Data Processing Addendum (DPA)

DONE MENAT FZCO

Effective Date: 24th April 2026

1. Parties

This Data Processing Addendum (“DPA”) forms part of the agreement between:

2. Purpose

This DPA governs the processing of Personal Data by DONE on behalf of the Client in connection with the DONE platform and services.

By using the services of DONE and by visiting our website and apps you agree to be bound by the following DPA.

3. Definitions

4. Scope of Processing

DONE processes Personal Data only to:

5. Nature of Data

May include:

6. Duration

Processing continues for the duration of the agreement and until the end of the applicable billing cycle after termination.

7. Obligations of DONE (Processor)

DONE shall:

8. Obligations of the Client (Controller)

The Client shall:

The Client is solely responsible for the data within its academy and applications.

9. Sub-Processors

DONE may use third-party providers for hosting, storage, analytics, and infrastructure. DONE ensures such providers maintain reasonable data protection standards.

10. International Transfers

Data may be processed outside the Client’s jurisdiction. By using DONE, the Client authorises such transfers.

11. Security Measures

DONE maintains commercially reasonable safeguards, including access controls, encryption where appropriate, and infrastructure security practices.

However, absolute security cannot be guaranteed.

12. Data Breach

In the event of a breach, DONE will take reasonable steps to investigate and mitigate and notify the Client where legally required.

13. Data Subject Rights

DONE will assist the Client, where reasonably possible, in responding to access, deletion, and data portability requests.

14. Data Deletion

Upon termination, data remains accessible until the end of the billing period. Thereafter, data may be deleted or made inaccessible.

15. Limitation of Liability

To the fullest extent permitted by law, DONE shall not be liable for indirect or consequential damages, data loss beyond its reasonable control, or client misuse of the platform.

16. Audit Rights

The Client may request reasonable information regarding DONE’s data protection practices. DONE is not required to allow intrusive audits.

17. Governing Law

This DPA is governed by the laws of the United Arab Emirates. Jurisdiction: Courts of Dubai.