Data Processing Agreement
Effective date: 27 July 2026 · Version 1.0
Applies to: zidaan.app · Operated by Zidaan
The short version: Zidaan's architecture means we process almost no personal data beyond your account identity. Your project data — tasks, documents, budgets — is stored in your own cloud storage and encrypted client-side. We never see it. This DPA documents our processing obligations for the identity data we do handle.
1. Definitions
"Controller" means the organisation or individual that determines the purposes and means of processing personal data (you, or your organisation).
"Processor" means the entity that processes personal data on behalf of the Controller (Zidaan, for the limited identity data described below).
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on personal data, including collection, storage, use, and deletion.
"Sub-processor" means a third party engaged by Zidaan to process personal data on behalf of the Controller.
2. What Zidaan Processes on Your Behalf
Zidaan processes the following personal data as a Processor on behalf of the Controller:
- Email addresses of workspace members (used for authentication and transactional email)
- Display names of workspace members
- Bcrypt password hashes (one-way; not reversible)
- PBKDF2 salt values (cryptographic parameter; does not allow data decryption)
- Workspace membership records and role assignments
- Plan status and subscription identifiers
- AI usage counts (request counts per day, not content)
Purpose of processing: To authenticate users, operate workspace access controls, enforce plan limits, and deliver transactional emails (password reset, invitation).
Legal basis: Performance of a contract between Zidaan and the Controller (the subscription agreement).
Duration: Personal data is retained while the workspace account is active and deleted within 30 days of account termination.
3. What Zidaan Does Not Process
Due to Zidaan's zero-vendor-data architecture, the following data is never transmitted to or stored on Zidaan's servers:
- Project content: tasks, subtasks, work packages, project names
- Financial data: expenses, budgets, cost estimates
- Documents and file attachments
- Stakeholder, risk, or issue register entries
- Audit trail and change history
- CRDT operation logs
- AI prompt content and responses
All project data is stored exclusively in the Controller's own cloud storage backend (Google Drive, Dropbox, OneDrive, SharePoint, AWS S3, Azure Blob, WebDAV, SFTP, or local folder) and is encrypted client-side with AES-256-GCM before leaving the user's device. Zidaan holds no decryption key.
4. Sub-processors
Zidaan engages the following sub-processors. The Controller consents to these sub-processors by accepting these terms. Zidaan will provide 30 days' notice of any material changes to this list.
| Sub-processor | Role | Data processed | Location |
|---|---|---|---|
| Railway | Backend hosting & PostgreSQL database | Email, name, password hash, workspace records | United States |
| Vercel | Frontend hosting | IP address (access logs only, not retained) | Global CDN |
| PostHog | Product analytics | Anonymised usage events (opt-out available) | European Union |
| Resend | Transactional email | Email address (for delivery only) | United States |
| LemonSqueezy | Payment processing | Email, subscription status (payment data not shared with Zidaan) | United States |
| Anthropic / Cerebras / Groq / Google (OpenRouter) | AI relay (plan-dependent) | AI prompt content relayed in real time; not logged by Zidaan | United States |
Each sub-processor has its own data processing terms. Zidaan has executed data processing agreements with sub-processors where required by applicable law.
5. Controller Rights
As Controller, you have the following rights with respect to personal data Zidaan processes on your behalf:
- Access: Request a copy of all personal data Zidaan holds for your workspace members
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of workspace member data (fulfilled within 30 days; account termination triggers automatic deletion)
- Portability: Request an export of workspace member identity data in JSON or CSV format
- Restriction: Request restriction of processing in circumstances prescribed by applicable law
- Audit: Request evidence of Zidaan's compliance with this DPA (we will provide documentation within 30 days)
To exercise any of these rights, contact security@zidaan.app with your workspace identifier. We will respond within 30 days.
6. Governing Law and Jurisdiction
This Data Processing Agreement is governed by the laws of the United Arab Emirates. Disputes arising under this DPA shall be subject to the non-exclusive jurisdiction of the courts of Dubai, United Arab Emirates.
For enterprise customers located in Saudi Arabia, Canada, the European Union, or other jurisdictions, the parties may agree in writing to apply the data protection laws of the relevant jurisdiction. Contact admin@zidaan.app to discuss jurisdiction-specific DPA addenda.
Zidaan is designed to support compliance with UAE PDPL, Saudi PDPL, PIPEDA (Canada), and GDPR (EU/EEA) through its zero-vendor-data architecture. Jurisdiction-specific compliance obligations remain the responsibility of the Controller under applicable local law.
7. Request a Signed DPA
Enterprise customers requiring a countersigned Data Processing Agreement for their internal compliance records, procurement processes, or regulatory audits may request one by emailing security@zidaan.app with the subject line "DPA Request — [Organisation Name]".
Please include:
- Your organisation's legal name and registered address
- The applicable regulatory framework(s) (UAE PDPL, Saudi PDPL, PIPEDA, GDPR, etc.)
- Any jurisdiction-specific addenda you require
- Your preferred execution method (e-signature or wet signature)
We aim to return a signed DPA within 5 business days of receiving a complete request.