اتفاقية معالجة البيانات
حُدِّثت في 12 سبتمبر 2026
تُبرم اتفاقية العملاء خارج المنطقة الاقتصادية الأوروبية باللغة الإنجليزية، والنص الإنجليزي هو النص المعتمد. لذلك تُعرض بنود الاتفاقية أدناه بالإنجليزية دون ترجمة، تفاديًا لإنشاء نص عربي لا يُوقَّع عليه أحد.
ما هذه الوثيقة
عندما يستخدم نشاط تجاري خدمة Onesync، يكون النشاط هو المتحكم في بيانات عملائه، وتكون Nordic Technologies L.L.C-FZ هي المعالِج. والنص أدناه هو اتفاقية المعالجة، وهو نفسه الملحق 1 من اتفاقية العميل، ويُعرض من المصدر ذاته حتى لا يختلف الاثنان.
Parties
Data controller: [Company] (the "Customer") Data processor: Nordic Technologies L.L.C-FZ ("Onesync"), as identified in the Agreement
Background and purpose
Within the service, Onesync processes certain personal data on the Customer’s behalf. This annex governs that processing. Where the processing falls within the scope of the EU General Data Protection Regulation (GDPR), this annex is the written contract required by Article 28 GDPR. Where it falls within the scope of UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, this annex governs the processing accordingly. Where both apply, the stricter requirement prevails.
Subject matter and duration
The processing covers the personal data necessary to provide the service under the Agreement and continues for as long as the Agreement is in force. On termination, the clause on deletion and return below applies.
Categories of personal data and data subjects
The processing covers principally:
- Names and email addresses of the Customer’s own clients and newsletter subscribers (for automated mailings) - Visit statistics (for example clicks and page views) relating to the Customer’s pages and widgets - Data connected to the Customer’s Google Business Profile account administered by Onesync
The data subjects are the Customer’s own clients and, where applicable, the Customer’s staff connected to the account.
Purpose of the processing
The personal data is processed solely to provide the services under the Agreement: mailings, analytics and administration of the Google Business Profile. Onesync may not use the data for its own or any other purpose.
Obligations of the processor
- Process personal data only on the Customer’s documented instructions, including as set out in this annex. - Ensure that personnel with access to the data are bound by confidentiality. - Implement appropriate technical and organisational security measures (for example access control and encryption in transit) to protect the data. - Assist the Customer in responding to requests from data subjects exercising their rights. - Notify the Customer without undue delay, and no later than 72 hours after becoming aware, of a personal data breach affecting the data processed. - Engage sub-processors only in accordance with the clause below, and impose on them obligations equivalent to those in this annex. - On request, provide the information reasonably required to demonstrate compliance with this annex.
Sub-processors
Onesync may engage sub-processors (for example providers of hosting, email delivery and AI services) to provide the service. Onesync is responsible for imposing on sub-processors the same data protection obligations as apply under this annex.
The current list of sub-processors is published at https://onesync.se/integritet/underbitraden and is also available on request. The Customer is notified in advance of any change of sub-processor processing personal data under this annex, with the opportunity to object.
International transfers
Onesync is Nordic Technologies L.L.C-FZ, established in the United Arab Emirates, which is not the subject of an adequacy decision under the GDPR. Personal data under this annex is stored on infrastructure inside the EU/EEA and is not stored in the United Arab Emirates; transfer out of the United Arab Emirates is made on the contractual basis provided for by Articles 22 and 23 of Federal Decree-Law No. 45 of 2021.
Where the Customer is established in the EU or the EEA, the transfer of personal data to Onesync is made on the basis of the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two or Module Three as applicable, which the Parties agree to enter into and which are incorporated into this annex by reference. Onesync has carried out a transfer impact assessment and supplies it on request, together with any further assistance the Customer reasonably requires.
Where sub-processors process personal data outside the EU/EEA, the same requirement applies. Onesync is responsible for monitoring that the transfer basis remains valid and for informing the Customer of changes affecting it. Which sub-processors are concerned appears at https://onesync.se/integritet/underbitraden.
Where required by Article 27 GDPR, Onesync shall designate in writing a representative in the European Union and make its details available to the Customer and to data subjects.
Deletion and return at the end of the Agreement
On termination of the Agreement, Onesync shall, at the Customer’s choice, delete or return all personal data processed on the Customer’s behalf, and delete existing copies, unless storage is required by applicable law. This shall be done within 30 days of termination.
Liability
Each Party is liable for damage caused by its failure to meet its obligations under applicable data protection law or this annex, in accordance with the limitation of liability in the Agreement.
Entry into force
This annex takes effect at the same time as the Agreement and applies for as long as the Agreement is in force, and thereafter to the extent required to fulfil the obligations in the clause on deletion and return.
متى تصبح ملزِمة
النشر وحده لا يجعل الاتفاقية ملزِمة. تسري اتفاقية المعالجة عند توقيع اتفاقية العميل، بوصفها الملحق 1 منها. والغرض من هذه الصفحة هو إتاحة قراءة البنود قبل ذلك، والوفاء فورًا بالتعهّد الوارد في الملحق بتقديمها عند الطلب.