding one, by email to the account owners and in the platform. If you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the affected part of the service and receive a pro-rated refund of any prepaid fees for it.
  • Assistance. We help you respond to data-subject requests through the platform's export, correction and deletion tools, and we help with data-protection impact assessments and consultations with authorities where they concern our processing.
  • Deletion and return. See section 9.
  • Records and audits. See section 8.

4.Your obligations as controller

  • You have a lawful basis for every category of Business Data you collect, and you give your data subjects the notices and obtain the consents your law requires — including for health data, records of minors, and marketing messages.
  • You use the platform's roles and permissions so that your staff see only what they need, and you keep your staff's credentials secure.
  • You answer data-subject requests addressed to you. Where a request reaches us instead, we forward it to you within 5 business days, and act on it directly only where the law places the obligation on us.
  • You do not instruct us to process Business Data in a way that would be unlawful for you or for us.

5.Personal-data breaches

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Business Data, we notify the owners of every affected business without undue delay and in any case within 72 hours of becoming aware, with what we know at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We update you as we learn more. We do not notify your data subjects or authorities on your behalf unless you ask us to in writing or the law requires it.

6.Technical and organisational measures

  • All traffic between browsers, mobile apps, our servers and our sub-processors is encrypted in transit with TLS.
  • Databases and object storage are encrypted at rest by our infrastructure providers. Secrets we store on your behalf — gateway keys, channel tokens, AI keys — are additionally encrypted with AES-256-GCM under a key held outside the database and the source code.
  • Every business's data is logically isolated. Every request is checked against the signed-in user's business and role before any data is returned.
  • Access to your data by your own staff is governed by roles and permissions that you define. Changes to bookings, prices and customer records are written to an audit trail with the previous value; reads of customer records are written to a data-access log.
  • Accounts support passkeys and phone one-time codes. Repeated failed sign-ins lock the account temporarily. Active sessions can be reviewed and revoked.
  • Card numbers never reach our systems; payment providers handle them directly.
  • Backups are encrypted and retained by our database provider with point-in-time recovery. Deleted data drops out of backups on the provider's rolling cycle.
  • Our own staff's access to production is limited to named engineers, protected by multi-factor authentication, and used only to operate and support the platform.

The current state of these measures is described in more detail on the Security page.

7.International transfers

Our infrastructure and sub-processors operate in more than one country, and the locations are listed on the Sub-processors page. Where Business Data is transferred to a country whose law does not provide adequate protection under the law that applies to you, we rely on the transfer mechanism that law provides — for example standard contractual clauses under the GDPR, or the conditions for transfer outside the Kingdom under the Saudi Personal Data Protection Law — and we make the relevant documents available on request.

8.Records, information and audits

  • We keep records of our processing activities as processor and make the relevant parts available to you on request.
  • Once per year, or after a breach affecting you, you may request the information reasonably necessary to demonstrate our compliance with this DPA, including summaries of any third-party assessments we hold.
  • Where that information is not sufficient to satisfy a legal obligation of yours, you or an independent auditor bound by confidentiality may audit our relevant systems and records, on at least 30 days' written notice, during business hours, no more than once per year, at your cost, and without access to other businesses' data.

9.Deletion and return of data

  • At any time during the term you can export Business Data from the platform in machine-readable formats.
  • Within 30 days after your account is closed, or after a written deletion request from an account owner, we delete Business Data from active systems. Encrypted backups are overwritten on the provider's rolling cycle.
  • We retain only what the law requires us to keep — for example invoicing records for tax purposes — and only for that purpose, as set out in section 8 of the Privacy Policy.

10.Liability, term and changes

  • Each party's liability under this DPA is subject to the limitations and exclusions in section 13 of the Terms.
  • This DPA lasts as long as we process Business Data for you.
  • We may update this DPA to reflect changes in law or in the platform. Changes that reduce your protections take effect no sooner than 30 days after we notify account owners; other changes take effect when published. The effective date at the top of the page is the date of the current version.

11.Contact

Data-protection matters, DPA copies and sub-processor objections: privacy@ihjiz.co. Legal notices should also be sent to the address on the Legal Entity page.