Skip go di main content

Legal

Data Processing Agreement

Last update: 5 October 2026

When we build and run your product, we dey handle your users personal data for you. Na you dey decide why and how dem go use am (na you be di controller); we dey act only on your instructions (na we be di processor). Dis agreement dey set out di terms wey GDPR Article 28 and UK GDPR require. E be part of our Terms of Service and e dey apply automatically to every subscription.

Parties

Di customer wey dem name for di subscription (controller) and Bose and Turing Innovations FZCO, wey dey trade as Plutonapps, IFZA Properties, A1 - 3641379065, Dubai Silicon Oasis, Dubai, United Arab Emirates (processor).

If you need signed copy, email hello@plutonapps.com and we go countersign am.

Wetin we dey process

  • Subject matter and purpose: to build, host, operate, maintain and support di customer product, as di Terms and di customer instructions describe.
  • Duration: for di term of di subscription, plus any handover period wey we agree.
  • Data subjects: di customer end users, staff and contacts wey their data dey inside di product.
  • Categories of data: as di customer product decide — usually identity and contact details, account data, content wey users create, usage and technical data, and any other data wey dem build di product to hold.
  • Special categories: only where di customer product need dem and di customer don tell us for writing.

Our commitments

  • We dey process di data only on your documented instructions (these terms, your requests and your product design), and we go tell you if we believe say one instruction dey break di law.
  • Everybody for Plutonapps wey fit access di data dey bound by confidentiality.
  • We dey apply correct technical and organisational security measures (Annex: Security) and we dey keep dem under review.
  • We dey use sub-processors only as dem dey listed for our Sub-processors page, bound by terms wey protect at least like these ones. We go give you 30 days notice before we add or replace one, and you fit object on reasonable grounds.
  • We dey help you respond to your users requests to use their rights, and with security, breach notification, impact assessments and consultations with authorities, as far as our role allow.
  • We go notify you without undue delay, and inside 48 hours after we become aware, of personal data breach wey affect your data.
  • At di end of di service, we go return or delete di data as you choose, unless di law require us to keep am.
  • We dey make available di information wey dem need to show say we comply with Article 28 and we dey allow audits, once every year, on 30 days notice, for di customer cost.

International transfers

We dey established for United Arab Emirates, wey no get EU adequacy decision. Where you transfer EU/EEA or UK personal data come meet us, and where we pass am go our sub-processors for United States or our staff for India, di EU Standard Contractual Clauses (Module 2 controller-to-processor for your transfer to us; Module 3 processor-to-processor onward) and di UK Addendum dey apply and dem dey incorporated by reference.

Law and courts

Di laws of United Arab Emirates dey govern dis agreement, and disputes dey go di courts for Dubai, as e dey our Terms, except where di Standard Contractual Clauses require di law and courts of EU member state (or of England and Wales for di UK Addendum) for matters under dem.

Infrastructure wey you own

Where your product dey run on hosting, database or other accounts wey you own and pay for directly, those providers na your processors, no be our own, and your own agreement with dem dey apply. We dey access dem as your processor.

Annex: Security

  • Access to production systems and data dey limited to staff wey need am for their work, and we dey record when staff view customer dashboards.
  • Database access need credentials wey only our servers and small number of named engineers dey hold; row-level security also dey protect customer data.
  • Our hosting and database providers dey encrypt data in transit (TLS) and at rest.
  • Dedicated identity provider dey handle sign-in; we dey store secrets as encrypted environment variables and never inside source code.
  • Na only Stripe dey handle payment card data.
  • We dey act fast on any security incident.