Data Processing Addendum
This addendum forms part of the Terms of Service and governs the personal data that WorkOSync processes on behalf of a customer. It is designed to satisfy the UAE Personal Data Protection Law and Article 28 of the GDPR, so most customers need nothing further. A signed copy is available on request.
Scope and precedence
This Data Processing Addendum (“DPA”) applies whenever Sixty Seven Digital FZCO (“WorkOSync”, the “Processor”) processes personal data on behalf of the customer identified in the WorkOSync account (the “Customer”, the “Controller”) in the course of providing the service under the Terms of Service. It applies automatically to every company created on WorkOSync; no signature is needed, although we will countersign a copy for customers whose procurement requires it.
If this DPA conflicts with the Terms of Service, this DPA prevails for the processing of personal data. If it conflicts with the Standard Contractual Clauses incorporated under section 9, the Clauses prevail.
Definitions
“Personal data”, “processing”, “data subject”, “controller”, “processor” and “personal data breach” have the meanings given in Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”) and, where the Customer is established in the EEA or the UK, in the GDPR or UK GDPR. “Customer Personal Data” means personal data contained in Customer Data as defined in the Terms of Service. “Sub-processor” means a third party engaged by WorkOSync to process Customer Personal Data. “Applicable Data Protection Law” means the PDPL and any other data protection law that applies to the Customer’s use of the service.
Roles of the parties
For Customer Personal Data, the Customer is the controller (or a processor acting for its own controller, in which case it warrants that it has authority to appoint WorkOSync as a sub-processor) and WorkOSync is the processor. WorkOSync processes Customer Personal Data only on the Customer’s documented instructions, which are: the Terms of Service, this DPA, the configuration the Customer applies in the service, and any further written instructions that are consistent with the service.
For account, billing, security-log and support data about the Customer’s own users, WorkOSync is an independent controller as described in the Privacy Policy. Where the Customer enables AI features with its own provider key, the Customer is the controller of that transfer and the provider is the Customer’s processor.
Details of the processing
| Item | Description |
|---|---|
| Subject matter | Provision of the WorkOSync Work OS: ERP modules (accounting, invoicing, inventory, CRM, HR and payroll, projects, procurement, manufacturing) and the AI layer (briefs, drafts, summaries, approvals). |
| Duration | The term of the Customer's subscription, plus the export and deletion periods in section 13. |
| Nature and purpose | Storage, organisation, retrieval, display, calculation, reporting, backup, transmission to gateways and services the Customer connects, and, when enabled, submission of specific records to an AI model provider to generate output for the Customer. |
| Categories of data subjects | The Customer's employees and contractors, customers and their contacts, suppliers and their contacts, leads, shareholders and any other person whose data the Customer enters. |
| Categories of personal data | Identification and contact details, job and employment details, salary, bank details for payroll and supplier payments, Emirates ID and passport numbers where the Customer records them for HR or KYC, transaction history, communications, documents and files, and any other data the Customer chooses to enter. |
| Special categories | Only if the Customer enters them, for example medical fitness or leave records in HR. The Customer is responsible for a lawful basis. |
WorkOSync's obligations as processor
- Process Customer Personal Data only on documented instructions, including for international transfers, unless required by law, in which case we inform the Customer before processing unless the law prohibits it.
- Tell the Customer immediately if we believe an instruction breaches Applicable Data Protection Law.
- Ensure that staff with access to Customer Personal Data are bound by confidentiality, trained, and given access only on a need-to-know basis.
- Implement the technical and organisational measures in section 7 and keep them under review.
- Assist the Customer, taking into account the nature of the processing, in responding to data subject requests, in carrying out data protection impact assessments and in consulting supervisory authorities where required.
- Maintain a record of processing activities carried out on the Customer’s behalf and make it available on request.
- Delete or return Customer Personal Data at the end of the service as set out in section 13.
- Make available the information necessary to demonstrate compliance and allow audits as set out in section 12.
- Not sell Customer Personal Data, use it for our own purposes, or use it to train machine-learning models.
Customer's obligations
The Customer is responsible for the lawfulness of the Customer Personal Data it processes through the service, including having a lawful basis, giving data subjects the notices required, responding to their requests, configuring roles and permissions appropriately, keeping its users’ credentials secure, and deciding whether to enable AI features and which region the company is hosted in. The Customer confirms that its instructions comply with Applicable Data Protection Law and that it will not enter data that it is not entitled to process.
