ZynDesk

This is an unofficial English translation provided for convenience only. The Arabic version is the sole legally binding version. In the event of any discrepancy or conflict between the two versions, the Arabic text shall prevail. View Arabic version

Data Processing Agreement

Last updated: August 2026

Last updated: August 2026

1.Chapter I: Definitions and General Provisions

Article (1) Purpose of the Agreement

This Data Processing Agreement ("Agreement") sets out the terms under which Zyntra Digital ("the Processor") processes personal data on behalf of the client ("the Controller") within the framework of the ZynDesk platform services. This Agreement supplements the Terms and Conditions and prevails over them in the event of any conflict with respect to the processing of personal data.

Article (2) Definitions

For the purposes of this Agreement, the following terms have the meanings set out opposite each:

  • "Personal Data": any information relating to an identified or identifiable natural person.
  • "Processing": any operation performed on Personal Data such as collection, storage, modification, retrieval, disclosure, or deletion.
  • "Controller": the client who determines the purposes and means of processing Personal Data.
  • "Processor": Zyntra Digital, which processes Personal Data on the instructions of the Controller.
  • "Sub-processors": third parties to whom Zyntra Digital delegates part of its processing operations.
  • "Data Subjects": the natural persons to whom the Personal Data relates.

2.Chapter II: Nature and Purposes of Processing

Article (3) Processing Details

The Processor shall process Personal Data for the following specified purposes:

  • Storing and managing the accounting firm's client data within the CRM system.
  • Processing employee data and attendance and leave records.
  • Archiving financial and tax documents and making them available for review.
  • Generating reports and statistics relating to firm operations.
  • Sending notifications and reminders relating to tax deadlines.

Article (4) Categories of Personal Data Processed

The categories of Personal Data that may be processed by the Processor under this Agreement include:

  • User identity data: name, email address, phone number, and job title.
  • Firm client data: client names and their financial, tax, and commercial data.
  • Employee data: attendance and leave records, qualifications, and salaries if entered by the Controller.
  • Technical data: IP addresses and usage logs for security purposes.

3.Chapter III: Processor Obligations

Article (5) Core Obligations

The Processor shall:

  • Process Personal Data solely in accordance with the written instructions of the Controller, and notify the Controller immediately if it considers that any such instruction infringes applicable law.
  • Ensure that Personal Data is kept confidential and not disclosed to third parties without explicit authorization or a legal obligation.
  • Implement all technical and organizational measures necessary to protect Personal Data against unauthorized access, damage, or loss.
  • Assist the Controller in responding to Data Subject requests relating to their rights.

Article (6) Security Breach Notification

The Processor shall notify the Controller within 48 hours of discovering any security breach that may pose a risk to the rights and freedoms of Data Subjects. Notification shall include: a description of the nature, scope, and likely impact of the breach, and the measures taken to mitigate its effects.


4.Chapter IV: Sub-processors

Article (7) List of Sub-processors

The Controller hereby acknowledges, under this Agreement, the engagement of the following current sub-processors:

Sub-processorPurposeData Location
Google FirebaseDatabases and authenticationEuropean Union (eur3)
CloudinaryFile and image storageGlobal (CDN)
ResendEmail sendingEuropean Union
RenderServer hostingFrankfurt, Germany
VercelFront-end hostingGlobal (CDN)

The Processor shall notify the Controller at least 30 days before adding any new sub-processor or replacing any of the current sub-processors.


5.Chapter V: Data Subject Rights

Article (8) Controller Obligations

The Controller alone bears responsibility for responding to Data Subject requests relating to their legal rights of access, rectification, erasure, objection, and restriction of processing. The Processor shall provide the Controller with the technical support necessary to respond to such requests within 30 days of their receipt.


6.Chapter VI: Security Measures

Article (9) Technical and Organizational Safeguards

The Processor applies a range of security measures including in particular:

  • Encryption of data in transit using TLS 1.3 and at rest using AES-256.
  • Application of the least-privilege principle and mandatory two-factor authentication for all production environments.
  • Automatic daily backups with periodic recovery testing.
  • Periodic security reviews and regular risk assessment.
  • Training of Company staff on data protection best practices.

7.Chapter VII: Data Transfers

Article (10) Transfer of Data Outside the Region

User data is stored primarily in European Union data centers. Some data may be transferred outside the EU subject to appropriate legal safeguards in accordance with applicable regulations. The Controller may enquire about the storage locations of their data at any time at: info@zyndesk.app.


8.Chapter VIII: Term and Termination

Article (11) Duration of Processing

This Agreement remains in force for the duration of the Controller's subscription to the ZynDesk platform. Upon termination of the subscription, the Processor shall make the Controller's data available for export for 30 days and then permanently delete it within 90 days of the termination date, unless applicable law requires it to be retained for a longer period.

Article (12) Enquiries Regarding the Agreement

For any enquiries relating to this Agreement or to request a signed copy, please contact: info@zyndesk.app