Legal

Data Processing Agreement

Effective date: 27 July 2026 · Version 1.0

Applies to: zidaan.app · Operated by Zidaan

The short version: Zidaan's architecture means we process almost no personal data beyond your account identity. Your project data — tasks, documents, budgets — is stored in your own cloud storage and encrypted client-side. We never see it. This DPA documents our processing obligations for the identity data we do handle.

1. Definitions

"Controller" means the organisation or individual that determines the purposes and means of processing personal data (you, or your organisation).

"Processor" means the entity that processes personal data on behalf of the Controller (Zidaan, for the limited identity data described below).

"Personal Data" means any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on personal data, including collection, storage, use, and deletion.

"Sub-processor" means a third party engaged by Zidaan to process personal data on behalf of the Controller.

2. What Zidaan Processes on Your Behalf

Zidaan processes the following personal data as a Processor on behalf of the Controller:

Purpose of processing: To authenticate users, operate workspace access controls, enforce plan limits, and deliver transactional emails (password reset, invitation).

Legal basis: Performance of a contract between Zidaan and the Controller (the subscription agreement).

Duration: Personal data is retained while the workspace account is active and deleted within 30 days of account termination.

3. What Zidaan Does Not Process

Due to Zidaan's zero-vendor-data architecture, the following data is never transmitted to or stored on Zidaan's servers:

All project data is stored exclusively in the Controller's own cloud storage backend (Google Drive, Dropbox, OneDrive, SharePoint, AWS S3, Azure Blob, WebDAV, SFTP, or local folder) and is encrypted client-side with AES-256-GCM before leaving the user's device. Zidaan holds no decryption key.

4. Sub-processors

Zidaan engages the following sub-processors. The Controller consents to these sub-processors by accepting these terms. Zidaan will provide 30 days' notice of any material changes to this list.

Sub-processor Role Data processed Location
Railway Backend hosting & PostgreSQL database Email, name, password hash, workspace records United States
Vercel Frontend hosting IP address (access logs only, not retained) Global CDN
PostHog Product analytics Anonymised usage events (opt-out available) European Union
Resend Transactional email Email address (for delivery only) United States
LemonSqueezy Payment processing Email, subscription status (payment data not shared with Zidaan) United States
Anthropic / Cerebras / Groq / Google (OpenRouter) AI relay (plan-dependent) AI prompt content relayed in real time; not logged by Zidaan United States

Each sub-processor has its own data processing terms. Zidaan has executed data processing agreements with sub-processors where required by applicable law.

5. Controller Rights

As Controller, you have the following rights with respect to personal data Zidaan processes on your behalf:

To exercise any of these rights, contact security@zidaan.app with your workspace identifier. We will respond within 30 days.

6. Governing Law and Jurisdiction

This Data Processing Agreement is governed by the laws of the United Arab Emirates. Disputes arising under this DPA shall be subject to the non-exclusive jurisdiction of the courts of Dubai, United Arab Emirates.

For enterprise customers located in Saudi Arabia, Canada, the European Union, or other jurisdictions, the parties may agree in writing to apply the data protection laws of the relevant jurisdiction. Contact admin@zidaan.app to discuss jurisdiction-specific DPA addenda.

Zidaan is designed to support compliance with UAE PDPL, Saudi PDPL, PIPEDA (Canada), and GDPR (EU/EEA) through its zero-vendor-data architecture. Jurisdiction-specific compliance obligations remain the responsibility of the Controller under applicable local law.

7. Request a Signed DPA

Enterprise customers requiring a countersigned Data Processing Agreement for their internal compliance records, procurement processes, or regulatory audits may request one by emailing security@zidaan.app with the subject line "DPA Request — [Organisation Name]".

Please include:

We aim to return a signed DPA within 5 business days of receiving a complete request.