Data Processing Addendum
Effective: 24 July 2026 · Version 1.0
This addendum forms part of the agreement between each merchant ("Controller") and Nooks Software Technologies Est. ("Processor", "Nooks") governing the processing of end-customer personal data through the Nooks platform. It supplements — and does not replace — the Privacy Policy and Terms & Conditions.
اتفاقية معالجة البيانات (DPA)
سارية من ٢٤ يوليو ٢٠٢٦ · النسخة ١٫٠
١. الأطراف وموضوع الاتفاقية
تُبرَم هذه الاتفاقية بين التاجر ("المتحكم في البيانات") المسجَّل في منصة نوكس، ومؤسسة نوكس لتقنيات البرمجيات ("المعالج"، "نوكس")، وتنظّم معالجة نوكس للبيانات الشخصية لعملاء التاجر النهائيين نيابة عنه، وفقاً لـنظام حماية البيانات الشخصية السعودي ولوائحه التنفيذية.
هذه الاتفاقية سارية تلقائياً وتُعتبر جزءاً من اتفاقية الخدمة بين التاجر ونوكس بمجرد تسجيل التاجر في المنصة، دون الحاجة لتوقيع منفصل.
٢. مدة الاتفاقية
تبقى هذه الاتفاقية سارية طوال مدة اتفاقية الخدمة (الاشتراك) بين التاجر ونوكس، وتنتهي تلقائياً عند انتهاء تلك الاتفاقية، مع بقاء الالتزامات المتعلقة بالحذف والسرية سارية بعد الإنهاء وفق القسم ١١.
٣. طبيعة المعالجة وغرضها
تعالج نوكس البيانات لغرض تشغيل تطبيق التاجر: استضافة قاعدة البيانات، معالجة الطلبات والمدفوعات (عبر Moyasar)، إرسال رموز التحقق والإشعارات، برنامج الولاء والمحفظة، التوصيل، ودعم العملاء الفني. لا تعالج نوكس البيانات لأي غرض آخر خارج هذا النطاق.
٤. فئات أصحاب البيانات والبيانات المعالَجة
- أصحاب البيانات: العملاء النهائيون لتطبيق التاجر، وأعضاء فريق التاجر المضافين إلى لوحة التحكم.
- فئات البيانات: رقم الجوال، الاسم، البريد الإلكتروني الاختياري، عناوين التوصيل وإحداثيات GPS، سجل الطلبات، رموز الدفع (بدون بيانات بطاقة كاملة)، رموز الإشعارات الفورية، سجلات OTP، صور الشكاوى، رصيد المحفظة ونقاط الولاء — كما هو مفصَّل في القسم ٣ من سياسة الخصوصية.
٥. التزامات المعالج
- تعالج نوكس البيانات فقط بناءً على تعليمات موثّقة من التاجر (بما فيها هذه الاتفاقية وإعدادات التطبيق)، ولا تعالجها لأي غرض آخر ما لم يُلزمها نظام سعودي بذلك.
- إذا رأت نوكس أن تعليمات التاجر تخالف نظام حماية البيانات الشخصية، تُخطر التاجر فوراً قبل التنفيذ.
- تضمن نوكس التزام موظفيها ومتعاقديها المخوَّلين بالوصول للبيانات بواجب السرية.
٦. إجراءات الأمن
تطبّق نوكس التدابير التقنية والتنظيمية الموضّحة في القسم ٦ من سياسة الخصوصية (تشفير TLS 1.2+، تشفير AES-256-GCM لرموز الدفع ومفاتيح API، ضوابط وصول على مستوى الصف، نسخ احتياطية يومية).
٧. المعالجون الفرعيون
يفوّض التاجر نوكس بالتعاقد مع المعالجين الفرعيين المدرجين في القسم ٥ من سياسة الخصوصية (Supabase، Moyasar، Foodics، المدار التقني/Corbit، Resend، Apple Push/Firebase، Vercel، Railway، Sentry، Mapbox). تُخطر نوكس التاجر قبل ٣٠ يوماً من إضافة أي معالج فرعي جديد، ويحق للتاجر الاعتراض خلال تلك المدة.
٨. المساعدة في طلبات أصحاب البيانات
تساعد نوكس التاجر في الاستجابة لطلبات أصحاب البيانات (الاطلاع، التصحيح، الحذف، الاعتراض، نقل البيانات) خلال مدة معقولة لا تتجاوز ١٥ يوماً من استلام الطلب من التاجر، بما يمكّن التاجر من الرد على العميل خلال ٣٠ يوماً وفق نظام حماية البيانات الشخصية.
٩. الإخطار بخرق البيانات
عند اكتشاف نوكس لأي خرق للبيانات الشخصية يؤثر على بيانات عملاء التاجر، تُخطر التاجر خلال ٧٢ ساعة من الاكتشاف، مع تفاصيل طبيعة الخرق والبيانات المتأثرة والإجراءات المتخذة، لتمكين التاجر من الوفاء بالتزاماته تجاه الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا) والعملاء المتأثرين.
١٠. الحذف والإرجاع عند إنهاء الاتفاقية
خلال ٣٠ يوماً من إنهاء اتفاقية الخدمة، تحذف نوكس البيانات الشخصية القابلة للحذف أو تُعيدها للتاجر بناءً على طلبه، مع تجهيل سجلات الطلبات (إبقاؤها لأغراض محاسبية بدون بيانات تعريفية) والاحتفاظ بالسجلات المالية ٧ سنوات وفقاً لمتطلبات هيئة الزكاة والضريبة والجمارك (ZATCA).