Technical and organisational security measures
WorkOSync maintains, at a minimum, the following measures. A fuller description is on the Security Overview page.
| Area | Measures |
|---|---|
| Encryption | TLS 1.2 or higher with HSTS for all traffic; encryption at rest for databases, file storage and backups; secrets such as gateway and AI keys encrypted with a server-held key; passwords stored as bcrypt hashes. |
| Access control | Role-based access with least privilege; server-side sessions with httpOnly, Secure, SameSite cookies; two-factor authentication for owners and admins; production access limited to named staff with MFA and logged. |
| Tenant isolation | Every query is scoped to the company; customers reach only their own portal; per-company region selection with data, files and backups kept in that region. |
| Application security | Escalating brute-force lockout, per-account throttling, constant-time credential checks, honeypot and timing traps on every form, rate limits, body limits, a site-wide bot classifier and scanner-probe banning; dependency audit before every deploy. |
| Logging and monitoring | Audit trail of sign-ins and every create, update and delete; security events retained 12 months; liveness probe and alerting. |
| Resilience | Encrypted daily backups with a 35-day rolling window; restore procedures tested; self-healing process supervision. |
| Organisational | Confidentiality obligations for all staff; security review of every change; documented incident response; annual review of this table. |
Sub-processors
The Customer gives general authorisation for WorkOSync to engage the sub-processors below. We impose on each sub-processor data protection obligations no less protective than this DPA, and we remain liable to the Customer for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud hosting provider | Compute, database, file storage and backups for the Customer's company | UAE (default); EU or US if the Customer selects that region |
| Email delivery provider | Sending transactional and notification email on the Customer's behalf | EU and US |
| Stripe, Tap Payments, PayPal, Razorpay | Processing subscription payments and, where the Customer enables it, payments collected from the Customer's own clients. Each gateway is an independent controller for the card data it receives. | UAE, EU, US and India, according to the gateway |
| AI model provider | Generating AI output from the records the Customer submits. Engaged only when the Customer enables WorkOSync-managed AI; not engaged when the Customer uses its own key. | EU or US |
We will give the Customer at least 30 days’ notice by email before adding or replacing a sub-processor. If the Customer has a reasonable objection on data protection grounds and we cannot resolve it, the Customer may terminate the affected subscription before the change takes effect and receive a pro-rated refund of prepaid, unused fees. The current list is always published on this page.
International transfers
Customer Personal Data is stored in the region the Customer selects, with the UAE as the default. Where a sub-processor or a support activity requires personal data to leave that region, the transfer is made only under a mechanism recognised by Applicable Data Protection Law:
- PDPL (Articles 22 and 23): transfer to a jurisdiction the UAE Data Office has deemed adequate, or under a contract that guarantees a level of protection equivalent to the PDPL, or with another safeguard the executive regulations permit.
- GDPR and UK GDPR: the European Commission’s Standard Contractual Clauses (Module 2, controller to processor, and Module 3 where applicable), together with the UK International Data Transfer Addendum, are incorporated into this DPA by reference for Customers established in the EEA or the UK, with the Customer as data exporter and WorkOSync as data importer. Annex I is completed by section 4 and Annex II by section 7 of this DPA.
We carry out and document a transfer risk assessment for each sub-processor located outside the UAE and the EEA and will share a summary on request.
Data subject requests
The Customer can satisfy most access, correction, export and deletion requests directly using the tools in the service. If a data subject contacts WorkOSync directly about Customer Personal Data, we will not respond substantively except to direct them to the Customer, and we will forward the request to the Customer within 3 working days. Where a request requires our assistance we will provide it within a reasonable time and without charge unless the request is manifestly excessive.
Personal data breach notification
If WorkOSync becomes aware of a personal data breach affecting Customer Personal Data, we will notify the Customer’s owner and security contacts without undue delay and in any event within 72 hours of confirming the breach. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed to address it, and a point of contact. We will provide updates as the investigation progresses, cooperate with the Customer’s own notifications to the UAE Data Office or a supervisory authority and to data subjects, and will not identify the Customer publicly without its consent unless the law requires.
Audits and reports
On written request, no more than once in any 12-month period unless a breach has occurred or a supervisory authority requires it, WorkOSync will make available the information reasonably necessary to demonstrate compliance with this DPA, including the results of internal security reviews and any third-party assessments we hold. If that information does not reasonably satisfy the Customer, the Customer or an independent auditor bound by confidentiality may audit our relevant controls, on 30 days’ notice, during working hours, without disrupting the service, at the Customer’s cost. Findings are confidential and we will remediate any material gap within an agreed period.
Return and deletion on termination
When a subscription ends, the Customer may export all Customer Data, including Customer Personal Data, in CSV and JSON formats from Settings for 30 days. After that period WorkOSync deletes the company’s database and files within 90 days of termination, and the data ages out of encrypted backups within the 35-day rolling backup window that follows. We will confirm deletion in writing on request. We may retain data only where and for as long as the law requires, such as tax invoices we issued to the Customer, and that data remains protected by this DPA.
Liability
Each party’s liability under this DPA is subject to the exclusions and the cap in the Terms of Service, except that the cap does not apply to fines imposed on one party as a result of the other’s breach of this DPA, or to a party’s liability to data subjects that cannot be limited under Applicable Data Protection Law.
Contact
Requests for a countersigned copy of this DPA, sub-processor objections, breach notifications and audit requests should go to our data protection contact.
Other addresses: privacy@workosync.com for data protection, support@workosync.com for billing and support, security@workosync.com for vulnerability reports.

