Skip to content

Legal

Data Processing Agreement

Last updated: 29 September 2026

When we build and run your product, we handle your users' personal data for you. You decide why and how it is used (you are the controller); we act only on your instructions (we are the processor). This agreement sets out the terms GDPR Article 28 and UK GDPR require. It forms part of our Terms of Service and applies automatically to every subscription.

Parties

The customer named on the subscription (controller) and Bose and Turing Innovations FZCO, trading as Plutonapps, IFZA Properties, A1 - 3641379065, Dubai Silicon Oasis, Dubai, United Arab Emirates (processor).

If you need a signed copy, email [email protected] and we will countersign it.

What we process

  • Subject matter and purpose: building, hosting, operating, maintaining and supporting the customer's product, as described in the Terms and the customer's instructions.
  • Duration: for the term of the subscription, plus any agreed handover period.
  • Data subjects: the customer's end users, staff and contacts whose data is in the product.
  • Categories of data: as determined by the customer's product — typically identity and contact details, account data, content users create, usage and technical data, and any other data the product is built to hold.
  • Special categories: only where the customer's product requires them and the customer has told us in writing.

Our commitments

  • We process the data only on your documented instructions (these terms, your requests and your product's design), and tell you if we believe an instruction breaks the law.
  • Everyone at Plutonapps who can access the data is bound by confidentiality.
  • We apply appropriate technical and organisational security measures (Annex: Security) and keep them under review.
  • We use sub-processors only as listed on our Sub-processors page, bound by terms at least as protective as these. We give you 30 days notice before adding or replacing one, and you can object on reasonable grounds.
  • We help you respond to your users' requests to exercise their rights, and with security, breach notification, impact assessments and consultations with authorities, as far as our role allows.
  • We notify you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data.
  • At the end of the service, we return or delete the data at your choice, unless the law requires us to keep it.
  • We make available the information needed to show we comply with Article 28 and allow for audits, once a year, on 30 days' notice, at the customer's cost.

International transfers

We are established in the United Arab Emirates, which has no EU adequacy decision. Where you transfer EU/EEA or UK personal data to us, and where we pass it on to our sub-processors in the United States or to our staff in India, the EU Standard Contractual Clauses (Module 2 controller-to-processor for your transfer to us; Module 3 processor-to-processor onward) and the UK Addendum apply and are incorporated by reference.

Law and courts

This agreement is governed by the laws of the United Arab Emirates, and disputes go to the courts of Dubai, as in our Terms, except where the Standard Contractual Clauses require the law and courts of an EU member state (or of England and Wales for the UK Addendum) for matters under them.

Infrastructure you own

Where your product runs on hosting, database or other accounts that you own and pay for directly, those providers are your processors, not ours, and your own agreement with them applies. We access them as your processor.

Annex: Security

  • Access to production data is limited to staff who need it for the work, and staff views of customer dashboards are recorded.
  • Databases are not exposed to the public internet; access goes through server code with row-level restrictions.
  • Data is encrypted in transit (TLS) and at rest by our hosting and database providers.
  • Sign-in is handled by a dedicated identity provider; secrets are stored as encrypted environment variables and never in source code.
  • Payment card data is handled only by Stripe.
  • Access to production systems is limited to the staff who need it for their work, and we act promptly on any security incident.