Legal
Data Processing Agreement
Version v1 · Last updated: 24 July 2026 · Draft pending legal review
This agreement governs how Darify processes personal data on behalf of a customer agency. It forms part of the Terms & Conditions and applies automatically to every agency using Darify CRM — no separate signature is required, though we will countersign a copy on request (legal@darify.ae).
- 1
Scope and roles
This agreement applies where Darify processes personal data on behalf of a customer agency ("Customer") in providing Darify CRM. For that data — leads, contacts, deals, listings, uploaded documents and messaging content — the Customer is the controller and Darify is the processor. For platform account data, verification documents and billing, Darify is a controller in its own right and the Privacy Policy applies instead. This agreement forms part of the Terms & Conditions.
- 2
Subject matter and duration
Darify processes Customer personal data for the duration of the subscription, plus the post-termination export and deletion window described below. The subject matter is the provision of a real-estate CRM and its features: lead and contact management, transaction records, verification support, messaging, AI assistance and reporting.
- 3
Categories of data and data subjects
Data subjects: the Customer’s prospective and existing clients (buyers, sellers, tenants, landlords), its own personnel, and transaction counterparties. Categories: identity and contact details; nationality and language; property preferences and budget; lead scores derived from those; communications content including WhatsApp messages and their media; transaction and financial records; and identity documents the Customer chooses to upload against a deal.
- 4
Darify’s obligations
Darify will: process Customer personal data only on the Customer’s documented instructions, of which use of the platform’s features is one, unless required otherwise by law (in which case we tell the Customer unless the law forbids it); ensure personnel with access are bound by confidentiality; implement appropriate technical and organisational security measures; assist the Customer in responding to data-subject requests and with its security, breach-notification and impact-assessment obligations; and make available the information needed to demonstrate compliance.
- 5
Customer’s obligations
The Customer warrants that it has a lawful basis for the personal data it enters into or imports to Darify, including any data captured through third-party campaigns, that it has given the notices its own data subjects are due, and that its instructions to Darify comply with applicable law. The Customer is responsible for the accuracy of the records it holds and for configuring access within its own team.
- 6
Sub-processors
The Customer authorises Darify to engage the sub-processors listed on our Sub-processors page, which names each recipient, its purpose, the data categories it receives and its location. Darify imposes data protection obligations on each sub-processor no less protective than those in this agreement and remains liable for their performance. We will give notice before adding or replacing a sub-processor in a way that materially changes how Customer data is handled, and the Customer may object on reasonable data protection grounds.
- 7
International transfers
Customer personal data is stored primarily in the UAE. Where a sub-processor processes it outside the UAE, Darify relies on the transfer conditions permitted by the PDPL, including transfers to jurisdictions recognised as providing adequate protection and otherwise appropriate contractual safeguards with the recipient.
- 8
Security measures
Encryption in transit and at rest; tenant isolation enforced at the database layer; role-based access control and least-privilege operational access; audit logging of access to personal data; private, access-controlled storage for identity documents; and periodic review of these measures. Darify may update its measures provided the level of protection is not reduced.
- 9
Personal data breaches
Darify will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, provide the information reasonably available to it, and cooperate with the Customer’s investigation and any notification it must make to the UAE Data Office or to affected individuals.
- 10
Data-subject requests
Where a data subject contacts Darify directly about Customer personal data, we will refer them to the Customer and will not respond substantively except to confirm the referral, unless legally required. Darify provides self-service tools — export and erasure of a data subject’s records — so the Customer can meet its own 30-day response duty, and will otherwise assist on request.
- 11
Return and deletion
On termination the Customer may export its data from the platform for 30 days. After that window Darify erases or anonymises Customer personal data, except where retention is required by law (for example DLD, anti-money-laundering or tax record-keeping), in which case the data is retained only for that purpose and for that period, and remains protected by this agreement.
- 12
Audit
Darify will make available the information necessary to demonstrate compliance with this agreement and will contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable notice, no more than once a year except where a supervisory authority requires otherwise or following a breach, and subject to confidentiality.