١١. النقل خارج المملكة
أي نقل للبيانات خارج المملكة العربية السعودية (لأغراض الاستضافة أو التشغيل مع المعالجين الفرعيين) يتم بموجب بنود تعاقدية مكافئة للبنود التعاقدية القياسية الصادرة عن سدايا، مع تقييمات موثّقة لمخاطر النقل، كما هو مبيَّن في القسم ٥ من سياسة الخصوصية.
١٢. حقوق التدقيق والاطلاع
يحق للتاجر، بإخطار مسبق مدته ٣٠ يوماً وبحد أقصى مرة واحدة سنوياً، طلب معلومات معقولة من نوكس أو إجراء تدقيق (مباشرة أو عبر طرف ثالث مستقل يخضع لالتزام سرية) للتحقق من التزام نوكس بهذه الاتفاقية، على أن يكون ذلك خلال ساعات العمل الاعتيادية وبما لا يعطّل تشغيل المنصة لبقية التجار.
١٣. القانون الواجب التطبيق واللغة السائدة
تخضع هذه الاتفاقية لأنظمة المملكة العربية السعودية. عند التعارض بين النسخة العربية والإنجليزية، تسود النسخة العربية.
١٤. التواصل
لأي استفسار بخصوص هذه الاتفاقية: privacy@nooks.space
Data Processing Addendum
Effective: 24 July 2026 · Version 1.0
1. Parties & Subject Matter
This Addendum is entered into between the merchant ("Controller") registered on the Nooks platform and Nooks Software Technologies Est. ("Processor", "Nooks"), and governs Nooks’ processing of the Controller’s end-customer personal data on the Controller’s behalf, in accordance with the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
This Addendum takes effect automatically and forms part of the service agreement between the merchant and Nooks upon the merchant’s registration on the platform, without requiring a separate signature.
2. Duration
This Addendum remains in effect for the duration of the service (subscription) agreement between the merchant and Nooks, and terminates automatically when that agreement ends, except that the deletion and confidentiality obligations survive termination as set out in Section 10.
3. Nature & Purpose of Processing
Nooks processes data for the purpose of operating the merchant’s app: database hosting, order and payment processing (via Moyasar), OTP and notification delivery, loyalty and wallet management, delivery coordination, and technical customer support. Nooks does not process data for any purpose outside this scope.
4. Categories of Data Subjects & Data
- Data subjects: the merchant’s end-customers, and merchant team members added to the dashboard.
- Categories of data: mobile number, name, optional email, delivery addresses and GPS coordinates, order history, payment tokens (no full card data), push notification tokens, OTP logs, complaint photos, wallet balance, and loyalty points — as detailed in Section 3 of the Privacy Policy.
5. Processor Obligations
- Nooks processes data only on the Controller’s documented instructions (including this Addendum and the app’s configuration), and for no other purpose unless required by Saudi law.
- If Nooks believes an instruction from the Controller conflicts with the PDPL, it will notify the Controller before carrying it out.
- Nooks ensures that personnel and contractors authorized to access the data are bound by a duty of confidentiality.
6. Security Measures
Nooks applies the technical and organizational measures described in Section 6 of the Privacy Policy (TLS 1.2+ encryption, AES-256-GCM encryption of payment tokens and API keys, row-level access controls, daily backups).
7. Sub-Processors
The Controller authorizes Nooks to engage the sub-processors listed in Section 5 of the Privacy Policy (Supabase, Moyasar, Foodics, Corbit, Resend, Apple Push/Firebase, Vercel, Railway, Sentry, Mapbox). Nooks will notify the Controller at least 30 days before adding any new sub-processor, and the Controller may object within that period.
8. Assistance with Data Subject Requests
Nooks assists the Controller in responding to data subject requests (access, correction, deletion, objection, portability) within a reasonable period not exceeding 15 days of receiving the request from the Controller, enabling the Controller to respond to the customer within the PDPL’s 30-day window.
9. Personal Data Breach Notification
If Nooks discovers a personal data breach affecting the Controller’s customer data, it will notify the Controller within 72 hours of discovery, including details of the breach’s nature, the affected data, and remedial actions taken, enabling the Controller to meet its own obligations to SDAIA and affected customers.
10. Deletion & Return on Termination
Within 30 days of the service agreement ending, Nooks will delete deletable personal data or return it to the Controller upon request, anonymize order records (retained for accounting purposes without identifying data), and retain financial records for 7 years as required by ZATCA.
11. Cross-Border Transfers
Any transfer of data outside Saudi Arabia (for hosting or operation with sub-processors) is carried out under contractual clauses equivalent to SDAIA’s Standard Contractual Clauses, supported by documented transfer risk assessments, as described in Section 5 of the Privacy Policy.
12. Audit & Information Rights
With 30 days’ prior notice and no more than once per year, the Controller may request reasonable information from Nooks or conduct an audit (directly or via an independent third party bound by confidentiality) to verify Nooks’ compliance with this Addendum, during normal business hours and without disrupting the platform for other merchants.
13. Governing Law & Prevailing Language
This Addendum is governed by the laws of the Kingdom of Saudi Arabia. In case of any conflict between the Arabic and English versions, the Arabic version prevails.
14. Contact
For any question about this Addendum: privacy@nooks.space