Legal

Data Processing Agreement

Version v1 · Last updated: 24 July 2026 · Draft pending legal review

This agreement governs how Darify processes personal data on behalf of a customer agency. It forms part of the Terms & Conditions and applies automatically to every agency using Darify CRM — no separate signature is required, though we will countersign a copy on request (legal@darify.ae).

  1. 1

    Scope and roles

    This agreement applies where Darify processes personal data on behalf of a customer agency ("Customer") in providing Darify CRM. For that data — leads, contacts, deals, listings, uploaded documents and messaging content — the Customer is the controller and Darify is the processor. For platform account data, verification documents and billing, Darify is a controller in its own right and the Privacy Policy applies instead. This agreement forms part of the Terms & Conditions.

  2. 2

    Subject matter and duration

    Darify processes Customer personal data for the duration of the subscription, plus the post-termination export and deletion window described below. The subject matter is the provision of a real-estate CRM and its features: lead and contact management, transaction records, verification support, messaging, AI assistance and reporting.

  3. 3

    Categories of data and data subjects

    Data subjects: the Customer’s prospective and existing clients (buyers, sellers, tenants, landlords), its own personnel, and transaction counterparties. Categories: identity and contact details; nationality and language; property preferences and budget; lead scores derived from those; communications content including WhatsApp messages and their media; transaction and financial records; and identity documents the Customer chooses to upload against a deal.

  4. 4

    Darify’s obligations

    Darify will: process Customer personal data only on the Customer’s documented instructions, of which use of the platform’s features is one, unless required otherwise by law (in which case we tell the Customer unless the law forbids it); ensure personnel with access are bound by confidentiality; implement appropriate technical and organisational security measures; assist the Customer in responding to data-subject requests and with its security, breach-notification and impact-assessment obligations; and make available the information needed to demonstrate compliance.

  5. 5

    Customer’s obligations

    The Customer warrants that it has a lawful basis for the personal data it enters into or imports to Darify, including any data captured through third-party campaigns, that it has given the notices its own data subjects are due, and that its instructions to Darify comply with applicable law. The Customer is responsible for the accuracy of the records it holds and for configuring access within its own team.

  6. 6

    Sub-processors

    The Customer authorises Darify to engage the sub-processors listed on our Sub-processors page, which names each recipient, its purpose, the data categories it receives and its location. Darify imposes data protection obligations on each sub-processor no less protective than those in this agreement and remains liable for their performance. We will give notice before adding or replacing a sub-processor in a way that materially changes how Customer data is handled, and the Customer may object on reasonable data protection grounds.

  7. 7

    International transfers

    Customer personal data is stored primarily in the UAE. Where a sub-processor processes it outside the UAE, Darify relies on the transfer conditions permitted by the PDPL, including transfers to jurisdictions recognised as providing adequate protection and otherwise appropriate contractual safeguards with the recipient.

  8. 8

    Security measures

    Encryption in transit and at rest; tenant isolation enforced at the database layer; role-based access control and least-privilege operational access; audit logging of access to personal data; private, access-controlled storage for identity documents; and periodic review of these measures. Darify may update its measures provided the level of protection is not reduced.

  9. 9

    Personal data breaches

    Darify will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, provide the information reasonably available to it, and cooperate with the Customer’s investigation and any notification it must make to the UAE Data Office or to affected individuals.

  10. 10

    Data-subject requests

    Where a data subject contacts Darify directly about Customer personal data, we will refer them to the Customer and will not respond substantively except to confirm the referral, unless legally required. Darify provides self-service tools — export and erasure of a data subject’s records — so the Customer can meet its own 30-day response duty, and will otherwise assist on request.

  11. 11

    Return and deletion

    On termination the Customer may export its data from the platform for 30 days. After that window Darify erases or anonymises Customer personal data, except where retention is required by law (for example DLD, anti-money-laundering or tax record-keeping), in which case the data is retained only for that purpose and for that period, and remains protected by this agreement.

  12. 12

    Audit

    Darify will make available the information necessary to demonstrate compliance with this agreement and will contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable notice, no more than once a year except where a supervisory authority requires otherwise or following a breach, and subject to confidentiality.

Darify CRM · Dubai real estate, verified. · Agency contract · Agent undertaking · Developer contract · Privacy · Terms · DPA · Sub-processors