Data Processing Addendum
Last updated: 4 August 2026
1. Purpose and status of this document
This Data Processing Addendum (“DPA”) summarizes how Xische FZ-LLC, trading as Sandooq (“Processor”, “we”), processes personal data on behalf of a business customer (“Controller”, “Customer”) using the Sandooq service (the “Service”).
This page is a plain-language summary for business customers evaluating Sandooq. A full, signable DPA is available on request for customers who require one, executed alongside the Terms of Service; in case of conflict, the executed DPA will prevail over this summary.
2. Roles of the parties
| Party | Role |
|---|---|
| Customer (the business using Sandooq) | Data Controller for its own staff and business data (e.g. driver names, expense records, uploaded receipts) |
| Sandooq / Xische FZ-LLC | Data Processor, acting only on the Customer's documented instructions to provide the Service |
3. Scope and nature of processing
- Categories of data subjects: the Customer's staff/users (owners, admins, accountants, drivers/field staff) and, incidentally, any individuals named or shown in uploaded receipts.
- Categories of personal data: names and email addresses, role assignments, company information, expense and cash-float records, uploaded receipts/documents, and usage/log data.
- Nature and purpose of processing: storage, display, and processing of the above data solely to provide the petty-cash and expense-tracking Service (account authentication, recording transactions, generating exports, sending transactional emails, and related support).
- Duration: for as long as the Customer maintains an active subscription, plus the post-termination retention period described in Section 9 below.
4. Sub-processors
We use the following sub-processors to provide the Service. Each is bound by a contract requiring data protection obligations no less protective than those in this DPA:
| Sub-processor | Purpose | Location / notes |
|---|---|---|
| Supabase | Database hosting, authentication infrastructure | Postgres database; data region currently Mumbai (ap-south-1) |
| Vercel | Application and website hosting / CDN | Global edge network; no persistent storage of Customer Data |
| Stripe | Subscription billing and payment processing | PCI-DSS certified; handles payment card data directly. Sandooq never receives or stores full card numbers |
| Resend | Transactional email delivery (OTP codes, notices, exports) | Processes recipient email address and message content |
We will provide at least 30 days' prior notice before adding or replacing a sub-processor that handles Customer Data, and you may object by emailing support@sandooq.ae.
5. Security measures
Sandooq applies the following technical and organizational measures:
- Encryption of data at rest using AES-256.
- Encryption of data in transit using TLS.
- Tenant isolation via database-level row-level security (RLS), so each Customer's data is logically separated from every other Customer's.
- Role-based access control within each Customer's account (owner, admin, accountant, driver).
- Restricted internal access to production data, limited to authorized personnel on a need-to-know basis.
- No storage of payment card data. Subscription payments are processed entirely by Stripe.
We are working toward independent certifications such as SOC 2 and ISO 27001; we do not currently hold these certifications.
6. International data transfers
Processing Customer Data may involve transfers outside the UAE, including to India (Supabase's current hosting region), the United States, and/or the European Union, depending on the sub-processor. Where we transfer personal data across borders, we rely on appropriate contractual safeguards with our sub-processors, including standard contractual clauses where applicable.
7. Assistance with data subject requests
Where the Customer receives a request from one of its staff or another data subject to access, correct, delete, or export their personal data, we will provide reasonable assistance to help the Customer respond, including through in-Service export tools where available.
8. Personal data breach notification
If we become aware of a personal data breach affecting Customer Data, we will notify the Customer without undue delay and, where feasible, within 72 hours of becoming aware, and provide information reasonably available to us to help the Customer meet its own notification obligations.
9. Deletion or return of data on termination
On termination or expiry of the Customer's subscription, the Customer may export its Customer Data for 30 days. After that period, Customer Data will be deleted or anonymized from production systems within 30 days, except where retention is required by law (e.g. accounting/tax records) or remains in backups until rotated out.
10. Confidentiality
Personnel authorized to process Customer Data are bound by confidentiality obligations, whether contractual or statutory, and access is limited to what is necessary to provide the Service.
11. Audit
On reasonable prior notice, and no more than once in any 12-month period, we will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of our security practices or any available third-party reports. We do not offer on-site audits.
12. Liability
Liability under this DPA is subject to the limitation of liability set out in our Terms of Service, unless a separately executed DPA states otherwise.
13. Contact
To request a signed copy of a full DPA, or with questions about this summary, contact:
- Email: support@sandooq.ae