This Data Processing Agreement (“DPA”) forms part of the Terms of Service, Privacy Policy, or any other agreement between usedcomputerserver.store (“Company”, “we”, “us”, or “Processor”) and any customer, business partner, merchant, or other organization (“Customer”, “you”, or “Controller”) that requires us to process personal data on its behalf.
This DPA is intended to describe how personal data is processed, protected, retained, and handled in accordance with applicable data protection laws, including, where applicable, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and the EU/UK General Data Protection Regulation (GDPR/UK GDPR).
1. Definitions
For the purposes of this DPA:
- Personal Data means information relating to an identified or identifiable individual.
- Processing includes collecting, recording, organizing, storing, modifying, retrieving, using, transmitting, sharing, restricting, or deleting personal data.
- Controller means the organization that determines the purposes and means of processing personal data.
- Processor means an organization that processes personal data on behalf of the Controller.
- Data Subject means the individual whose personal data is being processed.
- Subprocessor means a third party engaged by the Processor to process personal data.
2. Scope of Processing
We may process personal data when providing website, e-commerce, customer service, payment, delivery, account management, marketing, technical support, or related services.
Personal data may include:
- Customer name
- Email address
- Telephone number
- Billing and shipping address
- Order and transaction information
- Account information
- Customer communications
- Device and browser information
- IP address
- Website usage and analytics information
- Payment-related information processed through authorized payment service providers
We will only process personal data for legitimate business purposes and in accordance with documented instructions from the Controller where we act as a Processor.
3. Purpose of Processing
Personal data may be processed for purposes including:
- Processing and managing orders
- Delivering products
- Managing customer accounts
- Providing customer support
- Processing payments and refunds
- Preventing fraud and unauthorized transactions
- Maintaining website security
- Sending transactional communications
- Providing requested services
- Complying with legal and regulatory requirements
- Improving website functionality and customer experience
We will not use personal data for purposes that are incompatible with the purposes described above unless permitted by applicable law.
4. Processing Instructions
Where we process personal data on behalf of a Controller, we will:
- Process personal data only on documented instructions from the Controller.
- Notify the Controller if an instruction appears to violate applicable data protection law, where legally permitted.
- Ensure that persons authorized to process personal data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures.
5. Confidentiality
We will take reasonable measures to ensure that employees, contractors, and other authorized personnel who have access to personal data:
- Process the information only where necessary for their duties.
- Maintain the confidentiality of the information.
- Receive appropriate instructions regarding data protection and information security.
6. Security Measures
We use reasonable technical and organizational measures designed to protect personal data against:
- Unauthorized access
- Accidental loss
- Destruction
- Alteration
- Unauthorized disclosure
- Misuse
- Cybersecurity threats
Measures may include access controls, authentication systems, secure hosting, encryption where appropriate, security monitoring, backups, software updates, and restricted administrative access.
No online system can guarantee absolute security, but we take reasonable steps to reduce risks to personal information.
7. Subprocessors
We may use trusted third-party service providers to help operate our business and website. These providers may include:
- Website hosting companies
- Cloud service providers
- Payment processors
- Shipping and courier companies
- Email service providers
- Customer support platforms
- Security providers
- Website analytics providers
Where required by applicable law, subprocessors will be subject to contractual obligations requiring appropriate protection of personal data.
The Controller authorizes us to engage subprocessors where reasonably necessary to provide our services.
8. International Data Transfers
Personal data may be processed or stored in countries outside the country in which the Data Subject resides.
Where required by applicable law, we will take appropriate measures to protect international transfers of personal information, which may include:
- Standard Contractual Clauses
- Adequacy decisions
- Contractual safeguards
- Other legally recognized transfer mechanisms
9. Data Subject Rights
Depending on applicable law, individuals may have rights to:
- Access their personal data
- Correct inaccurate information
- Request deletion of personal data
- Restrict certain processing
- Object to certain processing
- Request transfer of their personal data
- Withdraw consent where processing is based on consent
- File a complaint with an appropriate regulatory authority
Where we process personal data solely on behalf of a Controller, we will reasonably assist the Controller in responding to valid Data Subject requests where required.
10. Personal Data Breach
If we become aware of a confirmed personal data breach affecting information processed on behalf of a Controller, we will take reasonable steps to:
- Contain and investigate the incident.
- Reduce potential harm.
- Notify the Controller without undue delay where legally required.
- Provide available information reasonably necessary for the Controller to comply with applicable breach-notification requirements.
11. Data Retention and Deletion
We retain personal data only for as long as reasonably necessary to:
- Provide our services
- Complete transactions
- Maintain business and accounting records
- Resolve disputes
- Prevent fraud
- Enforce agreements
- Meet legal and regulatory obligations
When personal data is no longer required, it may be securely deleted, anonymized, or otherwise disposed of in accordance with applicable law and our retention policies.
Upon termination of services, and where legally required, personal data processed solely on behalf of a Controller may be returned or deleted unless applicable law requires continued retention.
12. Assistance to the Controller
Where reasonably required and applicable, we may assist the Controller with:
- Data Subject requests
- Security assessments
- Personal data breach investigations
- Data protection impact assessments
- Regulatory compliance obligations
Assistance may be subject to reasonable limitations depending on the nature of the processing and information available to us.
13. Audit and Compliance Information
Where required under applicable data protection law, we may provide reasonable information necessary to demonstrate compliance with our obligations as a Processor.
Any audit request must be reasonable, appropriately limited, subject to confidentiality requirements, and must not compromise the security, privacy, or confidentiality of other customers or systems.
14. Controller Responsibilities
The Controller is responsible for ensuring that:
- Personal data is collected lawfully.
- Appropriate privacy notices are provided to Data Subjects.
- Necessary consent or other lawful bases for processing are obtained.
- Instructions provided to us comply with applicable laws.
- Personal data provided to us is accurate and limited to what is necessary.
- Appropriate safeguards are implemented within systems controlled by the Controller.
15. Cookies and Analytics
Our website may use cookies and similar technologies for functionality, security, analytics, and other permitted purposes.
Further information regarding cookies can be found in our Cookie Policy.
16. Payment Information
Payments may be processed through independent third-party payment service providers.
We may not directly store complete credit or debit card information. Payment providers process payment data according to their own privacy policies, security standards, and legal obligations.
17. Relationship with Privacy Policy
This DPA should be read together with the Privacy Policy and other applicable terms published on usedcomputerserver.store.
If there is a conflict between this DPA and another agreement concerning the processing of personal data, the terms providing the greater protection required by applicable data protection law will apply to the extent of the conflict.
18. Changes to This DPA
We may update this Data Processing Agreement from time to time to reflect:
- Changes in applicable laws
- Changes to our services
- New security or privacy practices
- Changes to third-party service providers
The latest version will be published on our website with an updated effective date.
19. Governing Law
This DPA will be governed by applicable laws of the United Arab Emirates, unless another jurisdiction is required by mandatory applicable data protection law or a separate written agreement.
20. Contact Us
For questions, requests, or concerns regarding this Data Processing Agreement or the processing of personal information, please contact us through the contact information provided on:
Website: https://usedcomputerserver.store/
Important Notice: This Data Processing Agreement is provided as general website content and should not be considered legal advice. Businesses with specific GDPR, UAE PDPL, international transfer, or enterprise data-processing requirements should have the agreement reviewed by a qualified legal professional.