This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the agreement between the customer (“Customer,” “you,” the Controller) and Sigmix (“Sigmix,” the Processor) for use of the Sigmix platform (the “Agreement”). It governs Sigmix’s processing of personal data on the Customer’s behalf and reflects the requirements of the Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
Roles and scope
For the Customer Personal Data described in Annex A, the Customer is the Controller and Sigmix is the Processor, processing only on the Customer’s documented instructions.
This DPA covers data the Customer submits to or processes through the modules — for example email recipient lists, survey respondents, meeting participants and recordings, chatbot/WhatsApp contacts, website-visitor data captured via the Website Builder, prompts and uploads, and CRM/contact data.
It does not cover data for which Sigmix is the controller (account, billing, security, and Sigmix’s own analytics) — that is governed by the Privacy Policy, not this DPA.
The Customer is responsible for the lawful basis to collect and process the Customer Personal Data, for any required notices and consents to data subjects, and for the lawfulness of its instructions.
Sigmix’s obligations as Processor
Sigmix will:
- Process only on documented instructions from the Customer (including those given through configuration and use of the Services), and as required by law — in which case Sigmix will inform the Customer unless legally prohibited.
- Not use Customer Personal Data for its own purposes, and not use it to train AI models. Module AI processing is performed for inference only, to deliver the Customer’s requested output.
- Ensure persons authorised to process the data are under a duty of confidentiality.
- Implement appropriate technical and organisational security measures (Annex C and Privacy Policy §10), appropriate to the risk.
- Respect the conditions in §4 for engaging sub-processors.
- Assist the Customer — taking into account the nature of processing and information available — in: responding to data-subject requests (§5); meeting security, breach-notification, and (where applicable) impact-assessment duties.
- Notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information the Customer reasonably needs to meet its own notification duties (including the 72-hour SDAIA timeline).
- On the Customer’s choice, delete or return Customer Personal Data at the end of the Services, and delete existing copies unless retention is required by law (§7).
- Make available information reasonably necessary to demonstrate compliance and allow for audits as set out in §6.
Customer’s obligations as Controller
The Customer will:
- Ensure it has a lawful basis and has given all required notices and obtained all required consents (including for marketing/messaging, recording of meetings, and tracking on websites it builds).
- Issue only lawful instructions and be responsible for the accuracy and legality of the Customer Personal Data.
- Not submit special-category/sensitive data or third-party data without a lawful basis and appropriate safeguards.
- Comply with its own duties as Controller under the PDPL, including handling data-subject requests for which it is responsible.
Sub-processors
The Customer provides general authorisation for Sigmix to engage sub-processors to deliver the Services. The current list is maintained at sigmix.ai/legal/subprocessors and includes the categories and providers set out in Annex B.
Sigmix imposes on each sub-processor data-protection obligations substantially equivalent to those in this DPA.
Sigmix will give the Customer reasonable notice of any intended addition or replacement of a sub-processor (for example, via the sub-processor page or email). If the Customer has a reasonable, data-protection-based objection, the parties will work in good faith to resolve it; if they cannot, the Customer may terminate the affected Service.
Sigmix remains responsible for its sub-processors’ performance of data-protection obligations.
Data-subject requests
If Sigmix receives a request from a data subject relating to Customer Personal Data (for example, a recipient on the Customer’s list, a survey respondent, or a meeting participant), Sigmix will not respond directly except to confirm it is a processor, and will refer or forward the request to the Customer without undue delay. Sigmix will provide reasonable assistance (including Service functionality) to help the Customer respond.
Audit
Sigmix will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow and contribute to audits, no more than once per year (unless required by a regulator or following a breach), on reasonable prior notice, during business hours, subject to confidentiality, and conducted so as not to disrupt Sigmix’s operations or other customers. Sigmix may satisfy audit requests by providing third-party certifications or reports where available.
Deletion and return
On termination or expiry of the Services, or on the Customer’s earlier written request, Sigmix will delete or return the Customer Personal Data and delete existing copies, except copies that must be retained by law (which remain subject to this DPA’s confidentiality and security terms) or that exist in routine backups, which are purged or anonymised on the normal backup cycle. Account/billing data that Sigmix holds as controller is retained per the Privacy Policy.
International transfers
Where Sigmix or a sub-processor processes Customer Personal Data outside the Kingdom of Saudi Arabia (see Annex B — for example, global AI inference, the email-delivery provider’s EU region, global meetings, and WhatsApp/Meta), it does so only as permitted by the PDPL transfer rules, with appropriate safeguards (such as SDAIA-approved standard contractual clauses) and, where required, a transfer risk assessment. KSA-sovereign / KSA-only options are available for several modules where the Customer requires in-Kingdom processing.
Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits liability that cannot be limited under KSA law.
Governing law, disputes, language
This DPA is governed by the laws of the Kingdom of Saudi Arabia, with disputes resolved as in the Agreement (SCCA arbitration, Riyadh, Arabic, for business customers). This DPA may be provided in English and Arabic; in case of conflict, the Arabic version prevails.
Annex A — Details of processing
- Subject-matter — Processing of Customer Personal Data to provide the Sigmix modules selected by the Customer
- Duration — For the term of the Agreement, plus deletion/return per §7
- Nature & purpose — Hosting, storage, transmission, AI inference, message delivery, meeting hosting, survey/chat capture, website hosting, and related processing to deliver the Services
- Categories of data subjects — The Customer’s contacts, recipients, leads, survey respondents, meeting participants, chatbot/website visitors, and other individuals the Customer processes through the Services
- Categories of personal data — Identifiers and contact details (name, email, phone), message and content data, meeting audio/video/transcripts (where enabled), survey responses, usage/interaction data, and any other personal data the Customer chooses to submit
- Special-category data — Not to be submitted without a lawful basis and safeguards; the Customer is responsible for any it submits
Annex B — Sub-processors (summary)
The current, versioned list is at sigmix.ai/legal/subprocessors. By category:
| Category | Provider(s) | Location |
|---|---|---|
| Hosting, database & storage | Oracle Cloud Infrastructure (Riyadh); self-hosted object storage | In-Kingdom |
| Payments | Paymob (swappable per partner) | In-Kingdom |
| E-invoicing | Qoyod | In-Kingdom |
| Email delivery | Amazon SES | Cross-border (EU) |
| AI inference (global) | Amazon Bedrock; Azure/OpenAI; Google; xAI | Cross-border |
| AI inference (KSA-sovereign) | Groq (Dammam); in-Kingdom GPU servers on Oracle, Google Cloud (Dammam), SCCC and Huawei | In-Kingdom |
| Real-time meetings (global) | Cloudflare Realtime | Cross-border |
| Messaging | WhatsApp / Meta | Cross-border |
| Analytics | Google Analytics (GA4) — see the current versioned list | Cross-border (as applicable) |
Annex C — Security measures (summary)
Encryption in transit and at rest; tenant isolation at database (row-level security) and application layers; separation of personal data into a dedicated, erasable user store (financial/tax ledgers carry only opaque IDs); role-based access control and least-privilege; authentication including OTP/MFA options; logging, monitoring, and audit trails; secure development practices; staff confidentiality obligations; and breach detection and response procedures aligned with relevant NCA controls.